General Info

File name

smadav2019rev1281.exe

Full analysis
https://app.any.run/tasks/7d5a8108-b9ee-4132-8f93-6557d81dd043
Verdict
Malicious activity
Analysis date
7/18/2019, 12:05:40
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

trojan

fakeav

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

9a620f33464fc3fc27b1b40308936564

SHA1

588cc2c2177567d90cb4b10c2384173062d8e30b

SHA256

8198f9c7f27b32ca5cb46e7cb1b2897c096f63eb723925efe767bfdc71b4f234

SSDEEP

24576:VxGV3TkkSJqqxNTqv/ors3gtuQX5dERofPk78/WsoY1c3BP188k4obg9pUQC2wVY:O90JBg3Y3pdERofPk78ToY698dRQCFGb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes settings of System certificates
  • SMΔRTP.exe (PID: 4028)
Loads the Task Scheduler COM API
  • schtasks.exe (PID: 3936)
Application was dropped or rewritten from another process
  • SMΔRTP.exe (PID: 2748)
  • SmadavProtect32.exe (PID: 2228)
  • SMΔRTP.exe (PID: 4028)
Changes the autorun value in the registry
  • SMΔRTP.exe (PID: 4028)
Loads dropped or rewritten executable
  • SMΔRTP.exe (PID: 2748)
  • regsvr32.exe (PID: 2860)
  • explorer.exe (PID: 304)
  • SMΔRTP.exe (PID: 4028)
  • regsvr32.exe (PID: 2192)
  • ctfmon.exe (PID: 404)
  • SmadavProtect32.exe (PID: 2228)
  • DllHost.exe (PID: 3920)
Actions looks like stealing of personal data
  • SMΔRTP.exe (PID: 2748)
Uses Task Scheduler to run other applications
  • SMΔRTP.exe (PID: 4028)
Registers / Runs the DLL via REGSVR32.EXE
  • smadav2019rev1281.tmp (PID: 2260)
Checks supported languages
  • SMΔRTP.exe (PID: 2748)
Reads the cookies of Mozilla Firefox
  • SMΔRTP.exe (PID: 2748)
Reads Microsoft Outlook installation path
  • SMΔRTP.exe (PID: 2748)
Reads mouse settings
  • SMΔRTP.exe (PID: 2748)
Reads Internet Cache Settings
  • SMΔRTP.exe (PID: 2748)
Adds / modifies Windows certificates
  • SMΔRTP.exe (PID: 4028)
Application launched itself
  • SMΔRTP.exe (PID: 4028)
Executable content was dropped or overwritten
  • smadav2019rev1281.exe (PID: 3648)
  • smadav2019rev1281.exe (PID: 3904)
  • smadav2019rev1281.tmp (PID: 2260)
Reads the cookies of Google Chrome
  • SMΔRTP.exe (PID: 2748)
Creates COM task schedule object
  • regsvr32.exe (PID: 2192)
  • regsvr32.exe (PID: 2860)
Creates files in the user directory
  • SMΔRTP.exe (PID: 4028)
Searches for installed software
  • smadav2019rev1281.tmp (PID: 2260)
Reads the Windows organization settings
  • smadav2019rev1281.tmp (PID: 2260)
Uses TASKKILL.EXE to kill process
  • smadav2019rev1281.tmp (PID: 2260)
Reads Windows owner or organization settings
  • smadav2019rev1281.tmp (PID: 2260)
Application was dropped or rewritten from another process
  • smadav2019rev1281.tmp (PID: 2312)
  • smadav2019rev1281.tmp (PID: 2260)
Loads dropped or rewritten executable
  • smadav2019rev1281.tmp (PID: 2260)
Creates a software uninstall entry
  • smadav2019rev1281.tmp (PID: 2260)
Creates files in the program directory
  • smadav2019rev1281.tmp (PID: 2260)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (45.2%)
.dll
|   Win32 Dynamic Link Library (generic) (20.9%)
.exe
|   Win32 Executable (generic) (14.3%)
.exe
|   Win16/32 Executable Delphi generic (6.6%)
.exe
|   Generic Win/DOS Executable (6.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2013:10:13 10:19:32+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
65024
InitializedDataSize:
72704
UninitializedDataSize:
null
EntryPoint:
0x113bc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
0.0.0.0
ProductVersionNumber:
0.0.0.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
Smadsoft
FileDescription:
SMADAV Setup
FileVersion:
LegalCopyright:
ProductName:
SMADAV
ProductVersion:
12.8.1
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
13-Oct-2013 08:19:32
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
Smadsoft
FileDescription:
SMADAV Setup
FileVersion:
null
LegalCopyright:
null
ProductName:
SMADAV
ProductVersion:
12.8.1
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
13-Oct-2013 08:19:32
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F12C 0x0000F200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.39148
.itext 0x00011000 0x00000B44 0x00000C00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.73207
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.24631
.bss 0x00013000 0x000056B4 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000DD0 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.97188
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x0000FDB8 0x0000FE00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.84335
Resources
1

2

3

4

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
55
Monitored processes
17
Malicious processes
7
Suspicious processes
2

Behavior graph

+
drop and start start drop and start drop and start smadav2019rev1281.exe smadav2019rev1281.tmp no specs smadav2019rev1281.exe smadav2019rev1281.tmp taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs regsvr32.exe no specs smδrtp.exe regsvr32.exe no specs schtasks.exe no specs smadavprotect32.exe no specs explorer.exe no specs ctfmon.exe no specs Thumbnail Cache Out of Proc Server no specs smδrtp.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
304
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\msutb.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\naturallanguage6.dll
c:\windows\system32\nlsdata0009.dll
c:\windows\system32\nlslexicons0009.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\tquery.dll
c:\program files\microsoft office\office14\onfilter.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\users\admin\appdata\local\temp\smadav2019rev1281.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\smadav\smδrtp.exe
c:\program files\smadav\smadhook32.dll

PID
404
CMD
C:\Windows\System32\ctfmon.exe
Path
C:\Windows\System32\ctfmon.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
CTF Loader
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msutb.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\program files\smadav\smadhook32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
3648
CMD
"C:\Users\admin\AppData\Local\Temp\smadav2019rev1281.exe"
Path
C:\Users\admin\AppData\Local\Temp\smadav2019rev1281.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Smadsoft
Description
SMADAV Setup
Version
Modules
Image
c:\users\admin\appdata\local\temp\smadav2019rev1281.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-46pa7.tmp\smadav2019rev1281.tmp

PID
2312
CMD
"C:\Users\admin\AppData\Local\Temp\is-46PA7.tmp\smadav2019rev1281.tmp" /SL5="$60128,1238529,138752,C:\Users\admin\AppData\Local\Temp\smadav2019rev1281.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-46PA7.tmp\smadav2019rev1281.tmp
Indicators
No indicators
Parent process
smadav2019rev1281.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-46pa7.tmp\smadav2019rev1281.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll

PID
3904
CMD
"C:\Users\admin\AppData\Local\Temp\smadav2019rev1281.exe" /SPAWNWND=$F0122 /NOTIFYWND=$60128
Path
C:\Users\admin\AppData\Local\Temp\smadav2019rev1281.exe
Indicators
Parent process
smadav2019rev1281.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Smadsoft
Description
SMADAV Setup
Version
Modules
Image
c:\users\admin\appdata\local\temp\smadav2019rev1281.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-a1vas.tmp\smadav2019rev1281.tmp

PID
2260
CMD
"C:\Users\admin\AppData\Local\Temp\is-A1VAS.tmp\smadav2019rev1281.tmp" /SL5="$130194,1238529,138752,C:\Users\admin\AppData\Local\Temp\smadav2019rev1281.exe" /SPAWNWND=$F0122 /NOTIFYWND=$60128
Path
C:\Users\admin\AppData\Local\Temp\is-A1VAS.tmp\smadav2019rev1281.tmp
Indicators
Parent process
smadav2019rev1281.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-a1vas.tmp\smadav2019rev1281.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\is-9ttpv.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\smadav\smδrtp.exe
c:\program files\smadav\unins000.exe
c:\windows\system32\regsvr32.exe
c:\program files\smadav\smadhook32.dll
c:\windows\system32\wintrust.dll

PID
2632
CMD
"C:\Windows\System32\taskkill.exe" /f /im SMΔRTP.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
smadav2019rev1281.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2972
CMD
"C:\Windows\System32\taskkill.exe" /f /im SMΔRTP.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
smadav2019rev1281.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2568
CMD
"C:\Windows\System32\taskkill.exe" /f /im SmadavProtect32.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
smadav2019rev1281.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
1492
CMD
"C:\Windows\System32\taskkill.exe" /f /im SmadavProtect64.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
smadav2019rev1281.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2860
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\SMADAV\SmadExtc.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
smadav2019rev1281.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\smadav\smadextc.dll

PID
3920
CMD
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Path
C:\Windows\system32\DllHost.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
COM Surrogate
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\propsys.dll
c:\program files\smadav\smadhook32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
4028
CMD
"C:\Program Files\SMADAV\SMΔRTP.exe" rtc
Path
C:\Program Files\SMADAV\SMΔRTP.exe
Indicators
Parent process
smadav2019rev1281.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Smadsoft
Description
Smadav USB Antivirus & Additional Protection
Version
4.128.0001
Modules
Image
c:\program files\smadav\smδrtp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\psapi.dll
c:\program files\smadav\smadengine.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\asycfilt.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\program files\smadav\smadavprotect32.exe
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\smadav\smadhook32.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\users\admin\appdata\local\temp\smadav2019rev1281.exe
c:\users\admin\appdata\local\temp\is-a1vas.tmp\smadav2019rev1281.tmp
c:\program files\qemu-ga\qemu-ga.exe
c:\windows\system32\windanr.exe
c:\program files\common files\adobe\arm\1.0\adobearm.exe
c:\program files\ccleaner\ccleaner.exe

PID
2192
CMD
"C:\Windows\System32\regsvr32.exe" /i /s "C:\Program Files\SMADAV\SmadExtc.dll"
Path
C:\Windows\System32\regsvr32.exe
Indicators
No indicators
Parent process
smadav2019rev1281.tmp
User
admin
Integrity Level
HIGH
Exit code
4
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\smadav\smadextc.dll

PID
3936
CMD
"C:\Windows\system32\schtasks.exe" /create /tn "smadav" /xml "C:\Users\admin\AppData\Roaming\Smadav\smadav.xml"
Path
C:\Windows\system32\schtasks.exe
Indicators
No indicators
Parent process
SMΔRTP.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll

PID
2228
CMD
"C:\Program Files\Smadav\SmadavProtect32.exe"
Path
C:\Program Files\Smadav\SmadavProtect32.exe
Indicators
No indicators
Parent process
SMΔRTP.exe
User
admin
Integrity Level
HIGH
Version:
Company
Smadav Software
Description
Smadav Whitelisting Protection
Version
1, 0, 0, 1
Modules
Image
c:\program files\smadav\smadavprotect32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\smadav\smadhook32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll

PID
2748
CMD
"C:\Program Files\Smadav\SMΔRTP.exe"
Path
C:\Program Files\Smadav\SMΔRTP.exe
Indicators
Parent process
SMΔRTP.exe
User
admin
Integrity Level
HIGH
Version:
Company
Smadsoft
Description
Smadav USB Antivirus & Additional Protection
Version
4.128.0001
Modules
Image
c:\program files\smadav\smδrtp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\psapi.dll
c:\program files\smadav\smadengine.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\program files\qemu-ga\qemu-ga.exe
c:\windows\system32\windanr.exe
c:\users\admin\appdata\local\temp\smadav2019rev1281.exe
c:\users\admin\appdata\local\temp\is-46pa7.tmp\smadav2019rev1281.tmp
c:\users\admin\appdata\local\temp\is-a1vas.tmp\smadav2019rev1281.tmp
c:\program files\smadav\smadavprotect32.exe
c:\windows\system32\uxtheme.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\asycfilt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\explorer.exe
c:\windows\system32\filemgmt.dll
c:\windows\regedit.exe
c:\program files\smadav\smadhook32.dll
c:\windows\microsoft.net\framework\v4.0.30319\aspnet_state.exe
c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehsched.exe
c:\windows\system32\fxssvc.exe
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\program files\google\chrome\application\75.0.3770.100\elevation_service.exe
c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe
c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe
c:\program files\common files\microsoft shared\source engine\ose.exe
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
c:\windows\system32\locator.exe
c:\windows\system32\snmptrap.exe
c:\windows\system32\ui0detect.exe
c:\windows\system32\vds.exe
c:\windows\system32\wbengine.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\dialer.exe
c:\program files\common files\adobe\arm\1.0\adobearm.exe
c:\program files\ccleaner\ccleaner.exe
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\filezilla ftp client\filezilla.exe
c:\program files\mozilla firefox\firefox.exe
c:\program files\opera\opera.exe
c:\program files\microsoft\skype for desktop\skype.exe
c:\program files\videolan\vlc\vlc.exe
c:\program files\dvd maker\dvdmaker.exe
c:\progra~1\micros~1\office14\excel.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\java\jre1.8.0_92\bin\javaws.exe
c:\program files\windows journal\journal.exe
c:\program files\common files\microsoft shared\ink\mip.exe
c:\program files\windows media player\wmplayer.exe
c:\progra~1\micros~1\office14\msaccess.exe
c:\program files\common files\microsoft shared\office14\msoxmled.exe
c:\progra~1\micros~1\office14\mspub.exe
c:\program files\notepad++\notepad++.exe
c:\progra~1\micros~1\office14\ois.exe
c:\progra~1\micros~1\office14\onenote.exe
c:\progra~1\micros~1\office14\outlook.exe
c:\windows\system32\mspaint.exe
c:\progra~1\micros~1\office14\powerpnt.exe
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\snippingtool.exe
c:\program files\common files\microsoft shared\ink\tabtip.exe
c:\program files\windows mail\wab.exe
c:\program files\windows mail\wabmig.exe
c:\program files\winrar\winrar.exe
c:\progra~1\micros~1\office14\winword.exe
c:\program files\windows nt\accessories\wordpad.exe
c:\windows\system32\bdeunlockwizard.exe
c:\windows\system32\infdefaultinstall.exe
c:\msocache\all users\{90140000-003d-0000-0000-0000000ff1ce}-c\ose.exe
c:\msocache\all users\{90140000-003d-0000-0000-0000000ff1ce}-c\setup.exe
c:\msocache\all users\{90140000-0115-0409-0000-0000000ff1ce}-c\dw20.exe
c:\msocache\all users\{90140000-0115-0409-0000-0000000ff1ce}-c\dwtrig20.exe
c:\program files\adobe\acrobat reader dc\reader\acrobroker.exe
c:\program files\adobe\acrobat reader dc\reader\acrord32info.exe
c:\program files\adobe\acrobat reader dc\reader\acrotextextractor.exe
c:\program files\adobe\acrobat reader dc\reader\adelrcp.exe
c:\program files\adobe\acrobat reader dc\reader\adobecollabsync.exe
c:\program files\adobe\acrobat reader dc\reader\arh.exe
c:\program files\adobe\acrobat reader dc\reader\eula.exe
c:\program files\adobe\acrobat reader dc\reader\logtransport2.exe
c:\program files\adobe\acrobat reader dc\reader\reader_sl.exe
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrservicesupdater.exe
c:\program files\adobe\acrobat reader dc\reader\browser\wcchromeextn\wcchromenativemessaginghost.exe
c:\program files\adobe\acrobat reader dc\reader\plug_ins\pi_brokers\32bitmapibroker.exe
c:\program files\ccleaner\uninst.exe
c:\program files\common files\adobe\arm\1.0\adobearmhelper.exe
c:\program files\common files\java\java update\jaureg.exe
c:\program files\common files\java\java update\jucheck.exe
c:\program files\common files\java\java update\jusched.exe
c:\program files\common files\microsoft shared\dw\dw20.exe
c:\program files\common files\microsoft shared\dw\dwtrig20.exe
c:\program files\common files\microsoft shared\equation\eqnedt32.exe
c:\program files\common files\microsoft shared\ink\convertinkstore.exe
c:\program files\common files\microsoft shared\ink\flicklearningwizard.exe
c:\program files\common files\microsoft shared\ink\inkwatson.exe
c:\program files\common files\microsoft shared\ink\inputpersonalization.exe
c:\program files\common files\microsoft shared\ink\shapecollector.exe
c:\program files\common files\microsoft shared\msinfo\msinfo32.exe
c:\program files\common files\microsoft shared\office14\fltldr.exe
c:\program files\common files\microsoft shared\office14\liclua.exe
c:\program files\common files\microsoft shared\office14\oarpmany.exe
c:\program files\common files\microsoft shared\office14\office setup controller\odeploy.exe
c:\program files\common files\microsoft shared\office14\office setup controller\promo.exe
c:\program files\common files\microsoft shared\office14\office setup controller\setup.exe
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\ospprearm.exe
c:\program files\common files\microsoft shared\smart tag\smarttaginstall.exe
c:\program files\common files\microsoft shared\textconv\wksconv\wkconv.exe
c:\program files\common files\microsoft shared\vsto\10.0\vstoinstaller.exe
c:\program files\common files\steam\steamservice.exe
c:\program files\common files\steam\steamservicetmp.exe
c:\program files\filezilla ftp client\fzputtygen.exe
c:\program files\filezilla ftp client\fzsftp.exe
c:\program files\filezilla ftp client\fzstorj.exe
c:\program files\filezilla ftp client\uninstall.exe
c:\program files\google\chrome\application\chrome_proxy.exe
c:\program files\google\chrome\application\75.0.3770.100\notification_helper.exe
c:\program files\google\chrome\application\75.0.3770.100\installer\chrmstp.exe
c:\program files\google\chrome\application\75.0.3770.100\installer\setup.exe
c:\program files\google\update\1.3.34.11\googlecrashhandler.exe
c:\program files\google\update\1.3.34.11\googleupdatebroker.exe
c:\program files\google\update\1.3.34.11\googleupdatecore.exe
c:\program files\google\update\1.3.34.11\googleupdateondemand.exe
c:\program files\google\update\1.3.34.11\googleupdatesetup.exe
c:\program files\google\update\1.3.34.11\googleupdatewebplugin.exe
c:\program files\google\update\download\{430fd4d0-b729-4f61-aa34-91526481799d}\1.3.34.11\googleupdatesetup.exe
c:\program files\google\update\download\{8a69d345-d564-463c-aff1-a69d9e530f96}\75.0.3770.100\chrome_installer.exe
c:\program files\google\update\install\{8c18ddf2-cb95-44ad-bb62-976d248ed2be}\googleupdatesetup.exe
c:\program files\internet explorer\extexport.exe
c:\program files\internet explorer\ieinstal.exe
c:\program files\internet explorer\ielowutil.exe
c:\program files\java\jre1.8.0_92\bin\jabswitch.exe
c:\program files\java\jre1.8.0_92\bin\java-rmi.exe
c:\program files\java\jre1.8.0_92\bin\java.exe
c:\program files\java\jre1.8.0_92\bin\javacpl.exe
c:\program files\java\jre1.8.0_92\bin\javaw.exe
c:\program files\java\jre1.8.0_92\bin\jjs.exe
c:\program files\java\jre1.8.0_92\bin\jp2launcher.exe
c:\program files\java\jre1.8.0_92\bin\keytool.exe
c:\program files\java\jre1.8.0_92\bin\kinit.exe
c:\program files\java\jre1.8.0_92\bin\klist.exe
c:\program files\java\jre1.8.0_92\bin\ktab.exe
c:\program files\java\jre1.8.0_92\bin\orbd.exe
c:\program files\java\jre1.8.0_92\bin\pack200.exe
c:\program files\java\jre1.8.0_92\bin\policytool.exe
c:\program files\java\jre1.8.0_92\bin\rmid.exe
c:\program files\java\jre1.8.0_92\bin\rmiregistry.exe
c:\program files\java\jre1.8.0_92\bin\servertool.exe
c:\program files\java\jre1.8.0_92\bin\ssvagent.exe
c:\program files\java\jre1.8.0_92\bin\tnameserv.exe
c:\program files\java\jre1.8.0_92\bin\unpack200.exe
c:\program files\microsoft\skype for desktop\unins000.exe
c:\program files\microsoft office\office14\clview.exe
c:\program files\microsoft office\office14\cnfnot32.exe
c:\program files\microsoft office\office14\excelcnv.exe
c:\program files\microsoft office\office14\graph.exe
c:\program files\microsoft office\office14\iecontentservice.exe
c:\program files\microsoft office\office14\msohtmed.exe
c:\program files\microsoft office\office14\msosync.exe
c:\program files\microsoft office\office14\msouc.exe
c:\program files\microsoft office\office14\msqry32.exe
c:\program files\microsoft office\office14\mstordb.exe
c:\program files\microsoft office\office14\mstore.exe
c:\program files\microsoft office\office14\namecontrolserver.exe
c:\program files\microsoft office\office14\onenotem.exe
c:\program files\microsoft office\office14\scanpst.exe
c:\program files\microsoft office\office14\selfcert.exe
c:\program files\microsoft office\office14\setlang.exe
c:\program files\microsoft office\office14\vpreview.exe
c:\program files\microsoft office\office14\wordconv.exe
c:\program files\microsoft office\office14\1033\onelev.exe
c:\program files\mozilla firefox\crashreporter.exe
c:\program files\mozilla firefox\maintenanceservice.exe
c:\program files\mozilla firefox\maintenanceservice_installer.exe
c:\program files\mozilla firefox\minidump-analyzer.exe
c:\program files\mozilla firefox\pingsender.exe
c:\program files\mozilla firefox\plugin-container.exe
c:\program files\mozilla firefox\plugin-hang-ui.exe
c:\program files\mozilla firefox\updater.exe
c:\program files\mozilla firefox\uninstall\helper.exe
c:\program files\notepad++\uninstall.exe
c:\program files\notepad++\updater\gup.exe
c:\program files\opera\updatechecker\opera_autoupdate.exe
c:\program files\smadav\smadav-updater.exe
c:\program files\smadav\unins000.exe
c:\program files\videolan\vlc\uninstall.exe
c:\program files\videolan\vlc\vlc-cache-gen.exe
c:\program files\windows defender\mpcmdrun.exe
c:\program files\windows journal\pdialog.exe
c:\program files\windows mail\winmail.exe
c:\program files\windows media player\setup_wm.exe
c:\program files\windows media player\wmlaunch.exe
c:\program files\windows media player\wmpconfig.exe
c:\program files\windows media player\wmpdmc.exe
c:\program files\windows media player\wmpenc.exe
c:\program files\windows media player\wmpnscfg.exe
c:\program files\windows media player\wmprph.exe
c:\program files\windows media player\wmpshare.exe
c:\program files\windows media player\wmpsideshowgadget.exe
c:\program files\windows photo viewer\imagingdevices.exe
c:\program files\winrar\default.sfx
c:\program files\winrar\rar.exe
c:\program files\winrar\uninstall.exe
c:\program files\winrar\unrar.exe
c:\program files\winrar\wincon.sfx
c:\program files\winrar\zip.sfx
c:\programdata\adobe\setup\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\setup.exe
c:\windows\ehome\ehshell.exe
c:\windows\system32\windowsanytimeupgradeui.exe
c:\windows\system32\wfs.exe
c:\windows\system32\xpsrchvw.exe
c:\windows\system32\calc.exe
c:\windows\system32\displayswitch.exe
c:\windows\system32\mblctr.exe
c:\windows\system32\netproj.exe
c:\windows\system32\mstsc.exe
c:\windows\system32\soundrecorder.exe
c:\windows\system32\stikynot.exe
c:\windows\system32\mobsync.exe
c:\windows\system32\rundll32.exe
c:\windows\speech\common\sapisvr.exe
c:\windows\system32\charmap.exe
c:\windows\system32\dfrgui.exe
c:\windows\system32\cleanmgr.exe
c:\windows\system32\perfmon.exe
c:\windows\system32\msinfo32.exe
c:\windows\system32\rstrui.exe
c:\windows\system32\migwiz\postmig.exe
c:\windows\system32\migwiz\migwiz.exe
c:\windows\system32\windowspowershell\v1.0\powershell_ise.exe
c:\windows\system32\odbcad32.exe
c:\windows\system32\iscsicpl.exe
c:\windows\system32\mdsched.exe
c:\windows\system32\msconfig.exe
c:\windows\system32\control.exe
c:\windows\system32\recdisc.exe
c:\windows\system32\msra.exe
c:\windows\installer\{90140000-003d-0000-0000-0000000ff1ce}\promoicon.exe
c:\programdata\package cache\{49697869-be8e-427d-81a0-c334d1d14950}\vc_redist.x86.exe
c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
c:\users\admin\appdata\local\temp\cr_e2cfb.tmp\setup.exe
c:\windows\system32\cmd.exe
c:\windows\system32\notepad.exe
c:\windows\system32\magnify.exe
c:\windows\system32\narrator.exe
c:\windows\system32\osk.exe
c:\windows\system32\eudcedit.exe
c:\windows\alcrmv.exe
c:\windows\bfsvc.exe
c:\windows\fveupdate.exe
c:\windows\helppane.exe
c:\windows\soundman.exe
c:\windows\twunk_32.exe
c:\windows\write.exe
c:\windows\assembly\gac_32\mcupdate\6.1.0.0__31bf3856ad364e35\mcupdate.exe
c:\windows\assembly\gac_32\msbuild\3.5.0.0__b03f5f7f11d50a3a\msbuild.exe
c:\windows\assembly\gac_msil\comsvcconfig\3.0.0.0__b03f5f7f11d50a3a\comsvcconfig.exe
c:\windows\assembly\gac_msil\ehexthost\6.1.0.0__31bf3856ad364e35\ehexthost.exe
c:\windows\assembly\gac_msil\loadmxf\6.1.0.0__31bf3856ad364e35\loadmxf.exe
c:\windows\assembly\gac_msil\narrator\6.1.0.0__31bf3856ad364e35\narrator.exe
c:\windows\assembly\gac_msil\smsvchost\3.0.0.0__b03f5f7f11d50a3a\smsvchost.exe
c:\windows\assembly\gac_msil\wsatconfig\3.0.0.0__b03f5f7f11d50a3a\wsatconfig.exe
c:\windows\boot\pcat\memtest.exe
c:\windows\ehome\ehmsas.exe
c:\windows\ehome\ehprivjob.exe
c:\windows\ehome\ehrec.exe
c:\windows\ehome\ehtray.exe
c:\windows\ehome\ehvid.exe
c:\windows\ehome\mcglidhost.exe
c:\windows\ehome\mcrmgr.exe
c:\windows\ehome\mcspad.exe
c:\windows\ehome\mcx2prov.exe
c:\windows\ehome\mcxtask.exe
c:\windows\ehome\mediacenterweblauncher.exe
c:\windows\ehome\registermceapp.exe
c:\windows\ehome\wtvconverter.exe
c:\windows\ehome\createdisc\sbeserver.exe
c:\windows\installer\$patchcache$\managed\000041091a0090400000000000f01fec\14.0.4763\onelev.exe_1033
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\clview.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\cnfnot32.exe_0004
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\dw20.exe_0001
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\dwtrig20.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\excel.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\fltldr.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\graph.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\iecontentservice.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\msaccess.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\msosync.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\msouc.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\mspub.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\mstordb.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\oarpmany.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\odeploy.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\ois.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\onenote.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\onenotem.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\outlook.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\powerpnt.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\promo.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\scanpst.exe_0002
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\selfcert.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\setup.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\vpreview.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\vstoinstaller_exe_x86.3643236f_fc70_11d3_a536_0090278a1bb8.923c1899_09ae_418b_b39d_a7a9eb6a7951
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\winword.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\wkconv.exe
c:\windows\installer\$patchcache$\managed\00004109d30000000000000000f01fec\14.0.4763\xl12cnv.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\acrobroker.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\acrocef.exe.15ee1c08_ed51_465d_b6f3_fb152b1cc435
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\acrord32.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\acrord32info.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\acrotextextractor.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\adelrcp.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\adobearm.exe.bdca7721_f290_4124_bbed_7a15fe7694eb
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\adobearmhelper.exe.bdca7721_f290_4124_bbed_7a15fe7694eb
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\adobecollabsync.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\armsvc.exe.bdca7721_f290_4124_bbed_7a15fe7694eb
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\eula.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\logtransport2.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\rdrservicesupdater.exe
c:\windows\installer\$patchcache$\managed\68ab67ca7da7ffffb744caf070e41400\15.7.20033\reader_sl.exe
c:\windows\installer\{7a3c7e05-ee37-47d6-99e1-2eb05a3da3f7}\skypeicon.exe
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\apifile_8.ico
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\fdffile_8.ico
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\pdffile_8.ico
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\pdxfile_8.ico
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\sc_reader.ico
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\secstorefile.ico
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\xdpfile_8.ico
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\xfdffile_8.ico
c:\windows\microsoft.net\netfxrepair.exe
c:\windows\microsoft.net\assembly\gac_msil\microsoft.workflow.compiler\v4.0_4.0.0.0__31bf3856ad364e35\microsoft.workflow.compiler.exe
c:\windows\microsoft.net\framework\netfxsbs10.exe
c:\windows\microsoft.net\framework\v2.0.50727\applaunch.exe
c:\windows\microsoft.net\framework\v2.0.50727\aspnet_compiler.exe
c:\windows\microsoft.net\framework\v2.0.50727\aspnet_regbrowsers.exe
c:\windows\microsoft.net\framework\v2.0.50727\aspnet_regiis.exe
c:\windows\microsoft.net\framework\v2.0.50727\aspnet_regsql.exe
c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe
c:\windows\microsoft.net\framework\v2.0.50727\aspnet_wp.exe
c:\windows\microsoft.net\framework\v2.0.50727\caspol.exe
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\windows\microsoft.net\framework\v2.0.50727\ieexec.exe
c:\windows\microsoft.net\framework\v2.0.50727\ilasm.exe
c:\windows\microsoft.net\framework\v2.0.50727\installutil.exe
c:\windows\microsoft.net\framework\v2.0.50727\jsc.exe
c:\windows\microsoft.net\framework\v2.0.50727\msbuild.exe
c:\windows\microsoft.net\framework\v2.0.50727\ngen.exe
c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe
c:\windows\microsoft.net\framework\v2.0.50727\regsvcs.exe
c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
c:\windows\microsoft.net\framework\v3.0\windows communication foundation\servicemodelreg.exe
c:\windows\microsoft.net\framework\v3.0\windows communication foundation\smconfiginstaller.exe
c:\windows\microsoft.net\framework\v3.0\wpf\xamlviewer\xamlviewer_v0300.exe
c:\windows\microsoft.net\framework\v3.5\addinprocess.exe
c:\windows\microsoft.net\framework\v3.5\addinprocess32.exe
c:\windows\microsoft.net\framework\v3.5\addinutil.exe
c:\windows\microsoft.net\framework\v3.5\csc.exe
c:\windows\microsoft.net\framework\v3.5\datasvcutil.exe
c:\windows\microsoft.net\framework\v3.5\edmgen.exe
c:\windows\microsoft.net\framework\v3.5\vbc.exe
c:\windows\microsoft.net\framework\v3.5\wfservicesreg.exe
c:\windows\microsoft.net\framework\v4.0.30319\addinprocess.exe
c:\windows\microsoft.net\framework\v4.0.30319\addinprocess32.exe
c:\windows\microsoft.net\framework\v4.0.30319\addinutil.exe
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\microsoft.net\framework\v4.0.30319\aspnet_compiler.exe
c:\windows\microsoft.net\framework\v4.0.30319\aspnet_regbrowsers.exe
c:\windows\microsoft.net\framework\v4.0.30319\aspnet_regiis.exe
c:\windows\microsoft.net\framework\v4.0.30319\aspnet_regsql.exe
c:\windows\microsoft.net\framework\v4.0.30319\aspnet_wp.exe
c:\windows\microsoft.net\framework\v4.0.30319\caspol.exe
c:\windows\microsoft.net\framework\v4.0.30319\comsvcconfig.exe
c:\windows\microsoft.net\framework\v4.0.30319\csc.exe
c:\windows\microsoft.net\framework\v4.0.30319\cvtres.exe
c:\windows\microsoft.net\framework\v4.0.30319\datasvcutil.exe
c:\windows\microsoft.net\framework\v4.0.30319\dfsvc.exe
c:\windows\microsoft.net\framework\v4.0.30319\edmgen.exe
c:\windows\microsoft.net\framework\v4.0.30319\ilasm.exe
c:\windows\microsoft.net\framework\v4.0.30319\installutil.exe
c:\windows\microsoft.net\framework\v4.0.30319\jsc.exe
c:\windows\microsoft.net\framework\v4.0.30319\microsoft.workflow.compiler.exe
c:\windows\microsoft.net\framework\v4.0.30319\msbuild.exe
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\windows\microsoft.net\framework\v4.0.30319\regtlibv12.exe
c:\windows\microsoft.net\framework\v4.0.30319\servicemodelreg.exe
c:\windows\microsoft.net\framework\v4.0.30319\vbc.exe
c:\windows\microsoft.net\framework\v4.0.30319\wsatconfig.exe
c:\windows\microsoft.net\framework\v4.0.30319\setupcache\v4.7.03062\setup.exe
c:\windows\microsoft.net\framework\v4.0.30319\setupcache\v4.7.03062\setuputility.exe
c:\windows\servicing\gc32\tzupd.exe
c:\windows\system32\adaptertroubleshooter.exe
c:\windows\system32\aitagent.exe
c:\windows\system32\appidcertstorecheck.exe
c:\windows\system32\appidpolicyconverter.exe
c:\windows\system32\arp.exe
c:\windows\system32\at.exe
c:\windows\system32\atbroker.exe
c:\windows\system32\attrib.exe
c:\windows\system32\auditpol.exe
c:\windows\system32\autochk.exe
c:\windows\system32\autoconv.exe
c:\windows\system32\autofmt.exe
c:\windows\system32\axinstui.exe
c:\windows\system32\bcdboot.exe
c:\windows\system32\bcdedit.exe
c:\windows\system32\bdeuisrv.exe
c:\windows\system32\bitsadmin.exe
c:\windows\system32\bootcfg.exe
c:\windows\system32\bridgeunattend.exe
c:\windows\system32\bthudtask.exe
c:\windows\system32\bubbles.scr
c:\windows\system32\cacls.exe
c:\windows\system32\certenrollctrl.exe
c:\windows\system32\certreq.exe
c:\windows\system32\certutil.exe
c:\windows\system32\change.exe
c:\windows\system32\chcp.com
c:\windows\system32\chglogon.exe
c:\windows\system32\chgport.exe
c:\windows\system32\chgusr.exe
c:\windows\system32\chkdsk.exe
c:\windows\system32\chkntfs.exe
c:\windows\system32\choice.exe
c:\windows\system32\cipher.exe
c:\windows\system32\clfs.sys
c:\windows\system32\cliconfg.exe
c:\windows\system32\clip.exe
c:\windows\system32\cmdkey.exe
c:\windows\system32\cmdl32.exe
c:\windows\system32\cmmon32.exe
c:\windows\system32\cmstp.exe
c:\windows\system32\cofire.exe
c:\windows\system32\colorcpl.exe
c:\windows\system32\comp.exe
c:\windows\system32\compact.exe
c:\windows\system32\compmgmtlauncher.exe
c:\windows\system32\computerdefaults.exe
c:\windows\system32\conhost.exe
c:\windows\system32\consent.exe
c:\windows\system32\convert.exe
c:\windows\system32\credwiz.exe
c:\windows\system32\csrstub.exe
c:\windows\system32\cttune.exe
c:\windows\system32\cttunesvr.exe
c:\windows\system32\dccw.exe
c:\windows\system32\dcomcnfg.exe
c:\windows\system32\ddodiag.exe
c:\windows\system32\defrag.exe
c:\windows\system32\devicedisplayobjectprovider.exe
c:\windows\system32\deviceeject.exe
c:\windows\system32\devicepairingwizard.exe
c:\windows\system32\deviceproperties.exe
c:\windows\system32\dfdwiz.exe
c:\windows\system32\diantz.exe
c:\windows\system32\dinotify.exe
c:\windows\system32\diskcomp.com
c:\windows\system32\diskcopy.com
c:\windows\system32\diskpart.exe
c:\windows\system32\diskperf.exe
c:\windows\system32\diskraid.exe
c:\windows\system32\dism.exe
c:\windows\system32\dispdiag.exe
c:\windows\system32\djoin.exe
c:\windows\system32\dnscacheugc.exe
c:\windows\system32\doskey.exe
c:\windows\system32\dpapimig.exe
c:\windows\system32\dpiscaling.exe
c:\windows\system32\dplaysvr.exe
c:\windows\system32\dpnsvr.exe
c:\windows\system32\driverquery.exe
c:\windows\system32\drvinst.exe
c:\windows\system32\dvdplay.exe
c:\windows\system32\dvdupgrd.exe
c:\windows\system32\dwwin.exe
c:\windows\system32\dxdiag.exe
c:\windows\system32\dxpserver.exe
c:\windows\system32\eap3host.exe
c:\windows\system32\efsui.exe
c:\windows\system32\ehstorauthn.exe
c:\windows\system32\esentutl.exe
c:\windows\system32\eventcreate.exe
c:\windows\system32\eventvwr.exe
c:\windows\system32\expand.exe
c:\windows\system32\extrac32.exe
c:\windows\system32\fc.exe
c:\windows\system32\find.exe
c:\windows\system32\findstr.exe
c:\windows\system32\finger.exe
c:\windows\system32\fixmapi.exe
c:\windows\system32\flashplayerapp.exe
c:\windows\system32\fltmc.exe
c:\windows\system32\fontview.exe
c:\windows\system32\forfiles.exe
c:\windows\system32\format.com
c:\windows\system32\fsutil.exe
c:\windows\system32\ftp.exe
c:\windows\system32\fvenotify.exe
c:\windows\system32\fveprompt.exe
c:\windows\system32\fxscover.exe
c:\windows\system32\fxsunatd.exe
c:\windows\system32\getmac.exe
c:\windows\system32\gettingstarted.exe
c:\windows\system32\gpresult.exe
c:\windows\system32\gpscript.exe
c:\windows\system32\gpupdate.exe
c:\windows\system32\graftabl.com
c:\windows\system32\grpconv.exe
c:\windows\system32\hdwwiz.exe
c:\windows\system32\help.exe
c:\windows\system32\hostname.exe
c:\windows\system32\hwrcomp.exe
c:\windows\system32\hwrreg.exe
c:\windows\system32\icacls.exe
c:\windows\system32\icardagt.exe
c:\windows\system32\icsunattend.exe
c:\windows\system32\ie4uinit.exe
c:\windows\system32\ieunatt.exe
c:\windows\system32\iexpress.exe
c:\windows\system32\ipconfig.exe
c:\windows\system32\irftp.exe
c:\windows\system32\iscsicli.exe
c:\windows\system32\isoburn.exe
c:\windows\system32\klist.exe
c:\windows\system32\ksetup.exe
c:\windows\system32\ktmutil.exe
c:\windows\system32\label.exe
c:\windows\system32\locationnotifications.exe
c:\windows\system32\lodctr.exe
c:\windows\system32\logagent.exe
c:\windows\system32\logman.exe
c:\windows\system32\logonui.exe
c:\windows\system32\lpksetup.exe
c:\windows\system32\lpremove.exe
c:\windows\system32\makecab.exe
c:\windows\system32\manage-bde.exe
c:\windows\system32\mcbuilder.exe
c:\windows\system32\mctadmin.exe
c:\windows\system32\mcupdate_authenticamd.dll
c:\windows\system32\mcupdate_genuineintel.dll
c:\windows\system32\mdres.exe
c:\windows\system32\mfpmp.exe
c:\windows\system32\migautoplay.exe
c:\windows\system32\mmc.exe
c:\windows\system32\mode.com
c:\windows\system32\more.com
c:\windows\system32\mountvol.exe
c:\windows\system32\mpnotify.exe
c:\windows\system32\mrinfo.exe
c:\windows\system32\msdt.exe
c:\windows\system32\msfeedssync.exe
c:\windows\system32\msg.exe
c:\windows\system32\mshta.exe
c:\windows\system32\mtstocom.exe
c:\windows\system32\muiunattend.exe
c:\windows\system32\multidigimon.exe
c:\windows\system32\mystify.scr
c:\windows\system32\napstat.exe
c:\windows\system32\nbtstat.exe
c:\windows\system32\ndadmin.exe
c:\windows\system32\net.exe
c:\windows\system32\net1.exe
c:\windows\system32\netbtugc.exe
c:\windows\system32\netcfg.exe
c:\windows\system32\netiougc.exe
c:\windows\system32\netplwiz.exe
c:\windows\system32\netsh.exe
c:\windows\system32\netstat.exe
c:\windows\system32\newdev.exe
c:\windows\system32\nltest.exe
c:\windows\system32\nslookup.exe
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\ntoskrnl.exe
c:\windows\system32\ntprint.exe
c:\windows\system32\ocsetup.exe
c:\windows\system32\odbcconf.exe
c:\windows\system32\openfiles.exe
c:\windows\system32\optionalfeatures.exe
c:\windows\system32\p2phost.exe
c:\windows\system32\pathping.exe
c:\windows\system32\pcalua.exe
c:\windows\system32\pcaui.exe
c:\windows\system32\pcawrk.exe
c:\windows\system32\pcwrun.exe
c:\windows\system32\photoscreensaver.scr
c:\windows\system32\pkgmgr.exe
c:\windows\system32\pnpunattend.exe
c:\windows\system32\pnputil.exe
c:\windows\system32\poqexec.exe
c:\windows\system32\powercfg.exe
c:\windows\system32\presentationhost.exe
c:\windows\system32\presentationsettings.exe
c:\windows\system32\prevhost.exe
c:\windows\system32\print.exe
c:\windows\system32\printbrmui.exe
c:\windows\system32\printfilterpipelinesvc.exe
c:\windows\system32\printisolationhost.exe
c:\windows\system32\printui.exe
c:\windows\system32\proquota.exe
c:\windows\system32\psr.exe
c:\windows\system32\pushprinterconnections.exe
c:\windows\system32\qappsrv.exe
c:\windows\system32\qprocess.exe
c:\windows\system32\query.exe
c:\windows\system32\quser.exe
c:\windows\system32\qwinsta.exe
c:\windows\system32\rasautou.exe
c:\windows\system32\rasdial.exe
c:\windows\system32\raserver.exe
c:\windows\system32\rasphone.exe
c:\windows\system32\rdpclip.exe
c:\windows\system32\rdrleakdiag.exe
c:\windows\system32\reagentc.exe
c:\windows\system32\recover.exe
c:\windows\system32\reg.exe
c:\windows\system32\regedt32.exe
c:\windows\system32\regini.exe
c:\windows\system32\registeriepkeys.exe
c:\windows\system32\regsvr32.exe
c:\windows\system32\rekeywiz.exe
c:\windows\system32\relog.exe
c:\windows\system32\relpost.exe
c:\windows\system32\repair-bde.exe
c:\windows\system32\replace.exe
c:\windows\system32\reset.exe
c:\windows\system32\resmon.exe
c:\windows\system32\ribbons.scr
c:\windows\system32\rmactivate.exe
c:\windows\system32\rmactivate_isv.exe
c:\windows\system32\rmactivate_ssp.exe
c:\windows\system32\rmactivate_ssp_isv.exe
c:\windows\system32\rmclient.exe
c:\windows\system32\robocopy.exe
c:\windows\system32\route.exe
c:\windows\system32\rpcping.exe
c:\windows\system32\rrinstaller.exe
c:\windows\system32\rtlcpl.exe
c:\windows\system32\runas.exe
c:\windows\system32\runlegacycplelevated.exe
c:\windows\system32\runonce.exe
c:\windows\system32\rwinsta.exe
c:\windows\system32\sbunattend.exe
c:\windows\system32\sc.exe
c:\windows\system32\schtasks.exe
c:\windows\system32\scrnsave.scr
c:\windows\system32\sdbinst.exe
c:\windows\system32\sdchange.exe
c:\windows\system32\sdclt.exe
c:\windows\system32\sdiagnhost.exe
c:\windows\system32\secedit.exe
c:\windows\system32\secinit.exe
c:\windows\system32\sethc.exe
c:\windows\system32\setieinstalleddate.exe
c:\windows\system32\setspn.exe
c:\windows\system32\setupcl.exe
c:\windows\system32\setupsnk.exe
c:\windows\system32\setupugc.exe
c:\windows\system32\setx.exe
c:\windows\system32\sfc.exe
c:\windows\system32\shadow.exe
c:\windows\system32\shrpubw.exe
c:\windows\system32\shutdown.exe
c:\windows\system32\sigverif.exe
c:\windows\system32\slui.exe
c:\windows\system32\sndvol.exe
c:\windows\system32\sort.exe
c:\windows\system32\spinstall.exe
c:\windows\system32\spreview.exe
c:\windows\system32\srdelayed.exe
c:\windows\system32\sstext3d.scr
c:\windows\system32\subst.exe
c:\windows\system32\sxstrace.exe
c:\windows\system32\synchost.exe
c:\windows\system32\syskey.exe
c:\windows\system32\systeminfo.exe
c:\windows\system32\systempropertiesadvanced.exe
c:\windows\system32\systempropertiescomputername.exe
c:\windows\system32\systempropertiesdataexecutionprevention.exe
c:\windows\system32\systempropertieshardware.exe
c:\windows\system32\systempropertiesperformance.exe
c:\windows\system32\systempropertiesprotection.exe
c:\windows\system32\systempropertiesremote.exe
c:\windows\system32\systray.exe
c:\windows\system32\tabcal.exe
c:\windows\system32\takeown.exe
c:\windows\system32\tapiunattend.exe
c:\windows\system32\taskkill.exe
c:\windows\system32\tasklist.exe
c:\windows\system32\tcmsetup.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\timeout.exe
c:\windows\system32\tpminit.exe
c:\windows\system32\tracerpt.exe
c:\windows\system32\tracert.exe
c:\windows\system32\tree.com
c:\windows\system32\tscon.exe
c:\windows\system32\tsdiscon.exe
c:\windows\system32\tskill.exe
c:\windows\system32\tstheme.exe
c:\windows\system32\tswbprxy.exe
c:\windows\system32\tswpfwrp.exe
c:\windows\system32\typeperf.exe
c:\windows\system32\tzutil.exe
c:\windows\system32\ucsvc.exe
c:\windows\system32\unlodctr.exe
c:\windows\system32\unregmp2.exe
c:\windows\system32\upnpcont.exe
c:\windows\system32\useraccountcontrolsettings.exe
c:\windows\system32\utilman.exe
c:\windows\system32\vaultcmd.exe
c:\windows\system32\vaultsysui.exe
c:\windows\system32\vdsldr.exe
c:\windows\system32\verclsid.exe
c:\windows\system32\verifier.exe
c:\windows\system32\vmicsvc.exe
c:\windows\system32\vssadmin.exe
c:\windows\system32\w32tm.exe
c:\windows\system32\waitfor.exe
c:\windows\system32\wbadmin.exe
c:\windows\system32\wecutil.exe
c:\windows\system32\werfault.exe
c:\windows\system32\werfaultsecure.exe
c:\windows\system32\wermgr.exe
c:\windows\system32\wevtutil.exe
c:\windows\system32\wextract.exe
c:\windows\system32\where.exe
c:\windows\system32\whoami.exe
c:\windows\system32\wiaacmgr.exe
c:\windows\system32\wimserv.exe
c:\windows\system32\win32k.sys
c:\windows\system32\windowsanytimeupgrade.exe
c:\windows\system32\windowsanytimeupgraderesults.exe
c:\windows\system32\winload.exe
c:\windows\system32\winresume.exe
c:\windows\system32\winrs.exe
c:\windows\system32\winrshost.exe
c:\windows\system32\winsat.exe
c:\windows\system32\winver.exe
c:\windows\system32\wisptis.exe
c:\windows\system32\wksprt.exe
c:\windows\system32\wlanext.exe
c:\windows\system32\wlrmdr.exe
c:\windows\system32\wpdshextautoplay.exe
c:\windows\system32\wpnpinst.exe
c:\windows\system32\wsmanhttpconfig.exe
c:\windows\system32\wsmprovhost.exe
c:\windows\system32\wsqmcons.exe
c:\windows\system32\wuapp.exe
c:\windows\system32\wudfhost.exe
c:\windows\system32\wusa.exe
c:\windows\system32\xcopy.exe
c:\windows\system32\xwizard.exe
c:\windows\system32\boot\winload.exe
c:\windows\system32\boot\winresume.exe
c:\windows\system32\com\comrepl.exe
c:\windows\system32\com\migregdb.exe
c:\windows\system32\dism\dismhost.exe
c:\windows\system32\drivers\1394bus.sys
c:\windows\system32\drivers\1394ohci.sys
c:\windows\system32\drivers\a3e64e55_fl.sys
c:\windows\system32\drivers\a3e64e55_pr.sys
c:\windows\system32\drivers\acpi.sys
c:\windows\system32\drivers\acpipmi.sys
c:\windows\system32\drivers\adp94xx.sys
c:\windows\system32\drivers\adpahci.sys
c:\windows\system32\drivers\adpu320.sys
c:\windows\system32\drivers\afd.sys
c:\windows\system32\drivers\agilevpn.sys
c:\windows\system32\drivers\agp440.sys
c:\windows\system32\drivers\aliide.sys
c:\windows\system32\drivers\amdagp.sys
c:\windows\system32\drivers\amdide.sys
c:\windows\system32\drivers\amdk8.sys
c:\windows\system32\drivers\amdppm.sys
c:\windows\system32\drivers\amdsata.sys
c:\windows\system32\drivers\amdsbs.sys
c:\windows\system32\drivers\amdxata.sys
c:\windows\system32\drivers\appid.sys
c:\windows\system32\drivers\arc.sys
c:\windows\system32\drivers\arcsas.sys
c:\windows\system32\drivers\asyncmac.sys
c:\windows\system32\drivers\atapi.sys
c:\windows\system32\drivers\ataport.sys
c:\windows\system32\drivers\b57nd60x.sys
c:\windows\system32\drivers\battc.sys
c:\windows\system32\drivers\blbdrive.sys
c:\windows\system32\drivers\bowser.sys
c:\windows\system32\drivers\brfiltlo.sys
c:\windows\system32\drivers\bridge.sys
c:\windows\system32\drivers\brserid.sys
c:\windows\system32\drivers\brserwdm.sys
c:\windows\system32\drivers\brusbmdm.sys
c:\windows\system32\drivers\brusbser.sys
c:\windows\system32\drivers\bthmodem.sys
c:\windows\system32\drivers\bxvbdx.sys
c:\windows\system32\drivers\cdfs.sys
c:\windows\system32\drivers\cdrom.sys
c:\windows\system32\drivers\circlass.sys
c:\windows\system32\drivers\classpnp.sys
c:\windows\system32\drivers\cmbatt.sys
c:\windows\system32\drivers\cmdide.sys
c:\windows\system32\drivers\compbatt.sys
c:\windows\system32\drivers\compositebus.sys
c:\windows\system32\drivers\crcdisk.sys
c:\windows\system32\drivers\csc.sys
c:\windows\system32\drivers\dfsc.sys
c:\windows\system32\drivers\discache.sys
c:\windows\system32\drivers\disk.sys
c:\windows\system32\drivers\diskdump.sys
c:\windows\system32\drivers\djsvs.sys
c:\windows\system32\drivers\dmvsc.sys
c:\windows\system32\drivers\dumpata.sys
c:\windows\system32\drivers\dxapi.sys
c:\windows\system32\drivers\dxg.sys
c:\windows\system32\drivers\dxgkrnl.sys
c:\windows\system32\drivers\dxgmms1.sys
c:\windows\system32\drivers\e1g60i32.sys
c:\windows\system32\drivers\elxstor.sys
c:\windows\system32\drivers\evbdx.sys
c:\windows\system32\drivers\exfat.sys
c:\windows\system32\drivers\fastfat.sys
c:\windows\system32\drivers\fdc.sys
c:\windows\system32\drivers\fileinfo.sys
c:\windows\system32\drivers\filetrace.sys
c:\windows\system32\drivers\flpydisk.sys
c:\windows\system32\drivers\fs_rec.sys
c:\windows\system32\drivers\fvevol.sys
c:\windows\system32\drivers\gagp30kx.sys
c:\windows\system32\drivers\hcw85cir.sys
c:\windows\system32\drivers\hdaudbus.sys
c:\windows\system32\drivers\hidbatt.sys
c:\windows\system32\drivers\hidbth.sys
c:\windows\system32\drivers\hidir.sys
c:\windows\system32\drivers\hidusb.sys
c:\windows\system32\drivers\hpsamd.sys
c:\windows\system32\drivers\http.sys
c:\windows\system32\drivers\i8042prt.sys
c:\windows\system32\drivers\iastorv.sys
c:\windows\system32\drivers\iirsp.sys
c:\windows\system32\drivers\intelide.sys
c:\windows\system32\drivers\intelppm.sys
c:\windows\system32\drivers\ipfltdrv.sys
c:\windows\system32\drivers\ipmidrv.sys
c:\windows\system32\drivers\ipnat.sys
c:\windows\system32\drivers\irda.sys
c:\windows\system32\drivers\irenum.sys
c:\windows\system32\drivers\isapnp.sys
c:\windows\system32\drivers\kbdclass.sys
c:\windows\system32\drivers\kbdhid.sys
c:\windows\system32\drivers\ksecpkg.sys
c:\windows\system32\drivers\lltdio.sys
c:\windows\system32\drivers\lsi_fc.sys
c:\windows\system32\drivers\lsi_sas.sys
c:\windows\system32\drivers\lsi_sas2.sys
c:\windows\system32\drivers\lsi_scsi.sys
c:\windows\system32\drivers\luafv.sys
c:\windows\system32\drivers\mcd.sys
c:\windows\system32\drivers\megasas.sys
c:\windows\system32\drivers\megasr.sys
c:\windows\system32\drivers\modem.sys
c:\windows\system32\drivers\monitor.sys
c:\windows\system32\drivers\mouclass.sys
c:\windows\system32\drivers\mouhid.sys
c:\windows\system32\drivers\mountmgr.sys
c:\windows\system32\drivers\mpio.sys
c:\windows\system32\drivers\mpsdrv.sys
c:\windows\system32\drivers\mrxdav.sys
c:\windows\system32\drivers\mrxsmb.sys
c:\windows\system32\drivers\mrxsmb10.sys
c:\windows\system32\drivers\mrxsmb20.sys
c:\windows\system32\drivers\msahci.sys
c:\windows\system32\drivers\msdsm.sys
c:\windows\system32\drivers\msfs.sys
c:\windows\system32\drivers\msisadrv.sys
c:\windows\system32\drivers\msiscsi.sys
c:\windows\system32\drivers\mskssrv.sys
c:\windows\system32\drivers\mssmbios.sys
c:\windows\system32\drivers\mtconfig.sys
c:\windows\system32\drivers\mup.sys
c:\windows\system32\drivers\ndis.sys
c:\windows\system32\drivers\ndiscap.sys
c:\windows\system32\drivers\ndistapi.sys
c:\windows\system32\drivers\ndisuio.sys
c:\windows\system32\drivers\ndiswan.sys
c:\windows\system32\drivers\ndproxy.sys
c:\windows\system32\drivers\netbios.sys
c:\windows\system32\drivers\netbt.sys
c:\windows\system32\drivers\netio.sys
c:\windows\system32\drivers\nfrd960.sys
c:\windows\system32\drivers\npfs.sys
c:\windows\system32\drivers\nsiproxy.sys
c:\windows\system32\drivers\ntfs.sys
c:\windows\system32\drivers\nvraid.sys
c:\windows\system32\drivers\nvstor.sys
c:\windows\system32\drivers\nv_agp.sys
c:\windows\system32\drivers\nwifi.sys
c:\windows\system32\drivers\ohci1394.sys
c:\windows\system32\drivers\pacer.sys
c:\windows\system32\drivers\parport.sys
c:\windows\system32\drivers\partmgr.sys
c:\windows\system32\drivers\parvdm.sys
c:\windows\system32\drivers\pci.sys
c:\windows\system32\drivers\pciide.sys
c:\windows\system32\drivers\pciidex.sys
c:\windows\system32\drivers\pcmcia.sys
c:\windows\system32\drivers\pcw.sys
c:\windows\system32\drivers\peauth.sys
c:\windows\system32\drivers\processr.sys
c:\windows\system32\drivers\ql2300.sys
c:\windows\system32\drivers\ql40xx.sys
c:\windows\system32\drivers\qwavedrv.sys
c:\windows\system32\drivers\rasacd.sys
c:\windows\system32\drivers\rasl2tp.sys
c:\windows\system32\drivers\raspppoe.sys
c:\windows\system32\drivers\raspptp.sys
c:\windows\system32\drivers\rassstp.sys
c:\windows\system32\drivers\rdbss.sys
c:\windows\system32\drivers\rdpbus.sys
c:\windows\system32\drivers\rdpdr.sys
c:\windows\system32\drivers\rdpwd.sys
c:\windows\system32\drivers\rdyboost.sys
c:\windows\system32\drivers\rmcast.sys
c:\windows\system32\drivers\rootmdm.sys
c:\windows\system32\drivers\rspndr.sys
c:\windows\system32\drivers\rtkvac.sys
c:\windows\system32\drivers\sbp2port.sys
c:\windows\system32\drivers\scfilter.sys
c:\windows\system32\drivers\scsiport.sys
c:\windows\system32\drivers\secdrv.sys
c:\windows\system32\drivers\serenum.sys
c:\windows\system32\drivers\serial.sys
c:\windows\system32\drivers\sermouse.sys
c:\windows\system32\drivers\sffdisk.sys
c:\windows\system32\drivers\sffp_mmc.sys
c:\windows\system32\drivers\sffp_sd.sys
c:\windows\system32\drivers\sfloppy.sys
c:\windows\system32\drivers\sisagp.sys
c:\windows\system32\drivers\sisraid2.sys
c:\windows\system32\drivers\sisraid4.sys
c:\windows\system32\drivers\smb.sys
c:\windows\system32\drivers\smclib.sys
c:\windows\system32\drivers\spldr.sys
c:\windows\system32\drivers\spsys.sys
c:\windows\system32\drivers\srv.sys
c:\windows\system32\drivers\srv2.sys
c:\windows\system32\drivers\srvnet.sys
c:\windows\system32\drivers\stexstor.sys
c:\windows\system32\drivers\storport.sys
c:\windows\system32\drivers\storvsc.sys
c:\windows\system32\drivers\swenum.sys
c:\windows\system32\drivers\tape.sys
c:\windows\system32\drivers\tcpip.sys
c:\windows\system32\drivers\tcpipreg.sys
c:\windows\system32\drivers\tdi.sys
c:\windows\system32\drivers\tdpipe.sys
c:\windows\system32\drivers\tdtcp.sys
c:\windows\system32\drivers\tdx.sys
c:\windows\system32\drivers\tssecsrv.sys
c:\windows\system32\drivers\tsusbflt.sys
c:\windows\system32\drivers\tsusbgd.sys
c:\windows\system32\drivers\tunnel.sys
c:\windows\system32\drivers\uagp35.sys
c:\windows\system32\drivers\udfs.sys
c:\windows\system32\drivers\uliagpkx.sys
c:\windows\system32\drivers\umbus.sys
c:\windows\system32\drivers\umpass.sys
c:\windows\system32\drivers\usb8023.sys
c:\windows\system32\drivers\usbccgp.sys
c:\windows\system32\drivers\usbcir.sys
c:\windows\system32\drivers\usbehci.sys
c:\windows\system32\drivers\usbhub.sys
c:\windows\system32\drivers\usbohci.sys
c:\windows\system32\drivers\usbprint.sys
c:\windows\system32\drivers\usbrpm.sys
c:\windows\system32\drivers\usbstor.sys
c:\windows\system32\drivers\usbuhci.sys
c:\windows\system32\drivers\vdrvroot.sys
c:\windows\system32\drivers\vga.sys
c:\windows\system32\drivers\vgapnp.sys
c:\windows\system32\drivers\vhdmp.sys
c:\windows\system32\drivers\viaagp.sys
c:\windows\system32\drivers\viac7.sys
c:\windows\system32\drivers\viaide.sys
c:\windows\system32\drivers\videoprt.sys
c:\windows\system32\drivers\vioser.sys
c:\windows\system32\drivers\vmbus.sys
c:\windows\system32\drivers\vmbushid.sys
c:\windows\system32\drivers\vmstorfl.sys
c:\windows\system32\drivers\volmgr.sys
c:\windows\system32\drivers\volmgrx.sys
c:\windows\system32\drivers\volsnap.sys
c:\windows\system32\drivers\vsmraid.sys
c:\windows\system32\drivers\vwifibus.sys
c:\windows\system32\drivers\vwififlt.sys
c:\windows\system32\drivers\vwifimp.sys
c:\windows\system32\drivers\wacompen.sys
c:\windows\system32\drivers\wanarp.sys
c:\windows\system32\drivers\watchdog.sys
c:\windows\system32\drivers\wd.sys
c:\windows\system32\drivers\wdf01000.sys
c:\windows\system32\drivers\wdfldr.sys
c:\windows\system32\drivers\wfplwf.sys
c:\windows\system32\drivers\wimmount.sys
c:\windows\system32\drivers\winhv.sys
c:\windows\system32\drivers\wmiacpi.sys
c:\windows\system32\drivers\wmilib.sys
c:\windows\system32\drivers\ws2ifsl.sys
c:\windows\system32\drivers\wudfpf.sys
c:\windows\system32\drivers\wudfrd.sys
c:\windows\system32\driverstore\filerepository\1394.inf_x86_neutral_832ec31f25d91fee\1394bus.sys
c:\windows\system32\driverstore\filerepository\1394.inf_x86_neutral_832ec31f25d91fee\1394ohci.sys
c:\windows\system32\driverstore\filerepository\1394.inf_x86_neutral_832ec31f25d91fee\ohci1394.sys
c:\windows\system32\driverstore\filerepository\61883.inf_x86_neutral_f2be571a17fa203a\61883.sys
c:\windows\system32\driverstore\filerepository\acpi.inf_x86_neutral_a1f4891fe0de4401\acpi.sys
c:\windows\system32\driverstore\filerepository\acpi.inf_x86_neutral_a1f4891fe0de4401\wmiacpi.sys
c:\windows\system32\driverstore\filerepository\acpipmi.inf_x86_neutral_71194ee3f26255a7\acpipmi.sys
c:\windows\system32\driverstore\filerepository\adp94xx.inf_x86_neutral_4928c8870f6a1577\adp94xx.sys
c:\windows\system32\driverstore\filerepository\adpahci.inf_x86_neutral_b082e95ec9f8c3f9\adpahci.sys
c:\windows\system32\driverstore\filerepository\adpu320.inf_x86_neutral_4ea3d42a9839982a\adpu320.sys
c:\windows\system32\driverstore\filerepository\af9035bda.inf_x86_neutral_aa11aa34552d1d4d\af9035bda.sys
c:\windows\system32\driverstore\filerepository\agp.inf_x86_neutral_a61b8b06718e8352\gagp30kx.sys
c:\windows\system32\driverstore\filerepository\agp.inf_x86_neutral_a61b8b06718e8352\uagp35.sys
c:\windows\system32\driverstore\filerepository\alcxau.inf_x86_neutral_43f2bfb06ea7fb7e\alcrmv.exe
c:\windows\system32\driverstore\filerepository\alcxau.inf_x86_neutral_43f2bfb06ea7fb7e\rtkvac.sys
c:\windows\system32\driverstore\filerepository\alcxau.inf_x86_neutral_43f2bfb06ea7fb7e\rtlcpl.exe
c:\windows\system32\driverstore\filerepository\alcxau.inf_x86_neutral_43f2bfb06ea7fb7e\soundman.exe
c:\windows\system32\driverstore\filerepository\amdsata.inf_x86_neutral_67db50590108ebd9\amdsata.sys
c:\windows\system32\driverstore\filerepository\amdsata.inf_x86_neutral_67db50590108ebd9\amdxata.sys
c:\windows\system32\driverstore\filerepository\amdsbs.inf_x86_neutral_5cae6933bef20aa8\amdsbs.sys
c:\windows\system32\driverstore\filerepository\angel.inf_x86_neutral_8bb84b2b92dfa947\angel.sys
c:\windows\system32\driverstore\filerepository\angel2.inf_x86_neutral_6a809c9c7f9c8486\angel2.sys
c:\windows\system32\driverstore\filerepository\angelusb.inf_x86_neutral_7bfd84ec2b59623e\angelusb.sys
c:\windows\system32\driverstore\filerepository\arc.inf_x86_neutral_11b52dec8e94d9aa\arc.sys
c:\windows\system32\driverstore\filerepository\arcsas.inf_x86_neutral_c763887719bed95d\arcsas.sys
c:\windows\system32\driverstore\filerepository\atiilhag.inf_x86_neutral_1d882551ede2c65b\atikmdag.sys
c:\windows\system32\driverstore\filerepository\atiriolh.inf_x86_neutral_cdb610d99bcbc631\atinavrr.sys
c:\windows\system32\driverstore\filerepository\avc.inf_x86_neutral_6ae951c52c898d14\avc.sys
c:\windows\system32\driverstore\filerepository\avc.inf_x86_neutral_6ae951c52c898d14\avcstrm.sys
c:\windows\system32\driverstore\filerepository\averfx2h826d_noaverir.inf_x86_neutral_4663ffee9c09b012\averfx2hbtv.sys
c:\windows\system32\driverstore\filerepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\avmcowan.sys
c:\windows\system32\driverstore\filerepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\b1cbase.sys
c:\windows\system32\driverstore\filerepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\fpcibase.sys
c:\windows\system32\driverstore\filerepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\fpcmbase.sys
c:\windows\system32\driverstore\filerepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\fus2base.sys
c:\windows\system32\driverstore\filerepository\avmisdnc.inf_x86_neutral_e8031e434b323b61\fxusbase.sys
c:\windows\system32\driverstore\filerepository\battery.inf_x86_neutral_5752155055c5e2d7\battc.sys
c:\windows\system32\driverstore\filerepository\battery.inf_x86_neutral_5752155055c5e2d7\cmbatt.sys
c:\windows\system32\driverstore\filerepository\battery.inf_x86_neutral_5752155055c5e2d7\compbatt.sys
c:\windows\system32\driverstore\filerepository\battery.inf_x86_neutral_5752155055c5e2d7\hidbatt.sys
c:\windows\system32\driverstore\filerepository\blbdrive.inf_x86_neutral_1aa816fe7dc98c3f\blbdrive.sys
c:\windows\system32\driverstore\filerepository\brmfcmdm.inf_x86_neutral_3b38c2e8e6f06c1b\brserid.sys
c:\windows\system32\driverstore\filerepository\brmfcmdm.inf_x86_neutral_3b38c2e8e6f06c1b\brusbser.sys
c:\windows\system32\driverstore\filerepository\brmfcmf.inf_x86_neutral_33717b093227cd8c\brmfrsmg.exe
c:\windows\system32\driverstore\filerepository\brmfcmf.inf_x86_neutral_33717b093227cd8c\brparwdm.sys
c:\windows\system32\driverstore\filerepository\brmfcmf.inf_x86_neutral_33717b093227cd8c\brserwdm.sys
c:\windows\system32\driverstore\filerepository\brmfcmf.inf_x86_neutral_33717b093227cd8c\brusbmdm.sys
c:\windows\system32\driverstore\filerepository\brmfcsto.inf_x86_neutral_39ae61431a44cded\brfiltlo.sys
c:\windows\system32\driverstore\filerepository\brmfcwia.inf_x86_neutral_2d38149df9cd17c4\brusbscn.sys
c:\windows\system32\driverstore\filerepository\bth.inf_x86_neutral_2d4ce84c4a0b8470\bthenum.sys
c:\windows\system32\driverstore\filerepository\bth.inf_x86_neutral_2d4ce84c4a0b8470\bthusb.sys
c:\windows\system32\driverstore\filerepository\bth.inf_x86_neutral_2d4ce84c4a0b8470\fsquirt.exe
c:\windows\system32\driverstore\filerepository\bthmtpenum.inf_x86_neutral_c70e85b87ee4ece9\bthmtpenum.sys
c:\windows\system32\driverstore\filerepository\bthpan.inf_x86_neutral_0ed0bba2c23dd70b\bthpan.sys
c:\windows\system32\driverstore\filerepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.sys
c:\windows\system32\driverstore\filerepository\circlass.inf_x86_neutral_5bbf290689fced8f\circlass.sys
c:\windows\system32\driverstore\filerepository\compositebus.inf_x86_neutral_a53ef080c39c3218\compositebus.sys
c:\windows\system32\driverstore\filerepository\cpu.inf_x86_neutral_729b871528391032\amdk8.sys
c:\windows\system32\driverstore\filerepository\cpu.inf_x86_neutral_729b871528391032\amdppm.sys
c:\windows\system32\driverstore\filerepository\cpu.inf_x86_neutral_729b871528391032\intelppm.sys
c:\windows\system32\driverstore\filerepository\cpu.inf_x86_neutral_729b871528391032\processr.sys
c:\windows\system32\driverstore\filerepository\cpu.inf_x86_neutral_729b871528391032\viac7.sys
c:\windows\system32\driverstore\filerepository\crcdisk.inf_x86_neutral_dd39b6b0a45226c4\crcdisk.sys
c:\windows\system32\driverstore\filerepository\cxfalcon_ibv32.inf_x86_neutral_01ff517b4c863eb6\cxfalcon_ibv32.sys
c:\windows\system32\driverstore\filerepository\cxraptor_fm1216mk5_ibv32.inf_x86_neutral_d4097f19ee2b5d2f\cxraptor_ibv32.sys
c:\windows\system32\driverstore\filerepository\cxraptor_philipstuv1236d_ibv32.inf_x86_neutral_2af0839f9805ea5f\cxraphd_ibv32.sys
c:\windows\system32\driverstore\filerepository\dc21x4vm.inf_x86_neutral_8887242a56ee027e\dc21x4vm.sys
c:\windows\system32\driverstore\filerepository\disk.inf_x86_neutral_b431b61a11f8df6c\disk.sys
c:\windows\system32\driverstore\filerepository\display.inf_x86_neutral_36353e26d7770ebb\vgapnp.sys
c:\windows\system32\driverstore\filerepository\divacx86.inf_x86_neutral_d9558f410186db36\dicapi.sys
c:\windows\system32\driverstore\filerepository\divacx86.inf_x86_neutral_d9558f410186db36\dicowan.sys
c:\windows\system32\driverstore\filerepository\divacx86.inf_x86_neutral_d9558f410186db36\dimaint.sys
c:\windows\system32\driverstore\filerepository\divacx86.inf_x86_neutral_d9558f410186db36\ditrace.exe
c:\windows\system32\driverstore\filerepository\divacx86.inf_x86_neutral_d9558f410186db36\xlog.exe
c:\windows\system32\driverstore\filerepository\djsvs.inf_x86_neutral_836a3a3240941631\djsvs.sys
c:\windows\system32\driverstore\filerepository\dot4.inf_x86_neutral_b079cf65ff1cb755\dot4.sys
c:\windows\system32\driverstore\filerepository\dot4.inf_x86_neutral_b079cf65ff1cb755\dot4scan.sys
c:\windows\system32\driverstore\filerepository\dot4.inf_x86_neutral_b079cf65ff1cb755\dot4usb.sys
c:\windows\system32\driverstore\filerepository\dot4prt.inf_x86_neutral_ff48d313003e46b8\dot4prt.sys
c:\windows\system32\driverstore\filerepository\elxstor.inf_x86_neutral_4263942b9dfe9077\elxstor.sys
c:\windows\system32\driverstore\filerepository\fdc.inf_x86_neutral_67322cb863995ea8\fdc.sys
c:\windows\system32\driverstore\filerepository\flpydisk.inf_x86_neutral_2102f5344367a352\flpydisk.sys
c:\windows\system32\driverstore\filerepository\flpydisk.inf_x86_neutral_2102f5344367a352\sfloppy.sys
c:\windows\system32\driverstore\filerepository\hcw72bda.inf_x86_neutral_8c31e8d2dc91b975\hcw72adfilter.sys
c:\windows\system32\driverstore\filerepository\hcw72bda.inf_x86_neutral_8c31e8d2dc91b975\hcw72atv.sys
c:\windows\system32\driverstore\filerepository\hcw72bda.inf_x86_neutral_8c31e8d2dc91b975\hcw72dtv.sys
c:\windows\system32\driverstore\filerepository\hcw85bda.inf_x86_neutral_0c9092aa3e31c11c\hcw85bda.sys
c:\windows\system32\driverstore\filerepository\hcw85cir.inf_x86_neutral_e96b5c9f415a42b6\hcw85cir.sys
c:\windows\system32\driverstore\filerepository\hdaudbus.inf_x86_neutral_77479a4820fb8643\hdaudbus.sys
c:\windows\system32\driverstore\filerepository\hdaudio.inf_x86_neutral_5a5e688ecb9e273f\hdaudio.sys
c:\windows\system32\driverstore\filerepository\hidbth.inf_x86_neutral_96487048bb26cf0c\hidbth.sys
c:\windows\system32\driverstore\filerepository\hiddigi.inf_x86_neutral_12aaf5742a9969da\wacompen.sys
c:\windows\system32\driverstore\filerepository\hidir.inf_x86_neutral_a7b6b38a183ef6fe\hidir.sys
c:\windows\system32\driverstore\filerepository\hpsamd.inf_x86_neutral_84ae149ecc9f8033\hpsamd.sys
c:\windows\system32\driverstore\filerepository\iastorv.inf_x86_neutral_668286aa35d55928\iastorv.sys
c:\windows\system32\driverstore\filerepository\iirsp.inf_x86_neutral_25c14d33af7f54f1\iirsp.sys
c:\windows\system32\driverstore\filerepository\image.inf_x86_neutral_7a389207019f8699\sonydcam.sys
c:\windows\system32\driverstore\filerepository\input.inf_x86_neutral_9e1eba5724be176f\hidusb.sys
c:\windows\system32\driverstore\filerepository\ipmidrv.inf_x86_neutral_2084908fa838c2b9\ipmidrv.sys
c:\windows\system32\driverstore\filerepository\iscsi.inf_x86_neutral_7ad2bf0be3b9a90e\msiscsi.sys
c:\windows\system32\driverstore\filerepository\keyboard.inf_x86_neutral_50ad659974198591\i8042prt.sys
c:\windows\system32\driverstore\filerepository\keyboard.inf_x86_neutral_50ad659974198591\kbdclass.sys
c:\windows\system32\driverstore\filerepository\keyboard.inf_x86_neutral_50ad659974198591\kbdhid.sys
c:\windows\system32\driverstore\filerepository\lsi_fc.inf_x86_neutral_a7088f3644ca646a\lsi_fc.sys
c:\windows\system32\driverstore\filerepository\lsi_sas.inf_x86_neutral_a4d6780f72cbd5b4\lsi_sas.sys
c:\windows\system32\driverstore\filerepository\lsi_sas2.inf_x86_neutral_e12a5c4cfbe49204\lsi_sas2.sys
c:\windows\system32\driverstore\filerepository\lsi_scsi.inf_x86_neutral_cfbbf0b0b66ba280\lsi_scsi.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\agp440.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\amdagp.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\isapnp.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\msisadrv.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\mssmbios.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\nv_agp.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\pci.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\sisagp.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\swenum.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\uliagpkx.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\vdrvroot.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\viaagp.sys
c:\windows\system32\driverstore\filerepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\volmgr.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\adicsc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\adicvls.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\atlmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\breecemc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\ddsmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\elmsmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\examc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\hpmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\jvcmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\libxprmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\m4mc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\nsmmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\plasmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\pnrmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\powerfil.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\qlstrmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\qntmmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\seaddsmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\snyaitmc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\sonymc.sys
c:\windows\system32\driverstore\filerepository\mchgr.inf_x86_neutral_185970e67258389c\spctramc.sys
c:\windows\system32\driverstore\filerepository\mdmagrm.inf_x86_neutral_8ff94c5737626019\ltmdmnt.sys
c:\windows\system32\driverstore\filerepository\mdmagrs.inf_x86_neutral_81c67a5080f3eef2\agrsm.sys
c:\windows\system32\driverstore\filerepository\mdmbr002.inf_x86_neutral_da2024ed84d3191d\brserib.sys
c:\windows\system32\driverstore\filerepository\mdmbr002.inf_x86_neutral_da2024ed84d3191d\brusbsib.sys
c:\windows\system32\driverstore\filerepository\mdmbtmdm.inf_x86_neutral_321fa2ecf7803227\bthmodem.sys
c:\windows\system32\driverstore\filerepository\mdmcpq.inf_x86_neutral_9f203c20b6f0dabd\usbser.sys
c:\windows\system32\driverstore\filerepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\vstali3.sys
c:\windows\system32\driverstore\filerepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\vstati3.sys
c:\windows\system32\driverstore\filerepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\vstcnxt3.sys
c:\windows\system32\driverstore\filerepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\vstdpv3.sys
c:\windows\system32\driverstore\filerepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\vstich3.sys
c:\windows\system32\driverstore\filerepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\vstsis3.sys
c:\windows\system32\driverstore\filerepository\mdmcxav3.inf_x86_neutral_3c9275be906b01dd\vstvia3.sys
c:\windows\system32\driverstore\filerepository\mdmcxhv3.inf_x86_neutral_15b13e9a734fb085\vstazl3.sys
c:\windows\system32\driverstore\filerepository\mdmcxhv3.inf_x86_neutral_15b13e9a734fb085\vstbs23.sys
c:\windows\system32\driverstore\filerepository\mdmcxhv3.inf_x86_neutral_15b13e9a734fb085\vstbs33.sys
c:\windows\system32\driverstore\filerepository\mdmirmdm.inf_x86_neutral_b64ae6e8f8db8514\msircomm.sys
c:\windows\system32\driverstore\filerepository\mdmmotsm.inf_x86_neutral_c1415d9789c54b89\smserial.sys
c:\windows\system32\driverstore\filerepository\megasas.inf_x86_neutral_395276dd9b7a7448\megasas.sys
c:\windows\system32\driverstore\filerepository\megasr.inf_x86_neutral_30b367f92ca46598\megasr.sys
c:\windows\system32\driverstore\filerepository\memory.inf_x86_neutral_0e5e977bd78905af\pnpmem.sys
c:\windows\system32\driverstore\filerepository\mf.inf_x86_neutral_feb8c30ef59487a2\mf.sys
c:\windows\system32\driverstore\filerepository\modemcsa.inf_x86_neutral_0243209867cd0efc\modemcsa.sys
c:\windows\system32\driverstore\filerepository\monitor.inf_x86_neutral_f7168ca1d7f8ec24\monitor.sys
c:\windows\system32\driverstore\filerepository\mpio.inf_x86_neutral_18f08f79e68b1972\mpio.sys
c:\windows\system32\driverstore\filerepository\msdsm.inf_x86_neutral_cacb427259f0d93e\msdsm.sys
c:\windows\system32\driverstore\filerepository\msdv.inf_x86_neutral_4322b3da4858d42a\msdv.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\aliide.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\amdide.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\ataport.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\cmdide.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\intelide.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\msahci.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\pciide.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\pciidex.sys
c:\windows\system32\driverstore\filerepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\viaide.sys
c:\windows\system32\driverstore\filerepository\msmouse.inf_x86_neutral_7a9084e0177406eb\mouclass.sys
c:\windows\system32\driverstore\filerepository\msmouse.inf_x86_neutral_7a9084e0177406eb\mouhid.sys
c:\windows\system32\driverstore\filerepository\msmouse.inf_x86_neutral_7a9084e0177406eb\sermouse.sys
c:\windows\system32\driverstore\filerepository\msports.inf_x86_neutral_c1a802e06677f73f\parport.sys
c:\windows\system32\driverstore\filerepository\msports.inf_x86_neutral_c1a802e06677f73f\parvdm.sys
c:\windows\system32\driverstore\filerepository\msports.inf_x86_neutral_c1a802e06677f73f\serenum.sys
c:\windows\system32\driverstore\filerepository\msports.inf_x86_neutral_c1a802e06677f73f\serial.sys
c:\windows\system32\driverstore\filerepository\mstape.inf_x86_neutral_b2cccf4ea41e4c0f\mstape.sys
c:\windows\system32\driverstore\filerepository\mtconfig.inf_x86_neutral_4de24f49b5e60c45\mtconfig.sys
c:\windows\system32\driverstore\filerepository\net1k32.inf_x86_neutral_78f8b10949489fd3\e1k6032.sys
c:\windows\system32\driverstore\filerepository\net1q32.inf_x86_neutral_18f9b5da166792ca\e1q6032.sys
c:\windows\system32\driverstore\filerepository\net1y32.inf_x86_neutral_17f1bc814dc1043f\e1y6032.sys
c:\windows\system32\driverstore\filerepository\net44x32.inf_x86_neutral_70a6663fd52fa256\bcm4sbxp.sys
c:\windows\system32\driverstore\filerepository\net8185.inf_x86_neutral_20a13cfe2956ed8a\rtl85n86.sys
c:\windows\system32\driverstore\filerepository\net8187bv32.inf_x86_neutral_4133912759f4531a\rtl8187b.sys
c:\windows\system32\driverstore\filerepository\net8187se86.inf_x86_neutral_dbc0aab1acd9c67e\rtl8187se.sys
c:\windows\system32\driverstore\filerepository\netathr.inf_x86_neutral_c6f6c3fd633fd5e7\athr.sys
c:\windows\system32\driverstore\filerepository\netb57vx.inf_x86_neutral_575b8ca932333f72\b57nd60x.sys
c:\windows\system32\driverstore\filerepository\netbc6.inf_x86_neutral_a7e1745ea707c8d1\bcmwl6.sys
c:\windows\system32\driverstore\filerepository\netbvbdx.inf_x86_neutral_6d29499ebc7c7338\bxvbdx.sys
c:\windows\system32\driverstore\filerepository\netbxndx.inf_x86_neutral_94ba965704caa228\bxnd60x.sys
c:\windows\system32\driverstore\filerepository\nete1e32.inf_x86_neutral_4bf5bdee9123a61d\e1e6032.sys
c:\windows\system32\driverstore\filerepository\nete1g32.inf_x86_neutral_ce57dbaa251ea290\e1g60i32.sys
c:\windows\system32\driverstore\filerepository\netefe32.inf_x86_neutral_9590f3b23d1d64f3\e100b325.sys
c:\windows\system32\driverstore\filerepository\netevbdx.inf_x86_neutral_7f439b41eebc75ae\evbdx.sys
c:\windows\system32\driverstore\filerepository\netgb6.inf_x86_neutral_437f729e64df024b\sisgb6.sys
c:\windows\system32\driverstore\filerepository\netk57x.inf_x86_neutral_5cfca89527c3f708\k57nd60x.sys
c:\windows\system32\driverstore\filerepository\netl160x.inf_x86_neutral_cef6a4c5e38079d6\l160x86.sys
c:\windows\system32\driverstore\filerepository\netl1c86.inf_x86_neutral_49e2658f4a72e53f\l1c62x86.sys
c:\windows\system32\driverstore\filerepository\netl1e86.inf_x86_neutral_a34f2431367128ea\l1e62x86.sys
c:\windows\system32\driverstore\filerepository\netl260x.inf_x86_neutral_30b3156b81adc0bb\l260x86.sys
c:\windows\system32\driverstore\filerepository\netmyk01.inf_x86_neutral_a3f8c82b61266bbe\yk62x86.sys
c:\windows\system32\driverstore\filerepository\netnvm32.inf_x86_neutral_163a5a97980bb89d\nvm62x32.sys
c:\windows\system32\driverstore\filerepository\netnvmx.inf_x86_neutral_7af3f06863f3b983\nvm60x32.sys
c:\windows\system32\driverstore\filerepository\netr28.inf_x86_neutral_980e8922b9be3562\netr28.sys
c:\windows\system32\driverstore\filerepository\netr28u.inf_x86_neutral_b42b25ec42f762c2\netr28u.sys
c:\windows\system32\driverstore\filerepository\netr73.inf_x86_neutral_d8d856fa32ab7ec2\netr73.sys
c:\windows\system32\driverstore\filerepository\netrndis.inf_x86_neutral_4c56d83f6e4d75b0\usb80236.sys
c:\windows\system32\driverstore\filerepository\netrndis.inf_x86_neutral_4c56d83f6e4d75b0\usb8023x.sys
c:\windows\system32\driverstore\filerepository\netrtl32.inf_x86_neutral_79fee35a46b8dacd\rtnicxp.sys
c:\windows\system32\driverstore\filerepository\netrtx32.inf_x86_neutral_aa92429bfa083dca\rt86win7.sys
c:\windows\system32\driverstore\filerepository\netvfx86.inf_x86_neutral_325ccb4cde393e5d\fetnd6.sys
c:\windows\system32\driverstore\filerepository\netvg62.inf_x86_neutral_4a0e9c58796bca8a\getn62.sys
c:\windows\system32\driverstore\filerepository\netw5v32.inf_x86_neutral_a8056bed0ad979c3\netw5v32.sys
c:\windows\system32\driverstore\filerepository\netxe32.inf_x86_neutral_2d971e2b4a578e3d\ixe6032.sys
c:\windows\system32\driverstore\filerepository\nfrd960.inf_x86_neutral_cfc8c0013e9ede68\nfrd960.sys
c:\windows\system32\driverstore\filerepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvraid.sys
c:\windows\system32\driverstore\filerepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
c:\windows\system32\driverstore\filerepository\nv_lh.inf_x86_neutral_bbe628dbdd6fce25\nvlddmkm.sys
c:\windows\system32\driverstore\filerepository\pcmcia.inf_x86_neutral_42dda5eb5768a3df\pcmcia.sys
c:\windows\system32\driverstore\filerepository\ph3xibc0.inf_x86_neutral_c24bcc939e6dfc23\ph3xib32.sys
c:\windows\system32\driverstore\filerepository\ph6xib32c0.inf_x86_neutral_a7233f8f3a9f58ff\ph6xib32.sys
c:\windows\system32\driverstore\filerepository\ql2300.inf_x86_neutral_ca8487daf77ff7cb\ql2300.sys
c:\windows\system32\driverstore\filerepository\ql40xx.inf_x86_neutral_77a826e5c0a07842\ql40xx.sys
c:\windows\system32\driverstore\filerepository\ramdisk.inf_x86_neutral_a5e0c07c2a8b4571\ramdisk.sys
c:\windows\system32\driverstore\filerepository\rdpbus.inf_x86_neutral_27637529205407be\rdpbus.sys
c:\windows\system32\driverstore\filerepository\sbp2.inf_x86_neutral_bfc02db3bc163c19\sbp2port.sys
c:\windows\system32\driverstore\filerepository\sdbus.inf_x86_neutral_47b152eccdb186c8\sdbus.sys
c:\windows\system32\driverstore\filerepository\sffdisk.inf_x86_neutral_7e5210507f8fc265\sffdisk.sys
c:\windows\system32\driverstore\filerepository\sffdisk.inf_x86_neutral_7e5210507f8fc265\sffp_mmc.sys
c:\windows\system32\driverstore\filerepository\sffdisk.inf_x86_neutral_7e5210507f8fc265\sffp_sd.sys
c:\windows\system32\driverstore\filerepository\sisraid2.inf_x86_neutral_845e008c32615283\sisraid2.sys
c:\windows\system32\driverstore\filerepository\sisraid4.inf_x86_neutral_65ab84e9830f6f4b\sisraid4.sys
c:\windows\system32\driverstore\filerepository\smartcrd.inf_x86_neutral_63e72c669d043f14\cmbp0wdm.sys
c:\windows\system32\driverstore\filerepository\smartcrd.inf_x86_neutral_63e72c669d043f14\cxbp0wdm.sys
c:\windows\system32\driverstore\filerepository\smartcrd.inf_x86_neutral_63e72c669d043f14\grserial.sys
c:\windows\system32\driverstore\filerepository\smartcrd.inf_x86_neutral_63e72c669d043f14\pscr.sys
c:\windows\system32\driverstore\filerepository\smartcrd.inf_x86_neutral_63e72c669d043f14\scmstcs.sys
c:\windows\system32\driverstore\filerepository\smartcrd.inf_x86_neutral_63e72c669d043f14\scr111.sys
c:\windows\system32\driverstore\filerepository\smartcrd.inf_x86_neutral_63e72c669d043f14\stcusb.sys
c:\windows\system32\driverstore\filerepository\stexstor.inf_x86_neutral_80ee226e29362f51\stexstor.sys
c:\windows\system32\driverstore\filerepository\sti.inf_x86_neutral_6a74c91c1f723826\scsiscan.sys
c:\windows\system32\driverstore\filerepository\sti.inf_x86_neutral_6a74c91c1f723826\serscan.sys
c:\windows\system32\driverstore\filerepository\sti.inf_x86_neutral_6a74c91c1f723826\usbscan.sys
c:\windows\system32\driverstore\filerepository\sti.inf_x86_neutral_6a74c91c1f723826\wsdscan.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\4mmdat.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\dlttape.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\exabyte2.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\ltotape.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\mammoth.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\miniqic.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\qic157.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\sonyait.sys
c:\windows\system32\driverstore\filerepository\tape.inf_x86_neutral_2ad11993c0ac6624\tandqic.sys
c:\windows\system32\driverstore\filerepository\tdibth.inf_x86_neutral_b67cdc538738f6b9\rfcomm.sys
c:\windows\system32\driverstore\filerepository\tpm.inf_x86_neutral_8d77c50b5c066979\tpm.sys
c:\windows\system32\driverstore\filerepository\transfercable.inf_x86_neutral_82f4c743c8996d67\x86\winusb.sys
c:\windows\system32\driverstore\filerepository\tsgenericusbdriver.inf_x86_neutral_10faa3d9ed6a6c29\tsusbgd.sys
c:\windows\system32\driverstore\filerepository\umbus.inf_x86_neutral_79120b2cb6857971\umbus.sys
c:\windows\system32\driverstore\filerepository\umpass.inf_x86_neutral_8f915e601c25e75b\umpass.sys
c:\windows\system32\driverstore\filerepository\usb.inf_x86_neutral_2620fd493cad7d41\usbccgp.sys
c:\windows\system32\driverstore\filerepository\usb.inf_x86_neutral_2620fd493cad7d41\usbhub.sys
c:\windows\system32\driverstore\filerepository\usbcir.inf_x86_neutral_43aeabd51df61d2c\usbcir.sys
c:\windows\system32\driverstore\filerepository\usbport.inf_x86_neutral_f9abf85fd00186bd\usbehci.sys
c:\windows\system32\driverstore\filerepository\usbport.inf_x86_neutral_f9abf85fd00186bd\usbhub.sys
c:\windows\system32\driverstore\filerepository\usbport.inf_x86_neutral_f9abf85fd00186bd\usbohci.sys
c:\windows\system32\driverstore\filerepository\usbport.inf_x86_neutral_f9abf85fd00186bd\usbuhci.sys
c:\windows\system32\driverstore\filerepository\usbprint.inf_x86_neutral_203e16627752a160\usbprint.sys
c:\windows\system32\driverstore\filerepository\usbstor.inf_x86_neutral_c77d41a490bdc63d\usbstor.sys
c:\windows\system32\driverstore\filerepository\usbvideo.inf_x86_neutral_8fe3504355514e0c\usbvideo.sys
c:\windows\system32\driverstore\filerepository\vhdmp.inf_x86_neutral_efa659e9a38d5b8c\vhdmp.sys
c:\windows\system32\driverstore\filerepository\vioser.inf_x86_neutral_0c576f858ae52129\vioser.sys
c:\windows\system32\driverstore\filerepository\volume.inf_x86_neutral_6dee0205881d1a1d\volsnap.sys
c:\windows\system32\driverstore\filerepository\vsmraid.inf_x86_neutral_be11b7aaa746e92d\vsmraid.sys
c:\windows\system32\driverstore\filerepository\wd.inf_x86_neutral_81cae93d8afd51d5\wd.sys
c:\windows\system32\driverstore\filerepository\wdma_usb.inf_x86_neutral_a721e4f3907a2769\usbaudio.sys
c:\windows\system32\driverstore\filerepository\wdmvsc.inf_x86_neutral_a2cf745000e2ea92\dmvsc.sys
c:\windows\system32\driverstore\filerepository\winusb.inf_x86_neutral_6cb50ae9f480775b\winusb.sys
c:\windows\system32\driverstore\filerepository\wnetvsc.inf_x86_neutral_548addf09cb466fa\netvsc50.sys
c:\windows\system32\driverstore\filerepository\wnetvsc.inf_x86_neutral_548addf09cb466fa\netvsc60.sys
c:\windows\system32\driverstore\filerepository\wsdprint.inf_x86_neutral_05711b33589b27a9\wsdprint.sys
c:\windows\system32\driverstore\filerepository\wstorflt.inf_x86_neutral_3db956c41708f7f5\vmstorfl.sys
c:\windows\system32\driverstore\filerepository\wstorvsc.inf_x86_neutral_d7bf942e99bb1d41\storvsc.sys
c:\windows\system32\driverstore\filerepository\wvmbus.inf_x86_neutral_fca91999602b0343\vmbus.sys
c:\windows\system32\driverstore\filerepository\wvmbus.inf_x86_neutral_fca91999602b0343\winhv.sys
c:\windows\system32\driverstore\filerepository\wvmbushid.inf_x86_neutral_337ff5bbc81c06e8\vmbushid.sys
c:\windows\system32\driverstore\filerepository\wvmbusvideo.inf_x86_neutral_1b297af3587246aa\vmbusvideom.sys
c:\windows\system32\driverstore\filerepository\wvmic.inf_x86_neutral_b94eb92e8150fa35\vmicsvc.exe
c:\windows\system32\driverstore\filerepository\xcbdav.inf_x86_neutral_8e8664e62708b91f\xcbdav.sys
c:\windows\system32\driverstore\filerepository\xcbdav.inf_x86_neutral_8e8664e62708b91f\xcfev.sys
c:\windows\system32\driverstore\filerepository\xcbdav.inf_x86_neutral_8e8664e62708b91f\xchalv.sys
c:\windows\system32\driverstore\filerepository\xcbdav.inf_x86_neutral_8e8664e62708b91f\xcmemv.sys
c:\windows\system32\driverstore\filerepository\xnacc.inf_x86_neutral_13c4e272a96185a1\xnacc.sys
c:\windows\system32\ime\imejp10\imjpdadm.exe
c:\windows\system32\ime\imejp10\imjpdct.exe
c:\windows\system32\ime\imejp10\imjpdsvr.exe
c:\windows\system32\ime\imejp10\imjpmgr.exe
c:\windows\system32\ime\imejp10\imjppdmg.exe
c:\windows\system32\ime\imejp10\imjpuex.exe
c:\windows\system32\ime\imejp10\imjpuexc.exe
c:\windows\system32\ime\imesc5\imscprop.exe
c:\windows\system32\ime\imetc10\imtcprop.exe
c:\windows\system32\ime\shared\imccphr.exe
c:\windows\system32\ime\shared\imepadsv.exe
c:\windows\system32\macromed\flash\flashplayerplugin_26_0_0_131.exe
c:\windows\system32\macromed\flash\flashplayerupdateservice.exe
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_pepper.exe
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_plugin.exe
c:\windows\system32\migwiz\mighost.exe
c:\windows\system32\migwiz\migsetup.exe
c:\windows\system32\oobe\audit.exe
c:\windows\system32\oobe\msoobe.exe
c:\windows\system32\oobe\oobeldr.exe
c:\windows\system32\oobe\setup.exe
c:\windows\system32\oobe\setupsqm.exe
c:\windows\system32\oobe\windeploy.exe
c:\windows\system32\speech\speechux\speechuxtutorial.exe
c:\windows\system32\speech\speechux\speechuxwiz.exe
c:\windows\system32\spool\tools\printbrm.exe
c:\windows\system32\spool\tools\printbrmengine.exe
c:\windows\system32\sysprep\sysprep.exe
c:\windows\system32\wbem\mofcomp.exe
c:\windows\system32\wbem\scrcons.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wbem\wbemtest.exe
c:\windows\system32\wbem\winmgmt.exe
c:\windows\system32\wbem\wmiadap.exe
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\windowspowershell\v1.0\compiledcomposition.microsoft.powershell.gpowershell.dll
c:\windows\winsxs\backup\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.1.7601.17514_none_d7186da9aafbefce_sdbinst.exe_8725e339
c:\windows\winsxs\backup\x86_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.17514_none_59537a3710696511_appid.sys_fe1d01e3
c:\windows\winsxs\backup\x86_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.17514_none_59537a3710696511_appidcertstorecheck.exe_03352f5f
c:\windows\winsxs\backup\x86_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.17514_none_59537a3710696511_appidpolicyconverter.exe_83972af0
c:\windows\winsxs\backup\x86_microsoft-windows-axinstallservice_31bf3856ad364e35_6.1.7601.17514_none_d90cb8d0cf2f6362_axinstui.exe_eba3b15b
c:\windows\winsxs\backup\x86_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.17514_none_6b400115eb0cb724_winload.exe_75835076
c:\windows\winsxs\backup\x86_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7601.17514_none_6b400115eb0cb724_winresume.exe_85cd1215
c:\windows\winsxs\backup\x86_microsoft-windows-b..re-memorydiagnostic_31bf3856ad364e35_6.1.7601.17514_none_da3cb85562df73c9_memtest.exe_01d80391
c:\windows\winsxs\backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953_winload.exe_75835076
c:\windows\winsxs\backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953_winresume.exe_85cd1215
c:\windows\winsxs\backup\x86_microsoft-windows-basic-misc-tools_31bf3856ad364e35_6.1.7600.16385_none_17330d9420bf24e8_expand.exe_f43b24c8
c:\windows\winsxs\backup\x86_microsoft-windows-cdfs_31bf3856ad364e35_6.1.7600.16385_none_a63de9327e477e37_cdfs.sys_02574081
c:\windows\winsxs\backup\x86_microsoft-windows-commonlog_31bf3856ad364e35_6.1.7600.16385_none_7e58f0d088df9b66_clfs.sys_04dfdff9
c:\windows\winsxs\backup\x86_microsoft-windows-coreos_31bf3856ad364e35_6.1.7601.17514_none_2759b0329c936042_fs_rec.sys_dfd2dd83
c:\windows\winsxs\backup\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.1.7601.17514_none_790915218b2e1210_drvinst.exe_6593e92a
c:\windows\winsxs\backup\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.1.7601.17514_none_8faafe001b741442_dwm.exe_04cf416e
c:\windows\winsxs\backup\x86_microsoft-windows-dfsclient_31bf3856ad364e35_6.1.7601.17514_none_89a197c9445dfde9_dfsc.sys_ff9a943d
c:\windows\winsxs\backup\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_e3e9e6c8e09b7c76_dnscacheugc.exe_aa32623e
c:\windows\winsxs\backup\x86_microsoft-windows-dynamicvolumemanager_31bf3856ad364e35_6.1.7600.16385_none_dcd91825e77c6c5d_volmgrx.sys_f02896c6
c:\windows\winsxs\backup\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_6.1.7601.17514_none_227e1c01642654f4_wermgr.exe_d92a3b6c
c:\windows\winsxs\backup\x86_microsoft-windows-fat_31bf3856ad364e35_6.1.7600.16385_none_ae8981a3b8b7be50_fastfat.sys_0ffee946
c:\windows\winsxs\backup\x86_microsoft-windows-fileinfominifilter_31bf3856ad364e35_6.1.7600.16385_none_d68b514892a16884_fileinfo.sys_9be2dfcd
c:\windows\winsxs\backup\x86_microsoft-windows-htmlhelp_31bf3856ad364e35_6.1.7600.16385_none_c82c4cd5e6101085_hh.exe_f87e0044
c:\windows\winsxs\backup\x86_microsoft-windows-i..i_initiator_service_31bf3856ad364e35_6.1.7601.17514_none_dc7b1529735a0950_iscsicli.exe_20e14d4f
c:\windows\winsxs\backup\x86_microsoft-windows-international-core_31bf3856ad364e35_6.1.7601.17514_none_ebb1ce7438031941_muiunattend.exe_1e11bb40
c:\windows\winsxs\backup\x86_microsoft-windows-irdaircomm_31bf3856ad364e35_6.1.7600.16385_none_2867d22e85fcfdfa_irenum.sys_58570547
c:\windows\winsxs\backup\x86_microsoft-windows-kernelstreamingsupport_31bf3856ad364e35_6.1.7600.16385_none_61cb11453c0f45a5_mskssrv.sys_10d1b7c8
c:\windows\winsxs\backup\x86_microsoft-windows-l..istry-support-tcpip_31bf3856ad364e35_6.1.7601.17514_none_88249ff263af1397_tcpipreg.sys_e872d013
c:\windows\winsxs\backup\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.1.7601.17514_none_add0028a41cede87_dxgkrnl.sys_8aad3dfb
c:\windows\winsxs\backup\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.1.7601.17514_none_add0028a41cede87_dxgmms1.sys_9c98a5d4
c:\windows\winsxs\backup\x86_microsoft-windows-legacyhwui_31bf3856ad364e35_6.1.7600.16385_none_e24a7886a9947ebf_hdwwiz.exe_b6a1c2df
c:\windows\winsxs\backup\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_a851f4adbb0d5141_ksecpkg.sys_0029f5a5
c:\windows\winsxs\backup\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_a851f4adbb0d5141_lsass.exe_682060de
c:\windows\winsxs\backup\x86_microsoft-windows-lua-filevirtualization_31bf3856ad364e35_6.1.7600.16385_none_67b77af705ee409d_luafv.sys_602842f9
c:\windows\winsxs\backup\x86_microsoft-windows-lua_31bf3856ad364e35_6.1.7601.17514_none_a851c71dbb0d8483_consent.exe_9075a1c2
c:\windows\winsxs\backup\x86_microsoft-windows-m..update-authenticamd_31bf3856ad364e35_6.1.7600.16385_none_fd79ede1b2ed5d1f_mcupdate_authenticamd.dll_0c1b7cf5
c:\windows\winsxs\backup\x86_microsoft-windows-m..update-genuineintel_31bf3856ad364e35_6.1.7601.17514_none_bec7764d108f674f_mcupdate_genuineintel.dll_940e6a7f
c:\windows\winsxs\backup\x86_microsoft-windows-mountpointmanager_31bf3856ad364e35_6.1.7601.17514_none_f49f8eb16547dc9f_mountmgr.sys_77371b26
c:\windows\winsxs\backup\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.1.7600.16385_none_c718d071d9c10a2d_auditpol.exe_83c870f4
c:\windows\winsxs\backup\x86_microsoft-windows-msfs_31bf3856ad364e35_6.1.7600.16385_none_a646965e7e3ffc0c_msfs.sys_ea96697c
c:\windows\winsxs\backup\x86_microsoft-windows-mup_31bf3856ad364e35_6.1.7600.16385_none_acc89f51b9d75e29_mup.sys_ea6a9c41
c:\windows\winsxs\backup\x86_microsoft-windows-nbsmb_31bf3856ad364e35_6.1.7600.16385_none_5f40e7575949d6a9_smb.sys_d745e761
c:\windows\winsxs\backup\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_a9ce95b27a512623_ndis.sys_e2e1846f
c:\windows\winsxs\backup\x86_microsoft-windows-netbios_31bf3856ad364e35_6.1.7600.16385_none_59b80e4dcc72e431_netbios.sys_6f23c4df
c:\windows\winsxs\backup\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7601.17514_none_626c324d55864070_netbt.sys_9226f314
c:\windows\winsxs\backup\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7601.17514_none_626c324d55864070_netbtugc.exe_825f4f74
c:\windows\winsxs\backup\x86_microsoft-windows-netio-infrastructure_31bf3856ad364e35_6.1.7601.17514_none_58a2d6c1138fa06a_netio.sys_a06e75d0
c:\windows\winsxs\backup\x86_microsoft-windows-networkbridge_31bf3856ad364e35_6.1.7600.16385_none_07c046fe67692e98_bridge.sys_4e5f368e
c:\windows\winsxs\backup\x86_microsoft-windows-networkbridge_31bf3856ad364e35_6.1.7600.16385_none_07c046fe67692e98_bridgeunattend.exe_60b7e340
c:\windows\winsxs\backup\x86_microsoft-windows-newdev_31bf3856ad364e35_6.1.7600.16385_none_114ca177b1fcad24_ndadmin.exe_8e57269f
c:\windows\winsxs\backup\x86_microsoft-windows-newdev_31bf3856ad364e35_6.1.7600.16385_none_114ca177b1fcad24_newdev.exe_7eb73dcd
c:\windows\winsxs\backup\x86_microsoft-windows-npfs_31bf3856ad364e35_6.1.7600.16385_none_a647db007e3ec880_npfs.sys_e6c97a48
c:\windows\winsxs\backup\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7601.17514_none_a87893a87b2db29e_ntfs.sys_e80dca04
c:\windows\winsxs\backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7601.17514_none_0014e305d0cff0a7_csrstub.exe_f65f4340
c:\windows\winsxs\backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7601.17514_none_0014e305d0cff0a7_graftabl.com_a9c93904
c:\windows\winsxs\backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7601.17514_none_0014e305d0cff0a7_ntvdm.exe_aacb2a51
c:\windows\winsxs\backup\x86_microsoft-windows-offlinefiles-core_31bf3856ad364e35_6.1.7601.17514_none_a04fb2d2ba296321_csc.sys_06be9334
c:\windows\winsxs\backup\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73_ntkrnlpa.exe_165c312a
c:\windows\winsxs\backup\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73_ntoskrnl.exe_0fb0ab79
c:\windows\winsxs\backup\x86_microsoft-windows-p..installerandprintui_31bf3856ad364e35_6.1.7601.17514_none_d85ba98b542e63f7_printui.exe_bb673fff
c:\windows\winsxs\backup\x86_microsoft-windows-p..unterinfrastructure_31bf3856ad364e35_6.1.7601.17514_none_738d67435d28e27c_lodctr.exe_b02cefba
c:\windows\winsxs\backup\x86_microsoft-windows-p..unterinfrastructure_31bf3856ad364e35_6.1.7601.17514_none_738d67435d28e27c_unlodctr.exe_69df45bb
c:\windows\winsxs\backup\x86_microsoft-windows-partitionmanager_31bf3856ad364e35_6.1.7601.17514_none_e3a37d7718b1a99e_partmgr.sys_fcac898c
c:\windows\winsxs\backup\x86_microsoft-windows-pcw_31bf3856ad364e35_6.1.7600.16385_none_afe7ec81b7d3fc8d_pcw.sys_dbeb0bbd
c:\windows\winsxs\backup\x86_microsoft-windows-qos_31bf3856ad364e35_6.1.7600.16385_none_ae21beb3b8f83754_pacer.sys_c93de3d8
c:\windows\winsxs\backup\x86_microsoft-windows-rasautodial_31bf3856ad364e35_6.1.7600.16385_none_0fb054d9c6a6b4d4_rasacd.sys_43640ee7
c:\windows\winsxs\backup\x86_microsoft-windows-rasautodial_31bf3856ad364e35_6.1.7600.16385_none_0fb054d9c6a6b4d4_rasautou.exe_477abe34
c:\windows\winsxs\backup\x86_microsoft-windows-rasbase-asyncmac_31bf3856ad364e35_6.1.7600.16385_none_242e2506962cd3e0_asyncmac.sys_095e4be2
c:\windows\winsxs\backup\x86_microsoft-windows-rasbase-ndiswan_31bf3856ad364e35_6.1.7601.17514_none_f53ffaacb58ce159_ndiswan.sys_4be8047f
c:\windows\winsxs\backup\x86_microsoft-windows-rasbase-rasl2tp_31bf3856ad364e35_6.1.7600.16385_none_99b2a2c04941dfb7_rasl2tp.sys_d69e0fa7
c:\windows\winsxs\backup\x86_microsoft-windows-rasbase-raspppoe_31bf3856ad364e35_6.1.7600.16385_none_5609da43fbeb6e85_raspppoe.sys_5bc9d88d
c:\windows\winsxs\backup\x86_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_6.1.7600.16385_none_99c574fc492a728d_raspptp.sys_25e89db1
c:\windows\winsxs\backup\x86_microsoft-windows-rasbase_31bf3856ad364e35_6.1.7601.17514_none_0fe7d1ccd8b15e24_ndistapi.sys_8cfad169
c:\windows\winsxs\backup\x86_microsoft-windows-rasbase_31bf3856ad364e35_6.1.7601.17514_none_0fe7d1ccd8b15e24_ndproxy.sys_4a9480d5
c:\windows\winsxs\backup\x86_microsoft-windows-rasbase_31bf3856ad364e35_6.1.7601.17514_none_0fe7d1ccd8b15e24_wanarp.sys_19b9c668
c:\windows\winsxs\backup\x86_microsoft-windows-rdbss_31bf3856ad364e35_6.1.7601.17514_none_5bdc41b7bfab889f_rdbss.sys_f97a2535
c:\windows\winsxs\backup\x86_microsoft-windows-recdisc-main_31bf3856ad364e35_6.1.7601.17514_none_8683645d11e35ebc_recdisc.exe_20690b49
c:\windows\winsxs\backup\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.1.7601.17514_none_5685361ce62d187b_rmcast.sys_fa0d18a3
c:\windows\winsxs\backup\x86_microsoft-windows-s..ive-blackbox-driver_31bf3856ad364e35_6.1.7600.16385_none_0948d857092a4b6c_spsys.sys_95b9c9e3
c:\windows\winsxs\backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23_spldr.sys_98bd87a0
c:\windows\winsxs\backup\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b_services.exe_abfc33da
c:\windows\winsxs\backup\x86_microsoft-windows-security-spp_31bf3856ad364e35_6.1.7601.17514_none_1c68c1637f350bf1_sppsvc.exe_fc6922a9
c:\windows\winsxs\backup\x86_microsoft-windows-session0viewer_31bf3856ad364e35_6.1.7600.16385_none_e1bd3e25a80193e3_ui0detect.exe_639495e3
c:\windows\winsxs\backup\x86_microsoft-windows-smartcardsubsystem_31bf3856ad364e35_6.1.7601.17514_none_1a04a98fc835016d_scfilter.sys_87d261f5
c:\windows\winsxs\backup\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.17514_none_8198d720af5f882e_mrxsmb.sys_cf1a02fc
c:\windows\winsxs\backup\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_ac10fe207a85352b_smss.exe_d7209c3a
c:\windows\winsxs\backup\x86_microsoft-windows-standardvga_31bf3856ad364e35_6.1.7600.16385_none_9c6287a93b5351ec_vga.sys_ccdb57c9
c:\windows\winsxs\backup\x86_microsoft-windows-systemindexer_31bf3856ad364e35_6.1.7600.16385_none_d5726d6f847c1ef3_discache.sys_5d0af5cd
c:\windows\winsxs\backup\x86_microsoft-windows-systemrestore-main_31bf3856ad364e35_6.1.7601.17514_none_48e739d311811734_rstrui.exe_dfa7225b
c:\windows\winsxs\backup\x86_microsoft-windows-t..localsessionmanager_31bf3856ad364e35_6.1.7601.17514_none_a74c36ac68ccc898_lsm.exe_ecbd567a
c:\windows\winsxs\backup\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_b5257c3dc4a85a01_tcpip.sys_3339bd51
c:\windows\winsxs\backup\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.1.7601.17514_none_638cffc7ed9bc3c3_netiougc.exe_94123cfe
c:\windows\winsxs\backup\x86_microsoft-windows-tdi-driver_31bf3856ad364e35_6.1.7601.17514_none_68f5b27794389235_tdi.sys_d1537112
c:\windows\winsxs\backup\x86_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.1.7601.17514_none_ec4532373a57c1c2_tdx.sys_d0cc4fd9
c:\windows\winsxs\backup\x86_microsoft-windows-tunnel_31bf3856ad364e35_6.1.7601.17514_none_a57172f9e2f67385_tunnel.sys_90392579
c:\windows\winsxs\backup\x86_microsoft-windows-u..em-core-classdriver_31bf3856ad364e35_6.1.7600.16385_none_2fdad9144fff701e_modem.sys_10d2ecc1
c:\windows\winsxs\backup\x86_microsoft-windows-udfs_31bf3856ad364e35_6.1.7601.17514_none_a881022e7b25c9ef_udfs.sys_cf08a343
c:\windows\winsxs\backup\x86_microsoft-windows-unimodem-core_31bf3856ad364e35_6.1.7600.16385_none_946e88ef35e184db_rootmdm.sys_69a65c29
c:\windows\winsxs\backup\x86_microsoft-windows-usermodensi_31bf3856ad364e35_6.1.7600.16385_none_7238790328c77613_nsiproxy.sys_ebb6a83d
c:\windows\winsxs\backup\x86_microsoft-windows-useros_31bf3856ad364e35_6.1.7600.16385_none_cd450af4ce8086e8_dxapi.sys_be04d03f
c:\windows\winsxs\backup\x86_microsoft-windows-videoport_31bf3856ad364e35_6.1.7600.16385_none_bbf0a23665b80f3d_videoprt.sys_3ed5b0a0
c:\windows\winsxs\backup\x86_microsoft-windows-virtualdiskservice_31bf3856ad364e35_6.1.7601.17514_none_6cf23c8b58f0b544_vds.exe_cb461c29
c:\windows\winsxs\backup\x86_microsoft-windows-virtualdiskservice_31bf3856ad364e35_6.1.7601.17514_none_6cf23c8b58f0b544_vdsldr.exe_20c491b3
c:\windows\winsxs\backup\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2_ws2ifsl.sys_2d588da9
c:\windows\winsxs\backup\x86_microsoft-windows-watchdog_31bf3856ad364e35_6.1.7600.16385_none_603f3e600acfa722_watchdog.sys_6114703c
c:\windows\winsxs\backup\x86_microsoft-windows-win32k_31bf3856ad364e35_6.1.7601.17514_none_bafae3a5f8c8e2cb_win32k.sys_0d7a6fb3
c:\windows\winsxs\backup\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13_wininit.exe_7a527f28
c:\windows\winsxs\backup\x86_microsoft-windows-winlogon-tools_31bf3856ad364e35_6.1.7600.16385_none_9449cff8ee4f6cca_mpnotify.exe_bd6992f8
c:\windows\winsxs\backup\x86_microsoft-windows-winlogon-tools_31bf3856ad364e35_6.1.7600.16385_none_9449cff8ee4f6cca_wlrmdr.exe_f8ebac58
c:\windows\winsxs\backup\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500_winlogon.exe_ac37d0c5
c:\windows\winsxs\backup\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_d9efac7dbcaf385b_afd.sys_084af4a8
c:\windows\winsxs\backup\x86_microsoft-windows-wmi-core-svc_31bf3856ad364e35_6.1.7601.17514_none_a2ba25bb55333799_winmgmt.exe_8f8eb7b1
c:\windows\winsxs\backup\x86_microsoft-windows-wmilib_31bf3856ad364e35_6.1.7600.16385_none_592b507a658046bb_wmilib.sys_0dcce989
c:\windows\winsxs\backup\x86_microsoft-windows-x..rtificateenrollment_31bf3856ad364e35_6.1.7601.17514_none_f59e20ddece8f922_certenrollctrl.exe_9495aa75
c:\windows\winsxs\backup\x86_microsoft.windows.s..se.scsi_port_driver_31bf3856ad364e35_6.1.7601.17514_none_e78797ce8860e655_scsiport.sys_40c5fe6c
c:\windows\winsxs\backup\x86_networking-mpssvc-svc_31bf3856ad364e35_6.1.7601.17514_none_9c1ba564261ed6a4_mpsdrv.sys_77874865

Registry activity

Total events
3656
Read events
3525
Write events
125
Delete events
6

Modification events

PID
Process
Operation
Key
Name
Value
304
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
304
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus\SMADAV.lnk
1
304
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus\SMADAV.lnk
1
304
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
304
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\FZNQNI\FZΔEGC.rkr
00000000000000000100000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
304
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000000F000000100000006CBF0300040000000400000029E900004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000000000000000000100000064666C7464666C7400000000400000000459CA76C306012500000000000000000100000000000000000000000000000000000000E803000000000000FFFFFFFF000000000000000008B7540254E7D90105000000FFFFFFFFAC54CA76000000003853F6023052F602D0E7D9013DA9727500000000FBFFFF7FF4E7D901987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF00000000000000000000000005DF440321DF440305DF4403000000000000000000000000080000002E006C006E006B0000005300630068006500640075006C00650072002E006C006E006B000000530000005300000000000000000007000A008F030000A487D8760800000064025300E72FF9769487D8763F030000CC045300000053000200D4001D7E010011000000B8455600B045560030C4F402FCE800004F88652EACE8D90182917275FCE8D901B0E8D9012795727500000000A486F602D8E8D901CD947275A486F60284E9D9011882F602E1947275000000001882F60284E9D901E0E8D901040000000400000029E900004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000000000000000000100000064666C7464666C7400000000400000000459CA76C306012500000000000000000100000000000000000000000000000000000000E803000000000000FFFFFFFF000000000000000008B7540254E7D90105000000FFFFFFFFAC54CA76000000003853F6023052F602D0E7D9013DA9727500000000FBFFFF7FF4E7D901987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF00000000000000000000000005DF440321DF440305DF4403000000000000000000000000080000002E006C006E006B0000005300630068006500640075006C00650072002E006C006E006B000000530000005300000000000000000007000A008F030000A487D8760800000064025300E72FF9769487D8763F030000CC045300000053000200D4001D7E010011000000B8455600B045560030C4F402FCE800004F88652EACE8D90182917275FCE8D901B0E8D9012795727500000000A486F602D8E8D901CD947275A486F60284E9D9011882F602E1947275000000001882F60284E9D901E0E8D901040000000400000029E900004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000000000000000000100000064666C7464666C7400000000400000000459CA76C306012500000000000000000100000000000000000000000000000000000000E803000000000000FFFFFFFF000000000000000008B7540254E7D90105000000FFFFFFFFAC54CA76000000003853F6023052F602D0E7D9013DA9727500000000FBFFFF7FF4E7D901987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF00000000000000000000000005DF440321DF440305DF4403000000000000000000000000080000002E006C006E006B0000005300630068006500640075006C00650072002E006C006E006B000000530000005300000000000000000007000A008F030000A487D8760800000064025300E72FF9769487D8763F030000CC045300000053000200D4001D7E010011000000B8455600B045560030C4F402FCE800004F88652EACE8D90182917275FCE8D901B0E8D9012795727500000000A486F602D8E8D901CD947275A486F60284E9D9011882F602E1947275000000001882F60284E9D901E0E8D901
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
Language
1
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
LanguageSet
1
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
Path
C:\Program Files\SMADAV\
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
AutoScan
1
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
Smad-Lock
1
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
HideScanner
1
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
AllowMacro
0
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
AllowUSB
0
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
StartCount
0
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
AfterFix
0
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
UserVir1a
0
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
UserVir1b
0
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
RestartCount
0
2260
smadav2019rev1281.tmp
write
HKEY_CURRENT_USER\Software\SMADΔV
BlockStat
0
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
Inno Setup: Setup Version
5.5.4 (u)
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
Inno Setup: App Path
C:\Program Files\SMADAV
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
InstallLocation
C:\Program Files\SMADAV\
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
Inno Setup: Icon Group
SMADAV Antivirus
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
Inno Setup: User
admin
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
Inno Setup: Selected Tasks
desktopicon,statistik
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
Inno Setup: Deselected Tasks
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
Inno Setup: Language
English
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
DisplayName
SMADAV version 12.8.1
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
UninstallString
"C:\Program Files\SMADAV\unins000.exe"
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
QuietUninstallString
"C:\Program Files\SMADAV\unins000.exe" /SILENT
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
DisplayVersion
12.8.1
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
Publisher
Smadsoft
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
URLInfoAbout
https://www.smadav.net/
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
HelpLink
https://www.smadav.net/
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
URLUpdateInfo
https://www.smadav.net/
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
NoModify
1
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
NoRepair
1
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
InstallDate
20190718
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
MajorVersion
12
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
MinorVersion
8
2260
smadav2019rev1281.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1
EstimatedSize
4216
2860
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Smadav extension
{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
2860
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
SmadExt Class
2860
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}\InprocServer32
C:\Program Files\SMADAV\SmadExtc.dll
2860
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}\InprocServer32
ThreadingModel
Apartment
2860
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\SmadExt
{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
2860
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\SmadExt
{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
DateLock
18-Jul-2019 11:06:12 AM
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
VerMain
995
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
VerEngine
170
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
VerLoov
38411
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security
VBAWarnings
3
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security
VBAWarnings
2
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\PowerPoint\Security
VBAWarnings
3
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings
Enabled
0
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
Enabled
0
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
1
Mshta.exe
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
2
powershell.exe
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
3
bitsadmin.exe
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
AllowMacro
0
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SMΔRT-Protection
C:\Program Files\Smadav\SMΔRTP.exe rts
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
CommandRTP
1
4028
SMΔRTP.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASAPI32
EnableFileTracing
0
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASAPI32
EnableConsoleTracing
0
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASAPI32
FileTracingMask
4294901760
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASAPI32
ConsoleTracingMask
4294901760
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASAPI32
MaxFileSize
1048576
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASAPI32
FileDirectory
%windir%\tracing
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASMANCS
EnableFileTracing
0
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASMANCS
EnableConsoleTracing
0
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASMANCS
FileTracingMask
4294901760
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASMANCS
ConsoleTracingMask
4294901760
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASMANCS
MaxFileSize
1048576
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SM?RTP_RASMANCS
FileDirectory
%windir%\tracing
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
BuildSent
995
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
UserVir1b
3
4028
SMΔRTP.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
0400000001000000100000008CCADC0B22CEF5BE72AC411A11A8D8120F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B81190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D2000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
StartCount
1
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
UserVir1b
0
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
UpdateN
0
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
UserVir1a
3
4028
SMΔRTP.exe
write
HKEY_CURRENT_USER\Software\SMADΔV
UserVir1a
0
2192
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}\InprocServer32
2192
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
2192
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\SmadExt
2192
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\SmadExt
2192
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Smadav extension
{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
2192
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
SmadExt Class
2192
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}\InprocServer32
C:\Program Files\SMADAV\SmadExtc.dll
2192
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}\InprocServer32
ThreadingModel
Apartment
2192
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\SmadExt
{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
2192
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\SmadExt
{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C}
2748
SMΔRTP.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US

Files activity

Executable files
12
Suspicious files
1
Text files
3
Unknown types
4

Dropped files

PID
Process
Filename
Type
3648
smadav2019rev1281.exe
C:\Users\admin\AppData\Local\Temp\is-46PA7.tmp\smadav2019rev1281.tmp
executable
MD5: b78df96d71ce996fbda12992b9648597
SHA256: 9a112915cee1102fd5b4a3142b4e2170ac889db9ba70abac426606d86c5217ac
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\SmadExtc.dll
executable
MD5: 9e6434902f38a98a8792c438d4ba46c3
SHA256: e802de0e51995379489b2c1ee922a598655e0a3b135d3b6970b8e8ccd369267f
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\SmadHook32.dll
executable
MD5: dfee43ed65af697a3ef89252d38854af
SHA256: 966c3c2ca8bf429ddde07b3f9a9444bbdb2bc22dbfc36b2620ed9de1daf3df01
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\SmadavProtect32.exe
executable
MD5: b830cd1b49bd31bcdb6192c20cf0b141
SHA256: 21d34a02ec28e9bd6f7b2f96ac7921f5ef08d291416b38a3fc8cf651f11fc820
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\Smadav-Updater.exe
executable
MD5: 93c0e3a80b75758120ee278c5123e698
SHA256: 150f54a0aa90f659190a1ad3bc138a2f4330c9c291eebfbbceb59a54ae28342a
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\SmadHook64.dll
executable
MD5: 8b2225457bebdb545cbc812632b42f81
SHA256: fdbb89620e263781ac000c1dded99061a37132a4031329f69816bc78ee9516ee
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\unins000.exe
executable
MD5: fa593352ad38c734aa2a6c9480566f49
SHA256: cdaa76c7d2307d49bfbb67f7f5fd263c53202a842380bb1a62e0bf4e7c881452
2260
smadav2019rev1281.tmp
C:\Users\admin\AppData\Local\Temp\is-9TTPV.tmp\_isetup\_shfoldr.dll
executable
MD5: 92dc6ef532fbb4a5c3201469a5b5eb63
SHA256: 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
3904
smadav2019rev1281.exe
C:\Users\admin\AppData\Local\Temp\is-A1VAS.tmp\smadav2019rev1281.tmp
executable
MD5: b78df96d71ce996fbda12992b9648597
SHA256: 9a112915cee1102fd5b4a3142b4e2170ac889db9ba70abac426606d86c5217ac
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\SmadEngine.dll
executable
MD5: 1940278edcdfe3e75ed96d0d781db6d3
SHA256: b1f724adddb454c20c7d413801c394b2030d2ad8e525c41bbc288721b5434f90
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\SmadavProtect64.exe
executable
MD5: 19c5087c1b1f24b0c94e628c4aa0006f
SHA256: f421997ca4345e59a7b2fd9dcc198deb5559072c758c156322d50f0494595218
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\SMΔRTP.exe
executable
MD5: 6e62f846a0d1832cf3366fd1a2504e4a
SHA256: 8ab617cf6e5b61052838c83871bf8af05d866e6de10de300f279f25993b330a8
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-UHCKG.tmp
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-GC3OC.tmp
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\unins000.dat
dat
MD5: 6fe7b94757133fc28332859b93c89265
SHA256: f26c1d0c8e89e8c39a5064fccf0182dbedaba4b2be8d6e4bf7d65f928d4da519
2260
smadav2019rev1281.tmp
C:\Users\Public\Desktop\SMADΔV.lnk
lnk
MD5: 4686258086a96315780c569f867d2ad1
SHA256: 3566436c52aab9f52a2c82bf60c76c75776359eb2694719f568f3d553a865ab9
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-1GV80.tmp
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-GE3S5.tmp
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus\Uninstall SMADAV.lnk
lnk
MD5: 1a9056a9378d09ec4b12d87ec2cb45c9
SHA256: 5cf2e62bbadbdc12678014bad9bc7c6be743d1169f9f721e0efa7d1abb55d7a1
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-PIM7E.tmp
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus\SMADAV.lnk
lnk
MD5: 35647d69a8d89fbce97d35ecfc24c5dc
SHA256: 0c4454d0358cfe79bcfc56e65456d74b625e335fc2d51db08df8a7715c9f09d5
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\Smadav.loov
binary
MD5: 062807b6133b9c8a12a044d3d7f9a96b
SHA256: f6563e3b01c2305e37f52d85d7141ffbf61fa03ffd27f01c46cf3a6755def804
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-CINUB.tmp
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-GLH5P.tmp
––
MD5:  ––
SHA256:  ––
4028
SMΔRTP.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\secure-smadav[1].txt
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-AAE2N.tmp
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\Readme.txt
text
MD5: 42bd2f197f5972eab8aa8d26cf26b9cd
SHA256: 8dd3529d09ed58295e9043169b32d8abb074b60ac6c3cdaa65824002454be710
4028
SMΔRTP.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\smadstat[1].php
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-7GOA5.tmp
––
MD5:  ––
SHA256:  ––
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-INE49.tmp
––
MD5:  ––
SHA256:  ––
4028
SMΔRTP.exe
C:\Users\admin\AppData\Roaming\Smadav\smadav.xml
xml
MD5: e75bf945f52470519e60d15e8c4b4c9a
SHA256: 0a69cfae24564994090789a3912b770fe73bdf65e3067d67b3b2dc13c02b1214
2260
smadav2019rev1281.tmp
C:\Program Files\SMADAV\is-PHSKE.tmp
––
MD5:  ––
SHA256:  ––
4028
SMΔRTP.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\smadavstats27[1].php
text
MD5: 028ec8ffe0998d944087b776df75bc0a
SHA256: da43e55f7d4ea4532a1bc80633955b3bd9371f735606b90c5b5dd752cf329621

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
3
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
4028 SMΔRTP.exe GET 200 148.72.212.69:80 http://lempar.com/smadstat.php?mac=1994429369A727963&key=0&name=0&os=2%2E6%2E1%2E7601&build=995&old=-1&mode=0&stat1=777&stat2=1&stat3=0&stat4=3&stat5=8002&stat6=6 US
binary
malicious
4028 SMΔRTP.exe POST 200 132.148.148.111:80 http://www.prblm.com/smadavstats27.php US
text
text
unknown
4028 SMΔRTP.exe GET 200 148.72.212.69:80 http://www.lempar.com/update/secure-smadav.txt US
text
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
4028 SMΔRTP.exe 148.72.212.69:80 US malicious
–– –– 132.148.148.111:80 GoDaddy.com, LLC US unknown

DNS requests

Domain IP Reputation
lempar.com 148.72.212.69
malicious
www.prblm.com 132.148.148.111
unknown
www.lempar.com 148.72.212.69
malicious

Threats

PID Process Class Message
4028 SMΔRTP.exe A Network Trojan was detected MALWARE [PTsecurity] Trojan.Win32.Bublik.ezgt

Debug output strings

No debug info.