OTL logfile created on: 2013-02-14 10:52:09 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Arturo\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 7,96 Gb Total Physical Memory | 6,13 Gb Available Physical Memory | 76,97% Memory free 15,92 Gb Paging File | 14,03 Gb Available in Paging File | 88,12% Paging File free Paging file location(s): c:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 119,14 Gb Total Space | 71,74 Gb Free Space | 60,21% Space Free | Partition Type: NTFS Drive D: | 74,41 Gb Total Space | 0,45 Gb Free Space | 0,61% Space Free | Partition Type: NTFS Drive F: | 6,86 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: ARTURO-KOMPUTER | User Name: Arturo | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-02-14 10:46:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Arturo\Desktop\OTL.exe PRC - [2013-02-08 00:36:26 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2013-02-07 14:31:10 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2013-02-07 14:30:43 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2013-02-07 14:30:42 | 000,385,248 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2013-02-07 12:04:08 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012-06-25 14:27:00 | 000,028,672 | ---- | M] () -- C:\Windows\SysWOW64\UMonit.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-02-07 12:03:57 | 003,023,256 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2012-06-25 14:27:00 | 000,028,672 | ---- | M] () -- C:\Windows\SysWOW64\UMonit.exe [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012-12-17 14:27:22 | 000,037,816 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp) SRV:[b]64bit:[/b] - [2012-08-03 06:27:50 | 000,027,792 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService) SRV:[b]64bit:[/b] - [2012-04-20 14:16:12 | 000,635,104 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R) SRV:[b]64bit:[/b] - [2010-09-22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:[b]64bit:[/b] - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2013-02-08 14:29:15 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013-02-08 00:36:26 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2013-02-07 14:31:10 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013-02-07 14:30:43 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2013-02-07 12:04:08 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013-02-05 14:09:51 | 000,541,608 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012-12-17 14:27:26 | 002,402,232 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc) SRV - [2012-12-17 14:27:24 | 000,030,136 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp) SRV - [2012-12-14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2012-09-01 18:07:22 | 000,014,904 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2012-07-25 18:58:26 | 000,126,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe -- (Te.Service) SRV - [2012-07-17 14:57:22 | 000,365,376 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2012-07-17 14:57:20 | 000,277,824 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2012-06-25 10:57:14 | 000,166,720 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service) SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard) DRV:[b]64bit:[/b] - [2012-12-14 02:42:22 | 005,353,888 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:[b]64bit:[/b] - [2012-12-13 16:24:10 | 000,342,528 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) DRV:[b]64bit:[/b] - [2012-12-03 15:36:36 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:[b]64bit:[/b] - [2012-12-03 15:36:35 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:[b]64bit:[/b] - [2012-11-16 20:17:15 | 000,027,800 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr) DRV:[b]64bit:[/b] - [2012-09-01 18:01:56 | 000,647,736 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA) DRV:[b]64bit:[/b] - [2012-09-01 18:01:56 | 000,028,216 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF) DRV:[b]64bit:[/b] - [2012-08-23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2012-08-23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2012-08-03 06:27:44 | 002,206,352 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService) DRV:[b]64bit:[/b] - [2012-07-17 18:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:[b]64bit:[/b] - [2012-07-06 13:50:36 | 000,060,928 | ---- | M] (GenesysLogic) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GeneStor.sys -- (GeneStor) DRV:[b]64bit:[/b] - [2012-05-30 10:27:32 | 000,210,944 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ViaHub3.sys -- (VUSB3HUB) DRV:[b]64bit:[/b] - [2012-05-30 10:27:26 | 000,261,120 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xhcdrv.sys -- (xhcdrv) DRV:[b]64bit:[/b] - [2012-05-14 07:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:[b]64bit:[/b] - [2012-04-25 08:07:18 | 000,104,560 | ---- | M] (Qualcomm Atheros Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) DRV:[b]64bit:[/b] - [2012-03-27 01:13:20 | 000,789,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc) DRV:[b]64bit:[/b] - [2012-03-27 01:13:20 | 000,356,632 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub) DRV:[b]64bit:[/b] - [2012-03-27 01:13:18 | 000,019,224 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs) DRV:[b]64bit:[/b] - [2012-03-08 18:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:[b]64bit:[/b] - [2012-03-01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2012-02-01 16:16:40 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2011-08-09 06:42:36 | 000,315,696 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mvs91xx.sys -- (mvs91xx) DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-11-20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2013-02-08 01:03:19 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv) DRV - [2012-09-19 10:50:50 | 000,011,880 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv) DRV - [2011-06-02 10:08:34 | 000,017,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys -- (cpudrv64) DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com.vn IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.myplaycity.com/ IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com.vn IE - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.myplaycity.com/ IE - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\..\SearchScopes,DefaultScope = {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} IE - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://home.myplaycity.com/results.php?category=web&s={searchTerms} IE - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..Keyword.Enabled: "true" FF - prefs.js..browser.search.selectedEngine: "MyPlayCity" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.google.pl/" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2 FF - prefs.js..keyword.URL: "http://home.myplaycity.com/results.php?category=web&s=" FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll () FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: E:\Uplay\Ubisoft Game Launcher\npuplaypc.dll File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013-02-07 12:04:08 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013-01-28 17:02:25 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013-02-07 12:04:08 | 000,000,000 | ---D | M] [2013-01-28 14:17:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Arturo\AppData\Roaming\mozilla\Extensions [2013-02-08 20:27:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Arturo\AppData\Roaming\mozilla\Firefox\Profiles\sqrs4gef.default\extensions [2013-01-30 09:33:35 | 000,000,000 | ---D | M] (Better Battlelog (BBLog)) -- C:\Users\Arturo\AppData\Roaming\mozilla\Firefox\Profiles\sqrs4gef.default\extensions\jid1-qQSMEVsYTOjgYA@jetpack [2013-02-08 20:27:26 | 000,817,973 | ---- | M] () (No name found) -- C:\Users\Arturo\AppData\Roaming\mozilla\firefox\profiles\sqrs4gef.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-02-07 12:03:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013-02-07 12:04:08 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2013-01-17 01:46:35 | 000,002,767 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml [2013-01-17 01:46:35 | 000,001,406 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml [2013-01-17 01:46:35 | 000,000,917 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml [2013-01-17 01:46:35 | 000,000,858 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml [2013-01-17 01:46:35 | 000,001,183 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml [2013-01-17 01:46:35 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2013-02-05 22:18:20 | 000,000,762 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [UMonit] C:\Windows\SysWOW64\UMonit.exe () O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation) O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 1 O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1 = rund1132.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2 = m5vbvm60.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 3 = Unoccupied.reg O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 4 = Regedit32.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 5 = Shell32.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 6 = dllchache.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 7 = services_test.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 8 = New Folder.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 9 = systemio.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 10 = JK.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 11 = rundl132.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 12 = Logo1_.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 13 = RichDll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 14 = loveRabbit.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 15 = msexch400.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 16 = Rabbit.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 17 = aut0exec.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 18 = ntde1ect.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 19 = Mixa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 20 = apvo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 21 = expressav.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 22 = apv0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 23 = l33na.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 24 = ed.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 25 = spooisv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 26 = rttrwq.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 27 = _use.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 28 = 11-00.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 29 = wmibus.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 30 = wmisys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 31 = Normal.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 32 = execute.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 33 = leena.job O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 34 = leena.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 35 = aneel.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 36 = wuauc1t.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 37 = Win32dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 38 = Win32.dll.vbs O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 39 = SteamDll32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 40 = WinSteam.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 41 = SteamHelper.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 42 = kavo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 43 = spoclsv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 44 = dfqnabib.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 45 = sfsxachu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 46 = stjxakin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 47 = tjfyabyt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 48 = kdaic.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 49 = zsdjabmp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 50 = lpmxajkl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 51 = dfqnabib.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 52 = WINLOG0N.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 53 = SVCH0ST.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 54 = System.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 55 = phim nguoi lon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 56 = password_viewer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 57 = SVCHOST555.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 58 = inst_vinh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 59 = Bro_Act.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 60 = braviax.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 61 = CbEvtSvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 62 = MySexy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 63 = msconfig.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 64 = regedit.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 65 = default__.pif O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 66 = jvosoft.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 67 = 9sky8pia.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 68 = amvo0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 69 = lphc9dkj0ec6a.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 70 = rhcahej0ej6v.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 71 = chiCkie.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 72 = ExeServ.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 73 = Av-Prev.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 74 = ati2avxx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 75 = Sex Picture.scr O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 77 = comine.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 78 = autochl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 79 = log.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 80 = comboClt.ocx.vbs O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 81 = Sos.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 82 = kxvo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 83 = zz.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 84 = lsasss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 85 = order.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 86 = Flashy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 87 = meex.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 88 = xibgptd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 89 = xmjisnw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 90 = asd0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 91 = windowsupd2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 92 = winhost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 93 = quicken.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 94 = editpad.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 95 = nwonknu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 96 = rasrun.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 97 = psdrv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 98 = svci.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 99 = unknown.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 100 = castlecops[1].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 101 = 1014[1].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 102 = is[1].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 103 = wcs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 104 = Sizhu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 105 = ibrv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 106 = vgguxso.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 107 = uitxjwa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 108 = loadam.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 109 = sunny.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 110 = etialof.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 111 = sdjxeqi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 112 = tsnqtjn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 113 = dluxde.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 114 = Soft0 O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 115 = 1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 116 = 10.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 117 = SVOHOST.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 118 = sxs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 119 = phimnguoilon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 120 = amvo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 121 = n1deiect.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 122 = qwc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 123 = tknn6.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 124 = 6l6w8.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 125 = hay.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 126 = more.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 127 = nontay.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 128 = boom.vbs O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 129 = drivers.cab.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 130 = KEYBOARD.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 131 = Global.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 132 = jdbgmgr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 133 = secret.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 134 = xdict.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 135 = algssl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 136 = phimhot.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 137 = other.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 138 = fun.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 139 = winsit.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 140 = sal.xls.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 141 = msfir80.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 142 = .exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 143 = MSconfigg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 144 = servics.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 145 = expl0rer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 146 = tel.xls.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 147 = funni.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 148 = kvosoft.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 149 = 4.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 150 = 2008.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 151 = folder.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 152 = knx32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 153 = Mixa_I.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 154 = Fuck.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 155 = Happy99.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 156 = SKA.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 157 = sysmgr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 158 = Mixa_1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 159 = skynet.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 160 = Isass.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 161 = 8out.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 162 = lotto.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 163 = ieav.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 164 = win32.host.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 165 = osgjaaj.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 166 = info.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 167 = ads.jpg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 168 = CKVO.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 169 = a2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 170 = rundii32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 171 = cd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 172 = ph.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 173 = winivstr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 174 = Default.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 175 = NTDETECH.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 176 = l63snn8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 177 = svhost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 178 = svchot.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 179 = svch0t.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 180 = svh0st.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 181 = my_80004.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 182 = explorcr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 183 = admin6_ver0424.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 184 = yeSetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 185 = dodolook591.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 186 = alexa240.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 187 = 1072.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 188 = atmpvcno.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 189 = atmlib.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 190 = musica.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 191 = ...exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 192 = ..exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 193 = crack.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 194 = dwintl.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 195 = explorer.zip.scr O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 196 = pictures.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 197 = readme.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 198 = 12520437.cpx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 199 = 12520850.cpx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 200 = 3com_dmi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 201 = 6to4svc.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 202 = access.cpl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 203 = acctres.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 204 = acelpdec.ax.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 205 = acledit.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 206 = aclui.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 207 = activeds.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 208 = activeds.tlb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 209 = actxprxy.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 210 = admparse.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 211 = adodc.srg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 212 = adptif.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 213 = adsldp.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 214 = adsldpc.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 215 = adsmsext.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 216 = adsnds.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 217 = adsnt.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 218 = adsnw.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 219 = advapi32.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 220 = advpack.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 221 = alrsvc.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 222 = amcompat.tlb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 223 = amstream.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 224 = ansi.sys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 225 = apcups.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 226 = apphelp.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 227 = appmgmts.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 228 = appmgr.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 229 = appwiz.cpl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 230 = asctrls.ocx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 231 = asferror.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 232 = asycfilt.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 233 = atkctrs.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 234 = atl.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 235 = atmfd.dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 236 = 100.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 237 = 101.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 238 = 102.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 239 = 103.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 240 = 104.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 241 = 105.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 242 = 106.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 243 = 107.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 244 = 108.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 245 = 109.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 246 = 11.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 247 = 110.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 248 = 111.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 249 = 112.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 250 = 113.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 251 = 114.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 252 = 115.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 253 = 116.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 254 = 117.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 255 = 118.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 256 = 119.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 257 = 12.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 258 = 120.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 259 = 122.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 260 = 123.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 261 = 124.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 262 = 125.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 263 = blastk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 264 = 126.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 265 = 127.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 266 = 128.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 267 = 129.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 268 = 13.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 269 = 130.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 270 = 131.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 271 = 132.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 272 = 133.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 273 = 134.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 274 = 135.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 275 = 136.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 276 = 137.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 277 = 138.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 278 = 139.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 279 = 14.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 280 = 140.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 281 = 141.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 282 = 142.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 283 = 143.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 284 = 144.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 285 = 145.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 286 = 146.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 287 = 147.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 288 = 148.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 289 = 149.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 290 = 15.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 291 = 150.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 292 = 151.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 293 = 152.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 294 = 153.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 295 = 154.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 296 = 155.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 297 = 156.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 298 = 157.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 299 = 158.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 300 = 159.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 301 = 16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 302 = 160.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 303 = 161.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 304 = 162.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 305 = 163.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 306 = 164.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 307 = 165.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 308 = 166.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 309 = 167.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 310 = 168.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 311 = 169.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 312 = 17.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 313 = 170.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 314 = 171.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 315 = 172.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 316 = 173.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 317 = 174.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 318 = 175.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 319 = 176.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 320 = 177.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 321 = 178.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 322 = 179.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 323 = 18.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 324 = 180.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 325 = 181.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 326 = 182.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 327 = 183.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 328 = 184.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 329 = 185.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 330 = 186.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 331 = 187.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 332 = 188.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 333 = 189.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 334 = 19.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 335 = 190.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 336 = 191.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 337 = 192.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 338 = 193.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 339 = 194.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 340 = 195.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 341 = 196.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 342 = 197.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 343 = 198.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 344 = 199.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 345 = 20.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 346 = 21.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 347 = 22.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 348 = 23.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 349 = 24.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 350 = 25.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 351 = 26.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 352 = 27.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 353 = 28.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 354 = 29.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 355 = 3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 356 = 30.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 357 = 1000.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 358 = 1001.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 359 = 1002.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 360 = 1003.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 361 = 1004.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 362 = 1005.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 363 = 1006.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 364 = 1007.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 365 = 1008.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 366 = 1009.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 367 = 1010.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 368 = 1011.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 369 = 1012.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 370 = 1013.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 371 = 1014.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 372 = 1015.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 373 = 1016.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 374 = 1017.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 375 = 1018.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 376 = 1019.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 377 = 1020.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 378 = 1021.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 379 = 1022.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 380 = 1023.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 381 = 1024.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 382 = 1025.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 383 = 1026.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 384 = 1027.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 385 = 1028.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 386 = 1029.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 387 = 1030.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 388 = 1031.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 389 = 1032.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 390 = 1033.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 391 = 1034.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 392 = 1035.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 393 = 1036.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 394 = 1037.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 395 = 1038.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 396 = 1039.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 397 = 1040.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 398 = 1041.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 399 = 1042.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 400 = 1043.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 401 = 1044.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 402 = 1045.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 403 = 1046.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 404 = 1047.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 405 = 1048.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 406 = 1049.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 407 = 1050.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 408 = 1051.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 409 = 1052.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 410 = 1053.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 411 = 1054.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 412 = 1055.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 413 = 1056.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 414 = 1057.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 415 = 1058.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 416 = 1059.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 417 = 1060.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 418 = 1061.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 419 = 1062.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 420 = 1063.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 421 = 1064.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 422 = 1065.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 423 = 1066.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 424 = 1067.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 425 = 1068.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 426 = 1069.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 427 = 1070.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 428 = 1071.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 429 = 1072.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 430 = 1073.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 431 = 1074.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 432 = 1075.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 433 = 1076.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 434 = 1077.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 435 = 1078.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 436 = 1079.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 437 = 1080.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 438 = 1081.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 439 = 1082.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 440 = 1083.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 441 = 1084.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 442 = 1085.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 443 = 1086.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 444 = 1087.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 445 = 1088.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 446 = 1089.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 447 = 1090.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 448 = 1091.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 449 = 1092.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 450 = 1093.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 451 = 1094.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 452 = 1095.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 453 = 1096.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 454 = 1097.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 455 = 1099.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 456 = 6307.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 457 = 6308.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 458 = 6309.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 459 = 6310.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 460 = 6311.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 461 = 6312.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 462 = 6314.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 463 = 6313.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 464 = 6315.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 465 = 6316.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 466 = 6317.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 467 = 6318.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 468 = 6319.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 469 = 6320.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 470 = 6321.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 471 = 6322.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 472 = 6323.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 473 = 6324.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 474 = 6325.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 475 = 6326.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 476 = 6327.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 477 = 6328.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 478 = 6329.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 479 = 6330.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 480 = 6331.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 481 = 6332.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 482 = 6333.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 483 = 6334.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 484 = 6335.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 485 = 6336.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 486 = 6337.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 487 = 6338.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 488 = 6339.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 489 = 6340.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 490 = 6341.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 491 = 6342.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 492 = 6343.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 493 = 6344.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 494 = 6345.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 495 = 6346.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 496 = 6347.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 497 = 6348.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 498 = 6349.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 499 = 6350.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 500 = 6351.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 501 = 6352.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 502 = 6353.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 503 = 6354.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 504 = 6355.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 505 = 6356.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 506 = 6357.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 507 = 6358.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 508 = 6359.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 509 = 6360.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 510 = 6361.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 511 = 6362.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 512 = 6363.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 513 = 6364.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 514 = 6365.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 515 = 6366.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 516 = 6367.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 517 = 6369.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 518 = 6368.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 519 = 6370.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 520 = 6371.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 521 = 6372.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 522 = 6373.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 523 = 6374.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 524 = 6375.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 525 = 6376.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 526 = 6377.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 527 = 6378.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 528 = 6379.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 529 = 6380.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 530 = 6381.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 531 = 6382.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 532 = 6383.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 533 = 6384.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 534 = 6385.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 535 = 6386.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 536 = 6387.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 537 = 6388.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 538 = 6389.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 539 = 6390.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 540 = 6391.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 541 = 6392.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 542 = 6393.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 543 = 6394.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 544 = 6395.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 545 = 6396.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 546 = 6397.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 547 = 6398.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 548 = 6399.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 549 = 6400.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 550 = 6401.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 551 = 6402.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 552 = 6403.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 553 = 6404.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 554 = 6405.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 555 = 6406.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 556 = 6407.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 557 = regfixxsx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 558 = documents.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 559 = favorites.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 560 = ernsjyi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 561 = jjcmdrj.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 562 = nheste.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 563 = nxmwp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 564 = rwmgh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 565 = tbljxjk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 566 = vohth.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 567 = vvpmyvaw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 568 = aa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 569 = _cw0srv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 570 = links.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 571 = serivces01.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 572 = serivces05.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 573 = sruninstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 574 = serivcesb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 575 = serivcesf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 576 = servcies04.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 577 = jxzub5410451.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 578 = chert5-998.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 579 = kernel1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 580 = beep.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 581 = iexpl0re.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 582 = crasos.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 583 = cmdbcs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 584 = realschd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 585 = wsvbs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 586 = msdccrt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 587 = run1132.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 588 = sysload3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 589 = tempicon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 590 = sysbmw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 591 = rpcs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 592 = msvce32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 593 = svhost32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 594 = internat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 595 = ctmontv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 596 = ncscv32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 597 = spo0lsv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 598 = wdfmgr32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 599 = upxdnd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 600 = ssopure.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 601 = c0nime.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 602 = nvscv32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 603 = fuckjacks.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 604 = lying.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 605 = jbele1.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 606 = vt2n8re.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 607 = 0011E924.vbs O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 608 = 672.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 609 = ciygje.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 610 = kmbbvua.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 611 = mkqn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 612 = pajto.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 613 = rbgc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 614 = rs32net.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 615 = vbmwi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 616 = wfthnpkw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 617 = wsxyguvs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 618 = servcies9.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 619 = servciesa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 620 = servciesaa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 621 = Vxl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 622 = ~.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 623 = YUR7.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 624 = YUR8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 625 = YUR9.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 626 = YURA.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 627 = Rapid Antivirus.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 628 = zPharoh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 629 = winiguard.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 630 = zPharaoh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 631 = lphcns0j0e1av.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 632 = serverx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 633 = Sulfnbk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 634 = 11122oo7.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 635 = newfolder.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 636 = qq.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 637 = 75976W.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 638 = 75976L.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 639 = brastk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 640 = lky.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 641 = whi.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 642 = sq.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 643 = kamsoft.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 644 = rs32net.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 645 = Gool.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 646 = brnu492.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 647 = apipr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 648 = apiph32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 649 = BNH1.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 650 = ce1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 651 = dq1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 652 = purger.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 653 = s-1-5-21.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 654 = lockbar.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 655 = aa0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 755 = zip0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 855 = soft0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 656 = aa1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 756 = zip1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 856 = soft1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 657 = aa2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 757 = zip2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 857 = soft2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 658 = aa3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 758 = zip3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 858 = soft3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 659 = aa4.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 759 = zip4.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 859 = soft4.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 660 = aa5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 760 = zip5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 860 = soft5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 661 = aa6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 761 = zip6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 861 = soft6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 662 = aa7.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 762 = zip7.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 862 = soft7.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 663 = aa8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 763 = zip8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 863 = soft8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 664 = aa9.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 764 = zip9.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 864 = soft9.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 665 = aa10.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 765 = zip10.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 865 = soft10.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 666 = aa11.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 766 = zip11.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 866 = soft11.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 667 = aa12.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 767 = zip12.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 867 = soft12.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 668 = aa13.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 768 = zip13.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 868 = soft13.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 669 = aa14.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 769 = zip14.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 869 = soft14.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 670 = aa15.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 770 = zip15.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 870 = soft15.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 671 = aa16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 771 = zip16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 871 = soft16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 672 = aa17.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 772 = zip17.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 872 = soft17.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 673 = aa18.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 773 = zip18.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 873 = soft18.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 674 = aa19.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 774 = zip19.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 874 = soft19.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 675 = aa20.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 775 = zip20.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 875 = soft20.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 676 = aa21.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 776 = zip21.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 876 = soft21.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 677 = aa22.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 777 = zip22.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 877 = soft22.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 678 = aa23.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 778 = zip23.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 878 = soft23.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 679 = aa24.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 779 = zip24.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 879 = soft24.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 680 = aa25.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 780 = zip25.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 880 = soft25.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 681 = aa26.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 781 = zip26.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 881 = soft26.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 682 = aa27.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 782 = zip27.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 882 = soft27.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 683 = aa28.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 783 = zip28.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 883 = soft28.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 684 = aa29.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 784 = zip29.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 884 = soft29.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 685 = aa30.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 785 = zip30.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 885 = soft30.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 686 = aa31.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 786 = zip31.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 886 = soft31.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 687 = aa32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 787 = zip32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 887 = soft32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 688 = aa33.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 788 = zip33.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 888 = soft33.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 689 = aa34.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 789 = zip34.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 889 = soft34.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 690 = aa35.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 790 = zip35.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 890 = soft35.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 691 = aa36.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 791 = zip36.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 891 = soft36.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 692 = aa37.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 792 = zip37.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 892 = soft37.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 693 = aa38.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 793 = zip38.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 893 = soft38.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 694 = aa39.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 794 = zip39.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 894 = soft39.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 695 = aa40.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 795 = zip40.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 895 = soft40.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 696 = aa41.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 796 = zip41.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 896 = soft41.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 697 = aa42.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 797 = zip42.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 897 = soft42.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 698 = aa43.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 798 = zip43.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 898 = soft43.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 699 = aa44.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 799 = zip44.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 899 = soft44.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 700 = aa45.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 800 = zip45.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 900 = soft45.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 701 = aa46.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 801 = zip46.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 901 = soft46.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 702 = aa47.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 802 = zip47.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 902 = soft47.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 703 = aa48.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 803 = zip48.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 903 = soft48.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 704 = aa49.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 804 = zip49.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 904 = soft49.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 705 = aa50.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 805 = zip50.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 905 = soft50.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 706 = aa51.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 806 = zip51.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 906 = soft51.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 707 = aa52.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 807 = zip52.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 907 = soft52.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 708 = aa53.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 808 = zip53.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 908 = soft53.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 709 = aa54.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 809 = zip54.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 909 = soft54.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 710 = aa55.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 810 = zip55.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 910 = soft55.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 711 = aa56.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 811 = zip56.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 911 = soft56.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 712 = aa57.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 812 = zip57.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 912 = soft57.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 713 = aa58.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 813 = zip58.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 913 = soft58.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 714 = aa59.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 814 = zip59.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 914 = soft59.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 715 = aa60.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 815 = zip60.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 915 = soft60.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 716 = aa61.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 816 = zip61.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 916 = soft61.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 717 = aa62.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 817 = zip62.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 917 = soft62.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 718 = aa63.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 818 = zip63.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 918 = soft63.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 719 = aa64.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 819 = zip64.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 919 = soft64.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 720 = aa65.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 820 = zip65.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 920 = soft65.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 721 = aa66.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 821 = zip66.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 921 = soft66.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 722 = aa67.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 822 = zip67.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 922 = soft67.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 723 = aa68.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 823 = zip68.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 923 = soft68.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 724 = aa69.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 824 = zip69.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 924 = soft69.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 725 = aa70.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 825 = zip70.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 925 = soft70.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 726 = aa71.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 826 = zip71.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 926 = soft71.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 727 = aa72.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 827 = zip72.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 927 = soft72.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 728 = aa73.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 828 = zip73.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 928 = soft73.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 729 = aa74.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 829 = zip74.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 929 = soft74.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 730 = aa75.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 830 = zip75.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 930 = soft75.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 731 = aa76.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 831 = zip76.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 931 = soft76.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 732 = aa77.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 832 = zip77.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 932 = soft77.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 733 = aa78.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 833 = zip78.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 933 = soft78.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 734 = aa79.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 834 = zip79.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 934 = soft79.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 735 = aa80.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 835 = zip80.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 935 = soft80.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 736 = aa81.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 836 = zip81.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 936 = soft81.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 737 = aa82.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 837 = zip82.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 937 = soft82.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 738 = aa83.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 838 = zip83.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 938 = soft83.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 739 = aa84.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 839 = zip84.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 939 = soft84.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 740 = aa85.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 840 = zip85.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 940 = soft85.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 741 = aa86.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 841 = zip86.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 941 = soft86.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 742 = aa87.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 842 = zip87.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 942 = soft87.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 743 = aa88.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 843 = zip88.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 943 = soft88.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 744 = aa89.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 844 = zip89.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 944 = soft89.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 745 = aa90.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 845 = zip90.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 945 = soft90.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 746 = aa91.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 846 = zip91.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 946 = soft91.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 747 = aa92.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 847 = zip92.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 947 = soft92.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 748 = aa93.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 848 = zip93.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 948 = soft93.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 749 = aa94.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 849 = zip94.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 949 = soft94.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 750 = aa95.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 850 = zip95.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 950 = soft95.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 751 = aa96.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 851 = zip96.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 951 = soft96.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 752 = aa97.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 852 = zip97.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 952 = soft97.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 753 = aa98.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 853 = zip98.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 953 = soft98.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 754 = aa99.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 854 = zip99.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 954 = soft99.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 955 = $sys$drv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 956 = $sys$sos$sys$.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 957 = $sys$xp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 958 = ~565.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 959 = 0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 960 = 004.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 961 = 005.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 962 = 006.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 963 = 007.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 964 = 007ssinstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 965 = 008.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 966 = 009.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 968 = 01logo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 969 = 04s28lat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 970 = 06qytm1a.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 971 = 09857728.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 972 = 1004270.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 973 = 1054571.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 974 = 11421604.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 975 = 123bar.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 976 = 123hiddensender.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 977 = 12nail.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 978 = 14hi1qs8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 979 = 17131762.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 980 = 180ax.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 981 = 180pack6480.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 982 = 180sa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 983 = 180sainstallernusac.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 984 = 180stuninstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 985 = 1lyu2k.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 986 = 1o32cwjn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 987 = 2.sfx.exe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 988 = 2005.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 989 = 202_app13.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 990 = 26-593.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 991 = 29904603.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 992 = 2search.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 993 = 302v2fp0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 994 = 39987557.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 995 = 50cent.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 996 = 53648356.svd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 997 = 5thkf354.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 998 = 63de0cc3d01 O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 999 = 63mm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1000 = 666.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1001 = 66978039.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1002 = 69254441.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1003 = 9spj1iiq.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1004 = a_clearsearch.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1005 = a0011142.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1006 = a006.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1007 = a006.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1008 = a0067423.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1009 = a0067428.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1010 = a64sddd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1011 = abg-aceh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1012 = abox.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1013 = abs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1014 = absr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1015 = access members area.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1016 = access.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1017 = accwizz.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1018 = acespy331t.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1019 = aclservice.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1020 = aconti.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1021 = actalert.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1022 = activeds.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1023 = activeplus.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1024 = activex_300_it.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1025 = actualspy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1026 = actx1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1027 = ad.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1028 = adaware.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1029 = adl_mteststub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1030 = adlinstallwin32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1031 = adm4005.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1032 = admanctl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1033 = admilliserv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1034 = admlib32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1035 = adobe_flash.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1036 = adobes.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1037 = adp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1038 = adsetup.silent.1.13.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1039 = adstatserv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1040 = adtech2006.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1041 = adupdater.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1042 = adv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1043 = advapi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1044 = adx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1045 = ahadp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1046 = aim spy plugin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1047 = ajrpbi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1048 = alchem.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1049 = alevir.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1050 = alp2plib.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1051 = amero.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1052 = amp2pl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1053 = angelex.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1054 = anti_troj.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1055 = antiav.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1056 = antispy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1058 = antivirus32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1059 = aocbhm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1060 = aornum.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1061 = ap0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1062 = ap2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1063 = apd123.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1064 = app.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1065 = appsetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1066 = aq3hel~1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1067 = archive.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1068 = arr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1070 = arupld32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1071 = asd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1072 = asearchassist.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1073 = asm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1074 = asmonitor.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1075 = astart.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1076 = atipta.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1078 = atmsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1079 = aupdate_uninstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1080 = aurora(1).exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1081 = aurora.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1082 = aurora-wise1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1083 = ause3-decoded.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1084 = ausvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1085 = autoexec.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1086 = automove.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1087 = autoupdatev2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1088 = aux32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1089 = av.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1090 = avghalsb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1091 = avserve.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1092 = avserve2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1093 = b2search_v17.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1094 = backdoor.prorat.13.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1095 = backdoor.prorat.13_(57).exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1096 = backup-20040105-225929-414.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1097 = backweb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1098 = banmanpro.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1099 = bargain3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1100 = bargain4.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1101 = bargainbuddy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1102 = bargains.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1103 = basfipm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1104 = bazzi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1105 = bb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1106 = bbchk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1107 = bbfbeola.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1108 = bbi8015.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1109 = bbi8018.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1110 = bbi8032.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1111 = bbntqcbw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1112 = bboy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1113 = bdrqbac.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1114 = bedo9iz1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1115 = belt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1116 = berasjatah.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1117 = beta.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1118 = bhp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1119 = bhsv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1120 = bi5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1121 = bifrost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1122 = bil.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1123 = bindshell.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1124 = bionet.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1125 = bk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1126 = block-checker.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1127 = blondes.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1128 = bloodhound.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1129 = blss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1130 = bman.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1131 = bml8pjp7.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1133 = bokja.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1134 = bookedspace.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1135 = boot.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1136 = bootconf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1137 = bot.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1138 = bp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1139 = bpc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1140 = safesys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1141 = bpsinstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1142 = brasil.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1143 = brengkolang.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1144 = bronstab.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1145 = bsoft.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1146 = buddy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1147 = bugsfix.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1148 = bundle.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1149 = bundle~1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1150 = bundleouter.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1151 = bundleouter2501031120.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1152 = bundleouter2601031121.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1153 = bundles.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1154 = bundles118.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1155 = bxproxy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1156 = camviewer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1157 = card.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1158 = cartao.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1159 = cas2stub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1160 = casclient.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1162 = cb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1163 = cc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1164 = cd_install.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1165 = cd_install_291.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1166 = cd_load.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1167 = cd5a8b2bd01 O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1168 = cdaengine O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1169 = cdaengine0500 O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1170 = cdf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1171 = cds.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1172 = cdsm32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1173 = cfgmgr52.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1174 = cfmon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1175 = cg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1176 = cgtask.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1177 = check.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1178 = checkreg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1179 = checkup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1180 = chkntsv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1181 = chkras.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1182 = choke.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1183 = chq7gv5g.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1184 = cisvvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1185 = cjqxe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1186 = ckusdll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1187 = clbcatex.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1188 = client.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1189 = clientax.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1190 = cm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1191 = cmappsetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1193 = cmd32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1194 = cmdinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1195 = cmesys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1196 = cmeupd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1197 = cmman.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1198 = cmqcemmpm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1199 = cmrsr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1200 = cmrss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1201 = cmsystem.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1202 = cnqmax.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1203 = codecsetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1204 = comctl_32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1205 = commando.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1206 = conscorr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1207 = consol32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1208 = cool.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1209 = copy of optimize.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1210 = corpstats.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1211 = cp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1212 = cpanel.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1213 = cpr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1214 = crackserver-service.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1215 = crmss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1216 = crss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1217 = crsss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1218 = cryptfg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1219 = csaolinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1220 = csaolldr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1221 = csbiinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1222 = csieinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1223 = csmsv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1224 = csrcs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1225 = csrdeu32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1226 = csrrs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1227 = csrs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1228 = csrsc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1229 = csrse.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1230 = csrss32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1231 = ctfmon32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1232 = cucu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1233 = cxq8ojka.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1234 = cxtpls.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1235 = cydoor.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1236 = cydoor_uninstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1237 = cz.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1238 = czncin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1239 = d.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1240 = d6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1241 = data2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1242 = data3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1243 = datemanager.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1244 = dbaccess.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1245 = dc1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1246 = dc37.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1247 = dc38.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1248 = dc39.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1249 = dc42.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1250 = dc43.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1251 = dc44.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1252 = dc82.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1253 = dc83.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1254 = dc84.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1255 = dc85.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1256 = dc86.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1257 = dcomcfg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1258 = dcomx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1259 = ddcman.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1260 = dealhelper.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1261 = delmsbb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1262 = deskadkeep.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1263 = deskadserv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1264 = desktop.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1265 = dfe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1266 = dfrgsrv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1267 = dgwojz0h.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1268 = dhbrwsr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1269 = dho.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1270 = dhupdt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1271 = dial.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1272 = dinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1273 = dioxin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1274 = directs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1275 = directx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1276 = directxset.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1277 = disp1150.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1278 = display.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1279 = divx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1280 = dlgli.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1281 = dlhost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1282 = dll32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1283 = dllreg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1284 = dmserver.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1285 = dodrrr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1286 = down.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1287 = download.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1288 = downloadplus.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1289 = dp-b23011805.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1290 = dpul6zoa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1291 = dr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1292 = dr_s.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1293 = drpmon(1).exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1294 = drpmon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1295 = drv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1296 = drvddll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1297 = drwtsn16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1298 = ds.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1299 = dscbtshl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1300 = dssagent.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1301 = dtloader.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1302 = duel.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1303 = dun.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1304 = dvbern.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1305 = dvchost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1306 = dvdkeyauth.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1307 = dvldr32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1308 = dvwnhd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1309 = dw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1310 = dwcg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1311 = dwe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1312 = dwnupdt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1313 = usbautotuner.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1314 = dxnf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1315 = e85b8fb2d01.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1316 = easy.windows.monitoring.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1317 = easyav.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1318 = ecodec.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1319 = edit server.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1320 = ee.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1321 = ee1a8f91d01.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1322 = ee248fa7d01.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1323 = eeea8fa3d01.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1324 = eeef8fa2d01.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1325 = eetu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1326 = eksplorasi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1327 = elos.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1328 = eml.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1329 = emsw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1330 = enbiei.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1331 = enuubwafo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1332 = epswad4.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1333 = errorguard.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1334 = ers.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1335 = ersvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1336 = escan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1337 = esyndicateinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1338 = evr8gkxb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1339 = exchng32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1340 = exclean.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1341 = exdl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1342 = exec.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1343 = exp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1344 = expl32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1345 = explore.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1346 = explored.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1347 = exploreff.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1348 = explorer32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1349 = explorere.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1350 = exul.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1351 = ezinstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1352 = ezpopstub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1353 = ezstub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1354 = ezstub22.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1355 = ezulumain.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1356 = f3403484.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1357 = f4bbfeaed01 O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1358 = farmmext.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1359 = fash.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1360 = fasterxp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1361 = fbi_facebook.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1362 = fc.exe (Microsoft Corporation) O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1363 = fixtitle.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1364 = fjdbfvk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1365 = flashtalk-wise1000.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1366 = fntldr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1367 = fontloader.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1368 = fontview.exe (Microsoft Corporation) O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1369 = formulario.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1370 = fph.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1371 = fqc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1372 = freexxx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1373 = frsk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1374 = fservice.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1375 = fsg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1376 = fsg_4104.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1377 = fsjyhc5r.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1378 = fsw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1379 = fullgames.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1380 = fuwxenc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1381 = fvprotect.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1382 = g181511.a.stub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1383 = g4eyp3kf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1384 = gaedzsxe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1385 = gah95on6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1386 = gain_trickler_3102.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1387 = gain_trickler_3202.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1388 = my music.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1389 = gateway.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1390 = gator.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1391 = gatorstubsetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1392 = get.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1394 = getbuys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1395 = gfjgj.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1396 = ghost.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1397 = ginst_001_1234_4201.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1398 = gld.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1399 = glf2fglf2f.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1400 = gm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1401 = gmt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1402 = gogoaddisplay.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1403 = gogoaddressbar.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1404 = gogofileshare.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1405 = gogotoolbar.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1406 = gogotools.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1407 = gogotools0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1408 = gogotoolsinstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1409 = gsohy92a.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1410 = gstartup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1411 = szace.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1412 = guninstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1413 = h2g140n1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1414 = hacker.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1415 = haiyang.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1416 = hbinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1417 = hbtv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1418 = heat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1419 = hellmsn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1420 = helpexp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1421 = hgfedcba.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1422 = hgqhp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1423 = hhs32.pif O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1424 = hidden32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1425 = hidedown.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1426 = hidr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1427 = hloader.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1428 = hnm_svc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1429 = hookdump.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1430 = host.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1431 = hot.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1432 = hot_tarts_mc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1433 = hprog.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1434 = hro.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1435 = htmdeng.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1436 = hwclock.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1437 = hxdef.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1438 = hxdl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1439 = hxiul.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1440 = i3k0hgad.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1441 = ibm00001.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1442 = icon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1443 = idemlog.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1444 = idleui.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1445 = iebtm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1446 = iedll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1447 = iedriver.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1448 = iegator.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1449 = iehost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1450 = iep.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1451 = iesetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1452 = iexpiore.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1453 = iexplor32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1454 = iexplore32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1455 = iexplorer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1456 = igetnet_3845_3645.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1457 = igps.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1458 = igpsdon6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1459 = iinstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1460 = im_2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1461 = imguninst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1462 = infoctl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1463 = infus.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1464 = infwin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1465 = init32m.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1466 = ink.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1467 = inst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1468 = install1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1469 = installdatemanager.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1470 = installer1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1471 = instant access.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1472 = intdel.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1473 = intel32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1474 = intell321.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1475 = intenat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1476 = internet.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1477 = internetfeatures.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1478 = ipfw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1479 = ipu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1480 = ipwins.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1481 = irasyncd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1482 = iroffer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1483 = isamini.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1484 = isamntr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1485 = isamonitor.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1486 = isass.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1487 = ishost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1488 = isinstalldonecrazy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1489 = ismon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1490 = isnotify.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1491 = ispsupport.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1492 = issearch.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1493 = istsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1494 = itbill.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1495 = itphwd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1496 = iwatch.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1497 = j4g8w5m8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1498 = j7k8ug16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1499 = j95i15ei.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1500 = jabber.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1501 = jammer2nd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1502 = jawa32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1503 = jdbgmrg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1504 = jif.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1505 = jkill.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1506 = jmnmxr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1507 = jnfdtdi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1508 = jq34042x.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1509 = jre4i3q6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1510 = jushed32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1511 = jxcevib2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1512 = k4eboy6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1513 = kaboom.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1514 = kahlisetup_demo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1515 = kane.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1516 = kazza.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1517 = kb021119.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1518 = keenvalue.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1519 = kernal32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1520 = kerne1412.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1521 = kernel32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1522 = kernels32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1523 = kernels64.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1524 = keu2zfke.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1525 = keylogger plugin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1526 = keyword.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1527 = kl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1528 = kmwoa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1529 = kmwol.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1530 = kmwop.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1531 = knuzql.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1532 = krxz.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1533 = l6y07fu5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1534 = lass.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1535 = launchadware.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1536 = layer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1537 = lcc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1538 = lex.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1539 = lexplore.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1540 = license_manager.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1541 = bmonq.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1542 = live.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1543 = lmu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1544 = load.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1545 = load32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1546 = loader(1).exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1547 = l26.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1548 = loader[1].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1549 = lockx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1550 = lodctr32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1551 = Duel_v2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1552 = logon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1553 = loud.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1554 = lp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1555 = lsa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1556 = lsas.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1557 = lsass32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1558 = lsassa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1559 = lssas.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1560 = lsserv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1561 = ma.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1562 = mahtfi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1563 = mapisvc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1564 = mario.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1565 = matcli.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1567 = mcf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1568 = md.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1569 = mdms.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1570 = me.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1571 = medgs1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1572 = mediaaccess.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1573 = mediaaccessinstpack.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1574 = mediaacck.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1575 = mediagateway.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1576 = mediaman.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1577 = mediapass.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1578 = mediapassk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1579 = members-area.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1580 = memorymeter.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1581 = menu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1582 = mfc71.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1583 = mfin32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1584 = mfx8k065.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1585 = microsystem.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1586 = minibug.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1587 = mirc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1588 = mirindaa1i.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1589 = mirror_plugin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1590 = mksc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1591 = mm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1592 = mm15201518.stub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1593 = mmbun.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1594 = mmm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1595 = mmod.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1596 = mmsg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1597 = mmups.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1598 = mnss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1599 = mostat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1600 = mousedrv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1601 = mp3serch.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1602 = mp7eq7hx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1603 = mrjj.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1604 = mrtstub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1605 = msaa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1606 = msapp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1607 = msbb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1608 = msbb[1].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1609 = msblast.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1610 = msc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1611 = mscache.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1612 = msccn32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1613 = msckin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1614 = mscman.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1615 = mscnsz.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1616 = mscommand.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1617 = msconfgh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1618 = msconfig32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1619 = mscornet.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1620 = mscvb32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1621 = msdm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1622 = msexreg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1623 = msgdmf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1624 = msgfix.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1625 = msgrsv32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1626 = msiexec16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1627 = msinfo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1628 = mslagent.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1629 = mslaugh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1630 = msmc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1631 = msmgs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1632 = msmgt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1633 = msmm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1634 = msmsg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1635 = msnlive.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1636 = msnst32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1637 = msole32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1638 = mspath.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1639 = mspmspv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1640 = msrexe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1641 = mssearchnet.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1642 = mssecure.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1643 = msshed32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1644 = mssvc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1645 = mssvr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1646 = mssys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1647 = mstasks.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1648 = mstc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1649 = mstcs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1651 = msvc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1652 = msvcrl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1653 = msvgr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1654 = msvxd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1655 = msw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1656 = mswin32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1657 = mswinb32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1658 = msxct.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1659 = mt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1660 = mtask.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1661 = mtjuhp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1662 = mudsc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1663 = murphy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1664 = mwd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1665 = mwfirewall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1666 = mwsoemon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1667 = mwsvm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1668 = mypcsearch.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1669 = mysearch2.0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1670 = mysetp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1671 = myurlff.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1672 = myurlsagain.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1673 = n.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1674 = n1hvjmy9.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1675 = n20050308.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1676 = nail(1).exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1677 = nail.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1678 = namedpipe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1679 = nav32sp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1680 = navapp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1681 = nbthlp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1682 = ncaselib.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1683 = ndcx3xyq.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1684 = netclient.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1685 = netddeclnt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1686 = netinfo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1687 = netlib.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1688 = netmail.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1689 = netmeeting.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1690 = netmon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1691 = netserver.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1692 = netsurf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1693 = netsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1694 = network.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1695 = newdevin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1696 = newdot.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1697 = newpop447.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1698 = nfomon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1699 = nl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1700 = nlnp49.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1701 = nls.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1702 = noat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1703 = nomoreporn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1704 = nopat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1706 = note.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1707 = notesweb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1708 = npkcsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1709 = nrcs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1710 = nrpc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1711 = nscheck.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1712 = nssys32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1713 = nstask32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1715 = nsvsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1716 = ntdetect.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1717 = ntfs64.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1718 = ntosa32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1719 = ntsys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1720 = nvctrl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1721 = nvsc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1722 = o84u7fwq.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1723 = obllak.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1724 = ocxdll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1725 = odcfg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1726 = oeet.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1727 = oeloader.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1728 = offers.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1729 = The sky.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1730 = nt.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1731 = office.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1732 = offun.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1733 = okpelq4p.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1734 = olehelp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1735 = optimize.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1736 = optimize313.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1737 = osalogbe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1738 = othb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1739 = p23oorr3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1740 = p2p networking.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1741 = p2p networking2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1742 = p2p networking3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1743 = p2pnetworking.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1744 = p2pnetworking3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1745 = pagerevisor.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1746 = paytime.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1747 = pbl8ey0e.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1748 = pchealth.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1749 = pcsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1750 = pec.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1751 = pgmonitr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1752 = phantom.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1753 = phqghum.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1754 = phqghume.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1755 = pi1_??.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1756 = picsvr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1757 = pictureshare.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1758 = recycle.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1759 = picx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1760 = pisf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1761 = piuw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1762 = 1ogf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1763 = gwr0lyd.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1764 = play[2].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1765 = play[3].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1766 = play[4].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1767 = play_mp3(2).exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1768 = play_mp3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1769 = play_mp3[1].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1770 = play_mp3[2].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1771 = play_mp3[3].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1772 = play_mp3[4].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1773 = WantsU.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1774 = My heart.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1775 = A smile.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1776 = Forever.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1777 = My love.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1778 = CritProc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1779 = play_mp3[5].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1780 = play_mp3[6].exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1781 = play_mp3-3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1782 = plscd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1783 = plugin compressor.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1784 = pmmnt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1785 = pmmon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1786 = pmr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1787 = pmsngr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1788 = pmsnrr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1789 = pmt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1790 = points manager.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1791 = pokapoka O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1792 = pokapoka66.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1793 = pokapoka67.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1794 = pokapoka70.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1795 = pokapoka72.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1796 = pokapoka73.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1797 = pokapoka76.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1798 = pokapoka79.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1799 = poker.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1800 = popuper.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1801 = powerreg O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1802 = powerreg scheduler.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1803 = powerscan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1804 = precisiontime.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1805 = precisiontimesetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1806 = prevadcomm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1807 = prizesurfer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1808 = prmt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1809 = prositefinder.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1810 = prositefinder1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1811 = prositefinderh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1812 = prot.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1813 = protector.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1814 = pruttct.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1815 = ps_install-grokster.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1816 = ps_uninstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1817 = ps1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1818 = pscanw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1819 = psof1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1820 = psoft1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1821 = My desire.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1822 = My hope.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1823 = My wish.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1824 = psqeelsr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1825 = ptop.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1826 = ptuninstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1827 = purityscan install.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1828 = purityscan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1829 = purityscan2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1830 = purityscanuninstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1831 = puszinyuszi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1832 = pvxusmtu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1833 = pyr0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1834 = q17i9a4j.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1835 = q7moyha2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1836 = qerbi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1837 = qerbif.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1838 = qhutst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1839 = qi8lu5s9.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1840 = qoologic.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1841 = qqpr8h33.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1842 = randreco.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1843 = ravmond.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1844 = ray.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1845 = rb32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1846 = rcsync.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1847 = realtray.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1848 = realupd32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1849 = register.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1850 = registration.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1851 = regloadr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1852 = regmaping.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1853 = regperf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1854 = regscan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1855 = regsrv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1856 = regsvc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1857 = regsync.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1858 = relatedsetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1859 = remote.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1860 = removed.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1861 = removedisplayutility.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1862 = removejk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1863 = requester.11.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1864 = resetservice.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1865 = richup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1866 = rk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1867 = rlid.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1868 = rlvknlg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1869 = rogue.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1870 = rpcmon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1871 = rtf32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1872 = svchost000.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1873 = run32dll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1874 = rundl32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1875 = rundll16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1876 = ruxdll32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1877 = rxtoolbar.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1878 = s.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1879 = s1p1y_bad.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1880 = saap.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1881 = sac.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1882 = sacc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1883 = saccu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1884 = sachostb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1885 = sachostc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1886 = sachostm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1887 = sachostp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1888 = sachosts.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1889 = sachostw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1890 = sachostx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1891 = safemode.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1892 = sahagent.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1893 = sahdownloader_.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1894 = saie.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1895 = sais.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1896 = salm.delete.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1897 = salm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1898 = salmbundle.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1899 = sass.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1900 = satmat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1901 = scam32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1902 = scanregistry.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1903 = scardsvr32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1904 = scbar.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1905 = scchost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1906 = schedulingagent O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1907 = schost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1908 = screensaver.v.2.1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1909 = scrigz.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1910 = scrss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1911 = scrsvr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1912 = scrtkfg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1913 = scvhost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1914 = se.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1915 = se2ppc4you.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1916 = search.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1917 = searchnavversion.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1918 = searchnugget.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1919 = searchupdate33.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1920 = searchupgrader.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1921 = sectoriate.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1922 = secure.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1923 = sed.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1924 = sedk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1925 = seekmo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1926 = seeve.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1927 = semanticinsight.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1928 = sempalong.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1929 = senslogn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1930 = sepinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1931 = servce.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1932 = servercon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1933 = servic.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1934 = service5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1935 = services32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1936 = setup_jalapeno.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1937 = setup32i.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1938 = sf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1939 = sfc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1940 = sfgdulkp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1941 = sfwqi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1942 = shell32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1943 = shell386.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1944 = shine.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1945 = shlhook.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1946 = shmgrate.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1947 = shnlog.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1948 = shutdownutility.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1949 = si.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1950 = sideb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1951 = sidedb_install.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1952 = sksockserver.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1953 = skynetave.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1954 = skype32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1955 = slmss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1956 = slserve.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1957 = slserves.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1958 = slsk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1959 = smmss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1960 = sms.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1961 = smschk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1962 = smsonx32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1963 = smsss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1964 = smszac32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1965 = soap.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1966 = Cn911.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1967 = soproc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1968 = sp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1969 = sp2ctr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1970 = spoler.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1971 = spollsv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1972 = spool.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1973 = spooler.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1974 = spools.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1975 = spoolsrv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1976 = spoolsrv32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1977 = spoolsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1978 = sprite.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1979 = spvspool.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1980 = spyagent.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1981 = spyagent4.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1982 = spyaxe.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1983 = spybuddy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1984 = spysheriff.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1985 = spytrooper.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1986 = spyware.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1987 = sqlexp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1988 = sqlexp1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1989 = sqlrep.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1990 = sqlscan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1991 = sqlserver.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1992 = sr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1993 = srng.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1994 = srv1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1995 = srv2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1996 = srv32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1997 = srv4.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1998 = srvc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1999 = sservice.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2000 = ssgrate.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2001 = ssk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2002 = ssk3_b5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2003 = ssk3_installerv5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2004 = sskb5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2005 = sskupdater.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2006 = ssl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2007 = ssrms.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2008 = ssyszu2r.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2009 = Home Video.avi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2010 = stcloader.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2011 = stealth.dcom.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2012 = stealth.ddos.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2013 = stealth.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2014 = stealth.injector.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2015 = stealth.stat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2016 = stealth.worm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2017 = stmtdlr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2018 = str.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2019 = stubinstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2020 = stubinstaller4292.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2021 = suchost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2022 = supportinstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2023 = surfsidekick.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2024 = susp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2025 = svaplayer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2026 = svc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2027 = svcdata.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2028 = 2j.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2029 = svchoost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2030 = svchos1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2031 = svchosl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2032 = svchostl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2033 = svchosts.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2034 = svchosts.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2035 = system volume.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2036 = svcinit.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2037 = svcman.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2038 = svcproc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2039 = svhost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2040 = svhosts.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2041 = svohcst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2042 = svshost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2043 = svshots.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2044 = svwhost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2045 = svzhost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2046 = swin32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2047 = switpa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2048 = swrt01.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2049 = sychost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2050 = sync.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2051 = synchost.exe (Microsoft Corporation) O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2052 = sys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2053 = sysai.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2054 = syscfg32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2055 = sysconf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2056 = sysfit.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2057 = syshost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2058 = sysldr32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2059 = syslog.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2060 = sysmonitor.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2061 = syspol.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2062 = syspools.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2063 = sysreg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2064 = syss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2065 = syssfitb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2066 = systask32l.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2067 = systb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2068 = system plugin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2069 = system16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2070 = system32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2071 = system32win.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2072 = systemdll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2073 = systemtray.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2074 = systemup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2075 = systime.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2076 = systool.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2077 = systra.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2078 = systray32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2079 = systune.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2080 = sysupd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2082 = sysvcs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2083 = syswin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2084 = sywsvcs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2085 = szchost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2086 = t8nascmw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2087 = ta.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2088 = tapicfg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2089 = targetsaver.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2090 = task.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2091 = task32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2092 = taskbar.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2093 = taskcntr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2094 = taskdrv32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2095 = tasker.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2096 = taskg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2097 = taskgmr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2098 = taskmngr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2099 = taskmon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2100 = tbon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2101 = tbps.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2102 = tcpservice2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2103 = teekids.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2104 = temp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2105 = testing.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2106 = tmp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2107 = tmp11e.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2108 = tmp333.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2109 = tool.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2110 = tool3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2111 = trans.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2112 = translator.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2113 = trickler.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2114 = ts.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2115 = ts2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2116 = tsa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2117 = tsadbot.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2118 = tsinstall_4_0_3_8_b17.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2119 = tskdbg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2120 = tskmgr32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2121 = tsl2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2122 = tsm2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2123 = tsuninst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2124 = tsupdate_4_0_3_9_b2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2125 = tsysytd8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2126 = tt_reco.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2127 = tv media display.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2128 = tvm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2129 = tvm_b5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2130 = tvm_b5_bundle_17.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2131 = tvmedia.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2132 = tvmupdater.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2133 = twain_16.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2134 = twunk_64.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2135 = u6c9mpll.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2136 = uc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2137 = uc1362.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2138 = ucsi.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2139 = udcpas.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2140 = udcsdr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2141 = uinfo?.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2142 = uj4tgbhc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2143 = umqltg4cl_.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2144 = umxfwhlp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2145 = unins001.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2146 = uninsc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2147 = uninstdsk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2148 = unpacked-svc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2149 = unstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2150 = uopcjly.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2151 = updater.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2152 = updatexp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2153 = updinst.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2154 = updmgr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2155 = updtscheduler.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2156 = upgrade1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2157 = upgrade3.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2158 = usbn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2159 = userint32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2160 = usofrpyqzgrhcumw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2161 = uvu-channel.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2162 = uwfx5.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2163 = vabctqp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2164 = vb2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2165 = vbouncer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2166 = vbstub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2167 = vcclient.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2168 = vcmpin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2169 = vco8n6ix.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2170 = video.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2171 = vidmon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2172 = vmlib.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2173 = vmss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2174 = voclslqn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2175 = vsnpstd2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2176 = w.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2177 = w11150.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2178 = w181609.stub.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2179 = w32_systm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2180 = w32backdoor-axc.trojan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2181 = w32backdoor-axg.trojan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2182 = w32backdoor-axh.trojan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2183 = w32backdoor-dvl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2184 = w32backdoor-egl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2185 = pnc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2186 = w32backdoor-egv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2187 = w32backdoor-hd.trojan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2188 = w32backdoor-jz.trojan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2189 = w32backdoor-nt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2190 = w32backdoor-ny.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2191 = w32backdoor-yx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2192 = w32banito-k.trojan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2193 = w32banito-p.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2194 = w32downloader-ggs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2195 = w32downloader-gns.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2196 = w32downloader-gpq.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2197 = w32haxdoor-ft.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2198 = w32hupigon-ar.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2199 = w32hupigon-cj.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2200 = w32istbar-la.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2201 = w32lecna-a.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2202 = w32time.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2203 = wareout.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2204 = watch_free_porn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2205 = wauclt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2206 = wdfmrg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2207 = weatherstudio desktop.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2208 = web.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2209 = webbullion.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2210 = webinstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2211 = weblookup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2212 = webpmger.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2213 = webrebates.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2214 = wfdmgr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2215 = whagent.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2216 = whg14100.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2217 = whse.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2218 = whsurvey.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2219 = wid32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2220 = wimanager.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2221 = win.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2222 = win.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2223 = win24.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2224 = win32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2225 = win32api.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2226 = win32debug.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2227 = win32us.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2228 = winactive.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2229 = winad.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2230 = winadalt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2231 = winadctl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2232 = winadm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2233 = winadserv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2234 = winadslave.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2235 = winadtools.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2236 = winav.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2237 = win-bugsfix.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2238 = wincfg32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2239 = wincomm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2240 = wincomp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2241 = winctlad.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2242 = winctladalt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2243 = winctrl?.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2244 = wind2ll2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2245 = windbg32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2246 = winde.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2247 = windefault.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2248 = windio778.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2249 = windir32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2250 = windirect.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2251 = windows.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2252 = windowsupdated32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2253 = winds.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2254 = windspl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2255 = winex.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2256 = winexec.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2257 = winexec32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2258 = winfixer O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2259 = winform.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2260 = winfrw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2261 = wingate.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2262 = wingo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2263 = winhost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2264 = winhound.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2265 = wininfo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2266 = wininit32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2267 = winldr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2268 = winldra.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2269 = winlock.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2270 = winlogin.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2271 = winlogonn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2272 = winlogons.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2273 = winmain.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2274 = winmgm32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2275 = winnet.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2276 = winnt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2277 = winoie789.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2278 = winole.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2279 = winotify.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2280 = winpack.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2281 = winproc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2282 = winpsd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2283 = winpup32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2284 = winrarshell32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2285 = winratchet.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2286 = winrecon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2287 = winresw.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2288 = winrpc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2290 = winserv.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2291 = winservices.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2292 = winservn.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2293 = winservs.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2294 = winservsuit.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2295 = winsetup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2296 = winsfc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2297 = winshost.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2298 = winsocks.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2299 = winspector.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2300 = winsrv32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2301 = winssk32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2302 = winstall.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2303 = winstart.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2304 = winstart001.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2305 = winstat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2306 = winstatkeep.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2307 = winsupdater.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2308 = winsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2309 = winsvc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2310 = winsvr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2311 = winsys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2312 = winsys2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2313 = winsys32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2314 = wintask.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2315 = wintaskad.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2316 = wintbp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2317 = wintems.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2318 = wintime.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2319 = wintools.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2320 = wintoolsa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2321 = wintrust32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2322 = wintsk32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2323 = wintsvtr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2325 = winupdates.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2326 = winupdt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2327 = winupdtl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2328 = winwan.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2329 = winxp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2330 = 81859749.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2331 = winzip_tmp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2332 = wiseupdt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2333 = wkssvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2334 = wkssvc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2335 = wmon32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2336 = wo.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2337 = word.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2338 = wovax.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2339 = wp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2340 = wpa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2341 = wpd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2342 = wrapperouter.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2343 = wrgrci.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2344 = wsebate2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2345 = wsup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2347 = wsxsvc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2348 = wsys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2349 = wtools.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2350 = wtoolsa 1.0.8.11.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2351 = wtoolsa.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2352 = wtoolss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2353 = wtssvtr.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2354 = wuactl2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2355 = wuamgrd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2356 = wuamkop.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2357 = wuauclt2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2359 = wupdated.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2360 = wupdater.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2361 = wupdates.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2362 = wupdt.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2363 = wups.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2364 = x234cpiroff.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2365 = xfullgames.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2366 = xhrmy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2367 = xmailer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2368 = xpujbkz6.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2369 = xtcfgloader.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2370 = xtmbgajp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2371 = xupiterstartup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2372 = xupitertoolbarloader.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2373 = xvid-1.0.3-beta3-setup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2374 = xwrm.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2375 = xxx.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2376 = xzciqim.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2377 = xzz.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2378 = y.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2379 = y38p3fqy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2380 = yaemu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2381 = ystckao32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2382 = zango.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2383 = zangohook.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2384 = zangoinstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2385 = zangotb.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2386 = zangotbinstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2387 = zangotbuninstaller.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2388 = zanu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2389 = zanuhook.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2390 = zb9uu7p0.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2391 = zcbridge.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2392 = zcz.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2393 = zeta.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2394 = zhopaizdupla.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2395 = lvhf.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2396 = 2aaxaiy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2397 = 2.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2398 = 1utbfd.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2399 = 0bcobed.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2400 = ib8979.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2401 = j6445622.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2402 = o4445627.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2403 = 2u.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2404 = program files.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2405 = winsmss.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2406 = document.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2407 = Gerger_files.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2408 = drvspace.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2409 = EraleuH.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2410 = PowerPoint temlates.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2411 = Excel templates.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2412 = My Media Files.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2413 = MP3 Files.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2414 = Admin Files.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2415 = filesrv32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2416 = My Documents.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2417 = Important Documents.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2418 = Saved Documents.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2419 = My Videos.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2420 = System Volume Information.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2421 = System Volume Information.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2422 = System Volume Information.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2423 = System Volume Information.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2424 = ChiNiu.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2425 = winomc.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2426 = vang anh.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2427 = autorun.inf.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2428 = autorun.inf.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2429 = autorun.inf.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2430 = autorun.inf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2431 = autorun.ini.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2432 = autorun.ini.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2433 = autorun.ini.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2434 = autorun.ini.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2435 = desktop.ini.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2436 = desktop.ini.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2437 = desktop.ini.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2438 = desktop.ini.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2439 = ntos.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2440 = fqmcnfl.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2441 = jscuup.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2442 = msbootlog.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2443 = website.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2444 = Mr.kokoro.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2445 = MR.KOKORO website.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2446 = jjxzwzjy090223.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2447 = usbmon.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2448 = kb2006a.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2449 = GOBACK.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2450 = SSERVER.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2451 = GOST.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2452 = lap.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2453 = 91255398.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2454 = newdev.exe (Microsoft Corporation) O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2455 = my game.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2456 = my games.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2457 = xn9uu8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2458 = xdw.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2459 = xcisvxl.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2460 = x2csvg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2461 = w.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2462 = w98.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2463 = w2.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2464 = ve.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2465 = uxkl0apt.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2466 = uvsqfgwd.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2467 = ur0.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2468 = upw.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2469 = ujyew68.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2470 = u.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2471 = tx.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2472 = sbju2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2473 = rveunh.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2474 = rcvk.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2475 = qxty9be.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2476 = qphdin.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2477 = qoes.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2478 = q0dhfjf.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2479 = pook.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2480 = opgde.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2481 = o8.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2482 = o3n9k.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2483 = mk.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2484 = minm.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2485 = m0vnonh.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2486 = luk1ylq.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2487 = ltdjr2ia.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2488 = lhylec9x.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2489 = jodi2nb.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2490 = jm3cx96.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2491 = jeorels.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2492 = je9.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2493 = j60osk9.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2494 = iq.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2495 = i.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2496 = i6g6x.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2497 = hyetn1i.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2498 = hl80c6b1.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2499 = gy.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2500 = gi2ky.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2501 = gfqgq.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2502 = gc6.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2503 = em8tqm.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2504 = ej.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2505 = dy9.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2506 = dbrxubcw.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2507 = cv22.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2508 = cqxj.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2509 = bvc0gyp.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2510 = bg3e9.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2511 = bd3q0qix.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2512 = a2h2.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2513 = a1agmur.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2514 = 210ebnkd.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2515 = 93to.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2516 = 6tbvtj.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2517 = 2nw3rjta.cmd O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2518 = 2fiy.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2519 = 82521011.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2520 = 43980195.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2521 = REGEDT.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2522 = Cfg.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2523 = kbdsys.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2524 = Read1st!.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2525 = hlpsvc2.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2526 = hlpsvc1.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2527 = Classified.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2528 = option.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2529 = sysinf.bat O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2530 = pagefile.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2531 = kavupda.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2532 = HelpCat.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2533 = ????8.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2534 = SKServer.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2535 = msddrv42.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2536 = Romantic.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2537 = WPV001253926400.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2538 = DPLTAINEXI-517.PMS.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2539 = 96971452.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2540 = sasnative32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2541 = clc32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2542 = m9ma.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2543 = 6fnlpetp.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2544 = xlk9.com O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2545 = ahnrpta.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2546 = olhrwef.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2547 = vamsoft.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2548 = vsse33.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2549 = wpv791239289922.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2550 = wpv29125338862.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2551 = wpv481254425989.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2552 = wpv261254042811.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2553 = ikowin32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2554 = lizkavd.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2555 = restorer32_a.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2556 = DPLTNOQDBS-327.PMS.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2557 = WINBQB0SCA.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2558 = WJQS.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2559 = SERES.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2560 = SVCST.EXE O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2561 = winzip.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2562 = fun.xls.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2563 = autorunme.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2564 = MSwindows.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2565 = player32.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2566 = Home Video.exe O7 - HKU\S-1-5-21-696344351-3799042256-4134383898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2567 = EPL0RER.EXE O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BBB9D90A-8B90-48D7-8777-5C9D8F117FB1}: DhcpNameServer = 192.168.1.1 O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O20:[b]64bit:[/b] - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation) O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - No CLSID value found. O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\SysWOW64\ExplorerFrame.dll (Microsoft Corporation) O27:[b]64bit:[/b] - HKLM IFEO\iastorui.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe (TuneUp Software) O27:[b]64bit:[/b] - HKLM IFEO\teamviewer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe (TuneUp Software) O27 - HKLM IFEO\iastorui.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe (TuneUp Software) O27 - HKLM IFEO\teamviewer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe (TuneUp Software) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013-02-05 21:50:39 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2013-02-13 00:39:49 | 000,000,000 | ---D | M] - D:\AutoMapa 6.10B -- [ NTFS ] O32 - AutoRun File - [2013-02-13 00:39:49 | 000,000,000 | ---D | M] - D:\AutoMapa_6.10e_PL -- [ NTFS ] O32 - AutoRun File - [2012-09-05 21:17:04 | 000,000,054 | R--- | M] () - F:\autorun.inf -- [ UDF ] O33 - MountPoints2\{7c02862b-7176-11e2-859a-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{7c02862b-7176-11e2-859a-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe -- [2012-09-07 02:13:42 | 000,298,640 | R--- | M] (2K Sports) O33 - MountPoints2\{a8e7d9f1-6982-11e2-88cc-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{a8e7d9f1-6982-11e2-88cc-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Run.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-02-14 10:46:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Arturo\Desktop\OTL.exe [2013-02-14 09:21:58 | 000,000,000 | ---D | C] -- C:\Nowy folder [2013-02-14 09:16:57 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\OCCT_-_Ocbase_-_Adrien_Me [2013-02-14 09:01:47 | 000,000,000 | ---D | C] -- C:\Users\Arturo\Documents\OCCT [2013-02-14 08:28:51 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OCCT [2013-02-14 08:28:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OCCT [2013-02-14 08:28:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OCCTPT [2013-02-14 08:28:48 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx [2013-02-14 08:12:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune [2013-02-14 08:12:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HD Tune [2013-02-13 00:40:03 | 000,000,000 | ---D | C] -- C:\Assassins Creed 2 - po wypakowaniu [2013-02-12 21:46:27 | 000,000,000 | ---D | C] -- C:\ProgramData\FarmFrenzy3 [2013-02-12 20:24:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPlayCity.com [2013-02-12 20:24:12 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2013-02-12 20:24:12 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2013-02-12 20:24:12 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013-02-12 20:24:12 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2013-02-12 20:24:12 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2013-02-12 20:24:12 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013-02-12 20:24:12 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2013-02-12 20:24:12 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2013-02-12 20:24:12 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2013-02-12 20:24:12 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2013-02-12 20:24:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MyPlayCity.com [2013-02-12 20:24:11 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013-02-12 20:24:11 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013-02-12 20:24:11 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013-02-12 20:24:11 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013-02-12 20:24:11 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2013-02-12 20:24:00 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll [2013-02-12 20:24:00 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2013-02-12 20:23:59 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2013-02-12 20:23:59 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2013-02-12 20:23:59 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2013-02-12 20:23:58 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2013-02-12 20:23:53 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS [2013-02-12 20:23:52 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2013-02-12 20:23:52 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2013-02-12 20:23:52 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2013-02-09 19:47:27 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\AVI ReComp [2013-02-08 20:20:42 | 000,037,816 | ---- | C] (TuneUp Software) -- C:\Windows\SysNative\uxtuneup.dll [2013-02-08 20:20:42 | 000,030,136 | ---- | C] (TuneUp Software) -- C:\Windows\SysWow64\uxtuneup.dll [2013-02-08 16:08:42 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\TS3Client [2013-02-08 16:08:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client [2013-02-08 16:08:33 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client [2013-02-08 14:35:41 | 008,323,072 | ---- | C] (Genesys) -- C:\Windows\SysNative\GeneIcon.dll [2013-02-08 14:35:40 | 000,060,928 | ---- | C] (GenesysLogic) -- C:\Windows\SysNative\drivers\GeneStor.sys [2013-02-08 14:34:46 | 000,210,944 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\drivers\ViaHub3.sys [2013-02-08 14:34:09 | 000,261,120 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\drivers\xhcdrv.sys [2013-02-08 14:23:21 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\driveridentifier [2013-02-08 12:00:09 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\HP [2013-02-08 11:55:23 | 000,000,000 | ---D | C] -- C:\ProgramData\WEBREG [2013-02-08 11:52:47 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant [2013-02-08 11:52:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\HP [2013-02-08 11:52:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP [2013-02-08 11:52:21 | 000,000,000 | -H-D | C] -- C:\Config.Msi [2013-02-08 11:48:24 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\HP [2013-02-08 07:53:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp [2013-02-08 07:53:02 | 000,000,000 | ---D | C] -- C:\Program Files\Core Temp [2013-02-08 07:41:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0 [2013-02-08 07:39:01 | 000,035,256 | ---- | C] (TuneUp Software) -- C:\Windows\SysNative\TURegOpt.exe [2013-02-08 07:39:01 | 000,026,552 | ---- | C] (TuneUp Software) -- C:\Windows\SysNative\authuitu.dll [2013-02-08 07:39:01 | 000,021,944 | ---- | C] (TuneUp Software) -- C:\Windows\SysWow64\authuitu.dll [2013-02-08 07:39:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013 [2013-02-08 07:38:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TuneUp Utilities 2013 [2013-02-08 01:03:07 | 000,025,640 | ---- | C] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys [2013-02-08 00:15:26 | 000,000,000 | ---D | C] -- C:\Windows\pss [2013-02-07 23:52:28 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA [2013-02-07 23:51:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies [2013-02-07 23:51:27 | 006,392,096 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll [2013-02-07 23:51:27 | 003,472,160 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll [2013-02-07 23:51:27 | 002,555,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll [2013-02-07 23:51:27 | 000,237,856 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll [2013-02-07 23:51:27 | 000,063,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll [2013-02-07 23:51:18 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation [2013-02-07 23:51:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation [2013-02-07 23:50:55 | 026,946,848 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2013-02-07 23:50:55 | 025,256,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2013-02-07 23:50:55 | 020,534,048 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2013-02-07 23:50:55 | 017,985,632 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2013-02-07 23:50:55 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2013-02-07 23:50:55 | 015,182,544 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll [2013-02-07 23:50:55 | 015,037,248 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll [2013-02-07 23:50:55 | 012,771,784 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll [2013-02-07 23:50:55 | 009,422,672 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2013-02-07 23:50:55 | 007,964,168 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2013-02-07 23:50:55 | 007,569,184 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2013-02-07 23:50:55 | 006,267,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2013-02-07 23:50:55 | 002,911,008 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2013-02-07 23:50:55 | 002,855,880 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll [2013-02-07 23:50:55 | 002,726,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2013-02-07 23:50:55 | 002,530,376 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll [2013-02-07 23:50:55 | 002,352,416 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll [2013-02-07 23:50:55 | 001,990,944 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll [2013-02-07 23:50:55 | 001,807,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6420294.dll [2013-02-07 23:50:55 | 001,510,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6420162.dll [2013-02-07 23:50:55 | 001,114,144 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvumdshimx.dll [2013-02-07 23:50:55 | 000,963,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll [2013-02-07 23:50:55 | 000,420,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncodeAPI64.dll [2013-02-07 23:50:55 | 000,364,832 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncodeAPI.dll [2013-02-07 23:50:55 | 000,250,504 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll [2013-02-07 23:50:55 | 000,205,184 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll [2013-02-07 23:49:47 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation [2013-02-07 23:40:12 | 000,041,984 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\USB3Ver.dll [2013-02-07 23:40:00 | 000,789,272 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\iusb3xhc.sys [2013-02-07 23:40:00 | 000,356,632 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\iusb3hub.sys [2013-02-07 23:40:00 | 000,019,224 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\iusb3hcs.sys [2013-02-07 23:38:47 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\ElevatedDiagnostics [2013-02-07 23:32:10 | 002,206,352 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\drivers\viahduaa.sys [2013-02-07 23:32:10 | 001,161,360 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\ViaKaraokeApo.dll [2013-02-07 23:32:10 | 001,119,376 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\ViaMicArrayAPO.dll [2013-02-07 23:32:10 | 000,123,536 | ---- | C] (VIA Technologies,Inc.) -- C:\Windows\SysNative\ViaKaraokePropPageExt.dll [2013-02-07 23:32:10 | 000,095,376 | ---- | C] (VIA Technologies,Inc.) -- C:\Windows\SysNative\ViaMicArrayPropPageExt.dll [2013-02-07 23:32:10 | 000,070,800 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\VtSrdAPO.dll [2013-02-07 23:32:09 | 000,055,440 | ---- | C] (TODO: ) -- C:\Windows\SysNative\PropPageExt.dll [2013-02-07 23:32:08 | 000,248,976 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\Dts2APO.dll [2013-02-07 23:32:08 | 000,092,304 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\Dts2PropPageExt.dll [2013-02-07 23:32:08 | 000,027,792 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\ViakaraokeSrv.exe [2013-02-07 23:30:23 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel [2013-02-07 23:30:03 | 000,647,736 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\iaStorA.sys [2013-02-07 23:30:03 | 000,028,216 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\iaStorF.sys [2013-02-07 23:27:11 | 000,015,168 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\IntelMEFWVer.dll [2013-02-07 21:08:24 | 000,000,000 | ---D | C] -- C:\Program Files\VIA [2013-02-07 21:08:24 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SRSLabs [2013-02-07 21:08:22 | 003,141,496 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioVIA64.dll [2013-02-07 21:08:22 | 002,993,296 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\VIAPropPageExt.dll [2013-02-07 21:08:22 | 002,080,120 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib64.dll [2013-02-07 21:08:22 | 000,879,616 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMAPO64.DLL [2013-02-07 21:08:22 | 000,860,024 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPOShell64.dll [2013-02-07 21:08:22 | 000,739,328 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysWow64\VMAPO32.DLL [2013-02-07 21:08:22 | 000,681,104 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\VIASysFx.dll [2013-02-07 21:08:22 | 000,394,104 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO30.dll [2013-02-07 21:08:22 | 000,086,016 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQPropPageExt.dll [2013-02-07 21:08:22 | 000,057,856 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMPPLD64.DLL [2013-02-07 21:08:22 | 000,053,760 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMPPCN64.DLL [2013-02-07 21:08:22 | 000,025,600 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\VMfilt64.sys [2013-02-07 21:08:21 | 007,163,744 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EEP64H.dll [2013-02-07 21:08:21 | 000,619,520 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMTHX64.DLL [2013-02-07 21:08:21 | 000,554,496 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysWow64\VMTHX32.DLL [2013-02-07 21:08:21 | 000,433,504 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EED64H.dll [2013-02-07 21:08:21 | 000,433,504 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EED64A.dll [2013-02-07 21:08:21 | 000,137,056 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EEL64H.dll [2013-02-07 21:08:21 | 000,137,056 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EEL64A.dll [2013-02-07 21:08:21 | 000,120,160 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EEA64H.dll [2013-02-07 21:08:21 | 000,120,160 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EEA64A.dll [2013-02-07 21:08:21 | 000,075,104 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EEG64H.dll [2013-02-07 21:08:21 | 000,075,104 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\EEG64A.dll [2013-02-07 21:08:21 | 000,074,240 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMWRP64.DLL [2013-02-07 18:43:27 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\TeamViewer [2013-02-07 18:25:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer [2013-02-07 15:09:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SystemRequirementsLab [2013-02-07 15:08:52 | 000,000,000 | ---D | C] -- C:\Users\Arturo\SystemRequirementsLab [2013-02-07 14:12:29 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Avira [2013-02-07 14:10:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2013-02-07 14:10:11 | 000,129,216 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys [2013-02-07 14:10:11 | 000,099,912 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys [2013-02-07 14:10:11 | 000,027,800 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys [2013-02-07 14:10:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2013-02-07 14:10:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira [2013-02-07 14:07:37 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Wise Registry Cleaner [2013-02-07 14:07:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner [2013-02-07 14:07:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wise [2013-02-07 13:51:14 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\GoforFiles [2013-02-07 13:37:54 | 000,000,000 | ---D | C] -- C:\Drivers [2013-02-07 12:07:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard [2013-02-07 12:05:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Hewlett-Packard [2013-02-07 12:05:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP [2013-02-07 12:04:07 | 000,938,496 | ---- | C] (Hewlett-Packard) -- C:\Windows\SysNative\hpowiax7.dll [2013-02-07 12:04:07 | 000,740,864 | ---- | C] (Hewlett-Packard Co.) -- C:\Windows\SysNative\hpotscl6.dll [2013-02-07 12:04:07 | 000,642,360 | ---- | C] (Hewlett-Packard) -- C:\Windows\SysNative\hpzids40.dll [2013-02-07 12:04:07 | 000,551,424 | ---- | C] (Hewlett-Packard) -- C:\Windows\SysNative\hppldcoi.dll [2013-02-07 12:04:07 | 000,505,344 | ---- | C] (Hewlett-Packard Co.) -- C:\Windows\SysNative\hpovst15.dll [2013-02-07 12:03:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013-02-07 11:47:32 | 000,000,000 | ---D | C] -- C:\ProgramData\HP [2013-02-05 22:17:20 | 000,608,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\COMCTL32.OCX [2013-02-05 22:17:20 | 000,511,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\capicom.dll [2013-02-05 22:17:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FixAuto [2013-02-05 22:13:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PCSafeDoctor [2013-02-05 21:50:28 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013-02-05 21:44:16 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\SpeedyPC Software [2013-02-05 21:44:16 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\DriverCure [2013-02-05 21:44:11 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedyPC Software [2013-02-05 21:02:52 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\GlarySoft [2013-02-05 18:45:15 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Diagnostics [2013-02-05 14:25:50 | 000,000,000 | ---D | C] -- C:\Users\Arturo\Documents\FIFA 13 [2013-02-05 14:19:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 13 [2013-02-05 14:06:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam [2013-02-05 14:06:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam [2013-02-05 10:02:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Futuremark [2013-02-05 09:55:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Futuremark [2013-02-05 09:55:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard [2013-02-05 09:54:24 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\NVIDIA [2013-02-05 09:54:24 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\MAXON [2013-02-05 09:36:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [2013-02-05 09:23:36 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe [2013-02-05 09:23:34 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe [2013-02-05 09:23:34 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe [2013-02-05 09:23:34 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll [2013-02-05 09:23:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2013-02-05 09:21:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phyxion.net [2013-02-05 09:21:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Phyxion.net [2013-01-30 11:06:37 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\PunkBuster [2013-01-30 11:06:34 | 000,000,000 | ---D | C] -- C:\Users\Arturo\Documents\Battlefield 3 [2013-01-30 11:06:21 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Core [2013-01-30 11:06:07 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Logs [2013-01-30 10:38:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits [2013-01-30 10:38:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Microsoft [2013-01-30 10:38:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Kits [2013-01-30 10:32:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache [2013-01-30 10:29:59 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2013-01-30 09:36:35 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NumiMaster [2013-01-30 09:36:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NumiMaster [2013-01-30 09:32:48 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\ESN [2013-01-30 09:32:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Battlelog Web Plugins [2013-01-30 09:28:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2013-01-30 09:28:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2013-01-30 09:28:03 | 000,861,088 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll [2013-01-30 09:28:03 | 000,782,240 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll [2013-01-29 00:19:16 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z [2013-01-29 00:19:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GPU-Z [2013-01-29 00:18:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID [2013-01-29 00:18:23 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID [2013-01-29 00:13:04 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Ubisoft [2013-01-29 00:13:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft [2013-01-28 23:58:25 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft [2013-01-28 23:58:23 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Ubisoft Game Launcher [2013-01-28 22:09:22 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\EAInstaller [2013-01-28 22:09:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3 [2013-01-28 22:08:45 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_7.dll [2013-01-28 22:08:45 | 000,518,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_7.dll [2013-01-28 22:08:45 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_7.dll [2013-01-28 22:08:45 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_7.dll [2013-01-28 22:08:45 | 000,077,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_5.dll [2013-01-28 22:08:45 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_5.dll [2013-01-28 22:08:44 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_43.dll [2013-01-28 22:08:44 | 002,401,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_43.dll [2013-01-28 22:08:44 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll [2013-01-28 22:08:44 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll [2013-01-28 22:08:44 | 001,907,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_43.dll [2013-01-28 22:08:44 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_43.dll [2013-01-28 22:08:44 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_43.dll [2013-01-28 22:08:44 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll [2013-01-28 22:08:44 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_43.dll [2013-01-28 22:08:44 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll [2013-01-28 22:08:43 | 002,582,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_42.dll [2013-01-28 22:08:43 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_42.dll [2013-01-28 22:08:43 | 000,530,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_6.dll [2013-01-28 22:08:43 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_6.dll [2013-01-28 22:08:43 | 000,517,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_5.dll [2013-01-28 22:08:43 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_6.dll [2013-01-28 22:08:43 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_5.dll [2013-01-28 22:08:43 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_6.dll [2013-01-28 22:08:43 | 000,176,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_5.dll [2013-01-28 22:08:43 | 000,078,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_4.dll [2013-01-28 22:08:43 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_4.dll [2013-01-28 22:08:43 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_7.dll [2013-01-28 22:08:43 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_7.dll [2013-01-28 22:08:42 | 005,554,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dcsx_42.dll [2013-01-28 22:08:42 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_42.dll [2013-01-28 22:08:42 | 002,475,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_42.dll [2013-01-28 22:08:42 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_42.dll [2013-01-28 22:08:42 | 000,285,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx11_42.dll [2013-01-28 22:08:42 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_42.dll [2013-01-28 22:08:41 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_3.dll [2013-01-28 22:08:39 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_3.dll [2013-01-28 22:08:39 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll [2013-01-28 22:08:39 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_2.dll [2013-01-28 22:08:39 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll [2013-01-28 22:08:39 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll [2013-01-28 22:08:39 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_3.dll [2013-01-28 22:08:39 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_2.dll [2013-01-28 22:08:39 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_1.dll [2013-01-28 22:08:39 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll [2013-01-28 22:08:39 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll [2013-01-28 22:08:39 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_5.dll [2013-01-28 22:08:39 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll [2013-01-28 22:08:38 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll [2013-01-28 22:08:38 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_2.dll [2013-01-28 21:15:59 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\2K Sports [2013-01-28 21:15:14 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_41.dll [2013-01-28 21:15:14 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_41.dll [2013-01-28 21:15:13 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_41.dll [2013-01-28 21:15:13 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll [2013-01-28 21:15:13 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_4.dll [2013-01-28 21:15:13 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll [2013-01-28 21:15:13 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll [2013-01-28 21:15:13 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_4.dll [2013-01-28 21:15:13 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_6.dll [2013-01-28 21:15:13 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll [2013-01-28 21:15:12 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_40.dll [2013-01-28 21:15:12 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll [2013-01-28 21:15:12 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_40.dll [2013-01-28 21:15:12 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll [2013-01-28 21:15:12 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_40.dll [2013-01-28 21:15:12 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll [2013-01-28 21:15:11 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_39.dll [2013-01-28 21:15:11 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll [2013-01-28 21:15:11 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_39.dll [2013-01-28 21:15:11 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll [2013-01-28 21:15:11 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_39.dll [2013-01-28 21:15:11 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll [2013-01-28 21:15:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent [2013-01-28 21:15:10 | 001,941,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_38.dll [2013-01-28 21:15:10 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_38.dll [2013-01-28 21:15:10 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_38.dll [2013-01-28 21:15:10 | 000,511,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_1.dll [2013-01-28 21:15:10 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll [2013-01-28 21:15:10 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_38.dll [2013-01-28 21:15:10 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll [2013-01-28 21:15:10 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_1.dll [2013-01-28 21:15:10 | 000,068,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAPOFX1_0.dll [2013-01-28 21:15:10 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll [2013-01-28 21:15:10 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_4.dll [2013-01-28 21:15:10 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_4.dll [2013-01-28 21:15:09 | 004,991,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_38.dll [2013-01-28 21:15:09 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_38.dll [2013-01-28 21:15:09 | 000,489,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XAudio2_0.dll [2013-01-28 21:15:09 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_0.dll [2013-01-28 21:15:09 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_0.dll [2013-01-28 21:15:09 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine3_0.dll [2013-01-28 21:15:09 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_3.dll [2013-01-28 21:15:09 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_3.dll [2013-01-28 21:15:08 | 004,910,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_37.dll [2013-01-28 21:15:08 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_37.dll [2013-01-28 21:15:08 | 001,860,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_37.dll [2013-01-28 21:15:08 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_37.dll [2013-01-28 21:15:08 | 000,529,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_37.dll [2013-01-28 21:15:08 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_37.dll [2013-01-28 21:15:08 | 000,411,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_10.dll [2013-01-28 21:15:08 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_10.dll [2013-01-28 21:15:07 | 005,081,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_36.dll [2013-01-28 21:15:07 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_36.dll [2013-01-28 21:15:07 | 002,006,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_36.dll [2013-01-28 21:15:07 | 001,985,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_35.dll [2013-01-28 21:15:07 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_36.dll [2013-01-28 21:15:07 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_35.dll [2013-01-28 21:15:07 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_36.dll [2013-01-28 21:15:07 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_35.dll [2013-01-28 21:15:07 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_36.dll [2013-01-28 21:15:07 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_35.dll [2013-01-28 21:15:07 | 000,411,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_9.dll [2013-01-28 21:15:07 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_9.dll [2013-01-28 21:15:06 | 005,073,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_35.dll [2013-01-28 21:15:06 | 004,496,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_34.dll [2013-01-28 21:15:06 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll [2013-01-28 21:15:06 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll [2013-01-28 21:15:06 | 001,401,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_34.dll [2013-01-28 21:15:06 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_34.dll [2013-01-28 21:15:06 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_34.dll [2013-01-28 21:15:06 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_34.dll [2013-01-28 21:15:06 | 000,409,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_8.dll [2013-01-28 21:15:06 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_8.dll [2013-01-28 21:15:06 | 000,021,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\X3DAudio1_2.dll [2013-01-28 21:15:06 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_2.dll [2013-01-28 21:15:05 | 004,494,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_33.dll [2013-01-28 21:15:05 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_33.dll [2013-01-28 21:15:05 | 001,400,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_33.dll [2013-01-28 21:15:05 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_33.dll [2013-01-28 21:15:05 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_33.dll [2013-01-28 21:15:05 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_33.dll [2013-01-28 21:15:05 | 000,403,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_7.dll [2013-01-28 21:15:05 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_7.dll [2013-01-28 21:15:05 | 000,107,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_3.dll [2013-01-28 21:15:05 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_3.dll [2013-01-28 21:15:04 | 000,469,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10.dll [2013-01-28 21:15:04 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10.dll [2013-01-28 21:15:04 | 000,393,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_6.dll [2013-01-28 21:15:04 | 000,390,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_5.dll [2013-01-28 21:15:04 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_6.dll [2013-01-28 21:15:04 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_5.dll [2013-01-28 21:15:03 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_31.dll [2013-01-28 21:15:03 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll [2013-01-28 21:15:03 | 000,364,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_4.dll [2013-01-28 21:15:03 | 000,363,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_3.dll [2013-01-28 21:15:03 | 000,354,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_2.dll [2013-01-28 21:15:03 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_4.dll [2013-01-28 21:15:03 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_3.dll [2013-01-28 21:15:03 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_2.dll [2013-01-28 21:15:03 | 000,083,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_2.dll [2013-01-28 21:15:03 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_2.dll [2013-01-28 21:15:03 | 000,017,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_1.dll [2013-01-28 21:15:03 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_1.dll [2013-01-28 21:15:02 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_1.dll [2013-01-28 21:15:02 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll [2013-01-28 21:15:02 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_1.dll [2013-01-28 21:15:02 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll [2013-01-28 21:15:01 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_30.dll [2013-01-28 21:15:01 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll [2013-01-28 21:15:00 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_29.dll [2013-01-28 21:15:00 | 003,815,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_28.dll [2013-01-28 21:15:00 | 003,807,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_27.dll [2013-01-28 21:15:00 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_29.dll [2013-01-28 21:15:00 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_28.dll [2013-01-28 21:15:00 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_27.dll [2013-01-28 21:15:00 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_0.dll [2013-01-28 21:15:00 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll [2013-01-28 21:15:00 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_0.dll [2013-01-28 21:15:00 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll [2013-01-28 21:14:59 | 003,823,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_25.dll [2013-01-28 21:14:59 | 003,767,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_26.dll [2013-01-28 21:14:59 | 003,544,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_24.dll [2013-01-28 21:14:59 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_25.dll [2013-01-28 21:14:59 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_26.dll [2013-01-28 21:14:59 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_24.dll [2013-01-28 21:13:02 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\uTorrent [2013-01-28 20:41:19 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2013-01-28 20:41:11 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2013-01-28 20:40:40 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2013-01-28 20:31:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin Games [2013-01-28 20:31:56 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Origin [2013-01-28 20:31:50 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Origin [2013-01-28 20:30:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin [2013-01-28 20:30:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin [2013-01-28 20:30:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts [2013-01-28 19:58:07 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RdpGroupPolicyExtension.dll [2013-01-28 19:58:07 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll [2013-01-28 19:58:07 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe [2013-01-28 19:58:06 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll [2013-01-28 19:58:06 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpendp_winip.dll [2013-01-28 19:58:06 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys [2013-01-28 19:58:06 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll [2013-01-28 19:58:06 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll [2013-01-28 19:58:06 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll [2013-01-28 19:58:06 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll [2013-01-28 19:58:06 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys [2013-01-28 19:58:06 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll [2013-01-28 19:58:06 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll [2013-01-28 19:58:05 | 005,773,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll [2013-01-28 19:58:05 | 004,916,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll [2013-01-28 19:58:05 | 003,174,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll [2013-01-28 19:58:05 | 001,123,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe [2013-01-28 19:58:05 | 001,048,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe [2013-01-28 19:58:05 | 000,384,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe [2013-01-28 19:58:05 | 000,322,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aaclient.dll [2013-01-28 19:58:05 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll [2013-01-28 19:58:05 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpendp_winip.dll [2013-01-28 19:58:05 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe [2013-01-28 19:58:05 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll [2013-01-28 19:56:58 | 001,448,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll [2013-01-28 19:56:57 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys [2013-01-28 19:56:57 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcorehc.dll [2013-01-28 19:56:57 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncsi.dll [2013-01-28 19:56:57 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll [2013-01-28 19:56:57 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll [2013-01-28 19:56:57 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll [2013-01-28 19:56:57 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll [2013-01-28 19:56:55 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OxpsConverter.exe [2013-01-28 19:56:53 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore6.dll [2013-01-28 19:56:53 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll [2013-01-28 19:56:53 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll [2013-01-28 19:56:53 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys [2013-01-28 19:56:52 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll [2013-01-28 19:56:52 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll [2013-01-28 19:56:50 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskhost.exe [2013-01-28 19:52:22 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\LibreOffice [2013-01-28 19:49:53 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 3.6 [2013-01-28 19:49:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LibreOffice 3.6 [2013-01-28 17:07:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview [2013-01-28 17:07:30 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders [2013-01-28 17:07:15 | 000,000,000 | ---D | C] -- C:\Windows\pl [2013-01-28 17:07:07 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Thunderbird [2013-01-28 17:07:07 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Thunderbird [2013-01-28 17:06:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition [2013-01-28 17:06:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live [2013-01-28 17:06:26 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2013-01-28 17:06:25 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live [2013-01-28 17:05:46 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll [2013-01-28 17:04:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3 [2013-01-28 17:04:55 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\AIMP3 [2013-01-28 17:04:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AIMP3 [2013-01-28 17:03:57 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Malwarebytes [2013-01-28 17:03:04 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RadioSure [2013-01-28 17:02:59 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\RadioSure [2013-01-28 17:02:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird [2013-01-28 17:01:52 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Canneverbe Limited [2013-01-28 17:01:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited [2013-01-28 17:01:48 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP [2013-01-28 16:59:28 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander [2013-01-28 16:59:27 | 000,000,000 | ---D | C] -- C:\totalcmd [2013-01-28 16:59:27 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\GHISLER [2013-01-28 16:58:58 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\TuneUp Software [2013-01-28 16:58:55 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [2013-01-28 16:58:55 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2013-01-28 16:58:55 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software [2013-01-28 16:58:43 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\NapiProjekt [2013-01-28 16:58:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt [2013-01-28 16:58:28 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\OpenCandy [2013-01-28 16:58:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NapiProjekt [2013-01-28 16:57:57 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Programs [2013-01-28 16:57:17 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\XnView [2013-01-28 16:57:05 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\BESTplayer [2013-01-28 16:56:58 | 001,123,840 | ---- | C] (Karol Winnicki) -- C:\Users\Arturo\Desktop\BESTplayer.exe [2013-01-28 16:54:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView [2013-01-28 16:54:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XnView [2013-01-28 16:52:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VobSub [2013-01-28 16:52:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gabest [2013-01-28 16:52:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid [2013-01-28 16:52:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xvid [2013-01-28 16:51:36 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013-01-28 16:51:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5 [2013-01-28 16:51:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5 [2013-01-28 16:51:28 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVI ReComp [2013-01-28 16:51:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVI ReComp [2013-01-28 16:50:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange [2013-01-28 16:50:30 | 000,000,000 | ---D | C] -- C:\Program Files\Tracker Software [2013-01-28 16:40:56 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat [2013-01-28 16:40:56 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat [2013-01-28 16:40:18 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll [2013-01-28 16:40:18 | 000,048,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netfxperf.dll [2013-01-28 16:40:15 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll [2013-01-28 16:40:13 | 001,838,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll [2013-01-28 16:40:11 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40.dll [2013-01-28 16:40:11 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40u.dll [2013-01-28 16:40:10 | 014,633,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll [2013-01-28 16:40:09 | 004,120,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll [2013-01-28 16:40:09 | 003,205,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmcndmgr.dll [2013-01-28 16:40:09 | 003,008,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xpsservices.dll [2013-01-28 16:40:09 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll [2013-01-28 16:40:09 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll [2013-01-28 16:40:09 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll [2013-01-28 16:40:09 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe [2013-01-28 16:40:09 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe [2013-01-28 16:40:08 | 002,086,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll [2013-01-28 16:40:08 | 001,219,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll [2013-01-28 16:40:08 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll [2013-01-28 16:40:08 | 000,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe [2013-01-28 16:40:08 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe [2013-01-28 16:40:07 | 003,207,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll [2013-01-28 16:40:07 | 001,866,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll [2013-01-28 16:40:07 | 001,753,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vssapi.dll [2013-01-28 16:40:07 | 001,556,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RacEngn.dll [2013-01-28 16:40:07 | 001,340,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diagperf.dll [2013-01-28 16:40:07 | 001,197,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskschd.dll [2013-01-28 16:40:07 | 000,263,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwizui.dll [2013-01-28 16:40:06 | 011,410,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll [2013-01-28 16:40:06 | 003,860,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIRibbon.dll [2013-01-28 16:40:06 | 001,334,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll [2013-01-28 16:40:06 | 001,326,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NaturalLanguage6.dll [2013-01-28 16:40:06 | 000,299,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcupdate_GenuineIntel.dll [2013-01-28 16:40:05 | 003,957,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSAT.exe [2013-01-28 16:40:05 | 003,027,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVCORE.DLL [2013-01-28 16:40:05 | 001,975,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll [2013-01-28 16:40:05 | 000,598,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spinstall.exe [2013-01-28 16:40:05 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe [2013-01-28 16:40:05 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spreview.exe [2013-01-28 16:40:05 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe [2013-01-28 16:40:05 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpdd.dll [2013-01-28 16:40:05 | 000,109,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll [2013-01-28 16:40:05 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll [2013-01-28 16:40:04 | 005,066,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AuthFWSnapin.dll [2013-01-28 16:40:04 | 005,066,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuthFWSnapin.dll [2013-01-28 16:40:04 | 003,391,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dbgeng.dll [2013-01-28 16:40:04 | 002,067,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d9.dll [2013-01-28 16:40:04 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL [2013-01-28 16:40:04 | 001,632,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll [2013-01-28 16:40:04 | 001,115,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RacEngn.dll [2013-01-28 16:40:04 | 000,867,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFolder.dll [2013-01-28 16:40:03 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll [2013-01-28 16:40:03 | 000,958,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\actxprxy.dll [2013-01-28 16:40:02 | 001,244,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imapi2fs.dll [2013-01-28 16:40:02 | 000,787,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll [2013-01-28 16:40:02 | 000,750,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll [2013-01-28 16:40:02 | 000,695,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netlogon.dll [2013-01-28 16:40:01 | 001,927,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll [2013-01-28 16:40:01 | 001,900,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupapi.dll [2013-01-28 16:40:01 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certmgr.dll [2013-01-28 16:40:01 | 001,281,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\werconcpl.dll [2013-01-28 16:40:01 | 001,212,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\propsys.dll [2013-01-28 16:40:01 | 001,008,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\user32.dll [2013-01-28 16:40:01 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll [2013-01-28 16:40:01 | 000,505,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskschd.dll [2013-01-28 16:40:01 | 000,464,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskeng.exe [2013-01-28 16:40:00 | 002,652,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netshell.dll [2013-01-28 16:40:00 | 001,509,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdtctm.dll [2013-01-28 16:40:00 | 001,371,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll [2013-01-28 16:40:00 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceApi.dll [2013-01-28 16:40:00 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll [2013-01-28 16:40:00 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll [2013-01-28 16:40:00 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shlwapi.dll [2013-01-28 16:40:00 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll [2013-01-28 16:40:00 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll [2013-01-28 16:40:00 | 000,299,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsmf.dll [2013-01-28 16:40:00 | 000,295,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\framedynos.dll [2013-01-28 16:40:00 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scavengeui.dll [2013-01-28 16:39:59 | 002,543,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpdshext.dll [2013-01-28 16:39:59 | 002,055,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Query.dll [2013-01-28 16:39:59 | 000,897,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\azroles.dll [2013-01-28 16:39:59 | 000,658,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll [2013-01-28 16:39:59 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll [2013-01-28 16:39:59 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comdlg32.dll [2013-01-28 16:39:59 | 000,524,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmicmiplugin.dll [2013-01-28 16:39:59 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcfgx.dll [2013-01-28 16:39:59 | 000,481,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpps.dll [2013-01-28 16:39:59 | 000,422,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drvstore.dll [2013-01-28 16:39:59 | 000,390,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe [2013-01-28 16:39:59 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsm.exe [2013-01-28 16:39:59 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apphelp.dll [2013-01-28 16:39:59 | 000,297,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ws2_32.dll [2013-01-28 16:39:59 | 000,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsmf.dll [2013-01-28 16:39:59 | 000,266,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QAGENT.DLL [2013-01-28 16:39:59 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3api.dll [2013-01-28 16:39:59 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tcpmonui.dll [2013-01-28 16:39:58 | 002,522,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbgeng.dll [2013-01-28 16:39:58 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL [2013-01-28 16:39:58 | 001,190,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll [2013-01-28 16:39:58 | 001,098,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Vault.dll [2013-01-28 16:39:58 | 000,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll [2013-01-28 16:39:58 | 000,653,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpksetup.exe [2013-01-28 16:39:58 | 000,582,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sxs.dll [2013-01-28 16:39:58 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll [2013-01-28 16:39:58 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcfgx.dll [2013-01-28 16:39:58 | 000,345,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cmd.exe [2013-01-28 16:39:58 | 000,281,600 | ---- | C] (Microsoft) -- C:\Windows\SysNative\DShowRdpFilter.dll [2013-01-28 16:39:57 | 002,151,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmcndmgr.dll [2013-01-28 16:39:57 | 001,808,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pnidui.dll [2013-01-28 16:39:57 | 001,792,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll [2013-01-28 16:39:57 | 001,158,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webservices.dll [2013-01-28 16:39:57 | 000,933,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sqlsrv32.dll [2013-01-28 16:39:57 | 000,732,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imapi2fs.dll [2013-01-28 16:39:57 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ipsmsnap.dll [2013-01-28 16:39:57 | 000,473,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskcomp.dll [2013-01-28 16:39:57 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfds.dll [2013-01-28 16:39:57 | 000,345,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fveapi.dll [2013-01-28 16:39:57 | 000,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wldap32.dll [2013-01-28 16:39:57 | 000,272,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcbuilder.exe [2013-01-28 16:39:57 | 000,252,928 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\DShowRdpFilter.dll [2013-01-28 16:39:57 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsta.dll [2013-01-28 16:39:57 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hgprint.dll [2013-01-28 16:39:57 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\upnp.dll [2013-01-28 16:39:57 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3api.dll [2013-01-28 16:39:57 | 000,049,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll [2013-01-28 16:39:56 | 001,712,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xpsservices.dll [2013-01-28 16:39:56 | 001,555,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certmgr.dll [2013-01-28 16:39:56 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanpref.dll [2013-01-28 16:39:56 | 001,243,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMNetMgr.dll [2013-01-28 16:39:56 | 001,009,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcmde.dll [2013-01-28 16:39:56 | 000,630,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll [2013-01-28 16:39:56 | 000,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\photowiz.dll [2013-01-28 16:39:56 | 000,403,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll [2013-01-28 16:39:56 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvstore.dll [2013-01-28 16:39:56 | 000,285,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\schtasks.exe [2013-01-28 16:39:56 | 000,263,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vpnike.dll [2013-01-28 16:39:56 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mcbuilder.exe [2013-01-28 16:39:56 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prncache.dll [2013-01-28 16:39:56 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\userenv.dll [2013-01-28 16:39:55 | 002,262,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SyncCenter.dll [2013-01-28 16:39:55 | 002,072,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPEncEn.dll [2013-01-28 16:39:55 | 001,082,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll [2013-01-28 16:39:55 | 001,024,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll [2013-01-28 16:39:55 | 000,605,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpeffects.dll [2013-01-28 16:39:55 | 000,501,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSATAPI.dll [2013-01-28 16:39:55 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2013-01-28 16:39:55 | 000,412,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll [2013-01-28 16:39:55 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cmd.exe [2013-01-28 16:39:55 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfds.dll [2013-01-28 16:39:55 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll [2013-01-28 16:39:55 | 000,279,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\framedyn.dll [2013-01-28 16:39:55 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll [2013-01-28 16:39:55 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\framedynos.dll [2013-01-28 16:39:55 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fde.dll [2013-01-28 16:39:54 | 001,050,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printui.dll [2013-01-28 16:39:54 | 000,762,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\azroles.dll [2013-01-28 16:39:54 | 000,571,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mspbda.dll [2013-01-28 16:39:54 | 000,551,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localsec.dll [2013-01-28 16:39:54 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\biocpl.dll [2013-01-28 16:39:54 | 000,503,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imapi2.dll [2013-01-28 16:39:54 | 000,378,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msinfo32.exe [2013-01-28 16:39:54 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netdiagfx.dll [2013-01-28 16:39:54 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scansetting.dll [2013-01-28 16:39:54 | 000,298,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcryptprimitives.dll [2013-01-28 16:39:54 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll [2013-01-28 16:39:54 | 000,253,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcpipcfg.dll [2013-01-28 16:39:54 | 000,244,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spp.dll [2013-01-28 16:39:54 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QSHVHOST.DLL [2013-01-28 16:39:54 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll [2013-01-28 16:39:54 | 000,166,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetpp.dll [2013-01-28 16:39:54 | 000,165,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netid.dll [2013-01-28 16:39:54 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll [2013-01-28 16:39:54 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll [2013-01-28 16:39:53 | 002,755,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\themeui.dll [2013-01-28 16:39:53 | 000,934,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FirewallControlPanel.dll [2013-01-28 16:39:53 | 000,854,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbghelp.dll [2013-01-28 16:39:53 | 000,625,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscms.dll [2013-01-28 16:39:53 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll [2013-01-28 16:39:53 | 000,477,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PhotoScreensaver.scr [2013-01-28 16:39:53 | 000,442,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winspool.drv [2013-01-28 16:39:53 | 000,405,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wisptis.exe [2013-01-28 16:39:53 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wusa.exe [2013-01-28 16:39:53 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskcomp.dll [2013-01-28 16:39:53 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll [2013-01-28 16:39:53 | 000,199,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PkgMgr.exe [2013-01-28 16:39:53 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll [2013-01-28 16:39:53 | 000,187,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpchttp.dll [2013-01-28 16:39:53 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ocsetup.exe [2013-01-28 16:39:53 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IPHLPAPI.DLL [2013-01-28 16:39:53 | 000,144,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\basecsp.dll [2013-01-28 16:39:53 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aitagent.exe [2013-01-28 16:39:52 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIRibbon.dll [2013-01-28 16:39:52 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmsys.cpl [2013-01-28 16:39:52 | 000,780,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll [2013-01-28 16:39:52 | 000,778,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sqlsrv32.dll [2013-01-28 16:39:52 | 000,776,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\calc.exe [2013-01-28 16:39:52 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll [2013-01-28 16:39:52 | 000,459,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXP.dll [2013-01-28 16:39:52 | 000,418,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppwinob.dll [2013-01-28 16:39:52 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapp3hst.dll [2013-01-28 16:39:52 | 000,335,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WinSATAPI.dll [2013-01-28 16:39:52 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapphost.dll [2013-01-28 16:39:52 | 000,264,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\upnp.dll [2013-01-28 16:39:52 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mprapi.dll [2013-01-28 16:39:52 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ocsetapi.dll [2013-01-28 16:39:52 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll [2013-01-28 16:39:52 | 000,128,000 | ---- | C] (Microsoft) -- C:\Windows\SysNative\Robocopy.exe [2013-01-28 16:39:52 | 000,078,720 | ---- | C] (Hewlett-Packard Company) -- C:\Windows\SysNative\drivers\HpSAMD.sys [2013-01-28 16:39:51 | 002,851,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\themeui.dll [2013-01-28 16:39:51 | 002,494,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netshell.dll [2013-01-28 16:39:51 | 001,457,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DxpTaskSync.dll [2013-01-28 16:39:51 | 001,160,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSMPEG2ENC.DLL [2013-01-28 16:39:51 | 000,932,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\printui.dll [2013-01-28 16:39:51 | 000,675,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXPTaskRingtone.dll [2013-01-28 16:39:51 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PerfCenterCPL.dll [2013-01-28 16:39:51 | 000,429,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\puiobj.dll [2013-01-28 16:39:51 | 000,352,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpeffects.dll [2013-01-28 16:39:51 | 000,263,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll [2013-01-28 16:39:51 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\onex.dll [2013-01-28 16:39:51 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scecli.dll [2013-01-28 16:39:51 | 000,179,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys [2013-01-28 16:39:51 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmredir.dll [2013-01-28 16:39:51 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prncache.dll [2013-01-28 16:39:51 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\thumbcache.dll [2013-01-28 16:39:51 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll [2013-01-28 16:39:50 | 001,689,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcenter.dll [2013-01-28 16:39:50 | 001,363,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdc.dll [2013-01-28 16:39:50 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sdengin2.dll [2013-01-28 16:39:50 | 000,799,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll [2013-01-28 16:39:50 | 000,691,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VAN.dll [2013-01-28 16:39:50 | 000,483,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StructuredQuery.dll [2013-01-28 16:39:50 | 000,475,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlangpui.dll [2013-01-28 16:39:50 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wiadefui.dll [2013-01-28 16:39:50 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scesrv.dll [2013-01-28 16:39:50 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVol.exe [2013-01-28 16:39:50 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scansetting.dll [2013-01-28 16:39:50 | 000,239,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dskquoui.dll [2013-01-28 16:39:50 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\net1.exe [2013-01-28 16:39:50 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rpchttp.dll [2013-01-28 16:39:50 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samcli.dll [2013-01-28 16:39:50 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscapi.dll [2013-01-28 16:39:49 | 002,146,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SyncCenter.dll [2013-01-28 16:39:49 | 001,750,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pnidui.dll [2013-01-28 16:39:49 | 000,782,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webservices.dll [2013-01-28 16:39:49 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appwiz.cpl [2013-01-28 16:39:49 | 000,684,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TabletPC.cpl [2013-01-28 16:39:49 | 000,560,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll [2013-01-28 16:39:49 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastls.dll [2013-01-28 16:39:49 | 000,411,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlangpui.dll [2013-01-28 16:39:49 | 000,340,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srchadmin.dll [2013-01-28 16:39:49 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netdiagfx.dll [2013-01-28 16:39:49 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QSHVHOST.DLL [2013-01-28 16:39:49 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fde.dll [2013-01-28 16:39:49 | 000,112,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe [2013-01-28 16:39:49 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll [2013-01-28 16:39:49 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QUTIL.DLL [2013-01-28 16:39:49 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\regapi.dll [2013-01-28 16:39:49 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupcl.exe [2013-01-28 16:39:49 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscapi.dll [2013-01-28 16:39:48 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMPEG2ENC.DLL [2013-01-28 16:39:48 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuxiliaryDisplayCpl.dll [2013-01-28 16:39:48 | 000,633,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\riched20.dll [2013-01-28 16:39:48 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXPTaskRingtone.dll [2013-01-28 16:39:48 | 000,392,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imapi2.dll [2013-01-28 16:39:48 | 000,372,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mtxclu.dll [2013-01-28 16:39:48 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hgcpl.dll [2013-01-28 16:39:48 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\clusapi.dll [2013-01-28 16:39:48 | 000,300,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msconfig.exe [2013-01-28 16:39:48 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netiohlp.dll [2013-01-28 16:39:48 | 000,166,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\basecsp.dll [2013-01-28 16:39:48 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscmmc.dll [2013-01-28 16:39:48 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdeploy.dll [2013-01-28 16:39:48 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsmproxy.dll [2013-01-28 16:39:48 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mimefilt.dll [2013-01-28 16:39:47 | 002,250,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SensorsCpl.dll [2013-01-28 16:39:47 | 002,193,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\themecpl.dll [2013-01-28 16:39:47 | 001,624,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPEncEn.dll [2013-01-28 16:39:47 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Narrator.exe [2013-01-28 16:39:47 | 000,777,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autochk.exe [2013-01-28 16:39:47 | 000,668,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autochk.exe [2013-01-28 16:39:47 | 000,658,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autofmt.exe [2013-01-28 16:39:47 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll [2013-01-28 16:39:47 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\powercpl.dll [2013-01-28 16:39:47 | 000,359,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eudcedit.exe [2013-01-28 16:39:47 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sharemediacpl.dll [2013-01-28 16:39:47 | 000,355,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Faultrep.dll [2013-01-28 16:39:47 | 000,232,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppcomapi.dll [2013-01-28 16:39:47 | 000,199,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\onex.dll [2013-01-28 16:39:47 | 000,188,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netjoin.dll [2013-01-28 16:39:47 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logoncli.dll [2013-01-28 16:39:47 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netiohlp.dll [2013-01-28 16:39:47 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll [2013-01-28 16:39:47 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nci.dll [2013-01-28 16:39:47 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hbaapi.dll [2013-01-28 16:39:47 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RpcRtRemote.dll [2013-01-28 16:39:47 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vpnikeapi.dll [2013-01-28 16:39:47 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\proquota.exe [2013-01-28 16:39:46 | 001,264,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sdclt.exe [2013-01-28 16:39:46 | 000,933,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmiEngine.dll [2013-01-28 16:39:46 | 000,905,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmsys.cpl [2013-01-28 16:39:46 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontext.dll [2013-01-28 16:39:46 | 000,793,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autoconv.exe [2013-01-28 16:39:46 | 000,763,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autofmt.exe [2013-01-28 16:39:46 | 000,679,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autoconv.exe [2013-01-28 16:39:46 | 000,665,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AuxiliaryDisplayCpl.dll [2013-01-28 16:39:46 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpd_ci.dll [2013-01-28 16:39:46 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshipsec.dll [2013-01-28 16:39:46 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\powercpl.dll [2013-01-28 16:39:46 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanui.dll [2013-01-28 16:39:46 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ipsmsnap.dll [2013-01-28 16:39:46 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msihnd.dll [2013-01-28 16:39:46 | 000,303,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msinfo32.exe [2013-01-28 16:39:46 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\srchadmin.dll [2013-01-28 16:39:46 | 000,222,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanconn.dll [2013-01-28 16:39:46 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapphost.dll [2013-01-28 16:39:46 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\framedyn.dll [2013-01-28 16:39:46 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tcpipcfg.dll [2013-01-28 16:39:46 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\schtasks.exe [2013-01-28 16:39:46 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QAGENT.DLL [2013-01-28 16:39:46 | 000,171,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\scsiport.sys [2013-01-28 16:39:46 | 000,168,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcdsrv.dll [2013-01-28 16:39:46 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msutb.dll [2013-01-28 16:39:46 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prntvpt.dll [2013-01-28 16:39:46 | 000,155,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscorier.dll [2013-01-28 16:39:46 | 000,154,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscorier.dll [2013-01-28 16:39:46 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shsetup.dll [2013-01-28 16:39:46 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe [2013-01-28 16:39:46 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netid.dll [2013-01-28 16:39:46 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll [2013-01-28 16:39:46 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\regapi.dll [2013-01-28 16:39:46 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mimefilt.dll [2013-01-28 16:39:45 | 002,217,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bootres.dll [2013-01-28 16:39:45 | 001,326,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanpref.dll [2013-01-28 16:39:45 | 001,227,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdc.dll [2013-01-28 16:39:45 | 001,202,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DiagCpl.dll [2013-01-28 16:39:45 | 001,066,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Display.dll [2013-01-28 16:39:45 | 001,003,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMNetMgr.dll [2013-01-28 16:39:45 | 000,957,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mblctr.exe [2013-01-28 16:39:45 | 000,933,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Vault.dll [2013-01-28 16:39:45 | 000,812,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpccpl.dll [2013-01-28 16:39:45 | 000,749,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\batmeter.dll [2013-01-28 16:39:45 | 000,625,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usercpl.dll [2013-01-28 16:39:45 | 000,624,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll [2013-01-28 16:39:45 | 000,433,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MCEWMDRMNDBootstrap.dll [2013-01-28 16:39:45 | 000,372,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll [2013-01-28 16:39:45 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll [2013-01-28 16:39:45 | 000,307,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scesrv.dll [2013-01-28 16:39:45 | 000,250,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ksproxy.ax [2013-01-28 16:39:45 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpsrcwp.dll [2013-01-28 16:39:45 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mprddm.dll [2013-01-28 16:39:45 | 000,098,816 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\Robocopy.exe [2013-01-28 16:39:45 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSTPager.ax [2013-01-28 16:39:45 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nci.dll [2013-01-28 16:39:45 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys [2013-01-28 16:39:45 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll [2013-01-28 16:39:44 | 001,400,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DxpTaskSync.dll [2013-01-28 16:39:44 | 001,040,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Display.dll [2013-01-28 16:39:44 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prnfldr.dll [2013-01-28 16:39:44 | 000,403,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\untfs.dll [2013-01-28 16:39:44 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\termmgr.dll [2013-01-28 16:39:44 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\puiobj.dll [2013-01-28 16:39:44 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mtxclu.dll [2013-01-28 16:39:44 | 000,300,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pdh.dll [2013-01-28 16:39:44 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eudcedit.exe [2013-01-28 16:39:44 | 000,279,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxdiagn.dll [2013-01-28 16:39:44 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSAC3ENC.DLL [2013-01-28 16:39:44 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskmgr.exe [2013-01-28 16:39:44 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskmgr.exe [2013-01-28 16:39:44 | 000,225,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVolSSO.dll [2013-01-28 16:39:44 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasppp.dll [2013-01-28 16:39:44 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll [2013-01-28 16:39:44 | 000,155,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ataport.sys [2013-01-28 16:39:44 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll [2013-01-28 16:39:44 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logoncli.dll [2013-01-28 16:39:44 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WPDShServiceObj.dll [2013-01-28 16:39:44 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shsetup.dll [2013-01-28 16:39:44 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hbaapi.dll [2013-01-28 16:39:44 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3cfg.dll [2013-01-28 16:39:44 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\proquota.exe [2013-01-28 16:39:44 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\userinit.exe [2013-01-28 16:39:43 | 003,745,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\accessibilitycpl.dll [2013-01-28 16:39:43 | 002,202,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SensorsCpl.dll [2013-01-28 16:39:43 | 002,157,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\themecpl.dll [2013-01-28 16:39:43 | 000,856,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FirewallControlPanel.dll [2013-01-28 16:39:43 | 000,649,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appwiz.cpl [2013-01-28 16:39:43 | 000,416,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wiadefui.dll [2013-01-28 16:39:43 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PhotoScreensaver.scr [2013-01-28 16:39:43 | 000,366,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\zipfldr.dll [2013-01-28 16:39:43 | 000,349,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slui.exe [2013-01-28 16:39:43 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msieftp.dll [2013-01-28 16:39:43 | 000,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hgcpl.dll [2013-01-28 16:39:43 | 000,233,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\defaultlocationcpl.dll [2013-01-28 16:39:43 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL [2013-01-28 16:39:43 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppcomapi.dll [2013-01-28 16:39:43 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasppp.dll [2013-01-28 16:39:43 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll [2013-01-28 16:39:43 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscmmc.dll [2013-01-28 16:39:43 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\userinit.exe [2013-01-28 16:39:42 | 002,146,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkmap.dll [2013-01-28 16:39:42 | 001,644,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcenter.dll [2013-01-28 16:39:42 | 001,065,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll [2013-01-28 16:39:42 | 000,898,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OobeFldr.dll [2013-01-28 16:39:42 | 000,828,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontext.dll [2013-01-28 16:39:42 | 000,780,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ActionCenter.dll [2013-01-28 16:39:42 | 000,769,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sud.dll [2013-01-28 16:39:42 | 000,740,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\batmeter.dll [2013-01-28 16:39:42 | 000,638,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VAN.dll [2013-01-28 16:39:42 | 000,600,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PerfCenterCPL.dll [2013-01-28 16:39:42 | 000,600,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\usercpl.dll [2013-01-28 16:39:42 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll [2013-01-28 16:39:42 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceCenter.dll [2013-01-28 16:39:42 | 000,472,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\azroleui.dll [2013-01-28 16:39:42 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\localsec.dll [2013-01-28 16:39:42 | 000,410,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanui.dll [2013-01-28 16:39:42 | 000,373,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\intl.cpl [2013-01-28 16:39:42 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcdedit.exe [2013-01-28 16:39:42 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVol.exe [2013-01-28 16:39:42 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mprddm.dll [2013-01-28 16:39:42 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskbarcpl.dll [2013-01-28 16:39:42 | 000,221,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OnLineIDCpl.dll [2013-01-28 16:39:42 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVolSSO.dll [2013-01-28 16:39:42 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scecli.dll [2013-01-28 16:39:42 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twext.dll [2013-01-28 16:39:42 | 000,154,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uxlib.dll [2013-01-28 16:39:42 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\recovery.dll [2013-01-28 16:39:42 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prntvpt.dll [2013-01-28 16:39:42 | 000,080,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscories.dll [2013-01-28 16:39:42 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\w32tm.exe [2013-01-28 16:39:41 | 003,727,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\accessibilitycpl.dll [2013-01-28 16:39:41 | 002,130,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\networkmap.dll [2013-01-28 16:39:41 | 001,003,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll [2013-01-28 16:39:41 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sdcpl.dll [2013-01-28 16:39:41 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bthprops.cpl [2013-01-28 16:39:41 | 000,701,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dsuiext.dll [2013-01-28 16:39:41 | 000,549,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ActionCenterCPL.dll [2013-01-28 16:39:41 | 000,516,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\main.cpl [2013-01-28 16:39:41 | 000,460,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll [2013-01-28 16:39:41 | 000,451,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shwebsvc.dll [2013-01-28 16:39:41 | 000,419,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\systemcpl.dll [2013-01-28 16:39:41 | 000,414,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanmsm.dll [2013-01-28 16:39:41 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwizeng.dll [2013-01-28 16:39:41 | 000,345,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MediaMetadataHandler.dll [2013-01-28 16:39:41 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Faultrep.dll [2013-01-28 16:39:41 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wusa.exe [2013-01-28 16:39:41 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\azroleui.dll [2013-01-28 16:39:41 | 000,312,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MCEWMDRMNDBootstrap.dll [2013-01-28 16:39:41 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\efscore.dll [2013-01-28 16:39:41 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\recdisc.exe [2013-01-28 16:39:41 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSAC3ENC.DLL [2013-01-28 16:39:41 | 000,207,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysclass.dll [2013-01-28 16:39:41 | 000,200,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\syncui.dll [2013-01-28 16:39:41 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VBICodec.ax [2013-01-28 16:39:41 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netplwiz.dll [2013-01-28 16:39:41 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adsldp.dll [2013-01-28 16:39:41 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netjoin.dll [2013-01-28 16:39:41 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autoplay.dll [2013-01-28 16:39:41 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuxiliaryDisplayServices.dll [2013-01-28 16:39:41 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cca.dll [2013-01-28 16:39:41 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\isoburn.exe [2013-01-28 16:39:41 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncryptui.dll [2013-01-28 16:39:41 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdeploy.dll [2013-01-28 16:39:41 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tzutil.exe [2013-01-28 16:39:41 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\httpapi.dll [2013-01-28 16:39:41 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sisbkup.dll [2013-01-28 16:39:40 | 000,755,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sud.dll [2013-01-28 16:39:40 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ActionCenter.dll [2013-01-28 16:39:40 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bthprops.cpl [2013-01-28 16:39:40 | 000,641,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll [2013-01-28 16:39:40 | 000,474,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysmon.ocx [2013-01-28 16:39:40 | 000,446,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sqlcese30.dll [2013-01-28 16:39:40 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwizeng.dll [2013-01-28 16:39:40 | 000,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shwebsvc.dll [2013-01-28 16:39:40 | 000,421,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\termmgr.dll [2013-01-28 16:39:40 | 000,395,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prnfldr.dll [2013-01-28 16:39:40 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sysmon.ocx [2013-01-28 16:39:40 | 000,345,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\intl.cpl [2013-01-28 16:39:40 | 000,313,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ReAgent.dll [2013-01-28 16:39:40 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msieftp.dll [2013-01-28 16:39:40 | 000,295,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\photowiz.dll [2013-01-28 16:39:40 | 000,279,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sethc.exe [2013-01-28 16:39:40 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iprtrmgr.dll [2013-01-28 16:39:40 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MediaMetadataHandler.dll [2013-01-28 16:39:40 | 000,240,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MFPlay.dll [2013-01-28 16:39:40 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\defaultlocationcpl.dll [2013-01-28 16:39:40 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OnLineIDCpl.dll [2013-01-28 16:39:40 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll [2013-01-28 16:39:40 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vdsutil.dll [2013-01-28 16:39:40 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ifsutil.dll [2013-01-28 16:39:40 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntlanman.dll [2013-01-28 16:39:40 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3cfg.dll [2013-01-28 16:39:40 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ksxbar.ax [2013-01-28 16:39:40 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ftp.exe [2013-01-28 16:39:40 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sisbkup.dll [2013-01-28 16:39:39 | 000,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OobeFldr.dll [2013-01-28 16:39:39 | 000,781,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll [2013-01-28 16:39:39 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpmde.dll [2013-01-28 16:39:39 | 000,656,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll [2013-01-28 16:39:39 | 000,537,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ActionCenterCPL.dll [2013-01-28 16:39:39 | 000,495,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll [2013-01-28 16:39:39 | 000,484,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DeviceCenter.dll [2013-01-28 16:39:39 | 000,410,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\systemcpl.dll [2013-01-28 16:39:39 | 000,344,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntprint.dll [2013-01-28 16:39:39 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ssText3d.scr [2013-01-28 16:39:39 | 000,321,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\unimdm.tsp [2013-01-28 16:39:39 | 000,297,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntprint.dll [2013-01-28 16:39:39 | 000,282,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iTVData.dll [2013-01-28 16:39:39 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iprtrmgr.dll [2013-01-28 16:39:39 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sethc.exe [2013-01-28 16:39:39 | 000,255,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wavemsp.dll [2013-01-28 16:39:39 | 000,225,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairingFolder.dll [2013-01-28 16:39:39 | 000,205,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\efscore.dll [2013-01-28 16:39:39 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dskquoui.dll [2013-01-28 16:39:39 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcdboot.exe [2013-01-28 16:39:39 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\powercfg.cpl [2013-01-28 16:39:39 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\syncui.dll [2013-01-28 16:39:39 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll [2013-01-28 16:39:39 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autoplay.dll [2013-01-28 16:39:39 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NAPHLPR.DLL [2013-01-28 16:39:39 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srvcli.dll [2013-01-28 16:39:39 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nslookup.exe [2013-01-28 16:39:39 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UserAccountControlSettings.dll [2013-01-28 16:39:39 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSTPager.ax [2013-01-28 16:39:39 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpd3d.dll [2013-01-28 16:39:39 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\acppage.dll [2013-01-28 16:39:39 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanprotdim.dll [2013-01-28 16:39:39 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slwga.dll [2013-01-28 16:39:38 | 001,672,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkexplorer.dll [2013-01-28 16:39:38 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll [2013-01-28 16:39:38 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfrgui.exe [2013-01-28 16:39:38 | 000,592,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll [2013-01-28 16:39:38 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanmsm.dll [2013-01-28 16:39:38 | 000,358,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpdxm.dll [2013-01-28 16:39:38 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshipsec.dll [2013-01-28 16:39:38 | 000,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srrstr.dll [2013-01-28 16:39:38 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpx.dll [2013-01-28 16:39:38 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ReAgent.dll [2013-01-28 16:39:38 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wavemsp.dll [2013-01-28 16:39:38 | 000,217,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll [2013-01-28 16:39:38 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\activeds.dll [2013-01-28 16:39:38 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ksproxy.ax [2013-01-28 16:39:38 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpsrcwp.dll [2013-01-28 16:39:38 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll [2013-01-28 16:39:38 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll [2013-01-28 16:39:38 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\remotepg.dll [2013-01-28 16:39:38 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NAPHLPR.DLL [2013-01-28 16:39:38 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kstvtune.ax [2013-01-28 16:39:38 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppnp.dll [2013-01-28 16:39:38 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\migisol.dll [2013-01-28 16:39:38 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabinet.dll [2013-01-28 16:39:38 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll [2013-01-28 16:39:38 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\isoburn.exe [2013-01-28 16:39:38 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wkscli.dll [2013-01-28 16:39:38 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ftp.exe [2013-01-28 16:39:38 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\httpapi.dll [2013-01-28 16:39:37 | 001,911,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OpcServices.dll [2013-01-28 16:39:37 | 000,899,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Bubbles.scr [2013-01-28 16:39:37 | 000,840,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll [2013-01-28 16:39:37 | 000,685,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dsuiext.dll [2013-01-28 16:39:37 | 000,636,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmdev.dll [2013-01-28 16:39:37 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wvc.dll [2013-01-28 16:39:37 | 000,586,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfrgui.exe [2013-01-28 16:39:37 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\main.cpl [2013-01-28 16:39:37 | 000,444,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wvc.dll [2013-01-28 16:39:37 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wimgapi.dll [2013-01-28 16:39:37 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3ui.dll [2013-01-28 16:39:37 | 000,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsqmcons.exe [2013-01-28 16:39:37 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unimdm.tsp [2013-01-28 16:39:37 | 000,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys [2013-01-28 16:39:37 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PkgMgr.exe [2013-01-28 16:39:37 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstask.dll [2013-01-28 16:39:37 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qasf.dll [2013-01-28 16:39:37 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll [2013-01-28 16:39:37 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ocsetup.exe [2013-01-28 16:39:37 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qcap.dll [2013-01-28 16:39:37 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\net1.exe [2013-01-28 16:39:37 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twext.dll [2013-01-28 16:39:37 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setupugc.exe [2013-01-28 16:39:37 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mapistub.dll [2013-01-28 16:39:37 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mapi32.dll [2013-01-28 16:39:37 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\unimdmat.dll [2013-01-28 16:39:37 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsnmp32.dll [2013-01-28 16:39:37 | 000,051,200 | ---- | C] (Twain Working Group) -- C:\Windows\twain_32.dll [2013-01-28 16:39:37 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tzutil.exe [2013-01-28 16:39:37 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsium.dll [2013-01-28 16:39:37 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WerFaultSecure.exe [2013-01-28 16:39:36 | 001,087,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dbghelp.dll [2013-01-28 16:39:36 | 000,616,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll [2013-01-28 16:39:36 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll [2013-01-28 16:39:36 | 000,363,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diskraid.exe [2013-01-28 16:39:36 | 000,327,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wimserv.exe [2013-01-28 16:39:36 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsAnytimeUpgradeResults.exe [2013-01-28 16:39:36 | 000,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ssText3d.scr [2013-01-28 16:39:36 | 000,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\diskraid.exe [2013-01-28 16:39:36 | 000,254,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qasf.dll [2013-01-28 16:39:36 | 000,242,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Mystify.scr [2013-01-28 16:39:36 | 000,241,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Ribbons.scr [2013-01-28 16:39:36 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\clusapi.dll [2013-01-28 16:39:36 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpencom.dll [2013-01-28 16:39:36 | 000,213,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ActionQueue.dll [2013-01-28 16:39:36 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairingFolder.dll [2013-01-28 16:39:36 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpencom.dll [2013-01-28 16:39:36 | 000,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ifsutil.dll [2013-01-28 16:39:36 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\perfmon.exe [2013-01-28 16:39:36 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpshell.dll [2013-01-28 16:39:36 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvfw32.dll [2013-01-28 16:39:36 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\uxlib.dll [2013-01-28 16:39:36 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nslookup.exe [2013-01-28 16:39:36 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll [2013-01-28 16:39:36 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tlscsp.dll [2013-01-28 16:39:36 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\umb.dll [2013-01-28 16:39:36 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NAPCRYPT.DLL [2013-01-28 16:39:36 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\acppage.dll [2013-01-28 16:39:36 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AzSqlExt.dll [2013-01-28 16:39:36 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netutils.dll [2013-01-28 16:39:36 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\muifontsetup.dll [2013-01-28 16:39:36 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slwga.dll [2013-01-28 16:39:35 | 001,232,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMADMOD.DLL [2013-01-28 16:39:35 | 001,111,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\onexui.dll [2013-01-28 16:39:35 | 000,666,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVSDECD.DLL [2013-01-28 16:39:35 | 000,623,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSAPI.dll [2013-01-28 16:39:35 | 000,402,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll [2013-01-28 16:39:35 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nltest.exe [2013-01-28 16:39:35 | 000,337,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\raschap.dll [2013-01-28 16:39:35 | 000,318,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\raschap.dll [2013-01-28 16:39:35 | 000,299,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpdxm.dll [2013-01-28 16:39:35 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstask.dll [2013-01-28 16:39:35 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iTVData.dll [2013-01-28 16:39:35 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpdwcn.dll [2013-01-28 16:39:35 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxdiagn.dll [2013-01-28 16:39:35 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\input.dll [2013-01-28 16:39:35 | 000,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wpdwcn.dll [2013-01-28 16:39:35 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vdsbas.dll [2013-01-28 16:39:35 | 000,174,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ocsetapi.dll [2013-01-28 16:39:35 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vdsbas.dll [2013-01-28 16:39:35 | 000,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\perfmon.exe [2013-01-28 16:39:35 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\remotepg.dll [2013-01-28 16:39:35 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MdSched.exe [2013-01-28 16:39:35 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rmcast.sys [2013-01-28 16:39:35 | 000,133,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Kswdmcap.ax [2013-01-28 16:39:35 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wiavideo.dll [2013-01-28 16:39:35 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QUTIL.DLL [2013-01-28 16:39:35 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UserAccountControlSettings.dll [2013-01-28 16:39:35 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\bfsvc.exe [2013-01-28 16:39:35 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\runonce.exe [2013-01-28 16:39:35 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\runonce.exe [2013-01-28 16:39:35 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PrintIsolationProxy.dll [2013-01-28 16:39:35 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NAPCRYPT.DLL [2013-01-28 16:39:35 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vpnikeapi.dll [2013-01-28 16:39:35 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\syssetup.dll [2013-01-28 16:39:34 | 001,160,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OpcServices.dll [2013-01-28 16:39:34 | 000,978,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMSPDMOD.DLL [2013-01-28 16:39:34 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Bubbles.scr [2013-01-28 16:39:34 | 000,527,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmnet.dll [2013-01-28 16:39:34 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmdev.dll [2013-01-28 16:39:34 | 000,431,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WPDSp.dll [2013-01-28 16:39:34 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll [2013-01-28 16:39:34 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sqlcese30.dll [2013-01-28 16:39:34 | 000,250,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdv.dll [2013-01-28 16:39:34 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapp3hst.dll [2013-01-28 16:39:34 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pdh.dll [2013-01-28 16:39:34 | 000,232,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bitsadmin.exe [2013-01-28 16:39:34 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceSyncProvider.dll [2013-01-28 16:39:34 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bitsadmin.exe [2013-01-28 16:39:34 | 000,183,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceSyncProvider.dll [2013-01-28 16:39:34 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qcap.dll [2013-01-28 16:39:34 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFPlay.dll [2013-01-28 16:39:34 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mprapi.dll [2013-01-28 16:39:34 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shacct.dll [2013-01-28 16:39:34 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QSVRMGMT.DLL [2013-01-28 16:39:34 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll [2013-01-28 16:39:34 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll [2013-01-28 16:39:34 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shacct.dll [2013-01-28 16:39:34 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpshell.dll [2013-01-28 16:39:34 | 000,104,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logman.exe [2013-01-28 16:39:34 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logagent.exe [2013-01-28 16:39:34 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll [2013-01-28 16:39:34 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\kstvtune.ax [2013-01-28 16:39:34 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logman.exe [2013-01-28 16:39:34 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tabcal.exe [2013-01-28 16:39:34 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spbcd.dll [2013-01-28 16:39:34 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vss_ps.dll [2013-01-28 16:39:34 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unimdmat.dll [2013-01-28 16:39:34 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpd3d.dll [2013-01-28 16:39:34 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscapi.dll [2013-01-28 16:39:34 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsium.dll [2013-01-28 16:39:34 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\lsmproxy.dll [2013-01-28 16:39:33 | 001,148,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10.IME [2013-01-28 16:39:33 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMADMOD.DLL [2013-01-28 16:39:33 | 000,541,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVSDECD.DLL [2013-01-28 16:39:33 | 000,436,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmnet.dll [2013-01-28 16:39:33 | 000,435,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceStatus.dll [2013-01-28 16:39:33 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceStatus.dll [2013-01-28 16:39:33 | 000,392,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll [2013-01-28 16:39:33 | 000,350,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WPDSp.dll [2013-01-28 16:39:33 | 000,318,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll [2013-01-28 16:39:33 | 000,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3ui.dll [2013-01-28 16:39:33 | 000,283,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdv.dll [2013-01-28 16:39:33 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mystify.scr [2013-01-28 16:39:33 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Ribbons.scr [2013-01-28 16:39:33 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VBICodec.ax [2013-01-28 16:39:33 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EhStorAPI.dll [2013-01-28 16:39:33 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\powercfg.cpl [2013-01-28 16:39:33 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\desk.cpl [2013-01-28 16:39:33 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fphc.dll [2013-01-28 16:39:33 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3msm.dll [2013-01-28 16:39:33 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wiavideo.dll [2013-01-28 16:39:33 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Kswdmcap.ax [2013-01-28 16:39:33 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QSVRMGMT.DLL [2013-01-28 16:39:33 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fphc.dll [2013-01-28 16:39:33 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cmstp.exe [2013-01-28 16:39:33 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll [2013-01-28 16:39:33 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\amstream.dll [2013-01-28 16:39:33 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QCLIPROV.DLL [2013-01-28 16:39:33 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\olethk32.dll [2013-01-28 16:39:33 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mapistub.dll [2013-01-28 16:39:33 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertPolEng.dll [2013-01-28 16:39:33 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\takeown.exe [2013-01-28 16:39:33 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PnPUnattend.exe [2013-01-28 16:39:33 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\djoin.exe [2013-01-28 16:39:33 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncryptui.dll [2013-01-28 16:39:33 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\takeown.exe [2013-01-28 16:39:33 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shimgvw.dll [2013-01-28 16:39:33 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\utildll.dll [2013-01-28 16:39:33 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\HotStartUserAgent.dll [2013-01-28 16:39:33 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nrpsrv.dll [2013-01-28 16:39:32 | 000,739,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMSPDMOD.DLL [2013-01-28 16:39:32 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe [2013-01-28 16:39:32 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll [2013-01-28 16:39:32 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\itircl.dll [2013-01-28 16:39:32 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msorcl32.dll [2013-01-28 16:39:32 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diskpart.exe [2013-01-28 16:39:32 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsicli.exe [2013-01-28 16:39:32 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iscsicli.exe [2013-01-28 16:39:32 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mydocs.dll [2013-01-28 16:39:32 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mydocs.dll [2013-01-28 16:39:32 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\desk.cpl [2013-01-28 16:39:32 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setupcln.dll [2013-01-28 16:39:32 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3msm.dll [2013-01-28 16:39:32 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mobsync.exe [2013-01-28 16:39:32 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppinst.dll [2013-01-28 16:39:32 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cmstp.exe [2013-01-28 16:39:32 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdProxy.dll [2013-01-28 16:39:32 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\QCLIPROV.DLL [2013-01-28 16:39:32 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MuiUnattend.exe [2013-01-28 16:39:32 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\amstream.dll [2013-01-28 16:39:32 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cca.dll [2013-01-28 16:39:32 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WavDest.dll [2013-01-28 16:39:32 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spbcd.dll [2013-01-28 16:39:32 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\g711codc.ax [2013-01-28 16:39:32 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vfwwdm32.dll [2013-01-28 16:39:32 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsnmp32.dll [2013-01-28 16:39:32 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MultiDigiMon.exe [2013-01-28 16:39:32 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wkscli.dll [2013-01-28 16:39:32 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pdhui.dll [2013-01-28 16:39:32 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbisurf.ax [2013-01-28 16:39:32 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\relog.exe [2013-01-28 16:39:32 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\relog.exe [2013-01-28 16:39:32 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdmo.dll [2013-01-28 16:39:32 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AzSqlExt.dll [2013-01-28 16:39:32 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netiougc.exe [2013-01-28 16:39:32 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BWUnpairElevated.dll [2013-01-28 16:39:32 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sscore.dll [2013-01-28 16:39:31 | 001,080,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\onexui.dll [2013-01-28 16:39:31 | 001,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10.IME [2013-01-28 16:39:31 | 000,434,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSTIFF.dll [2013-01-28 16:39:31 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe [2013-01-28 16:39:31 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe [2013-01-28 16:39:31 | 000,278,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe [2013-01-28 16:39:31 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\itircl.dll [2013-01-28 16:39:31 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppc.dll [2013-01-28 16:39:31 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpps.dll [2013-01-28 16:39:31 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\diskpart.exe [2013-01-28 16:39:31 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppc.dll [2013-01-28 16:39:31 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eappgnui.dll [2013-01-28 16:39:31 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mobsync.exe [2013-01-28 16:39:31 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eappgnui.dll [2013-01-28 16:39:31 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll [2013-01-28 16:39:31 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll [2013-01-28 16:39:31 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll [2013-01-28 16:39:31 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\manage-bde.exe [2013-01-28 16:39:31 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\resutils.dll [2013-01-28 16:39:31 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\findstr.exe [2013-01-28 16:39:31 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tlscsp.dll [2013-01-28 16:39:31 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastapi.dll [2013-01-28 16:39:31 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetmib1.dll [2013-01-28 16:39:31 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertPolEng.dll [2013-01-28 16:39:31 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\findstr.exe [2013-01-28 16:39:31 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\repair-bde.exe [2013-01-28 16:39:31 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\luainstall.dll [2013-01-28 16:39:31 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ksxbar.ax [2013-01-28 16:39:31 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mciqtz32.dll [2013-01-28 16:39:31 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\choice.exe [2013-01-28 16:39:31 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdiasqmmodule.dll [2013-01-28 16:39:31 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciqtz32.dll [2013-01-28 16:39:31 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe [2013-01-28 16:39:31 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFaultSecure.exe [2013-01-28 16:39:31 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\schedcli.dll [2013-01-28 16:39:31 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netbtugc.exe [2013-01-28 16:39:31 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ReAgentc.exe [2013-01-28 16:39:31 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\syssetup.dll [2013-01-28 16:39:31 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\muifontsetup.dll [2013-01-28 16:39:30 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIRibbonRes.dll [2013-01-28 16:39:30 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIRibbonRes.dll [2013-01-28 16:39:30 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RDPENCDD.dll [2013-01-28 16:39:30 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbcconf.dll [2013-01-28 16:39:30 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetmib1.dll [2013-01-28 16:39:30 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\g711codc.ax [2013-01-28 16:39:30 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\luainstall.dll [2013-01-28 16:39:30 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSMON.dll [2013-01-28 16:39:30 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcconf.dll [2013-01-28 16:39:30 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shimgvw.dll [2013-01-28 16:39:30 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unlodctr.exe [2013-01-28 16:39:30 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbisurf.ax [2013-01-28 16:39:30 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdmo.dll [2013-01-28 16:39:30 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll [2013-01-28 16:39:30 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tdi.sys [2013-01-28 16:39:30 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elsTrans.dll [2013-01-28 16:39:30 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TRAPI.dll [2013-01-28 16:39:30 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdprefdrvapi.dll [2013-01-28 16:39:30 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spopk.dll [2013-01-28 16:39:30 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spopk.dll [2013-01-28 16:39:30 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fixmapi.exe [2013-01-28 16:39:29 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imkr80.ime [2013-01-28 16:39:29 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\napdsnap.dll [2013-01-28 16:39:29 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\napdsnap.dll [2013-01-28 16:39:29 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dsauth.dll [2013-01-28 16:39:29 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbrpm.sys [2013-01-28 16:39:29 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dsauth.dll [2013-01-28 16:39:29 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscdll.dll [2013-01-28 16:39:29 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LogonUI.exe [2013-01-28 16:39:29 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsdchngr.dll [2013-01-28 16:39:29 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bitsperf.dll [2013-01-28 16:39:29 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdprefdrvapi.dll [2013-01-28 16:39:29 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elsTrans.dll [2013-01-28 16:39:29 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TRAPI.dll [2013-01-28 16:39:29 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bitsperf.dll [2013-01-28 16:39:29 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSUNATD.exe [2013-01-28 16:39:29 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\schedcli.dll [2013-01-28 16:39:29 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\perfts.dll [2013-01-28 16:39:29 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sscore.dll [2013-01-28 16:39:28 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imkr80.ime [2013-01-28 16:39:28 | 000,032,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBCAMD2.sys [2013-01-28 16:39:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shgina.dll [2013-01-28 16:39:28 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsdchngr.dll [2013-01-28 16:39:28 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shgina.dll [2013-01-28 16:39:28 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wshirda.dll [2013-01-28 16:39:28 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wshirda.dll [2013-01-28 16:39:28 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\riched32.dll [2013-01-28 16:39:28 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcfgex.dll [2013-01-28 16:39:28 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\riched32.dll [2013-01-28 16:39:27 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL [2013-01-28 16:39:27 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL [2013-01-28 16:39:27 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\C_ISCII.DLL [2013-01-28 16:39:27 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shunimpl.dll [2013-01-28 16:39:27 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\C_ISCII.DLL [2013-01-28 16:39:27 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll [2013-01-28 16:39:27 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll [2013-01-28 16:39:27 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTUQ.DLL [2013-01-28 16:39:27 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTUF.DLL [2013-01-28 16:39:27 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDSG.DLL [2013-01-28 16:39:27 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kbdlk41a.dll [2013-01-28 16:39:27 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDGKL.DLL [2013-01-28 16:39:27 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDCZ1.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTUQ.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTUF.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDSG.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDSF.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDPO.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDNEPR.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\kbdlk41a.dll [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINTAM.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINBEN.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDGR1.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDGR1.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDGKL.DLL [2013-01-28 16:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDCZ1.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDUS.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDUGHR1.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTURME.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDTAJIK.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDSF.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDPO.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDNEPR.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDMON.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDLT1.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINTAM.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINORI.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINMAR.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINKAN.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINHIN.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINBEN.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDBULG.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDBLR.DLL [2013-01-28 16:39:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDBASH.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDUS.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDUGHR1.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTURME.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDTAJIK.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDMON.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDMAORI.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDLT1.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDINTEL.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDGEO.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDGEO.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDBULG.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDBLR.DLL [2013-01-28 16:39:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\KBDBASH.DLL [2013-01-28 16:39:27 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx [2013-01-28 16:39:27 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll [2013-01-28 16:39:27 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx [2013-01-28 16:39:27 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll [2013-01-28 16:39:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-ums-l1-1-0.dll [2013-01-28 16:39:26 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nlsbres.dll [2013-01-28 16:39:26 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nlsbres.dll [2013-01-28 16:39:26 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BlbEvents.dll [2013-01-28 16:39:26 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pifmgr.dll [2013-01-28 16:39:26 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pifmgr.dll [2013-01-28 16:39:26 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwizres.dll [2013-01-28 16:39:26 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwizres.dll [2013-01-28 16:39:26 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDMAORI.DLL [2013-01-28 16:39:26 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINTEL.DLL [2013-01-28 16:39:26 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINORI.DLL [2013-01-28 16:39:26 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINMAR.DLL [2013-01-28 16:39:26 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINKAN.DLL [2013-01-28 16:39:26 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KBDINHIN.DLL [2013-01-28 16:39:23 | 000,399,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpx.dll [2013-01-28 16:39:23 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdscore.dll [2013-01-28 16:39:21 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sqmapi.dll [2013-01-28 16:39:14 | 000,529,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wbemcomn.dll [2013-01-28 16:39:14 | 000,244,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sqmapi.dll [2013-01-28 16:31:47 | 002,565,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\esent.dll [2013-01-28 16:31:47 | 001,699,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\esent.dll [2013-01-28 16:31:47 | 000,189,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys [2013-01-28 16:31:47 | 000,107,904 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdsata.sys [2013-01-28 16:31:47 | 000,027,008 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdxata.sys [2013-01-28 16:31:46 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fsutil.exe [2013-01-28 16:31:46 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fsutil.exe [2013-01-28 16:31:44 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys [2013-01-28 16:31:44 | 000,007,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys [2013-01-28 16:19:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2013-01-28 16:18:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2013-01-28 16:18:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2013-01-28 15:57:20 | 000,048,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fssfltr.sys [2013-01-28 15:57:20 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live [2013-01-28 15:57:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2013-01-28 15:56:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft [2013-01-28 15:56:10 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_42.dll [2013-01-28 15:56:10 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_5.dll [2013-01-28 15:56:10 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_42.dll [2013-01-28 15:56:10 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll [2013-01-28 15:56:08 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll [2013-01-28 15:56:08 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll [2013-01-28 15:55:21 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Windows Live [2013-01-28 15:55:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live [2013-01-28 15:54:57 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\WinRAR [2013-01-28 15:54:57 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2013-01-28 15:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2013-01-28 15:54:53 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR [2013-01-28 15:54:09 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Macromedia [2013-01-28 15:54:09 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Macromedia [2013-01-28 15:54:09 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Adobe [2013-01-28 15:53:58 | 000,697,712 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013-01-28 15:53:58 | 000,074,096 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013-01-28 15:53:57 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed [2013-01-28 15:53:56 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed [2013-01-28 15:17:15 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys [2013-01-28 15:17:15 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wdfres.dll [2013-01-28 15:11:14 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserchoice.exe [2013-01-28 15:10:08 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat [2013-01-28 15:10:08 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2013-01-28 15:10:08 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec [2013-01-28 15:10:08 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2013-01-28 15:10:08 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll [2013-01-28 15:10:08 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll [2013-01-28 15:10:08 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll [2013-01-28 15:10:08 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll [2013-01-28 15:10:08 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll [2013-01-28 15:10:08 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe [2013-01-28 15:10:08 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe [2013-01-28 15:10:08 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2013-01-28 15:10:08 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe [2013-01-28 15:10:08 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll [2013-01-28 15:10:08 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx [2013-01-28 15:10:08 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll [2013-01-28 15:10:08 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2013-01-28 15:10:08 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll [2013-01-28 15:10:08 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe [2013-01-28 15:10:07 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec [2013-01-28 15:10:07 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2013-01-28 15:10:07 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll [2013-01-28 15:10:07 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll [2013-01-28 15:10:07 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll [2013-01-28 15:10:07 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2013-01-28 15:10:07 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll [2013-01-28 15:10:07 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll [2013-01-28 15:10:07 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll [2013-01-28 15:10:07 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe [2013-01-28 15:10:07 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe [2013-01-28 15:10:07 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll [2013-01-28 15:10:07 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll [2013-01-28 15:10:07 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll [2013-01-28 15:10:07 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll [2013-01-28 15:10:07 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll [2013-01-28 15:10:07 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll [2013-01-28 15:10:07 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll [2013-01-28 15:10:07 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe [2013-01-28 15:10:07 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe [2013-01-28 15:10:07 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx [2013-01-28 15:10:07 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll [2013-01-28 15:10:07 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll [2013-01-28 15:10:07 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll [2013-01-28 15:10:07 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll [2013-01-28 15:10:07 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe [2013-01-28 15:10:07 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe [2013-01-28 15:10:06 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat [2013-01-28 15:10:06 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2013-01-28 15:10:06 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2013-01-28 15:10:06 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe [2013-01-28 15:10:06 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe [2013-01-28 15:10:06 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll [2013-01-28 15:10:06 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2013-01-28 15:10:06 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2013-01-28 15:10:06 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll [2013-01-28 15:10:06 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2013-01-28 15:10:06 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll [2013-01-28 15:02:23 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2013-01-28 15:02:23 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2013-01-28 15:02:23 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll [2013-01-28 15:02:23 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll [2013-01-28 15:02:23 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll [2013-01-28 15:02:23 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll [2013-01-28 15:02:00 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll [2013-01-28 15:01:59 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll [2013-01-28 15:01:59 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe [2013-01-28 15:01:59 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll [2013-01-28 14:58:45 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imagehlp.dll [2013-01-28 14:58:45 | 000,023,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fs_rec.sys [2013-01-28 14:53:10 | 000,750,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll [2013-01-28 14:53:10 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll [2013-01-28 14:52:29 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll [2013-01-28 14:52:29 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll [2013-01-28 14:52:29 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe [2013-01-28 14:52:28 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll [2013-01-28 14:52:28 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll [2013-01-28 14:52:28 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll [2013-01-28 14:52:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll [2013-01-28 14:52:26 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll [2013-01-28 14:52:26 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll [2013-01-28 14:52:17 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpnet.dll [2013-01-28 14:52:17 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpnet.dll [2013-01-28 14:52:17 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll [2013-01-28 14:52:17 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpnaddr.dll [2013-01-28 14:52:17 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpnaddr.dll [2013-01-28 14:52:16 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usp10.dll [2013-01-28 14:52:16 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2013-01-28 14:52:15 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wpc.dll [2013-01-28 14:52:15 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\fpb.rs [2013-01-28 14:52:15 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysNative\fpb.rs [2013-01-28 14:52:15 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc-nz.rs [2013-01-28 14:52:15 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc-nz.rs [2013-01-28 14:52:15 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegibbfc.rs [2013-01-28 14:52:15 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegibbfc.rs [2013-01-28 14:52:15 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\csrr.rs [2013-01-28 14:52:15 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysNative\csrr.rs [2013-01-28 14:52:15 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cob-au.rs [2013-01-28 14:52:15 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cob-au.rs [2013-01-28 14:52:15 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\usk.rs [2013-01-28 14:52:15 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysNative\usk.rs [2013-01-28 14:52:15 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\grb.rs [2013-01-28 14:52:15 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysNative\grb.rs [2013-01-28 14:52:15 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-pt.rs [2013-01-28 14:52:15 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-pt.rs [2013-01-28 14:52:15 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi.rs [2013-01-28 14:52:15 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi.rs [2013-01-28 14:52:15 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\djctq.rs [2013-01-28 14:52:15 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysNative\djctq.rs [2013-01-28 14:52:14 | 002,746,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gameux.dll [2013-01-28 14:52:14 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gameux.dll [2013-01-28 14:52:14 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Wpc.dll [2013-01-28 14:52:14 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cero.rs [2013-01-28 14:52:14 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cero.rs [2013-01-28 14:52:14 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\esrb.rs [2013-01-28 14:52:14 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysNative\esrb.rs [2013-01-28 14:52:14 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc.rs [2013-01-28 14:52:14 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc.rs [2013-01-28 14:52:14 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-fi.rs [2013-01-28 14:52:14 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-fi.rs [2013-01-28 14:52:11 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\profprov.dll [2013-01-28 14:52:01 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll [2013-01-28 14:52:00 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\synceng.dll [2013-01-28 14:52:00 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\synceng.dll [2013-01-28 14:51:59 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll [2013-01-28 14:51:59 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll [2013-01-28 14:51:59 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll [2013-01-28 14:51:59 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe [2013-01-28 14:51:58 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2013-01-28 14:51:58 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll [2013-01-28 14:51:58 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll [2013-01-28 14:51:58 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll [2013-01-28 14:51:58 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll [2013-01-28 14:51:58 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll [2013-01-28 14:51:58 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll [2013-01-28 14:51:58 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll [2013-01-28 14:51:58 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll [2013-01-28 14:51:57 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll [2013-01-28 14:51:57 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll [2013-01-28 14:51:57 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll [2013-01-28 14:51:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll [2013-01-28 14:51:48 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll [2013-01-28 14:51:48 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe [2013-01-28 14:51:48 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll [2013-01-28 14:51:48 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll [2013-01-28 14:51:48 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll [2013-01-28 14:50:49 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll [2013-01-28 14:50:47 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll [2013-01-28 14:50:47 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll [2013-01-28 14:50:45 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe [2013-01-28 14:34:20 | 002,315,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll [2013-01-28 14:34:20 | 002,223,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll [2013-01-28 14:34:20 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll [2013-01-28 14:34:20 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll [2013-01-28 14:34:20 | 000,778,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll [2013-01-28 14:34:20 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe [2013-01-28 14:34:19 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll [2013-01-28 14:34:19 | 000,491,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll [2013-01-28 14:34:19 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll [2013-01-28 14:34:19 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssphtb.dll [2013-01-28 14:34:19 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe [2013-01-28 14:34:19 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll [2013-01-28 14:34:18 | 001,544,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll [2013-01-28 14:34:18 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscntrs.dll [2013-01-28 14:34:07 | 001,464,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll [2013-01-28 14:34:06 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll [2013-01-28 14:34:05 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll [2013-01-28 14:34:04 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll [2013-01-28 14:34:00 | 001,118,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sbe.dll [2013-01-28 14:34:00 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll [2013-01-28 14:34:00 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll [2013-01-28 14:33:59 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sbe.dll [2013-01-28 14:33:59 | 000,259,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax [2013-01-28 14:33:59 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax [2013-01-28 14:33:58 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe [2013-01-28 14:33:58 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe [2013-01-28 14:33:57 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcjt32.dll [2013-01-28 14:33:57 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbctrac.dll [2013-01-28 14:33:57 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbctrac.dll [2013-01-28 14:33:57 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccp32.dll [2013-01-28 14:33:57 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccp32.dll [2013-01-28 14:33:57 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccu32.dll [2013-01-28 14:33:57 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccr32.dll [2013-01-28 14:33:57 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccu32.dll [2013-01-28 14:33:57 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccr32.dll [2013-01-28 14:33:55 | 000,509,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll [2013-01-28 14:33:48 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll [2013-01-28 14:33:48 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll [2013-01-28 14:33:47 | 001,731,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll [2013-01-28 14:33:46 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll [2013-01-28 14:33:46 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll [2013-01-28 14:33:44 | 001,395,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42.dll [2013-01-28 14:33:44 | 001,359,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42u.dll [2013-01-28 14:33:43 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42u.dll [2013-01-28 14:33:43 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42.dll [2013-01-28 14:33:41 | 000,321,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll [2013-01-28 14:33:41 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll [2013-01-28 14:33:39 | 000,861,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll [2013-01-28 14:33:39 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll [2013-01-28 14:33:39 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xmllite.dll [2013-01-28 14:33:38 | 002,871,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe [2013-01-28 14:33:38 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe [2013-01-28 14:33:37 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvinst.exe [2013-01-28 14:33:37 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cfgmgr32.dll [2013-01-28 14:33:37 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\devrtl.dll [2013-01-28 14:33:30 | 001,465,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll [2013-01-28 14:33:30 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll [2013-01-28 14:33:29 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll [2013-01-28 14:33:28 | 000,605,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe [2013-01-28 14:33:28 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll [2013-01-28 14:33:27 | 000,974,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WFS.exe [2013-01-28 14:33:27 | 000,642,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi [2013-01-28 14:33:27 | 000,566,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi [2013-01-28 14:33:27 | 000,518,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe [2013-01-28 14:33:27 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSCOVER.exe [2013-01-28 14:33:27 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll [2013-01-28 14:33:27 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdusb.dll [2013-01-28 14:33:27 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd1394.dll [2013-01-28 14:33:27 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdcom.dll [2013-01-28 14:33:26 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll [2013-01-28 14:33:26 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll [2013-01-28 14:33:26 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax [2013-01-28 14:33:26 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax [2013-01-28 14:33:26 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax [2013-01-28 14:33:26 | 000,104,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Mpeg2Data.ax [2013-01-28 14:33:26 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax [2013-01-28 14:33:26 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSDvbNP.ax [2013-01-28 14:33:26 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mpeg2Data.ax [2013-01-28 14:33:26 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSDvbNP.ax [2013-01-28 14:33:25 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll [2013-01-28 14:33:25 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscacheugc.exe [2013-01-28 14:33:25 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscacheugc.exe [2013-01-28 14:33:23 | 000,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcrt.dll [2013-01-28 14:33:23 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\timedate.cpl [2013-01-28 14:33:23 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\timedate.cpl [2013-01-28 14:33:23 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll [2013-01-28 14:33:22 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll [2013-01-28 14:33:22 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll [2013-01-28 14:33:22 | 000,027,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys [2013-01-28 14:33:21 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prevhost.exe [2013-01-28 14:33:21 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prevhost.exe [2013-01-28 14:17:28 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Mozilla [2013-01-28 14:17:28 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Mozilla [2013-01-28 14:17:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2013-01-28 14:17:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2013-01-28 14:12:24 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\ATI [2013-01-28 14:12:24 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\ATI [2013-01-28 14:11:17 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD [2013-01-28 14:10:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET [2013-01-28 14:05:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel Corporation [2013-01-28 14:04:38 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Intel Corporation [2013-01-28 13:59:47 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll [2013-01-28 13:59:46 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll [2013-01-28 13:58:09 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll [2013-01-28 13:58:09 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe [2013-01-28 13:58:09 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll [2013-01-28 13:58:08 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll [2013-01-28 13:58:08 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll [2013-01-28 13:58:08 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll [2013-01-28 13:58:08 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll [2013-01-28 13:58:08 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe [2013-01-28 13:57:55 | 001,721,576 | R--- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfCoInstaller01009.dll [2013-01-28 13:57:43 | 000,104,560 | ---- | C] (Qualcomm Atheros Co., Ltd.) -- C:\Windows\SysNative\drivers\L1C62x64.sys [2013-01-28 13:57:28 | 000,568,600 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\iaStor.sys [2013-01-28 13:57:28 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Atheros_L1e [2013-01-28 13:57:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Marvell [2013-01-28 13:57:03 | 000,083,968 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQAPO.dll [2013-01-28 13:56:54 | 000,414,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\difxapi.dll [2013-01-28 13:56:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VIA [2013-01-28 13:56:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield [2013-01-28 13:56:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel [2013-01-28 13:56:37 | 000,000,000 | ---D | C] -- C:\Program Files\Intel [2013-01-28 13:56:28 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2013-01-28 13:56:27 | 000,053,248 | ---- | C] (Intel(R) Corp) -- C:\Windows\SysWow64\CSVer.dll [2013-01-28 13:56:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent [2013-01-28 13:56:16 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information [2013-01-28 13:56:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel [2013-01-28 13:56:15 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\InstallShield [2013-01-28 13:54:10 | 000,000,000 | R--D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2013-01-28 13:54:10 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Searches [2013-01-28 13:54:10 | 000,000,000 | R--D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2013-01-28 13:54:04 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Identities [2013-01-28 13:54:03 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Contacts [2013-01-28 13:54:02 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\VirtualStore [2013-01-28 13:54:00 | 000,000,000 | --SD | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Videos [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Saved Games [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Pictures [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Music [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Links [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Favorites [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Downloads [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Documents [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\Desktop [2013-01-28 13:54:00 | 000,000,000 | R--D | C] -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Ustawienia lokalne [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\AppData\Local\Temporary Internet Files [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Szablony [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\SendTo [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Recent [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\PrintHood [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\NetHood [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Documents\Moje wideo [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Documents\Moje obrazy [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Moje dokumenty [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Documents\Moja muzyka [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Menu Start [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\AppData\Local\Historia [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Dane aplikacji [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\AppData\Local\Dane aplikacji [2013-01-28 13:54:00 | 000,000,000 | -HSD | C] -- C:\Users\Arturo\Cookies [2013-01-28 13:54:00 | 000,000,000 | -H-D | C] -- C:\Users\Arturo\AppData [2013-01-28 13:54:00 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Temp [2013-01-28 13:54:00 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Local\Microsoft [2013-01-28 13:54:00 | 000,000,000 | ---D | C] -- C:\Users\Arturo\AppData\Roaming\Media Center Programs [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\ProgramData\Ulubione [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\ProgramData\Szablony [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\Recovery [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\ProgramData\Pulpit [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje wideo [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje obrazy [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moja muzyka [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Start [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty [2013-01-28 13:53:56 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dane aplikacji [2013-01-28 13:53:55 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-02-14 10:46:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Arturo\Desktop\OTL.exe [2013-02-14 10:29:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013-02-14 08:45:30 | 000,015,984 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013-02-14 08:45:30 | 000,015,984 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013-02-14 08:28:52 | 000,000,967 | ---- | M] () -- C:\Users\Arturo\Desktop\OCCT.lnk [2013-02-14 08:24:56 | 000,797,902 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013-02-14 08:24:56 | 000,657,076 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013-02-14 08:24:56 | 000,125,314 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013-02-14 08:24:56 | 000,018,002 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2013-02-14 08:24:56 | 000,007,320 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2013-02-14 08:20:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013-02-14 08:20:38 | 2116,173,823 | -HS- | M] () -- C:\hiberfil.sys [2013-02-14 08:13:42 | 000,000,868 | ---- | M] () -- C:\Users\Arturo\Desktop\Core Temp.lnk [2013-02-14 08:12:10 | 000,000,926 | ---- | M] () -- C:\Users\Arturo\Desktop\HD Tune.lnk [2013-02-12 20:36:10 | 000,281,520 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2013-02-12 20:36:10 | 000,281,520 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2013-02-12 20:35:48 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0 [2013-02-12 20:30:18 | 000,312,920 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013-02-12 20:24:25 | 000,002,164 | ---- | M] () -- C:\Users\Arturo\Desktop\Farm Frenzy 3.lnk [2013-02-12 19:43:33 | 000,226,247 | ---- | M] () -- C:\Users\Arturo\Desktop\021213-5382-01.zip [2013-02-12 19:20:26 | 001,552,144 | ---- | M] () -- C:\Users\Arturo\Desktop\021213-5382-01.dmp [2013-02-12 19:20:25 | 524,624,063 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013-02-08 16:08:34 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk [2013-02-08 14:29:15 | 000,697,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013-02-08 14:29:15 | 000,074,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013-02-08 11:55:16 | 000,172,077 | ---- | M] () -- C:\Windows\hpoins27.dat [2013-02-08 11:52:47 | 000,001,377 | ---- | M] () -- C:\Users\Public\Desktop\Centrum obsługi HP.lnk [2013-02-08 07:39:01 | 000,002,239 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Konserwacja 1 kliknięciem.lnk [2013-02-08 07:39:01 | 000,002,197 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk [2013-02-08 01:03:19 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys [2013-02-08 00:36:26 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe [2013-02-07 23:38:06 | 000,812,962 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013-02-07 23:32:42 | 000,001,202 | ---- | M] () -- C:\Users\Public\Desktop\HD VDeck.lnk [2013-02-07 23:02:25 | 000,007,658 | ---- | M] () -- C:\Users\Arturo\AppData\Local\resmon.resmoncfg [2013-02-07 21:09:37 | 000,019,116 | ---- | M] () -- C:\Windows\SysNative\results.xml [2013-02-07 18:25:11 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013-02-07 14:10:12 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2013-02-07 14:07:17 | 000,001,227 | ---- | M] () -- C:\Users\Public\Desktop\Wise Registry Cleaner.lnk [2013-02-07 14:04:37 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif [2013-02-07 13:38:11 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_GeneStor_01009.Wdf [2013-02-05 22:13:55 | 000,000,022 | ---- | M] () -- C:\Windows\tpcsd [2013-02-05 21:50:39 | 000,000,000 | ---- | M] () -- C:\autoexec.bat [2013-02-05 17:20:00 | 000,000,201 | ---- | M] () -- C:\Users\Arturo\Desktop\Serious Sam 3 BFE.url [2013-02-05 14:43:00 | 000,000,659 | ---- | M] () -- C:\Users\Public\Desktop\NBA 2K12.lnk [2013-02-05 14:19:56 | 000,000,720 | ---- | M] () -- C:\Users\Public\Desktop\FIFA 13.lnk [2013-02-05 14:06:47 | 000,000,544 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk [2013-02-05 09:23:32 | 000,095,648 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll [2013-02-05 09:23:31 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll [2013-02-05 09:23:31 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll [2013-02-05 09:23:31 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe [2013-02-05 09:23:31 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe [2013-02-05 09:23:31 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe [2013-02-05 09:21:17 | 000,001,233 | ---- | M] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk [2013-01-30 09:36:35 | 000,001,031 | ---- | M] () -- C:\Users\Arturo\Desktop\NumiMaster.lnk [2013-01-30 09:30:51 | 000,000,277 | ---- | M] () -- C:\Users\Arturo\.JavaPowUpload.properties [2013-01-29 00:19:17 | 000,000,963 | ---- | M] () -- C:\Users\Arturo\Desktop\TechPowerUp GPU-Z.lnk [2013-01-29 00:18:23 | 000,000,869 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk [2013-01-28 23:58:25 | 000,000,696 | ---- | M] () -- C:\Users\Arturo\Desktop\Uplay.lnk [2013-01-28 23:35:25 | 020,534,048 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2013-01-28 23:35:25 | 012,771,784 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll [2013-01-28 23:35:25 | 009,422,672 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2013-01-28 23:35:25 | 002,855,880 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll [2013-01-28 23:35:25 | 002,352,416 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll [2013-01-28 23:35:25 | 001,114,144 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvumdshimx.dll [2013-01-28 23:35:25 | 000,963,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll [2013-01-28 23:35:25 | 000,420,128 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncodeAPI64.dll [2013-01-28 23:35:25 | 000,250,504 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll [2013-01-28 23:35:24 | 025,256,736 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2013-01-28 23:35:24 | 002,911,008 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2013-01-28 23:35:24 | 002,726,176 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2013-01-28 23:35:24 | 002,530,376 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll [2013-01-28 23:35:24 | 001,990,944 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll [2013-01-28 23:35:24 | 001,807,136 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6420294.dll [2013-01-28 23:35:24 | 001,510,176 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6420162.dll [2013-01-28 23:35:22 | 026,946,848 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2013-01-28 23:35:22 | 017,985,632 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2013-01-28 23:35:22 | 015,037,248 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll [2013-01-28 23:35:21 | 017,560,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2013-01-28 23:35:21 | 015,182,544 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll [2013-01-28 23:35:21 | 007,964,168 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2013-01-28 23:35:21 | 007,569,184 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2013-01-28 23:35:21 | 006,267,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2013-01-28 23:35:21 | 000,364,832 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncodeAPI.dll [2013-01-28 23:35:21 | 000,017,738 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb [2013-01-28 23:35:20 | 000,205,184 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll [2013-01-28 22:09:22 | 000,000,648 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 3.lnk [2013-01-28 21:15:13 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk [2013-01-28 21:13:32 | 000,000,659 | ---- | M] () -- C:\Users\Public\Desktop\NBA 2K13.lnk [2013-01-28 20:43:28 | 000,064,519 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2013-01-28 20:43:28 | 000,064,519 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2013-01-28 20:42:02 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2013-01-28 20:30:49 | 000,000,529 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk [2013-01-28 19:49:53 | 000,001,100 | ---- | M] () -- C:\Users\Public\Desktop\LibreOffice 3.6.lnk [2013-01-28 17:11:42 | 000,175,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msclmd.dll [2013-01-28 17:11:42 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msclmd.dll [2013-01-28 17:04:57 | 000,000,905 | ---- | M] () -- C:\Users\Public\Desktop\AIMP3.lnk [2013-01-28 17:03:04 | 000,001,109 | ---- | M] () -- C:\Users\Arturo\Desktop\RadioSure.lnk [2013-01-28 17:02:32 | 000,002,086 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk [2013-01-28 17:01:48 | 000,001,748 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2013-01-28 16:59:29 | 000,000,646 | ---- | M] () -- C:\Users\Arturo\Desktop\Total Commander 64 bit.lnk [2013-01-28 16:58:43 | 000,001,040 | ---- | M] () -- C:\Users\Arturo\Desktop\NapiProjekt.lnk [2013-01-28 16:57:20 | 000,000,919 | ---- | M] () -- C:\Users\Arturo\Desktop\XnView.lnk [2013-01-28 16:57:01 | 001,123,840 | ---- | M] (Karol Winnicki) -- C:\Users\Arturo\Desktop\BESTplayer.exe [2013-01-28 16:51:28 | 000,002,042 | ---- | M] () -- C:\Users\Arturo\Desktop\AVI ReComp.lnk [2013-01-28 16:50:32 | 000,001,045 | ---- | M] () -- C:\Users\Public\Desktop\PDF-XChange Viewer.lnk [2013-01-28 16:00:20 | 000,000,020 | ---- | M] () -- C:\Windows\Ěő± [2013-01-28 15:55:04 | 000,000,983 | ---- | M] () -- C:\Users\Arturo\Desktop\WinRAR.lnk [2013-01-28 15:10:08 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat [2013-01-28 15:10:08 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2013-01-28 15:10:08 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec [2013-01-28 15:10:08 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2013-01-28 15:10:08 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll [2013-01-28 15:10:08 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll [2013-01-28 15:10:08 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll [2013-01-28 15:10:08 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll [2013-01-28 15:10:08 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll [2013-01-28 15:10:08 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe [2013-01-28 15:10:08 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe [2013-01-28 15:10:08 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2013-01-28 15:10:08 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe [2013-01-28 15:10:08 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf [2013-01-28 15:10:08 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll [2013-01-28 15:10:08 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx [2013-01-28 15:10:08 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll [2013-01-28 15:10:08 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2013-01-28 15:10:08 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll [2013-01-28 15:10:08 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe [2013-01-28 15:10:07 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2013-01-28 15:10:07 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec [2013-01-28 15:10:07 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2013-01-28 15:10:07 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll [2013-01-28 15:10:07 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll [2013-01-28 15:10:07 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll [2013-01-28 15:10:07 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2013-01-28 15:10:07 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll [2013-01-28 15:10:07 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll [2013-01-28 15:10:07 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll [2013-01-28 15:10:07 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe [2013-01-28 15:10:07 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe [2013-01-28 15:10:07 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll [2013-01-28 15:10:07 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll [2013-01-28 15:10:07 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll [2013-01-28 15:10:07 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll [2013-01-28 15:10:07 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll [2013-01-28 15:10:07 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll [2013-01-28 15:10:07 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll [2013-01-28 15:10:07 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe [2013-01-28 15:10:07 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe [2013-01-28 15:10:07 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx [2013-01-28 15:10:07 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll [2013-01-28 15:10:07 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll [2013-01-28 15:10:07 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll [2013-01-28 15:10:07 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll [2013-01-28 15:10:07 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe [2013-01-28 15:10:07 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe [2013-01-28 15:10:06 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat [2013-01-28 15:10:06 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2013-01-28 15:10:06 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe [2013-01-28 15:10:06 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe [2013-01-28 15:10:06 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll [2013-01-28 15:10:06 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2013-01-28 15:10:06 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2013-01-28 15:10:06 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll [2013-01-28 15:10:06 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf [2013-01-28 15:10:06 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2013-01-28 15:10:06 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll [2013-01-28 13:59:15 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ViaHub3_01009.Wdf [2013-01-28 13:57:56 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_xhcdrv_01009.Wdf [2013-01-28 13:57:48 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_iusb3hcs_01009.Wdf [2013-01-28 13:54:55 | 000,000,010 | ---- | M] () -- C:\Windows\GSetup.ini [2013-01-25 12:27:37 | 006,392,096 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll [2013-01-25 12:27:37 | 003,472,160 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll [2013-01-25 12:27:32 | 002,555,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll [2013-01-25 12:27:32 | 000,237,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll [2013-01-25 12:27:32 | 000,063,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll [2013-01-23 21:07:02 | 002,977,906 | ---- | M] () -- C:\Windows\SysNative\nvcoproc.bin [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-02-14 08:28:52 | 000,000,967 | ---- | C] () -- C:\Users\Arturo\Desktop\OCCT.lnk [2013-02-14 08:12:10 | 000,000,926 | ---- | C] () -- C:\Users\Arturo\Desktop\HD Tune.lnk [2013-02-12 20:24:25 | 000,002,164 | ---- | C] () -- C:\Users\Arturo\Desktop\Farm Frenzy 3.lnk [2013-02-12 19:43:33 | 000,226,247 | ---- | C] () -- C:\Users\Arturo\Desktop\021213-5382-01.zip [2013-02-12 19:43:11 | 001,552,144 | ---- | C] () -- C:\Users\Arturo\Desktop\021213-5382-01.dmp [2013-02-08 16:08:34 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk [2013-02-08 14:35:41 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\UMonit.exe [2013-02-08 14:35:41 | 000,000,187 | ---- | C] () -- C:\Windows\SysNative\IconCfg0.ini [2013-02-08 14:35:40 | 000,172,097 | ---- | C] () -- C:\Windows\SysWow64\NoMSGuninstall.exe [2013-02-08 14:35:40 | 000,024,786 | ---- | C] () -- C:\Windows\SysWow64\GeneStor.INF [2013-02-08 14:35:40 | 000,001,519 | ---- | C] () -- C:\Windows\SysWow64\_IconCfg0.ini [2013-02-08 14:35:40 | 000,000,822 | ---- | C] () -- C:\Windows\SysWow64\ProductName.ini [2013-02-08 14:35:40 | 000,000,187 | ---- | C] () -- C:\Windows\SysWow64\IconCfg0.ini [2013-02-08 11:52:46 | 000,001,377 | ---- | C] () -- C:\Users\Public\Desktop\Centrum obsługi HP.lnk [2013-02-08 11:52:03 | 000,172,077 | ---- | C] () -- C:\Windows\hpoins27.dat [2013-02-08 11:52:03 | 000,000,442 | ---- | C] () -- C:\Windows\hpomdl27.dat [2013-02-08 07:53:02 | 000,000,868 | ---- | C] () -- C:\Users\Arturo\Desktop\Core Temp.lnk [2013-02-08 07:39:01 | 000,002,239 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Konserwacja 1 kliknięciem.lnk [2013-02-08 07:39:01 | 000,002,209 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk [2013-02-08 07:39:01 | 000,002,197 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk [2013-02-08 00:28:15 | 000,281,520 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2013-02-08 00:28:14 | 002,580,552 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe [2013-02-08 00:28:14 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2013-02-07 23:51:27 | 002,977,906 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin [2013-02-07 23:50:55 | 000,017,738 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb [2013-02-07 23:32:42 | 000,001,214 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk [2013-02-07 23:32:42 | 000,001,202 | ---- | C] () -- C:\Users\Public\Desktop\HD VDeck.lnk [2013-02-07 21:09:37 | 000,019,116 | ---- | C] () -- C:\Windows\SysNative\results.xml [2013-02-07 18:25:11 | 000,001,174 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2013-02-07 18:25:11 | 000,001,162 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2013-02-07 14:10:12 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2013-02-07 14:07:17 | 000,001,227 | ---- | C] () -- C:\Users\Public\Desktop\Wise Registry Cleaner.lnk [2013-02-07 13:38:11 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_GeneStor_01009.Wdf [2013-02-05 22:13:55 | 000,000,022 | ---- | C] () -- C:\Windows\tpcsd [2013-02-05 21:50:39 | 000,000,000 | ---- | C] () -- C:\autoexec.bat [2013-02-05 17:57:37 | 000,007,658 | ---- | C] () -- C:\Users\Arturo\AppData\Local\resmon.resmoncfg [2013-02-05 17:20:00 | 000,000,201 | ---- | C] () -- C:\Users\Arturo\Desktop\Serious Sam 3 BFE.url [2013-02-05 14:43:00 | 000,000,659 | ---- | C] () -- C:\Users\Public\Desktop\NBA 2K12.lnk [2013-02-05 14:19:56 | 000,000,720 | ---- | C] () -- C:\Users\Public\Desktop\FIFA 13.lnk [2013-02-05 14:06:47 | 000,000,544 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk [2013-02-05 09:21:17 | 000,001,233 | ---- | C] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk [2013-01-30 11:06:40 | 000,281,520 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2013-01-30 10:29:57 | 524,624,063 | ---- | C] () -- C:\Windows\MEMORY.DMP [2013-01-30 09:36:35 | 000,001,031 | ---- | C] () -- C:\Users\Arturo\Desktop\NumiMaster.lnk [2013-01-30 09:30:11 | 000,000,277 | ---- | C] () -- C:\Users\Arturo\.JavaPowUpload.properties [2013-01-29 00:37:56 | 224,531,763 | ---- | C] () -- C:\Users\Arturo\Desktop\2012 standard catalog of world paper money 1961 - date - modern issues, 17th ed..pdf [2013-01-29 00:37:11 | 000,641,751 | ---- | C] () -- C:\Users\Arturo\Desktop\Umowa_o_pozyczke_CDE0000239905.pdf [2013-01-29 00:19:17 | 000,000,963 | ---- | C] () -- C:\Users\Arturo\Desktop\TechPowerUp GPU-Z.lnk [2013-01-29 00:18:23 | 000,000,869 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk [2013-01-28 23:58:25 | 000,000,696 | ---- | C] () -- C:\Users\Arturo\Desktop\Uplay.lnk [2013-01-28 22:09:22 | 000,000,648 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 3.lnk [2013-01-28 22:08:54 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0 [2013-01-28 21:15:13 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk [2013-01-28 21:13:32 | 000,000,659 | ---- | C] () -- C:\Users\Public\Desktop\NBA 2K13.lnk [2013-01-28 20:43:24 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [2013-01-28 20:43:23 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2013-01-28 20:42:02 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2013-01-28 20:41:11 | 2116,173,823 | -HS- | C] () -- C:\hiberfil.sys [2013-01-28 20:30:49 | 000,000,529 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk [2013-01-28 19:49:53 | 000,001,100 | ---- | C] () -- C:\Users\Public\Desktop\LibreOffice 3.6.lnk [2013-01-28 17:06:59 | 000,001,305 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk [2013-01-28 17:06:54 | 000,001,374 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk [2013-01-28 17:06:48 | 000,001,458 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk [2013-01-28 17:04:57 | 000,000,905 | ---- | C] () -- C:\Users\Public\Desktop\AIMP3.lnk [2013-01-28 17:03:04 | 000,001,109 | ---- | C] () -- C:\Users\Arturo\Desktop\RadioSure.lnk [2013-01-28 17:02:32 | 000,002,098 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk [2013-01-28 17:02:32 | 000,002,086 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk [2013-01-28 17:01:48 | 000,001,748 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2013-01-28 17:01:48 | 000,001,692 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk [2013-01-28 16:59:29 | 000,000,646 | ---- | C] () -- C:\Users\Arturo\Desktop\Total Commander 64 bit.lnk [2013-01-28 16:58:43 | 000,001,040 | ---- | C] () -- C:\Users\Arturo\Desktop\NapiProjekt.lnk [2013-01-28 16:54:19 | 000,000,919 | ---- | C] () -- C:\Users\Arturo\Desktop\XnView.lnk [2013-01-28 16:52:12 | 000,255,488 | ---- | C] () -- C:\Windows\SysNative\xvidvfw.dll [2013-01-28 16:52:11 | 000,696,832 | ---- | C] () -- C:\Windows\SysNative\xvidcore.dll [2013-01-28 16:52:11 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2013-01-28 16:52:11 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2013-01-28 16:52:11 | 000,173,568 | ---- | C] () -- C:\Windows\SysNative\xvid.ax [2013-01-28 16:52:11 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax [2013-01-28 16:51:28 | 000,002,042 | ---- | C] () -- C:\Users\Arturo\Desktop\AVI ReComp.lnk [2013-01-28 16:50:32 | 000,001,045 | ---- | C] () -- C:\Users\Public\Desktop\PDF-XChange Viewer.lnk [2013-01-28 16:40:05 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd [2013-01-28 16:39:31 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml [2013-01-28 16:39:26 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml [2013-01-28 16:39:26 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml [2013-01-28 16:39:21 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml [2013-01-28 16:00:20 | 000,000,020 | ---- | C] () -- C:\Windows\Ěő± [2013-01-28 15:55:04 | 000,000,983 | ---- | C] () -- C:\Users\Arturo\Desktop\WinRAR.lnk [2013-01-28 15:53:59 | 000,000,930 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013-01-28 15:17:16 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2013-01-28 15:10:08 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf [2013-01-28 15:10:06 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf [2013-01-28 15:01:59 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2013-01-28 14:29:49 | 000,001,912 | ---- | C] () -- C:\Windows\epplauncher.mif [2013-01-28 14:29:25 | 000,812,962 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013-01-28 14:17:24 | 000,001,159 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013-01-28 13:59:45 | 000,031,272 | ---- | C] () -- C:\Windows\SysNative\AppleChargerSrv.exe [2013-01-28 13:59:45 | 000,021,616 | ---- | C] () -- C:\Windows\SysNative\drivers\AppleCharger.sys [2013-01-28 13:59:15 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ViaHub3_01009.Wdf [2013-01-28 13:57:56 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_xhcdrv_01009.Wdf [2013-01-28 13:57:55 | 000,008,227 | R--- | C] () -- C:\Windows\SysNative\drivers\viahub3.cat [2013-01-28 13:57:55 | 000,008,003 | R--- | C] () -- C:\Windows\SysNative\drivers\xhcdrv.cat [2013-01-28 13:57:55 | 000,004,508 | R--- | C] () -- C:\Windows\SysNative\drivers\xhcdrv.inf [2013-01-28 13:57:55 | 000,003,977 | R--- | C] () -- C:\Windows\SysNative\drivers\ViaHub3.inf [2013-01-28 13:57:48 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_iusb3hcs_01009.Wdf [2013-01-28 13:54:55 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini [2013-01-28 13:54:12 | 000,001,417 | ---- | C] () -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [2013-01-28 13:54:10 | 000,001,451 | ---- | C] () -- C:\Users\Arturo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2012-12-14 02:42:30 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2012-12-14 02:42:24 | 000,754,652 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng700.bin [2012-12-14 02:42:24 | 000,598,384 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng700.bin [2012-09-28 02:29:54 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012-09-28 02:29:54 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012-05-02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2012-04-20 13:59:44 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] < End of report >