Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
System 41.97 128 K 1,336 K 4
PlacesServer.exe 27.73 7,308 K 26,360 K 7500 Maps Microsoft Corporation (Verified) Microsoft Windows
procexp64.exe 14.58 45,116 K 66,932 K 5788 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
RuntimeBroker.exe 4.48 20,040 K 40,920 K 5084 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
Interrupts 2.49 0 K 0 K n/a Hardware Interrupts and DPCs
dwm.exe 2.35 42,352 K 41,852 K 1016 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
System Idle Process 2.00 0 K 4 K 0
svchost.exe 1.30 49,108 K 63,112 K 576 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
backgroundTaskHost.exe 1.29 20,040 K 21,084 K 5948 Background Task Host Microsoft Corporation (Verified) Microsoft Windows
csrss.exe 0.74 2,260 K 6,364 K 668 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
AvastSvc.exe 0.38 71,664 K 39,808 K 1696 avast! Service AVAST Software (Verified) AVAST Software a.s.
svchost.exe 0.24 5,224 K 10,700 K 908 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
explorer.exe 0.12 74,124 K 111,700 K 4572 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.08 12,000 K 27,744 K 1148 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
SearchIndexer.exe 0.08 26,272 K 27,200 K 5536 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.06 41,696 K 71,500 K 440 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
lsass.exe 0.05 5,840 K 15,000 K 784 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 0.02 18,808 K 30,600 K 600 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
plays_service.exe 0.02 13,380 K 24,368 K 2276 Plays.tv Service Plays.tv, LLC (Verified) Plays.tv
AvastUI.exe 0.01 13,464 K 11,780 K 5732 avast! Antivirus AVAST Software (Verified) AVAST Software a.s.
svchost.exe < 0.01 17,624 K 46,428 K 4132 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 10,808 K 24,724 K 852 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 4,864 K 11,728 K 3564 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
afwServ.exe < 0.01 7,628 K 10,188 K 1568 avast! firewall service AVAST Software (Verified) AVAST Software a.s.
PhotoshopElementsFileAgent.exe < 0.01 2,836 K 1,416 K 1548 (Verified) Adobe Systems Incorporated
TrustedInstaller.exe < 0.01 1,752 K 6,672 K 6832 Windows Modules Installer Microsoft Corporation (Verified) Microsoft Windows
WUDFHost.exe 2,076 K 9,164 K 620 Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 5,164 K 12,848 K 6076 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 2,568 K 8,396 K 5056 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
winlogon.exe 2,148 K 9,672 K 724 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows
wininit.exe 1,200 K 5,224 K 660 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows Publisher
unsecapp.exe 1,336 K 6,716 K 5960 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
TiWorker.exe 2,124 K 8,540 K 6872 Windows Modules Installer Worker Microsoft Corporation (Verified) Microsoft Windows
taskhostw.exe 5,748 K 17,544 K 4268 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 7,784 K 17,916 K 1232 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 9,164 K 21,220 K 2284 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,408 K 9,720 K 2248 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,600 K 11,984 K 1612 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,008 K 10,572 K 2056 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8,784 K 27,540 K 2112 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 15,504 K 26,872 K 1464 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,544 K 10,676 K 6300 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,396 K 9,492 K 1536 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,688 K 15,056 K 1684 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,696 K 6,816 K 2968 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
spoolsv.exe 6,772 K 16,760 K 1796 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
smss.exe 476 K 1,036 K 400 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows Publisher
smartscreen.exe 8,160 K 13,512 K 7088 SmartScreen Microsoft Corporation (Verified) Microsoft Windows
SkypeHost.exe Suspended 19,700 K 15,068 K 4844 Microsoft Skype Preview Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
sihost.exe 5,596 K 20,948 K 4100 Shell Infrastructure Host Microsoft Corporation (Verified) Microsoft Windows
ShellExperienceHost.exe 37,932 K 77,968 K 5072 Windows Shell Experience Host Microsoft Corporation (Verified) Microsoft Windows
SettingSyncHost.exe 4,708 K 8,808 K 6844 Host Process for Setting Synchronization Microsoft Corporation (Verified) Microsoft Windows
services.exe 3,976 K 8,200 K 776 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows Publisher
SearchUI.exe Suspended 42,704 K 87,956 K 1804 Search and Cortana application Microsoft Corporation (Verified) Microsoft Windows
SearchProtocolHost.exe 2,064 K 6,636 K 6224 Microsoft Windows Search Protocol Host Microsoft Corporation (Verified) Microsoft Windows
SearchFilterHost.exe 1,224 K 5,880 K 6920 Microsoft Windows Search Filter Host Microsoft Corporation (Verified) Microsoft Windows
RtkAudioService64.exe 1,668 K 7,292 K 1556 Realtek Audio Service Realtek Semiconductor (Verified) Realtek Semiconductor Corp
RichVideo64.exe 1,396 K 6,636 K 2256 RichVideo Module (Verified) CyberLink Corp.
RemindersServer.exe Suspended 8,812 K 18,848 K 244 Reminders WinRT OOP Server Microsoft Corporation (Verified) Microsoft Windows
RAVBg64.exe 6,044 K 13,720 K 1676 HD Audio Background Process Realtek Semiconductor (Verified) Realtek Semiconductor Corp
procexp.exe 2,800 K 10,200 K 6664 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
PlacesServer.exe Suspended 5,812 K 20,872 K 6360 Maps Microsoft Corporation (Verified) Microsoft Windows
opvapp.exe 2,008 K 8,164 K 4296 (No signature was present in the subject)
OPBHOBrokerDsktop.exe 2,424 K 1,768 K 4224 HP SimplePass BHO Broker Hewlett-Packard (Verified) Softex Incorporated
OmniServ.exe 4,420 K 13,060 K 1320 HP SimplePass Service Softex Inc. (No signature was present in the subject) Softex Inc.
Memory Compression 44 K 12,008 K 2604
mDNSResponder.exe 1,672 K 6,332 K 2064 Bonjour Service Apple Inc. (Verified) Apple Inc.
ijplmsvc.exe 1,212 K 5,844 K 2084 Inkjet Printer/Scanner/Fax Extended Survey Program Service (Verified) Canon Inc.
HPSupportSolutionsFrameworkService.exe 42,180 K 44,352 K 3288 HP Support Solutions Framework Service HP Inc. (Verified) Hewlett-Packard Company
GoogleUpdate.exe 2,092 K 496 K 4260 Google Installer Google Inc. (Verified) Google Inc
GoogleCrashHandler64.exe 1,516 K 256 K 4944 Google Crash Handler Google Inc. (Verified) Google Inc
GoogleCrashHandler.exe 1,652 K 224 K 4804 Google Crash Handler Google Inc. (Verified) Google Inc
fontdrvhost.exe 816 K 3,200 K 5656 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
DropboxUpdate.exe 2,060 K 2,092 K 4776 Dropbox Update Dropbox, Inc. (Verified) Dropbox
dasHost.exe 3,904 K 12,948 K 2632 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
csrss.exe 1,544 K 4,480 K 556 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Publisher
backgroundTaskHost.exe Suspended 21,804 K 42,212 K 5292 Background Task Host Microsoft Corporation (Verified) Microsoft Windows
backgroundTaskHost.exe Suspended 10,592 K 27,332 K 5388 Background Task Host Microsoft Corporation (Verified) Microsoft Windows
backgroundTaskHost.exe Suspended 27,412 K 40,900 K 6248 Background Task Host Microsoft Corporation (Verified) Microsoft Windows
audiodg.exe 13,680 K 18,780 K 4000 Windows Audio Device Graph Isolation Microsoft Corporation (Verified) Microsoft Windows
atiesrxx.exe 1,312 K 5,524 K 1380 AMD External Events Service Module AMD (Verified) Microsoft Windows Hardware Compatibility Publisher
atieclxx.exe 2,224 K 9,508 K 1412 AMD External Events Client Module AMD (Verified) Microsoft Windows Hardware Compatibility Publisher
Process: System Pid: 4
Type Name
ALPC Port \PowerPort
ALPC Port \PowerMonitorPort
ALPC Port \PdcPort
ALPC Port \SeRmCommandPort
Desktop \Disconnect
Desktop \Disconnect
Directory \GLOBAL??
Directory \Device\Harddisk0
Directory \Device\ClVtDrv
Directory \Windows\WindowStations
Directory \Sessions\1\Windows\WindowStations
Directory \Sessions\0\DosDevices\00000000-000003e4
Directory \Sessions\0\DosDevices\00000000-0000f186
Directory \Sessions\0\DosDevices\00000000-000003e5
Directory \Device\Http
Directory \Sessions\0\DosDevices\00000000-0005aeda
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708\RPC Control
Directory \Sessions\0\DosDevices\00000000-0005af04
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-2246530975-808720366-1776470054-230329187-4153223113-3550430174-4193313734\RPC Control
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742\RPC Control
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-2246530975-808720366-1776470054-230329187-4153223113-3550430174-4193313734
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-95739096-486727260-2033287795-3853587803-1685597119-444378811-2746676523
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433\RPC Control
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433
Directory \Sessions\1\AppContainerNamedObjects\S-1-15-2-95739096-486727260-2033287795-3853587803-1685597119-444378811-2746676523\RPC Control
Event \EFSInitEvent
Event \EFSInitEvent
Event \UniqueSessionIdEvent
Event \UniqueInteractiveSessionIdEvent
Event \Sessions\1\BaseNamedObjects\EventShutDownCSRSS
Event \BaseNamedObjects\aswstmbfeevnt
Event \BaseNamedObjects\aswstmbferefresh
Event \LanmanServerAnnounceEvent
Event \Sessions\1\BaseNamedObjects\DwmComposedEvent_1
File C:\Windows\System32\config\RegBack\SOFTWARE
File \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD.LOG
File C:\Windows\System32\config\DEFAULT.LOG1
File \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD
File C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.001
File C:\Windows\System32\drivers\en-US\USBXHCI.SYS.mui
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
File C:\Windows\System32\config\RegBack\SYSTEM
File C:\Windows\System32\config\DEFAULT
File C:\Program Files (x86)\Common Files\Microsoft Shared\EQUATION\MTEXTRA.TTF
File \Device\HarddiskVolume5\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
File \clfs
File \clfs
File \clfs
File D:\$Extend\$RmMetadata\$Txf
File \clfs
File \clfs
File D:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
File D:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
File \Device\HarddiskVolume5\$Extend\$RmMetadata\$Txf
File C:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
File \clfs
File \clfs
File C:\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
File C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
File C:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000003
File C:\$Extend\$RmMetadata\$Txf
File \clfs
File \clfs
File \clfs
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
File C:\System Volume Information\{98d35562-645a-11e6-82e7-0071c20b7792}{3808876b-c176-4e48-b7ae-04046e6cc752}
File D:\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
File D:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
File D:\System Volume Information\{98d35563-645a-11e6-82e7-0071c20b7792}{3808876b-c176-4e48-b7ae-04046e6cc752}
File \clfs
File \Device\HarddiskVolume5\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
File C:\Windows\System32\config\SOFTWARE.LOG1
File C:\Windows\System32\config\SOFTWARE.LOG2
File \Device\HarddiskVolume5\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
File C:\Windows\System32\config\RegBack\DEFAULT
File C:\Windows\System32\config\SYSTEM.LOG1
File \clfs
File \clfs
File \clfs
File \clfs
File C:\Windows\System32\config\SYSTEM.LOG2
File C:\Windows\System32\config\TxR\{f5b13570-4b48-11e6-80cb-e41d2d012050}.TM.blf
File \Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
File \Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001
File \Device\HarddiskVolume1\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002
File \clfs
File \clfs
File \Device\HarddiskVolume1\$Extend\$RmMetadata\$Txf
File \clfs
File \clfs
File \clfs
File C:\Windows\System32\config\SYSTEM
File C:\Windows\System32\config\SOFTWARE
File C:\Windows\System32\config\TxR\{f5b13570-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000001.regtrans-ms
File C:\Windows\System32\config\TxR\{f5b13570-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000002.regtrans-ms
File \clfs
File \clfs
File C:\hiberfil.sys
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
File C:\Windows\System32\config\DEFAULT.LOG2
File \Device\KsecDD
File C:\Windows\bootstat.dat
File \Device\KsecDD
File C:\pagefile.sys
File C:\swapfile.sys
File C:\Windows\System32\en-US\win32kbase.sys.mui
File C:\Program Files (x86)\Common Files\Microsoft Shared\EQUATION\MTEXTRA.TTF
File C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\Required\ADMUI3.fon
File \Device\0000003b
File C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\Required\ADMUI3.fon
File C:\Windows\System32\config\RegBack\SECURITY
File C:\Windows\System32\config\SECURITY
File C:\Windows\System32\config\SECURITY.LOG1
File C:\Windows\System32\config\SECURITY.LOG2
File C:\Windows\System32\config\RegBack\SAM
File C:\Windows\System32\config\SAM
File C:\Windows\System32\config\SAM.LOG1
File C:\Windows\System32\config\SAM.LOG2
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{f5b13604-4b48-11e6-80cb-e41d2d012050}.TM.blf
File C:\Windows\System32\SleepStudy\UserNotPresentSession.etl
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{f5b13604-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000001.regtrans-ms
File C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{f5b13604-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000002.regtrans-ms
File \clfs
File \clfs
File \Device\00000040
File C:\Users\NiTa\NTUSER.DAT{dd434f3b-625f-11e6-b28a-f3afb8f9ba47}.TMContainer00000000000000000001.regtrans-ms
File C:\Windows\System32\config\BBI
File C:\Windows\System32\config\BBI.LOG2
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{dd434f19-625f-11e6-b28a-f3afb8f9ba47}.TMContainer00000000000000000002.regtrans-ms
File C:\Windows\System32\config\BBI.LOG1
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{dd434f19-625f-11e6-b28a-f3afb8f9ba47}.TMContainer00000000000000000001.regtrans-ms
File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{dd434f19-625f-11e6-b28a-f3afb8f9ba47}.TM.blf
File \clfs
File \clfs
File C:\Windows\System32\config\DRIVERS{f5b135f1-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000002.regtrans-ms
File C:\Users\NiTa\AppData\Local\Microsoft\Windows\UsrClass.dat{dd435084-625f-11e6-b28a-f3afb8f9ba47}.TMContainer00000000000000000001.regtrans-ms
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
File \Device\Ndis
File C:\
File \Device\HarddiskVolume4
File \Device\Tcp
File \Device\Tcp
File \Device\Mup
File \Device\Mup
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagtrack-Listener.etl
File \Device\NamedPipe\
File C:\ProgramData\Microsoft\Windows\wfp\wfpdiag.etl
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTWFP-IPsec Diagnostics.etl
File \Device\Tcp
File \Device\NamedPipe\afwCallbackPipe2
File \Device\NamedPipe\afwCallbackPipe3
File \Device\NamedPipe\
File C:\Windows\System32\config\TxR\{f5b1356f-4b48-11e6-80cb-e41d2d012050}.TxR.0.regtrans-ms
File C:\Windows\System32\config\TxR\{f5b1356f-4b48-11e6-80cb-e41d2d012050}.TxR.blf
File C:\Windows\System32\config\TxR\{f5b1356f-4b48-11e6-80cb-e41d2d012050}.TxR.2.regtrans-ms
File C:\Windows\System32\config\TxR\{f5b1356f-4b48-11e6-80cb-e41d2d012050}.TxR.1.regtrans-ms
File \clfs
File \clfs
File \clfs
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.ShellExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat.LOG1
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat.LOG1
File \Device\00000041
File C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20160820.081903.631.1.etl
File C:\Users\NiTa\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File C:\Windows\appcompat\Programs\Amcache.hve.LOG2
File C:\Windows\appcompat\Programs\Amcache.hve.LOG1
File C:\Users\NiTa\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
File C:\Users\NiTa\AppData\Local\Microsoft\Windows\UsrClass.dat
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File C:\Users\NiTa\AppData\Local\Microsoft\Windows\UsrClass.dat{dd435084-625f-11e6-b28a-f3afb8f9ba47}.TM.blf
File \clfs
File \clfs
File C:\Users\NiTa\NTUSER.DAT{dd434f3b-625f-11e6-b28a-f3afb8f9ba47}.TMContainer00000000000000000002.regtrans-ms
File C:\Users\NiTa\NTUSER.DAT{dd434f3b-625f-11e6-b28a-f3afb8f9ba47}.TM.blf
File \Device\NamedPipe
File C:\Users\NiTa\ntuser.dat.LOG1
File C:\Users\NiTa\NTUSER.DAT
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat
File C:\Windows\System32\LogFiles\WMI\LwtNetLog.etl
File C:\ProgramData\AVAST Software\Avast\Fonts\OpenSans-Bold.ttf
File C:\Users\NiTa\AppData\Local\Microsoft\Windows\UsrClass.dat{dd435084-625f-11e6-b28a-f3afb8f9ba47}.TMContainer00000000000000000002.regtrans-ms
File \Device\aswSnx
File C:\Windows\appcompat\Programs\Amcache.hve
File \Device\Udp
File \Device\Udp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File C:\Windows\System32\LogFiles\WMI\Wifi.etl
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\Tcp
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File \Device\NetBT_Tcpip_{469B8358-7C69-4CC4-8B82-AF4310768011}
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c\ActivationStore.dat
File C:\Users\NiTa\ntuser.dat.LOG2
File C:\Windows\Logs\dosvc\dosvc.20160819_221922_912.etl
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG2
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG1
File C:\Windows\System32\config\DRIVERS.LOG2
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c\ActivationStore.dat.LOG1
File C:\Windows\System32\config\DRIVERS.LOG1
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.ShellExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat
File \Device\NamedPipe
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c\ActivationStore.dat.LOG2
File C:\Windows\System32\config\DRIVERS
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat.LOG1
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat.LOG2
File C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.ShellExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat.LOG2
File C:\ProgramData\AVAST Software\Avast\Fonts\RobotoCondensed-Regular.ttf
File \Device\NamedPipe
File C:\Windows\System32\config\DRIVERS{f5b135f1-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000001.regtrans-ms
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1
File C:\ProgramData\AVAST Software\Avast\Fonts\RobotoCondensed-Bold.ttf
File \Device\NamedPipe
File \clfs
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
File C:\Users\NiTa\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat.LOG2
File C:\ProgramData\AVAST Software\Avast\Fonts\OpenSans-Regular.ttf
File \Device\NamedPipe
File C:\ProgramData\AVAST Software\Avast\Fonts\OpenSans-Italic.ttf
File C:\ProgramData\AVAST Software\Avast\Fonts\OpenSans-Light.ttf
File \Device\HarddiskVolume4
File C:\Windows\System32\config\DRIVERS{f5b135f1-4b48-11e6-80cb-e41d2d012050}.TM.blf
File \clfs
File \clfs
File \clfs
File C:\Users\HeatherAnnique\NTUSER.DAT{dd434f3a-625f-11e6-b28a-f3afb8f9ba47}.TxR.0.regtrans-ms
File C:\Users\HeatherAnnique\NTUSER.DAT{dd434f3a-625f-11e6-b28a-f3afb8f9ba47}.TxR.2.regtrans-ms
File C:\Users\HeatherAnnique\NTUSER.DAT{dd434f3a-625f-11e6-b28a-f3afb8f9ba47}.TxR.1.regtrans-ms
File C:\Users\HeatherAnnique\NTUSER.DAT{dd434f3a-625f-11e6-b28a-f3afb8f9ba47}.TxR.blf
File C:\Users\HeatherAnnique\NTUSER.DAT{dd434f3b-625f-11e6-b28a-f3afb8f9ba47}.TMContainer00000000000000000002.regtrans-ms
File C:\Users\HeatherAnnique\NTUSER.DAT{dd434f3b-625f-11e6-b28a-f3afb8f9ba47}.TMContainer00000000000000000001.regtrans-ms
File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTPROCEXP TRACE.etl
File C:\Users\HeatherAnnique\ntuser.dat.LOG2
File C:\Users\HeatherAnnique\ntuser.dat.LOG1
File C:\Users\HeatherAnnique\NTUSER.DAT
File C:\Users\HeatherAnnique\NTUSER.DAT{dd434f3b-625f-11e6-b28a-f3afb8f9ba47}.TM.blf
File \clfs
FilterConnectionPort \SnxVlabCommPort
FilterConnectionPort \SnxCommPort
FilterConnectionPort \aswFsBlkPort
FilterConnectionPort \WcnfsPort
FilterConnectionPort \aswPort
FilterConnectionPort \WcifsPort
FilterConnectionPort \storqosfltport
Key \REGISTRY
Key HKLM\SYSTEM\ControlSet001\Control\hivelist
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager\Memory Management\PrefetchParameters
Key HKLM\SYSTEM\ControlSet001\Control\Notifications
Key HKLM\SYSTEM\Setup
Key HKLM\SYSTEM
Key HKLM\SYSTEM\ControlSet001
Key HKLM\SYSTEM\DriverDatabase
Key HKU
Key HKLM\SYSTEM\ControlSet001\Control\DeviceClasses
Key HKLM\SYSTEM\ControlSet001\Enum
Key HKLM\SYSTEM\ControlSet001\Control\DeviceContainers
Key HKLM\SYSTEM\ControlSet001\Control\Class
Key HKLM\SYSTEM\ControlSet001\Services
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Key HKLM\SYSTEM\RNG
Key HKLM\SYSTEM\ControlSet001\Control\WMI\Security
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0
Key HKLM\SYSTEM\ControlSet001\Services\NDIS\IfTypes\131
Key HKLM\SYSTEM\ControlSet001\Services\NDIS\IfTypes\23
Key HKLM\SYSTEM\ControlSet001\Control\Lsa
Key HKLM\SYSTEM\ControlSet001\Services\aswSnx
Key HKLM\SYSTEM\ControlSet001\Services\aswSP
Key HKLM\SYSTEM\ControlSet001\Control\hiveredirectionlist
Key HKLM\SYSTEM\ControlSet001\Control\FileSystem
Key HKLM\SYSTEM\ControlSet001\Control\Power\Profile\Events\{54533251-82be-4824-96c1-47b60b740d00}\{0DA965DC-8FCF-4c0b-8EFE-8DD5E7BC959A}\{7E01ADEF-81E6-4e1b-8075-56F373584694}
Key HKLM\SYSTEM\ControlSet001\Control\Power\Profile\Events\{54533251-82be-4824-96c1-47b60b740d00}\{EE1E4F72-E368-46b1-B3C6-5048B11C2DBD}\{9C1F0DBA-33E9-43af-9EDA-A607AA5139DA}
Key HKLM\SYSTEM\ControlSet001\Control\FileSystem
Key HKLM\SYSTEM\ControlSet001\Policies
Key HKLM\SYSTEM\ControlSet001\Services\NDIS\IfTypes\24
Key HKLM\SYSTEM\ControlSet001\Services\NDIS\IfTypes\6
Key HKLM\SYSTEM\ControlSet001\Services\NDIS\IfTypes\71
Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 1
Key HKLM\SYSTEM\ControlSet001\Services\Mup
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\Order
Key HKLM\SOFTWARE\Policies\Microsoft\Windows
Key HKLM\SYSTEM\ControlSet001\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{221601AB-48C7-4970-B0EC-96E66F578407}
Key HKLM\SYSTEM\ControlSet001\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{FB9F5B62-B48B-45F5-8586-E514958C92E2}
Key HKLM\SYSTEM\ControlSet001\Control\Lsa
Key HKLM\SYSTEM\ControlSet001\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{498B1B9F-8618-4E6C-9AD1-6A759BFBFB23}
Key HKLM\SYSTEM\ControlSet001\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}
Key HKLM\SYSTEM\ControlSet001\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{D73E01AC-F5A0-4D80-928B-33C1920C38BA}
Key HKLM\SYSTEM\ControlSet001\Services\Dfsc\Parameters
Key HKLM\SYSTEM\ControlSet001\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{A25AE4F2-1B96-4CED-8007-AA30E9B1A218}
Key HKLM\SYSTEM\ControlSet001\Control\FileSystem
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render
Key HKLM\SYSTEM\ControlSet001\Enum\USB\VID_04E8&PID_6860\c6ecdaa2\Device Parameters
Key HKLM\SYSTEM\ControlSet001\Enum\USB\VID_04E8&PID_6860\c6ecdaa2\Device Parameters
Key HKLM\SYSTEM\ControlSet001\Enum\USB\VID_04E8&PID_6860\c6ecdaa2\Device Parameters
Key HKLM\SYSTEM\ControlSet001\Enum\USB\VID_04E8&PID_6860&MS_COMP_MTP&SAMSUNG_Android\6&fab1280&1&0000\Device Parameters\WUDFDiagnosticInfo
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\Data
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications
Key HKLM\SYSTEM\ControlSet001\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}\0042
Key HKLM\SYSTEM\ControlSet001\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}\0001
Key HKLM\SYSTEM\ControlSet001\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}\0001
Key HKLM\SYSTEM\ControlSet001\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}\0001
Key HKLM\SYSTEM\ControlSet001\Control\Session Manager\Quota System
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\VolatileNotifications
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine
Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine
Key HKLM\SYSTEM\ControlSet001\Services\NativeWifiP
Key HKLM\SYSTEM\ControlSet001\Services\NativeWifiP\Parameters\Adapters
Key HKLM\SYSTEM\ControlSet001\Services\NativeWifiP\Parameters
Key HKLM\SYSTEM\ControlSet001\Services\NativeWifiP\Parameters\Adapters\{469b8358-7c69-4cc4-8b82-af4310768011}\ExtSTA
Key HKLM\SYSTEM\ControlSet001\Services\HTTP\Parameters\UrlAclInfo
Key HKLM\SYSTEM\ControlSet001\Services\NativeWifiP\Parameters\Adapters\{10fdea08-1168-4f59-b05d-e7c23af3e1b4}\WFD
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{10fdea08-1168-4f59-b05d-e7c23af3e1b4}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{469b8358-7c69-4cc4-8b82-af4310768011}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{e630b5b7-d1e5-4d84-ba7f-5965f9e1f034}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{7e979084-3c51-496d-8a2c-f361b4e39318}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{256469c7-09ae-428e-ae11-1c7360cf89b6}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{8332e81f-a923-431a-8ebc-b3e311f671e5}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{eeb093a2-d0b2-4795-aeda-bf16a4ecdede}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{8718928d-cbeb-45ea-a621-800a9249001d}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{dd434edb-625f-11e6-b28a-806e6f6e6963}
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\PersistentRoutes
Key HKLM\SYSTEM\ControlSet001\Services\NativeWifiP\Parameters\Adapters\{10fdea08-1168-4f59-b05d-e7c23af3e1b4}\WFDMib
Key HKLM\SYSTEM\ControlSet001\Services\NativeWifiP\Parameters\Adapters\{469b8358-7c69-4cc4-8b82-af4310768011}\ExtSTAMib
Key HKLM\SYSTEM\ControlSet001\Control\CoDeviceInstallers
Key HKLM\SYSTEM\DriverDatabase\DeviceIds
Key HKLM\SYSTEM\ControlSet001\Control\ProductOptions
Key HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Key HKLM\SYSTEM\ControlSet001\Enum\USB\VID_04E8&PID_6860\c6ecdaa2\Device Parameters
Key HKLM\SYSTEM\DriverDatabase\DriverInfFiles
Key HKLM\SYSTEM\DriverDatabase\DriverPackages
Key HKLM\SOFTWARE\Policies\Microsoft\Windows\NetworkProvider\HardenedPaths
Key HKLM\DRIVERS\DriverDatabase
Mutant \KernelObjects\BcdSyncMutant
Partition \KernelObjects\MemoryPartition0
Process System(4)
Process svchost.exe(4132)
Process System(4)
Process smss.exe(400)
Process smss.exe(400)
Process PlacesServer.exe(7500)
Process csrss.exe(556)
Process HPSupportSolutionsFrameworkService.exe(3288)
Process csrss.exe(556)
Process csrss.exe(556)
Process wininit.exe(660)
Process wininit.exe(660)
Process winlogon.exe(724)
Process csrss.exe(668)
Process explorer.exe(4572)
Process winlogon.exe(724)
Process lsass.exe(784)
Process services.exe(776)
Process lsass.exe(784)
Process services.exe(776)
Process lsass.exe(784)
Process lsass.exe(784)
Process lsass.exe(784)
Process backgroundTaskHost.exe(5292)
Process svchost.exe(852)
Process services.exe(776)
Process svchost.exe(852)
Process svchost.exe(852)
Process svchost.exe(908)
Process svchost.exe(908)
Process wininit.exe(660)
Process svchost.exe(852)
Process winlogon.exe(724)
Process svchost.exe(852)
Process SearchUI.exe(1804)
Process dwm.exe(1016)
Process svchost.exe(852)
Process svchost.exe(576)
Process svchost.exe(440)
Process svchost.exe(600)
Process svchost.exe(576)
Process svchost.exe(600)
Process svchost.exe(440)
Process WUDFHost.exe(620)
Process WUDFHost.exe(620)
Process WUDFHost.exe(620)
Process WUDFHost.exe(620)
Process WUDFHost.exe(620)
Process WUDFHost.exe(620)
Process spoolsv.exe(1796)
Process atiesrxx.exe(1380)
Process svchost.exe(440)
Process svchost.exe(440)
Process svchost.exe(600)
Process OmniServ.exe(1320)
Process svchost.exe(1148)
Process PlacesServer.exe(7500)
Process svchost.exe(600)
Process svchost.exe(1232)
Process OmniServ.exe(1320)
Process OmniServ.exe(1320)
Process OmniServ.exe(1320)
Process atiesrxx.exe(1380)
Process atiesrxx.exe(1380)
Process atieclxx.exe(1412)
Process atieclxx.exe(1412)
Process svchost.exe(1464)
Process svchost.exe(1148)
Process svchost.exe(1536)
Process svchost.exe(576)
Process RtkAudioService64.exe(1556)
Process svchost.exe(1536)
Process RtkAudioService64.exe(1556)
Process RtkAudioService64.exe(1556)
Process svchost.exe(1612)
Process svchost.exe(1612)
Process svchost.exe(1612)
Process svchost.exe(1612)
Process svchost.exe(1612)
Process svchost.exe(1612)
Process svchost.exe(1612)
Process AvastSvc.exe(1696)
Process AvastSvc.exe(1696)
Process RAVBg64.exe(1676)
Process AvastSvc.exe(1696)
Process svchost.exe(1684)
Process AvastSvc.exe(1696)
Process spoolsv.exe(1796)
Process spoolsv.exe(1796)
Process spoolsv.exe(1796)
Process SearchFilterHost.exe(6920)
Process svchost.exe(1232)
Process RAVBg64.exe(1676)
Process RAVBg64.exe(1676)
Process svchost.exe(3564)
Process afwServ.exe(1568)
Process afwServ.exe(1568)
Process afwServ.exe(1568)
Process afwServ.exe(1568)
Process svchost.exe(2112)
Process ijplmsvc.exe(2084)
Process PhotoshopElementsFileAgent.exe(1548)
Process svchost.exe(2056)
Process mDNSResponder.exe(2064)
Process svchost.exe(1464)
Process mDNSResponder.exe(2064)
Process svchost.exe(1464)
Process PhotoshopElementsFileAgent.exe(1548)
Process PhotoshopElementsFileAgent.exe(1548)
Process ijplmsvc.exe(2084)
Process ijplmsvc.exe(2084)
Process svchost.exe(2248)
Process PhotoshopElementsFileAgent.exe(1548)
Process RichVideo64.exe(2256)
Process svchost.exe(440)
Process svchost.exe(440)
Process svchost.exe(440)
Process ijplmsvc.exe(2084)
Process RichVideo64.exe(2256)
Process mDNSResponder.exe(2064)
Process svchost.exe(2284)
Process plays_service.exe(2276)
Process plays_service.exe(2276)
Process plays_service.exe(2276)
Process svchost.exe(2056)
Process RichVideo64.exe(2256)
Process svchost.exe(1464)
Process Memory Compression(2604)
Process dasHost.exe(2632)
Process svchost.exe(576)
Process dasHost.exe(2632)
Process plays_service.exe(2276)
Process spoolsv.exe(1796)
Process svchost.exe(440)
Process spoolsv.exe(1796)
Process GoogleUpdate.exe(4260)
Process svchost.exe(2112)
Process svchost.exe(2112)
Process taskhostw.exe(4268)
Process svchost.exe(852)
Process svchost.exe(2968)
Process svchost.exe(2968)
Process dasHost.exe(2632)
Process svchost.exe(3564)
Process SearchUI.exe(1804)
Process svchost.exe(4132)
Process GoogleCrashHandler.exe(4804)
Process svchost.exe(4132)
Process GoogleCrashHandler64.exe(4944)
Process GoogleCrashHandler64.exe(4944)
Process svchost.exe(440)
Process GoogleCrashHandler.exe(4804)
Process svchost.exe(852)
Process GoogleCrashHandler64.exe(4944)
Process backgroundTaskHost.exe(6248)
Process GoogleCrashHandler.exe(4804)
Process ShellExperienceHost.exe(5072)
Process SearchUI.exe(1804)
Process explorer.exe(4572)
Process opvapp.exe(4296)
Process SkypeHost.exe(4844)
Process smartscreen.exe(7088)
Process OPBHOBrokerDsktop.exe(4224)
Process opvapp.exe(4296)
Process GoogleUpdate.exe(4260)
Process svchost.exe(3564)
Process svchost.exe(3564)
Process svchost.exe(3564)
Process svchost.exe(440)
Process svchost.exe(600)
Process svchost.exe(2112)
Process services.exe(776)
Process svchost.exe(1148)
Process dasHost.exe(2632)
Process svchost.exe(1148)
Process svchost.exe(3564)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process RemindersServer.exe(244)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process dasHost.exe(2632)
Process svchost.exe(1148)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process dasHost.exe(2632)
Process svchost.exe(1148)
Process dasHost.exe(2632)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process svchost.exe(1148)
Process svchost.exe(3564)
Process smartscreen.exe(7088)
Process SearchProtocolHost.exe(6224)
Process svchost.exe(3564)
Process svchost.exe(3564)
Process svchost.exe(3564)
Process svchost.exe(3564)
Process svchost.exe(3564)
Process GoogleUpdate.exe(4260)
Process GoogleCrashHandler.exe(4804)
Process taskhostw.exe(4268)
Process sihost.exe(4100)
Process OPBHOBrokerDsktop.exe(4224)
Process AvastUI.exe(5732)
Process svchost.exe(4132)
Process sihost.exe(4100)
Process svchost.exe(852)
Process spoolsv.exe(1796)
Process OPBHOBrokerDsktop.exe(4224)
Process backgroundTaskHost.exe(5948)
Process SearchIndexer.exe(5536)
Process spoolsv.exe(1796)
Process backgroundTaskHost.exe(5292)
Process explorer.exe(4572)
Process backgroundTaskHost.exe(5292)
Process RuntimeBroker.exe(5084)
Process spoolsv.exe(1796)
Process svchost.exe(852)
Process ShellExperienceHost.exe(5072)
Process RuntimeBroker.exe(5084)
Process DropboxUpdate.exe(4776)
Process backgroundTaskHost.exe(5388)
Process DropboxUpdate.exe(4776)
Process SearchUI.exe(1804)
Process ShellExperienceHost.exe(5072)
Process RemindersServer.exe(244)
Process AvastUI.exe(5732)
Process audiodg.exe(4000)
Process svchost.exe(440)
Process svchost.exe(440)
Process backgroundTaskHost.exe(5388)
Process DropboxUpdate.exe(4776)
Process svchost.exe(440)
Process svchost.exe(4132)
Process svchost.exe(440)
Process SearchFilterHost.exe(6920)
Process svchost.exe(440)
Process SearchUI.exe(1804)
Process HPSupportSolutionsFrameworkService.exe(3288)
Process unsecapp.exe(5960)
Process AvastUI.exe(5732)
Process fontdrvhost.exe(5656)
Process SkypeHost.exe(4844)
Process svchost.exe(440)
Process svchost.exe(4132)
Process unsecapp.exe(5960)
Process HPSupportSolutionsFrameworkService.exe(3288)
Process backgroundTaskHost.exe(5948)
Process SkypeHost.exe(4844)
Process SettingSyncHost.exe(6844)
Process PlacesServer.exe(6360)
Process PlacesServer.exe(6360)
Process WmiPrvSE.exe(6076)
Process SkypeHost.exe(4844)
Process SearchIndexer.exe(5536)
Process svchost.exe(4132)
Process SettingSyncHost.exe(6844)
Process TrustedInstaller.exe(6832)
Process procexp.exe(6664)
Process SkypeHost.exe(4844)
Process smartscreen.exe(7088)
Process AvastUI.exe(5732)
Process PlacesServer.exe(6360)
Process WmiPrvSE.exe(5056)
Process fontdrvhost.exe(5656)
Process SkypeHost.exe(4844)
Process backgroundTaskHost.exe(6248)
Process SkypeHost.exe(4844)
Process audiodg.exe(4000)
Process SkypeHost.exe(4844)
Process svchost.exe(4132)
Process svchost.exe(6300)
Process backgroundTaskHost.exe(6248)
Process audiodg.exe(4000)
Process SkypeHost.exe(4844)
Process procexp.exe(6664)
Process SearchProtocolHost.exe(6224)
Process TiWorker.exe(6872)
Process TiWorker.exe(6872)
Process backgroundTaskHost.exe(5388)
Process TrustedInstaller.exe(6832)
Process backgroundTaskHost.exe(5292)
Process backgroundTaskHost.exe(5388)
Process PlacesServer.exe(7500)
Process procexp64.exe(5788)
Process procexp.exe(6664)
Process backgroundTaskHost.exe(6248)
Process PlacesServer.exe(7500)
Process procexp64.exe(5788)
Process procexp64.exe(5788)
Process procexp64.exe(5788)
Section \Win32kCrossSessionGlobals
Section \Device\PhysicalMemory
Section \Device\PhysicalMemory
Session \KernelObjects\Session0
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
Session \KernelObjects\Session1
SymbolicLink \GLOBAL??\ACPI#FixedButton#2&daba3ff&3#{4afa3d53-74a7-11d0-be5e-00a0c9062857}
SymbolicLink \GLOBAL??\ACPI#PNP0C0C#aa#{4afa3d53-74a7-11d0-be5e-00a0c9062857}
SymbolicLink \GLOBAL??\PCI#VEN_1022&DEV_7808&SUBSYS_2B56103C&REV_39#3&11583659&0&92#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
SymbolicLink \GLOBAL??\ROOT#vdrvroot#0000#{2e34d650-5819-42ca-84ae-d30803bae505}
SymbolicLink \GLOBAL??\ROOT#spaceport#0000#{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\ROOT#spaceport#0000#{ef66a56f-88d1-4cd8-98c4-49faf57ad8af}
SymbolicLink \GLOBAL??\ROOT#volmgr#0000#{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\PCI#VEN_1022&DEV_7801&SUBSYS_2B56103C&REV_40#3&11583659&0&88#{2accfe60-c130-11d2-b082-00a0c91efb8b}
SymbolicLink \GLOBAL??\STORAGE#Volume#{f99d45b9-fb89-11e4-8251-806e6f6e6963}#0000000040000000#{7f108a28-9833-4b3b-b780-2c6b5fa5c062}
SymbolicLink \GLOBAL??\STORAGE#Volume#{f99d45b9-fb89-11e4-8251-806e6f6e6963}#000000E415200000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\STORAGE#Volume#{f99d45b9-fb89-11e4-8251-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\STORAGE#Volume#{f99d45b9-fb89-11e4-8251-806e6f6e6963}#0000000056800000#{7f108a28-9833-4b3b-b780-2c6b5fa5c062}
SymbolicLink \GLOBAL??\STORAGE#Volume#{f99d45b9-fb89-11e4-8251-806e6f6e6963}#000000005E800000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\STORAGE#Volume#{f99d45b9-fb89-11e4-8251-806e6f6e6963}#000000E431400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\SCSI#Disk&Ven_&Prod_ST1000DM003-1ER1#4&35dce77&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\PCI#VEN_1022&DEV_7807&SUBSYS_2B56103C&REV_39#3&11583659&0&90#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
SymbolicLink \GLOBAL??\ROOT#SYSTEM#0000#{4747b320-62ce-11cf-a5d6-28db04c10000}
SymbolicLink \GLOBAL??\ROOT#SYSTEM#0000#{3c0d501a-140b-11d1-b40f-00a0c9223196}
SymbolicLink \GLOBAL??\ROOT#SYSTEM#0000#{53172480-4791-11d0-a5d6-28db04c10000}
SymbolicLink \GLOBAL??\ROOT#SYSTEM#0000#{0a4252a0-7e70-11d0-a5d6-28db04c10000}
SymbolicLink \GLOBAL??\PCI#VEN_1022&DEV_7808&SUBSYS_2B56103C&REV_39#3&11583659&0&9A#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
SymbolicLink \GLOBAL??\ROOT#SYSTEM#0000#{97ebaacb-95bd-11d0-a3ea-00a0c9223196}
SymbolicLink \GLOBAL??\PCI#VEN_1022&DEV_7807&SUBSYS_2B56103C&REV_39#3&11583659&0&98#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
SymbolicLink \GLOBAL??\ROOT#SYSTEM#0000#{cf1dda2c-9743-11d0-a3ee-00a0c9223196}
SymbolicLink \GLOBAL??\ROOT#SYSTEM#0000#{ffbb6e3f-ccfe-4d84-90d9-421418b03a8e}
SymbolicLink \GLOBAL??\ROOT#MEDIA#0000#{6994ad05-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\USB#ROOT_HUB20#4&3334158d&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
SymbolicLink \GLOBAL??\ROOT#MEDIA#0000#{65e8773d-8f56-11d0-a3b9-00a0c9223196}
SymbolicLink \GLOBAL??\ACPI#AuthenticAMD_-_AMD64_Family_22_Model_0_-_AMD_E1-6015_APU_with_Radeon_HD_Graphics____#_2#{97fadb10-4e33-40ae-359c-8bef029dbdd0}
SymbolicLink \GLOBAL??\SCSI#CdRom&Ven_hp&Prod_DVDRAM_GUB0N#4&35dce77&0&010000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\SCSI#CdRom&Ven_hp&Prod_DVDRAM_GUB0N#4&35dce77&0&010000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
SymbolicLink \GLOBAL??\USB#ROOT_HUB#4&751fc8a&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
SymbolicLink \GLOBAL??\PCI#VEN_10EC&DEV_8168&SUBSYS_2B56103C&REV_10#01000000684CE00000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
SymbolicLink \GLOBAL??\ROOT#UMBUS#0000#{65a9a6cf-64cd-480b-843e-32c86e1ba19f}
SymbolicLink \GLOBAL??\PCI#VEN_10EC&DEV_8168&SUBSYS_2B56103C&REV_10#01000000684CE00000#{cac88484-7515-4c03-82e6-71a87abac361}
SymbolicLink \GLOBAL??\PCI#VEN_1022&DEV_7814&SUBSYS_2B56103C&REV_01#3&11583659&0&80#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}
SymbolicLink \GLOBAL??\ACPI#AuthenticAMD_-_AMD64_Family_22_Model_0_-_AMD_E1-6015_APU_with_Radeon_HD_Graphics____#_1#{97fadb10-4e33-40ae-359c-8bef029dbdd0}
SymbolicLink \GLOBAL??\ACPI#AuthenticAMD_-_AMD64_Family_22_Model_0_-_AMD_E1-6015_APU_with_Radeon_HD_Graphics____#_1#{dbe4373d-3c81-40cb-ace4-e0e5d05f0c9f}
SymbolicLink \GLOBAL??\ACPI#AuthenticAMD_-_AMD64_Family_22_Model_0_-_AMD_E1-6015_APU_with_Radeon_HD_Graphics____#_2#{dbe4373d-3c81-40cb-ace4-e0e5d05f0c9f}
SymbolicLink \GLOBAL??\USB#ROOT_HUB#4&1745f490&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{9ff3b516-cd99-4eaf-8373-f2caf87ed26b}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{86841137-ed8e-4d97-9975-f2ed56b4430e}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{dda54a40-1e4c-11d1-a050-405705c10000}
SymbolicLink \GLOBAL??\USB#ROOT_HUB20#4&11a32b3&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
SymbolicLink \GLOBAL??\USB#VID_04E8&PID_6860&MS_COMP_MTP&SAMSUNG_Android#6&fab1280&1&0000#{6bdd1fc6-810f-11d0-bec7-08002be2092f}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{65e8773e-8f56-11d0-a3b9-00a0c9223196}
SymbolicLink \GLOBAL??\USB#ROOT_HUB30#4&1512d71&0&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\PCI#VEN_1022&DEV_7813&SUBSYS_2B56103C&REV_01#3&11583659&0&A7#{79626149-04a0-4353-be16-4b341b1107a9}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{dda54a40-1e4c-11d1-a050-405705c10000}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{65e8773d-8f56-11d0-a3b9-00a0c9223196}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{dda54a40-1e4c-11d1-a050-405705c10000}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{65e8773d-8f56-11d0-a3b9-00a0c9223196}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_10EC&DEV_0280&SUBSYS_103C2B56&REV_1000#4&3405719f&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
SymbolicLink \GLOBAL??\PCI#VEN_10EC&DEV_8179&SUBSYS_804B103C&REV_01#00E04CFFFE81910100#{cac88484-7515-4c03-82e6-71a87abac361}
SymbolicLink \GLOBAL??\PCI#VEN_10EC&DEV_8179&SUBSYS_804B103C&REV_01#00E04CFFFE81910100#{ad498944-762f-11d0-8dcb-00c04fc3358c}
SymbolicLink \GLOBAL??\PCI#VEN_10EC&DEV_8179&SUBSYS_804B103C&REV_01#00E04CFFFE81910100#{435b6226-1dcc-43b3-887e-217dbaa27ba3}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1005#4&a0ef172&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1005#4&a0ef172&0&0001#{a17579f0-4fec-4936-9364-249460863be5}
SymbolicLink \GLOBAL??\HDAUDIO#FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1005#4&a0ef172&0&0001#{dda54a40-1e4c-11d1-a050-405705c10000}
SymbolicLink \GLOBAL??\HID#VID_04CA&PID_004B&MI_00#7&aa66c92&0&0000#{4d1e55b2-f16f-11cf-88cb-001111000030}
SymbolicLink \GLOBAL??\HID#VID_04CA&PID_004B&MI_01&Col02#7&889afac&0&0001#{4afa3d53-74a7-11d0-be5e-00a0c9062857}
SymbolicLink \GLOBAL??\HID#VID_04CA&PID_004B&MI_00#7&aa66c92&0&0000#{884b96c3-56ef-11d1-bc8c-00a0c91405dd}
SymbolicLink \GLOBAL??\HID#VID_192F&PID_0916#6&2ca5b386&0&0000#{378de44c-56ef-11d1-bc8c-00a0c91405dd}
SymbolicLink \GLOBAL??\HID#VID_04CA&PID_004B&MI_01&Col01#7&889afac&0&0000#{4d1e55b2-f16f-11cf-88cb-001111000030}
SymbolicLink \GLOBAL??\HID#VID_04CA&PID_004B&MI_01&Col02#7&889afac&0&0001#{4d1e55b2-f16f-11cf-88cb-001111000030}
SymbolicLink \GLOBAL??\USB#VID_064E&PID_9324&MI_00#6&17f53ea7&0&0000#{6994ad05-93ef-11d0-a3cc-00a0c9223196}
SymbolicLink \GLOBAL??\HID#VID_192F&PID_0916#6&2ca5b386&0&0000#{4d1e55b2-f16f-11cf-88cb-001111000030}
SymbolicLink \GLOBAL??\USB#VID_064E&PID_9324#HF032B-T803-SE01-6-REV0101#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
SymbolicLink \GLOBAL??\USB#VID_192F&PID_0916#5&5788de0&0&1#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
SymbolicLink \GLOBAL??\USB#VID_04CA&PID_004B#5&5788de0&0&4#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
SymbolicLink \GLOBAL??\USB#VID_064E&PID_9324&MI_00#6&17f53ea7&0&0000#{e5323777-f976-4f5b-9b55-b94699c46e44}
SymbolicLink \GLOBAL??\USB#VID_064E&PID_9324&MI_00#6&17f53ea7&0&0000#{65e8773d-8f56-11d0-a3b9-00a0c9223196}
SymbolicLink \GLOBAL??\PCI#VEN_1002&DEV_9838&SUBSYS_2B56103C&REV_00#3&11583659&0&08#{5b45201d-f2f2-4f3b-85bb-30ff1f953599}
SymbolicLink \GLOBAL??\PCI#VEN_1002&DEV_9838&SUBSYS_2B56103C&REV_00#3&11583659&0&08#{1ca05180-a699-450a-9a0c-de4fbe3ddd89}
SymbolicLink \GLOBAL??\DISPLAY#HWP424E#4&8e79149&0&UID256#{dbe4373d-3c81-40cb-ace4-e0e5d05f0c9f}
SymbolicLink \GLOBAL??\ROOT#BasicDisplay#0000#{5b45201d-f2f2-4f3b-85bb-30ff1f953599}
SymbolicLink \GLOBAL??\ROOT#BasicRender#0000#{1ca05180-a699-450a-9a0c-de4fbe3ddd89}
SymbolicLink \GLOBAL??\DISPLAY#HWP424E#4&8e79149&0&UID256#{866519b5-3f07-4c97-b7df-24c5d8a8ccb8}
SymbolicLink \GLOBAL??\DISPLAY#HWP424E#4&8e79149&0&UID256#{e6f07b5f-ee97-4a90-b076-33f57bf4eaa7}
SymbolicLink \GLOBAL??\SWD#RADIO#{469B8358-7C69-4CC4-8B82-AF4310768011}#{a8804298-2d5f-42e3-9531-9c8c39eb29ce}
SymbolicLink \GLOBAL??\SWD#MMDEVAPI#MicrosoftGSWavetableSynth#{6dc23320-ab33-4ce4-80d4-bbb3ebbf2814}
SymbolicLink \GLOBAL??\SWD#MMDEVAPI#{0.0.0.00000000}.{faa09b11-fd03-4992-ad57-feafd580ceb7}#{e6327cad-dcec-4949-ae8a-991e976a79d2}
SymbolicLink \GLOBAL??\SWD#MMDEVAPI#{0.0.1.00000000}.{3449dc77-9b0f-4ac0-853f-20f6f1439e5b}#{2eef81be-33fa-4800-9670-1cd474972c3f}
SymbolicLink \GLOBAL??\{5d624f94-8850-40c3-a3fa-a4fd2080baf3}#vwifimp_wfd#5&27915378&3&13#{ad498944-762f-11d0-8dcb-00c04fc3358c}
SymbolicLink \GLOBAL??\{5d624f94-8850-40c3-a3fa-a4fd2080baf3}#vwifimp_wfd#5&27915378&3&13#{cac88484-7515-4c03-82e6-71a87abac361}
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433\Local
SymbolicLink \GLOBAL??\SWD#PRINTENUM#{D943D8D8-F7EB-4400-8EEE-A8CFF8C894B5}#{0ecef634-6ef0-472a-8085-5ad023ecbccd}
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708\Global
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-2246530975-808720366-1776470054-230329187-4153223113-3550430174-4193313734\Global
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708\Local
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708\Session
SymbolicLink \GLOBAL??\SWD#IP_TUNNEL_VBUS#ISATAP_0#{ad498944-762f-11d0-8dcb-00c04fc3358c}
SymbolicLink \GLOBAL??\SWD#IP_TUNNEL_VBUS#ISATAP_0#{cac88484-7515-4c03-82e6-71a87abac361}
SymbolicLink \GLOBAL??\SWD#IP_TUNNEL_VBUS#Teredo_Tunnel_Device#{ad498944-762f-11d0-8dcb-00c04fc3358c}
SymbolicLink \GLOBAL??\SWD#IP_TUNNEL_VBUS#Teredo_Tunnel_Device#{cac88484-7515-4c03-82e6-71a87abac361}
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-2246530975-808720366-1776470054-230329187-4153223113-3550430174-4193313734\Session
SymbolicLink \GLOBAL??\USB#VID_04E8&PID_6860#c6ecdaa2#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-95739096-486727260-2033287795-3853587803-1685597119-444378811-2746676523\Global
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742\Session
SymbolicLink \GLOBAL??\USB#VID_04E8&PID_6860&MS_COMP_MTP&SAMSUNG_Android#6&fab1280&1&0000#{6ac27878-a6fa-4155-ba85-f98f491d4f33}
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742\Local
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742\Global
SymbolicLink \GLOBAL??\SWD#PRINTENUM#{9D7DBACD-D102-4149-B2DB-FFEC94371EAB}#{0ecef634-6ef0-472a-8085-5ad023ecbccd}
SymbolicLink \GLOBAL??\SWD#PRINTENUM#{CE1CC774-39C5-4CBC-A690-0C933B6371A8}#{0ecef634-6ef0-472a-8085-5ad023ecbccd}
SymbolicLink \GLOBAL??\SWD#PRINTENUM#{FB6B87BC-B5BA-4020-AB9F-E9493D9FB1D5}#{0ecef634-6ef0-472a-8085-5ad023ecbccd}
SymbolicLink \GLOBAL??\SWD#PRINTENUM#{A0EAEC79-B4F1-47E1-9596-F87656B185C6}#{0ecef634-6ef0-472a-8085-5ad023ecbccd}
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-2246530975-808720366-1776470054-230329187-4153223113-3550430174-4193313734\Local
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-95739096-486727260-2033287795-3853587803-1685597119-444378811-2746676523\Local
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433\Global
SymbolicLink \GLOBAL??\USB#VID_04E8&PID_6860&MS_COMP_MTP&SAMSUNG_Android#6&fab1280&1&0000#{f33fdc04-d1ac-4e8e-9a30-19bbd4b108ae}
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433\Session
SymbolicLink \Sessions\1\AppContainerNamedObjects\S-1-15-2-95739096-486727260-2033287795-3853587803-1685597119-444378811-2746676523\Session
Thread System(4): 296
Thread System(4): 624
Thread System(4): 628
Thread System(4): 696
Thread System(4): 1608
Thread System(4): 1788
Thread System(4): 1784
Thread System(4): 1792
Thread System(4): 1868
Thread System(4): 2180
Thread System(4): 3576
Thread System(4): 3572
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\NETWORK SERVICE:3e4
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\NETWORK SERVICE:3e4
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\ANONYMOUS LOGON:242fd
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\NETWORK SERVICE:3e4
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\LOCAL SERVICE:3e5
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NARCISMAIN\NiTa:5af04
Token NT AUTHORITY\SYSTEM:3e7
Token NARCISMAIN\NiTa:5af04
Token NARCISMAIN\NiTa:5af04
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NT AUTHORITY\SYSTEM:3e7
Token NARCISMAIN\NiTa:5af04
Token NARCISMAIN\NiTa:5af04
Token NT AUTHORITY\SYSTEM:3e7
Token NARCISMAIN\NiTa:5af04
Token NARCISMAIN\NiTa:5af04
Token NARCISMAIN\NiTa:5af04
Token NARCISMAIN\NiTa:5af04