Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
procexp64.exe 68.59 26,016 K 44,436 K 2976 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
System Idle Process 15.11 0 K 24 K 0
WmiPrvSE.exe 5,664 K 10,248 K 2452 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
dwm.exe 5.66 65,484 K 30,424 K 2124 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
Interrupts 5.73 0 K 0 K n/a Hardware Interrupts and DPCs
csrss.exe 1.83 2,400 K 11,508 K 488 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows
System 1.47 368 K 12,560 K 4
AvastSvc.exe 0.74 75,992 K 40,960 K 1248 avast! Service AVAST Software (Verified) AVAST Software a.s.
svchost.exe 0.02 26,352 K 41,420 K 1020 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
firefox.exe 474,892 K 524,844 K 3096 Firefox Mozilla Corporation (Verified) Mozilla Corporation
explorer.exe 0.42 38,668 K 52,280 K 2176 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
lsass.exe 0.07 5,752 K 12,028 K 608 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows
lsm.exe 2,352 K 3,880 K 616 Local Session Manager Service Microsoft Corporation (Verified) Microsoft Windows
AvastUI.exe 0.03 12,748 K 26,316 K 2984 avast! Antivirus AVAST Software (Verified) AVAST Software a.s.
svchost.exe 0.12 3,808 K 7,936 K 720 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
services.exe 4,892 K 7,176 K 584 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows
wmpnetwk.exe 0.01 16,700 K 14,500 K 1404 Windows Media Player Network Sharing Service Microsoft Corporation (Verified) Microsoft Windows
unsecapp.exe 1,468 K 5,656 K 1816 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 10,244 K 12,780 K 1392 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.02 7,348 K 11,384 K 996 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.02 16,004 K 16,792 K 1176 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
taskhost.exe 0.03 12,988 K 14,336 K 1632 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.01 5,768 K 11,424 K 3064 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
SearchProtocolHost.exe 0.01 2,632 K 7,456 K 1008 Microsoft Windows Search Protocol Host Microsoft Corporation (Verified) Microsoft Windows
WLIDSVC.EXE 0.04 6,192 K 10,600 K 1936 Microsoft® Windows Live ID Service Microsoft Corp. (Verified) Microsoft Corporation
csrss.exe 2,308 K 6,360 K 440 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows
SearchIndexer.exe 0.04 25,784 K 20,516 K 2384 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 110,860 K 115,320 K 956 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
TODDSrv.exe < 0.01 1,348 K 3,980 K 1664 TDCSrv Application TOSHIBA Corporation (Verified) TOSHIBA CORPORATION
WmiPrvSE.exe 2,288 K 5,964 K 5080 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
WLIDSVCM.EXE 988 K 2,768 K 2004 Microsoft® Windows Live ID Service Monitor Microsoft Corp. (Verified) Microsoft Corporation
winlogon.exe 2,612 K 5,668 K 524 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows
wininit.exe 1,332 K 3,792 K 480 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows
TrustedInstaller.exe 163,056 K 162,180 K 4952 Windows Modules Installer Microsoft Corporation (Verified) Microsoft Windows
TosCoSrv.exe 2,228 K 3,680 K 1820 TOSHIBA Power Saver TOSHIBA Corporation (Verified) TOSHIBA CORPORATION
taskeng.exe 1,424 K 4,868 K 576 Task Scheduler Engine Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 4,608 K 8,020 K 796 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 1,408 K 4,868 K 2332 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 17,748 K 16,320 K 856 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 1,696 K 4,872 K 1592 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 2,416 K 4,980 K 736 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 4,636 K 9,208 K 1532 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 2,340 K 5,500 K 2204 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
spoolsv.exe 6,688 K 7,992 K 1356 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
smss.exe 412 K 1,052 K 340 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows
SearchFilterHost.exe 1,524 K 4,724 K 3996 Microsoft Windows Search Filter Host Microsoft Corporation (Verified) Microsoft Windows
procexp.exe 2,568 K 6,988 K 3456 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
igfxtray.exe 1,764 K 4,972 K 2868 igfxTray Module Intel Corporation (Verified) Intel Corporation
igfxpers.exe 1,800 K 5,616 K 2892 persistence Module Intel Corporation (Verified) Intel Corporation
hkcmd.exe 2,524 K 8,452 K 2884 hkcmd Module Intel Corporation (Verified) Intel Corporation
dllhost.exe 1,708 K 5,516 K 3964 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
cAudioFilterAgent64.exe 1,736 K 4,848 K 2520 Conexant High Definition Audio Filter Agent Conexant Systems, Inc. (Verified) Conexant Systems
BelkinService.exe 1,980 K 5,776 K 1492 BelkinService Affinegy, Inc. (Verified) Affinegy
audiodg.exe 16,272 K 16,500 K 1372 Windows Audio Device Graph Isolation Microsoft Corporation (Verified) Microsoft Windows
Process: procexp64.exe Pid: 2976
Type Name
ALPC Port \RPC Control\OLE037DA41719954EA89F98A27E735F
Desktop \Default
Directory \KnownDlls
Directory \Sessions\1\BaseNamedObjects
Event \BaseNamedObjects\CLR_PerfMon_DoneEnumEvent
Event \BaseNamedObjects\CLR_PerfMon_StartEnumEvent
Event \KernelObjects\MaximumCommitCondition
Event \BaseNamedObjects\TermSrvReadyEvent
Event \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterEvent
Event \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterEvent
Event \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterEvent
Event \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterEvent
File C:\Users\MWG\Desktop
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Windows\System32\en-US\setupapi.dll.mui
File C:\Windows\System32\en-US\advapi32.dll.mui
File \Device\PROCEXP152
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File \Device\KsecDD
File C:\Windows\Fonts\StaticCache.dat
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
File C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23508_none_145555328b95eaaa
File C:\ProgramData\AVAST Software\Avast
File C:\Program Files\AVAST Software\Avast\setup
File \Device\NamedPipe\srvsvc
File \Device\Afd
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File \Device\Afd
File \Device\Afd
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Windows\System32\en-US\wshtcpip.dll.mui
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File \Device\Afd
File C:\Windows\System32\en-US\crypt32.dll.mui
File C:\Windows\System32\en-US\comdlg32.dll.mui
File C:\Windows\System32\en-US\wship6.dll.mui
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
File \Device\Afd
File C:\Windows\System32\en-US\msxml3r.dll.mui
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
File \Device\KsecDD
File C:\Windows\System32\en-US\KernelBase.dll.mui
File C:\Windows\System32\en-US\user32.dll.mui
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
File C:\Windows\System32\en-US\thumbcache.dll.mui
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
File \Device\Nsi
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
File \Device\Afd
File \Device\Afd
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
File C:\Windows\System32\en-US\shell32.dll.mui
File C:\Windows\System32\en-US\propsys.dll.mui
File C:\Windows\System32\en-US\explorerframe.dll.mui
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
File C:\Windows\System32\en-US\oleaccrc.dll.mui
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
File C:\Users\MWG\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
File C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
File C:\Users\MWG\AppData\Roaming\Microsoft\SystemCertificates\My
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Key HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER
Key HKLM
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PERFLIB
Key HKCU
Key HKLM\SYSTEM\ControlSet001\services\.NET CLR Data\Performance
Key HKLM\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance
Key HKLM\SYSTEM\ControlSet001\services\.NET CLR Networking 4.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\.NET Data Provider for Oracle\Performance
Key HKLM\SYSTEM\ControlSet001\services\.NET Data Provider for SqlServer\Performance
Key HKLM\SYSTEM\ControlSet001\services\.NET Memory Cache 4.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\.NETFramework\Performance
Key HKLM\SYSTEM\ControlSet001\services\ASP.NET\Performance
Key HKLM\SYSTEM\ControlSet001\services\ASP.NET_4.0.30319\Performance
Key HKLM\SYSTEM\ControlSet001\services\aspnet_state\Performance
Key HKLM\SYSTEM\ControlSet001\services\BITS\Performance
Key HKLM\SYSTEM\ControlSet001\services\ESENT\Performance
Key HKLM\SYSTEM\ControlSet001\services\Lsa\Performance
Key HKLM\SYSTEM\ControlSet001\services\MSDTC\Performance
Key HKLM\SYSTEM\ControlSet001\services\MSDTC Bridge 3.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\MSDTC Bridge 4.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\MSSCNTRS\Performance
Key HKLM\SYSTEM\ControlSet001\services\PerfDisk\Performance
Key HKLM\SYSTEM\ControlSet001\services\PerfNet\Performance
Key HKLM\SYSTEM\ControlSet001\services\PerfOS\Performance
Key HKLM\SYSTEM\ControlSet001\services\PerfProc\Performance
Key HKLM\SYSTEM\ControlSet001\services\rdyboost\Performance
Key HKLM\SYSTEM\ControlSet001\services\RemoteAccess\Performance
Key HKLM\SYSTEM\ControlSet001\services\ServiceModelEndpoint 3.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\ServiceModelOperation 3.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\ServiceModelService 3.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\SMSvcHost 3.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\SMSvcHost 4.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\Spooler\Performance
Key HKLM\SYSTEM\ControlSet001\services\TapiSrv\Performance
Key HKLM\SYSTEM\ControlSet001\services\Tcpip\Performance
Key HKLM\SYSTEM\ControlSet001\services\TermService\Performance
Key HKLM\SYSTEM\ControlSet001\services\UGatherer\Performance
Key HKLM\SYSTEM\ControlSet001\services\UGTHRSVC\Performance
Key HKLM\SYSTEM\ControlSet001\services\usbhub\Performance
Key HKLM\SYSTEM\ControlSet001\services\Windows Workflow Foundation 3.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\Windows Workflow Foundation 4.0.0.0\Performance
Key HKLM\SYSTEM\ControlSet001\services\WmiApRpl\Performance
Key HKLM\SYSTEM\ControlSet001\services\WSearchIdxPi\Performance
Key HKCU\Software\Sysinternals\Process Explorer
Key HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups
Key HKLM\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9
Key HKLM\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5
Key HKCR
Key HKCU\Software\Classes
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Key HKCU\Software\Microsoft\Windows NT\CurrentVersion
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag
Key HKU
Key HKLM\SYSTEM\ControlSet001\services\crypt32
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT
Key HKCU\Software\Microsoft\SystemCertificates\My
Key HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\PropertyBag
Key HKCU\Software\Microsoft\SystemCertificates\CA
Key HKCU
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\CA
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA
Key HKCU\Software\Microsoft\SystemCertificates\Disallowed
Key HKCU
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed
Key HKCU\Software\Microsoft\SystemCertificates\Root
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot
Key HKCU\Software\Microsoft\SystemCertificates\TrustedPeople
Key HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot
Key HKCU
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople
Key HKCU\Software\Microsoft\SystemCertificates\trust
Key HKCU
Key HKLM\SOFTWARE\Microsoft\SystemCertificates\trust
Key HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4E80-94BC-9912D7504104}\PropertyBag
Key HKCU
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.organize
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PropertyBag
Key HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Key HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell
Key HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell
Key HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag
Key HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag
Key HKU\S-1-5-21-3432716916-1219727339-2741707856-501
Key HKCU\Software\Microsoft\Internet Explorer\EUPP Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\PropertyBag
Key HKCU\Software\Policies\Microsoft\SystemCertificates
Mutant \Sessions\1\BaseNamedObjects\.NET CLR Data_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\.NET CLR Networking_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\.NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\.NET Data Provider for Oracle_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\.NET Data Provider for SqlServer_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\.NET Memory Cache 4.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\.NETFramework_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\ASP.NET_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\ASP.NET_4.0.30319_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\aspnet_state_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\BITS_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\ESENT_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\Lsa_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\MSDTC_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\MSSCNTRS_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\PerfDisk_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\PerfNet_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\PerfOS_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\PerfProc_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\rdyboost_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\RemoteAccess_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\Spooler_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\TapiSrv_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\Tcpip_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\TermService_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\UGatherer_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\UGTHRSVC_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\usbhub_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\Windows Workflow Foundation 3.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\WmiApRpl_Perf_Library_Lock_PID_ba0
Mutant \Sessions\1\BaseNamedObjects\WSearchIdxPi_Perf_Library_Lock_PID_ba0
Mutant \BaseNamedObjects\LOADPERF_MUTEX
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
Mutant \BaseNamedObjects\C::Users:MWG:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
Section \BaseNamedObjects\__ComCatalogCache__
Section \BaseNamedObjects\__ComCatalogCache__
Section \Sessions\1\BaseNamedObjects\windows_shell_global_counters
Section \BaseNamedObjects\windows_shell_global_counters
Section \Sessions\1\BaseNamedObjects\windows_ie_global_counters
Section \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{EDAE6976-3F70-49D8-B65F-3D54A4FA1BC3}.2.ver0x0000000000000001.db
Section \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro
Section \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000034.db
Section \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro
Section \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro
Section \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db
Section \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro
Thread procexp64.exe(2976): 4100
Thread procexp64.exe(2976): 4624
Thread procexp64.exe(2976): 4624
Thread procexp64.exe(2976): 3736
Thread procexp64.exe(2976): 4100
Thread procexp64.exe(2976): 4156
Thread procexp64.exe(2976): 3640
Thread procexp64.exe(2976): 2640
Thread procexp64.exe(2976): 3060
Thread procexp64.exe(2976): 3060
Thread procexp64.exe(2976): 2960
Thread procexp64.exe(2976): 2960
Thread procexp64.exe(2976): 4832
Thread procexp64.exe(2976): 4076
Thread procexp64.exe(2976): 4076
Thread procexp64.exe(2976): 4276
Thread procexp64.exe(2976): 3916
Thread procexp64.exe(2976): 4992
Thread procexp64.exe(2976): 4924
Thread procexp64.exe(2976): 1580
Thread procexp64.exe(2976): 4276
Thread procexp64.exe(2976): 2956
Thread procexp64.exe(2976): 3916
Thread procexp64.exe(2976): 2640
Thread procexp64.exe(2976): 4324
Thread procexp64.exe(2976): 4832
Thread procexp64.exe(2976): 4992
Thread procexp64.exe(2976): 4324
Thread procexp64.exe(2976): 4740
Thread procexp64.exe(2976): 2092
Thread procexp64.exe(2976): 2092
WindowStation \Sessions\1\Windows\WindowStations\WinSta0
WindowStation \Sessions\1\Windows\WindowStations\WinSta0