SQLite format 3@ -r Zl !tableInjectRawInjectRawCREATE TABLE InjectRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, DestinationPID INTEGER NOT NULL, DestinationCreationTime INTEGER NOT NULL, OpClass INTEGER NOT NULL, OpType INTEGER NOT NULL, OpFlag INTEGER NOT NULL, HookID INTEGER NOT NULL, ObjName TEXT, Classification TEXT )GetableUserRAWUserRAWCREATE TABLE UserRAW( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpSID TEXT, OpType INTEGER NOT NULL )YtableFileRawFileRawCREATE TABLE FileRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpType INTEGER NOT NULL, FileName TEXT, CloseTime INTEGER NOT NULL, NewFileName TEXT, FileSize INTEGER NOT NULL, FileHash TEXT, FileType TEXT, UNIQUE ( PID, CreationTime, FileName, OpType, OpTime ) ON CONFLICT IGNORE )-Aindexsqlite_autoindex_FileRaw_1FileRaw stableNetRawNetRawCREATE TABLE NetRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpType INTEGER NOT NULL, URL TEXT, ResponseStatusCode INTEGER NOT NULL, Location TEXT, Referer TEXT, UserAgent TEXT, SrcIPAddr TEXT, SrcPort INTEGER NOT NULL, DstIPAddr TEXT, DstPort INTEGER NOT NULL, IsListening INTEGER NOT NULL, IANAProcol INTEGER NOT NULL, ConnectionCreationTime INTEGER NOT NULL, ConnectionTerminationTime INTEGER NOT NULL, BytesReceived INTEGER NOT NULL, BytesSent INTEGER NOT NULL, FlowId INTEGER NOT NULL, dns_response TEXT )'-tablePsRawPsRawCREATE TABLE PsRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpSID TEXT, OpType INTEGER NOT NULL, ImagePath TEXT, Args TEXT, ImageMD5 TEXT, ImageSigner TEXT, PPID INTEGER NOT NULL, PCreationTime INTEGER NOT NULL, CertificateDescriptionID INTEGER NOT NULL )/''tableSchemaVersionSchemaVersionCREATE TABLE SchemaVersion( Major INTEGER NOT NULL, Minor INTEGER NOT NULL, CreationDate INTEGER NOT N    Tn'WF ["X` +K+M/n$n$S-1-5-5-0-73228C:\Windows\system32\svchost.exe-k LocalServicec78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$% -KOM/n$n$S-1-5-5-0-134381C:\Windows\system32\svchost.exe-k LocalServiceAndNoImpersonationc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$M%9 MYn'Vn'VS-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\Remediation\RemediationService.exe4ec093608537d4d7a27d37b933ae4c69Check Point Software Technologies Ltd.n$~ %G M/n$n$S-1-5-32-544C:\Windows\system32\lsass.exed2e59cd552933171475c2dd59002af5cMicrosoft Windowshn$XG%)MY8n'Vn'VS-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\Threat Emulation\TESvc.exe-sf970c08539eebdeabdcf37ac1b8c2db3Check Point Software Technologies Ltd.n$8% MOn$_n$_S-1-5-32-544C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe/watch5e6c05d3f8a06f263e1d53fc5c2c53b2Beijing Qihu Technology Co., Ltd.Dn$| %C M/n$n$S-1-5-32-544C:\Windows\system32\lsm.exe9662ee182644511439f1c53745dc1c88Microsoft Windowshn$X i; M/n'9n'9S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\Explorer.EXE38ae1b3c38faef56fe4907922f0385baMicrosoft Windows  /W3M/0n'V!mn'V!mS-1-5-5-0-6966490C:\Windows\system32\wbem\wmiprvse.exe-secured -Embedding619a67c9f617b7e69315bb28ecd5e1dfMicrosoft Windows@n$Q %A MY \n'V(n'V(S-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\ZAARUpdateService.exec571d0897bddc5fb61098916e0f406b7Check Point Software Technologies Ltd.n$ W!M/n'V1n'V1S-1-5-18C:\Windows\sysWOW64\wbem\wmiprvse.exe-Embedding4fb491ac8d46aaf22ba8bc5c73dabef7Microsoft Windows@n${ %GM/n$Xn$XS-1-5-32-544C:\Windows\system32\csrss.exeObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=1660c2862b4bf0fd9f582ef344c2b1ec72Microsoft Windows`# iM M/ $n'9n'9S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\taskhost.exe639774c9acd063f028f6084abf5593adMicrosoft Windowsn$j%G9MYn'V5n'V5S-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Updater\Updater\EPNetUpdater.exe-k CK-C108EF3B05FD -t bc7f1201119341c04344b2f2a75fa65bCheck Point Software Technologies Ltd.8n'VX%K;M/n'V8n'V8S-1-5-32-544C:\Windows\system32\conhost.exe"-1210544685-1769637833-720194780-1025316100-2103757570-197801184714572352491662562627"11e8d2206380a09e80487baa7475519cMicrosoft Windows8n$NN iy MYn'J}n'J}S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe80dee6a4f26a4498a51ec4796ddd56f5Check Point Software Technologies Ltd.n'9fi' MY(n'VA?n'VA?S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\ZAAR.exe4d6519074a55560a59deb27d799b2906Check Point Software Technologies Ltd.n'9 +K=M/n$n$S-1-5-5-0-98620C:\Windows\system32\svchost.exe-k LocalServiceNoNetworkc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$=% MYTn'W%n'W%S-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\EFRService.exe7f642c068338e19a50510763b5ec352dCheck Point Software Technologies Ltd.n$=% MYTn'W%n'W%S-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\EFRService.exe7f642c068338e19a50510763b5ec352dCheck Point Software Technologies Ltd.n$D   vX>*~qY@(       ZN Zl !tableInjectRawInjectRawCREATE TABLE InjectRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, DestinationPID INTEGER NOT NULL, DestinationCreationTime INTEGER NOT NULL, OpClass INTEGER NOT NULL, OpType INTEGER NOT NULL, OpFlag INTEGER NOT NULL, HookID INTEGER NOT NULL, ObjName TEXT, Classification TEXT )GetableUserRAWUserRAWCREATE TABLE UserRAW( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpSID TEXT, OpType INTEGER NOT NULL )YtableFileRawFileRawCREATE TABLE FileRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpType INTEGER NOT NULL, FileName TEXT, CloseTime INTEGER NOT NULL, NewFileName TEXT, FileSize INTEGER NOT NULL, FileHash TEXT, FileType TEXT, UNIQUE ( PID, CreationTime, FileName, OpType, OpTime ) ON CONFLICT IGNORE )7Aindexsqlite_autoindex_FileRaw_1FileRaw stableNetRawNetRawCREATE TABLE NetRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpType INTEGER NOT NULL, URL TEXT, ResponseStatusCode INTEGER NOT NULL, Location TEXT, Referer TEXT, UserAgent TEXT, SrcIPAddr TEXT, SrcPort INTEGER NOT NULL, DstIPAddr TEXT, DstPort INTEGER NOT NULL, IsListening INTEGER NOT NULL, IANAProcol INTEGER NOT NULL, ConnectionCreationTime INTEGER NOT NULL, ConnectionTerminationTime INTEGER NOT NULL, BytesReceived INTEGER NOT NULL, BytesSent INTEGER NOT NULL, FlowId INTEGER NOT NULL, dns_response TEXT )'-tablePsRawPsRawCREATE TABLE PsRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpSID TEXT, OpType INTEGER NOT NULL, ImagePath TEXT, Args TEXT, ImageMD5 TEXT, ImageSigner TEXT, PPID INTEGER NOT NULL, PCreationTime INTEGER NOT NULL, CertificateDescriptionID INTEGER NOT NULL )/''tableSchemaVersionSchemaVersionCREATE TABLE SchemaVersion( Major INTEGER NOT NULL, Minor INTEGER NOT NULL, CreationDate INTEGER NOT NULL )    ktableAmsiRawAmsiRaw CREATE TABLE AmsiRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, Hash TEXT )f 'tableEnvRawEnvRaw CREATE TABLE EnvRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpSID TEXT, Name TEXT, Value TEXT )]##tableRegistryRawRegistryRaw CREATE TABLE RegistryRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpType INTEGER NOT NULL, RootKey INTEGER NOT NULL, RegKey TEXT NOT NULL, Value TEXT, DataType INTEGER NOT NULL, OldData TEXT, NewData TEXT )!tableInjectRawInjectRawCREATE TABLE InjectRaw( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, DestinationPID INTEGER NOT NULL, DestinationCreationTime INTEGER NOT NULL, OpClass INTEGER NOT NULL, OpType INTEGER NOT NULL, OpFlag INTEGER NOT NULL, HookID INTEGER NOT NULL, ObjName TEXT, Classification TEXT )GetableUserRAWUserRAWCREATE TABLE UserRAW( PID INTEGER NOT NULL, CreationTime INTEGER NOT NULL, OpTime INTEGER NOT NULL, OpSID TEXT, OpType INTEGER NOT NULL )-Aindexsqlite_autoindex_FileRaw_1FileRaw   :   tg["X` +K+M/n$n$S-1-5-5-0-73228C:\Windows\system32\svchost.exe-k LocalServicec78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$% -KOM/n$n$S-1-5-5-0-134381C:\Windows\system32\svchost.exe-k LocalServiceAndNoImpersonationc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$M%9 MYn'Vn'VS-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\Remediation\RemediationService.exe4ec093608537d4d7a27d37b933ae4c69Check Point Software Technologies Ltd.n$~ %G M/n$n$S-1-5-32-544C:\Windows\system32\lsass.exed2e59cd552933171475c2dd59002af5cMicrosoft Windowshn$XG%)MY8n'Vn'VS-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\Threat Emulation\TESvc.exe-sf970c08539eebdeabdcf37ac1b8c2db3Check Point Software Technologies Ltd.n$8% MOn$_n$_S-1-5-32-544C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe/watch5e6c05d3f8a06f263e1d53fc5c2c53b2Beijing Qihu Technology Co., Ltd.Dn$| %C M/n$n$S-1-5-32-544C:\Windows\system32\lsm.exe9662ee182644511439f1c53745dc1c88Microsoft Windowshn$X i; M/n'9n'9S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\Explorer.EXE38ae1b3c38faef56fe4907922f0385baMicrosoft Windows  /W3M/0n'V!mn'V!mS-1-5-5-0-6966490C:\Windows\system32\wbem\wmiprvse.exe-secured -Embedding619a67c9f617b7e69315bb28ecd5e1dfMicrosoft Windows@n$Q %A MY \n'V(n'V(S-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\ZAARUpdateService.exec571d0897bddc5fb61098916e0f406b7Check Point Software Technologies Ltd.n$ W!M/n'V1n'V1S-1-5-18C:\Windows\sysWOW64\wbem\wmiprvse.exe-Embedding4fb491ac8d46aaf22ba8bc5c73dabef7Microsoft Windows@n${ %GM/n$Xn$XS-1-5-32-544C:\Windows\system32\csrss.exeObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=1660c2862b4bf0fd9f582ef344c2b1ec72Microsoft Windows`# iM M/ $n'9n'9S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\taskhost.exe639774c9acd063f028f6084abf5593adMicrosoft Windowsn$j%G9MYn'V5n'V5S-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Updater\Updater\EPNetUpdater.exe-k CK-C108EF3B05FD -t bc7f1201119341c04344b2f2a75fa65bCheck Point Software Technologies Ltd.8n'VX%K;M/n'V8n'V8S-1-5-32-544C:\Windows\system32\conhost.exe"-1210544685-1769637833-720194780-1025316100-2103757570-197801184714572352491662562627"11e8d2206380a09e80487baa7475519cMicrosoft Windows8n$NN iy MYn'J}n'J}S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe80dee6a4f26a4498a51ec4796ddd56f5Check Point Software Technologies Ltd.n'9fi' MY(n'VA?n'VA?S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\ZAAR.exe4d6519074a55560a59deb27d799b2906Check Point Software Technologies Ltd.n'9 +K=M/n$n$S-1-5-5-0-98620C:\Windows\system32\svchost.exe-k LocalServiceNoNetworkc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$=% MYTn'W%n'W%S-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\EFRService.exe7f642c068338e19a50510763b5ec352dCheck Point Software Technologies Ltd.n$=% MYTn'W%n'W%S-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\EFRService.exe7f642c068338e19a50510763b5ec352dCheck Point Software Technologies Ltd.n$D   M n'Vn'WW00000000000000000000000000000000n$ .Z u I! K/./( % MY n'T6n'T6S-1-5-32-544C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exed3c5cae0588a0b18f47103822342efdcCheck Point Software Technologies Ltd.n$M' % M n$;n$;S-1-5-32-544System00000000000000000000000000000000& /_ M/Xn'Un'US-1-5-5-0-6494574C:\Windows\servicing\TrustedInstaller.exe773212b2aaa24c1e31f10246b15b276cMicrosoft Windowsn$% /KM/n'Uan'UaS-1-5-5-0-6455195C:\Windows\system32\msiexec.exe/V4153511a1ce96f3ed8f5140e91363242Microsoft Windowsn$7$% MODn$n$S-1-5-32-544C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exeb1f4972420ade7681643885ba86705afBeijing Qihu Technology Co., Ltd.n$# K!M/Pn$6n$6S-1-5-18C:\Windows\system32\svchost.exe-k netsvcsc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn${"%GM/8n$Nn$NS-1-5-32-544C:\Windows\system32\csrss.exeObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=1660c2862b4bf0fd9f582ef344c2b1ec72Microsoft Windows$! %M M/n$n$S-1-5-32-544C:\Windows\system32\services.exe71c85477df9347fe8e7bc55768473fcaMicrosoft Windowshn$X -K!M/ xn$n$S-1-5-5-0-357518C:\Windows\System32\svchost.exe-k secsvcsc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$Q%A MYn'Upn'UpS-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\SBACipollaSrvHost.exec9df3560f073c25199dfb4136fd442a0Check Point Software Technologies Ltd.n$3 %wMYn'Jn'JS-1-5-32-544C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe-serviceb5c5a13dc94e59f433224a88c32695a6Check Point Software Technologies Ltd.n$ KKM/ n$n$S-1-5-18C:\Windows\System32\svchost.exe-k LocalSystemNetworkRestrictedc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$ -W!M/ n$ېn$ېS-1-5-5-0-361156C:\Windows\system32\SearchIndexer.exe/Embedding12530c2f28d29eea368818c55e79ff37Microsoft Windowsn$ii7M5 n'9n'9S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Java\jdk1.7.0_79\bin\java.exe -Dfile.encoding=UTF-8 -Xms128m -Xmx1024m -XX:PermSize=64m -XX:MaxPermSize=256m "-Djdk.tls.ephemeralDHKeySize=2048" -Djava.util.logging.config.file="C:\apache-tomcat-7.0.69\conf\logging.properties" -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.endorsed.dirs="C:\apache-tomcat-7.0.69\endorsed" -classpath "C:\apache-tomcat-7.0.69\bin\bootstrap.jar;C:\apache-tomcat-7.0.69\bin\tomcat-juli.jar" -Dcatalina.base="C:\apache-tomcat-7.0.69" -Dcatalina.home="C:\apache-tomcat-7.0.69" -Djava.io.tmpdir="C:\apache-tomcat-7.0.69\temp" org.apache.catalina.startup.Bootstrap starta18b6624206485e5b0a1a83b15316097Oracle America, Inc.h  +KM/n$\n$\S-1-5-5-0-56499C:\Windows\system32\svchost.exe-k RPCSSc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$ +K'M/@n$n$S-1-5-5-0-35206C:\Windows\system32\svchost.exe-k DcomLaunchc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$8% MO n'9n'9S-1-5-32-544C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe/start242600e96106ffce3c8b594accc6eefbBeijing Qihu Technology Co., Ltd.Dn$ +K/M/n$!n$!S-1-5-5-0-82580C:\Windows\system32\svchost.exe-k NetworkServicec78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$# +KMM/n$n$S-1-5-5-0-58104C:\Windows\System32\svchost.exe-k LocalServiceNetworkRestrictedc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$  } 7e5c&_D@   M Hn'bn'b000000000000000000000000000000000Pn$6-? KoM/n'b n'b S-1-5-18C:\Windows\system32\DllHost.exe/Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$> K=M/Hn'bn'bS-1-5-18C:\Windows\system32\consent.exe848 496 000000000598EBB0c33ec7fa308bdaeb37546973865350d1Microsoft WindowsPn$6D=   M ,n'bn'b00000000000000000000000000000000n'9D<i M1,n'bn'bS-1-5-21-2732810954-1700855356-1339776706-1000C:\Users\Admin\Downloads\RevoUninstaller_Portable\RevoUPort.exe2f814a927d097a09911111dbf0fc2e93VS Revo Group Ltd.n'9; KM/n'bn'bS-1-5-19C:\Windows\system32\AUDIODG.EXE0x8707a41ff874eb2bdb9006045a0ae989418Microsoft Windowsn$S: iKoM/n'bmn'bmS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\DllHost.exe/Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$D9   M n'bcn'b00000000000000000000000000000000n'98 i; M/n'bcn'bcS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\explorer.exe38ae1b3c38faef56fe4907922f0385baMicrosoft Windowsn'9D7   M  n'bxdn'b00000000000000000000000000000000@n$D6   M n'J}n'bj00000000000000000000000000000000n'9D5   M n'Jn'by/00000000000000000000000000000000n$'4 /KQM/n'J4n'J4S-1-5-5-0-5361835C:\Windows\system32\svchost.exe-k NetworkServiceNetworkRestrictedc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$13 %KoM/ n'bxdn'bxdS-1-5-32-544C:\Windows\SysWOW64\DllHost.exe/Processid:{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}a63dc5c2ea944e6657203e0c8edeaf61Microsoft Windows@n$D2   M n'Uan'_IT00000000000000000000000000000000n$D1   M Xn'Un'_H00000000000000000000000000000000n$D0   M n'V8n'[E000000000000000000000000000000008n$ND/   M n'V5n'[E000000000000000000000000000000008n'VD.   M n'X׹n'Zp00000000000000000000000000000000 n'T6D-   M n'Xsn'Zp00000000000000000000000000000000n'X׹D,   M n'X n'Z00000000000000000000000000000000n'X׹'+i{;MYn'X n'X S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files (x86)\CheckPoint\ICM\cef\cefsimple.exe--type=renderer --no-sandbox --service-pipe-token=495646E56DDB4033170684D03C717276 --lang=en-US --log-file="C:\Program Files (x86)\CheckPoint\ICM\cef\debug.log" --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=495646E56DDB4033170684D03C717276 --renderer-client-id=3 --mojo-platform-channel-handle=1268 /prefetch:120604f126920ac16da045618fe2d17f9Check Point Software Technologies Ltd.n'X׹8*i{]MYn'Xsn'XsS-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files (x86)\CheckPoint\ICM\cef\cefsimple.exe--type=gpu-process --no-sandbox --log-file="C:\Program Files (x86)\CheckPoint\ICM\cef\debug.log" --lang=en-US --gpu-preferences=KAAAAAAAAAAABwAAAQAAAAAAAAAAAGAAAQAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --gpu-vendor-id=0x0000 --gpu-device-id=0x0000 --gpu-driver-vendor --gpu-driver-version --gpu-driver-date --log-file="C:\Program Files (x86)\CheckPoint\ICM\cef\debug.log" --lang=en-US --service-request-channel-token=FA447463BF4BDE6203AF0FC6A7E45AA6 --mojo-platform-channel-handle=1020 /prefetch:220604f126920ac16da045618fe2d17f9Check Point Software Technologies Ltd.n'X׹)i{#MYn'X׹n'X׹S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files (x86)\CheckPoint\ICM\cef\cefsimple.exe--url=https://sc1.checkpoint.com/sc1/za/icm/promotions/halloween-20019.html20604f126920ac16da045618fe2d17f9Check Point Software Technologies Ltd. n'T6 P - q + YvZ`jK1Y ie M38n'c2n'c2S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exe68ad21ca1a0070b39a53a4d7b98fcce3Mozilla Corporationn'c-DX   M  n'c-n'c200000000000000000000000000000000n$DW   M Tn'c.Mn'c200000000000000000000000000000000 n'c-܃V%YM3Tn'c.Mn'c.MS-1-5-32-544C:\Program Files (x86)\Mozilla Maintenance Service\update\updater.exeC:\ProgramData\Mozilla\updates\308046B0AF4A39CB\updates\0 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\updated" 1696/replace "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\firefox.exe"a901c16727dad300e8e538f406d09d50Mozilla Corporation n'c-܁-U% M3 n'c-n'c-S-1-5-32-544C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exee94b72f28c1557945b40d623c32977d6Mozilla Corporationn$DT   M n'c,n'c-00000000000000000000000000000000n'9SieYM3n'c-n'c-S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\updater.exeC:\ProgramData\Mozilla\updates\308046B0AF4A39CB\updates\0 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\updated" 1696/replace "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\firefox.exe"a901c16727dad300e8e538f406d09d50Mozilla Corporationn'c,ہ(R %{ MOtn'c-!n'c-!S-1-5-32-544C:\Program Files (x86)\360\Total Security\PromoUtil.exe6a3d49ed5f08cac95d09c367f00fd169Beijing Qihu Technology Co., Ltd. n'91Q ie M3n'c,n'c,S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exe68ad21ca1a0070b39a53a4d7b98fcce3Mozilla Corporationn'9DP   M n'bn'c00000000000000000000000000000000@n$SO iKoM/n'bn'bS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\DllHost.exe/Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$DN   M n'bn'b00000000000000000000000000000000n'9M i; M/n'bn'bS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\explorer.exe38ae1b3c38faef56fe4907922f0385baMicrosoft Windowsn'9DL   M pn'bn'bT00000000000000000000000000000000n'bWDK   M Ln'bn'bċ00000000000000000000000000000000@n$DJ   M n'b:n'b00000000000000000000000000000000@n$DI   M n'b n'b00000000000000000000000000000000@n$DH   M n'bmn'b00000000000000000000000000000000@n$SG iKoM/Ln'bn'bS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\DllHost.exe/Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$F ]=M/n'bn'bS-1-5-18C:\Windows\system32\SearchFilterHost.exe0 516 520 528 65536 524 d629a0630899e2f12213ae27de454c12Microsoft Windows n$ېEaM/n'bn'bS-1-5-18C:\Windows\system32\SearchProtocolHost.exeGlobal\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" b00fbc7cbcb11c45c9a7331b37677113Microsoft Windows n$ېDD   M n'bWn'b`00000000000000000000000000000000n'9#C% M1pn'bn'bS-1-5-32-544C:\Users\Admin\Downloads\RevoUninstaller_Portable\x64\RevoUn.exe1df4936e97012dcbfe9a406b9991f04bVS Revo Group Ltd.n'bW"B% M1n'bWn'bWS-1-5-32-544C:\Users\Admin\Downloads\RevoUninstaller_Portable\RevoUPort.exe2f814a927d097a09911111dbf0fc2e93VS Revo Group Ltd.n'9-A KoM/n'b:n'b:S-1-5-18C:\Windows\system32\DllHost.exe/Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$ %u/ 9  P J xw1iuMk%Dq   M  n'c_ n'c_A00000000000000000000000000000000n'cZ^_piMM/ n'c_ n'c_ S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\regsvr32.exe/s "C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll"59bce9f07985f8a4204f4d6554cff708Microsoft Windowsn'cZ^Do   M hn'c^n'c_00000000000000000000000000000000n'cZ^_niMM/hn'c^n'c^S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\regsvr32.exe/s "C:\Program Files\Mozilla Firefox\AccessibleHandler.dll"59bce9f07985f8a4204f4d6554cff708Microsoft Windowsn'cZ^Dm   M dn'c3Sn'c^000000000000000000000000000000008n'c2Dl   M n'cZzn'c^ 00000000000000000000000000000000dn'c3S1k ie M3n'c\n'c\S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exec1a8461f26a7aa5baefcc2926fc2f989Mozilla Corporationn'cZz1j ie M3n'cZzn'cZzS-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exec1a8461f26a7aa5baefcc2926fc2f989Mozilla Corporationdn'c3SEi iw#M3n'cZ^n'cZ^S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\uninstall\helper.exe/PostUpdateb44ffe1d5383634be3a58d4f4dcb2aa0Mozilla Corporationdn'c3SDh   M hn'cWn'cZ00000000000000000000000000000000n'c3xDg   M n'c3xn'cY00000000000000000000000000000000n$8f%'M3hn'cWn'cWS-1-5-32-544C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exeupgradeb89103f3e1ba77b9fe86e66fedbae683Mozilla Corporationn'c3xDe   M $n'c3n'cW00000000000000000000000000000000n'c3xDd   M  n'cLn'cW00000000000000000000000000000000$n'c3Dc   M dn'cQn'cT00000000000000000000000000000000 n'cL=b%MM/dn'cQn'cQS-1-5-32-544C:\Windows\system32\regsvr32.exe/s "C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll"59bce9f07985f8a4204f4d6554cff708Microsoft Windows n'cLDa   M n'cOn'cQ00000000000000000000000000000000 n'cL=`%MM/n'cOn'cOS-1-5-32-544C:\Windows\system32\regsvr32.exe/s "C:\Program Files\Mozilla Firefox\AccessibleHandler.dll"59bce9f07985f8a4204f4d6554cff708Microsoft Windows n'cL#_ %w#M3 n'cLn'cLS-1-5-32-544C:\Program Files\Mozilla Firefox\uninstall\helper.exe/PostUpdateb44ffe1d5383634be3a58d4f4dcb2aa0Mozilla Corporation$n'c3ڃ^%9M3$n'c3n'c3S-1-5-32-544C:\Program Files (x86)\Mozilla Maintenance Service\update\updater.exeC:\ProgramData\Mozilla\updates\308046B0AF4A39CB\updates\0 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox" 4408 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\firefox.exe"a901c16727dad300e8e538f406d09d50Mozilla Corporationn'c3x-]% M3n'c3xn'c3xS-1-5-32-544C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exee94b72f28c1557945b40d623c32977d6Mozilla Corporationn$D\   M n'c-n'c3j00000000000000000000000000000000n'c,D[   M 8n'c2n'c3g00000000000000000000000000000000n'c-Zie9M3dn'c3Sn'c3SS-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\updater.exeC:\ProgramData\Mozilla\updates\308046B0AF4A39CB\updates\0 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox" 4408 "C:\Program Files\Mozilla Firefox" "C:\Program Files\Mozilla Firefox\firefox.exe"a901c16727dad300e8e538f406d09d50Mozilla Corporation8n'c2  ~ : @n> S~ iKoM/n'cln'clS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\DllHost.exe/Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$}% UMG n'cn'cS-1-5-32-544C:\Program Files (x86)\360\Total Security\safemon\WDSafeDown.exeFiles (x86)\360\Total Security\safemon\WDSafeDown.exe "C:\Users\Admin\AppData\Local\Temp\wd1775.tmp"5f0ec71e12648d465454f03604faf817QIHU 360 SOFTWARE CO. LIMITED n'9D|   M n'cn'c000000000000000000000000000000008n$ND{   M ln'cn'c00000000000000000000000000000000 xn$gziCM/n'cn'cS-1-5-20c:\program files\windows defender\MpCmdRun.exeSpyNetService -RestrictPrivileges -AccessKey 81BCA720-0C96-DF2F-6D1A-9EFC35EAB76B -Reinvoke6bd4d7f68924301051c22e8a951aecbaMicrosoft Windowsln'cӁOyK1M/n'cn'cS-1-5-18C:\Windows\system32\conhost.exe"1431226506772757555-1005482763-964695286-27236079318956909441331720679-468447336"11e8d2206380a09e80487baa7475519cMicrosoft Windows8n$N]xi/M/ln'cn'cS-1-5-18c:\program files\windows defender\MpCmdRun.exeSpyNetService -RestrictPrivileges -AccessKey 81BCA720-0C96-DF2F-6D1A-9EFC35EAB76B6bd4d7f68924301051c22e8a951aecbaMicrosoft Windows xn$ w -KM/(n$n$S-1-5-5-0-119532C:\Windows\System32\svchost.exe-k utcsvcc78655bc80301d76ed4fef1c1ea40a7dMicrosoft Windowsn$Dv   M n'cZ^n'chJ00000000000000000000000000000000dn'c3SAuie+M3n'cd^n'cd^S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exe-contentproc --channel="6636.18.707162192\815548143" -childID 4 -isForBrowser -prefsHandle 2732 -prefMapHandle 2728 -prefsLen 7257 -prefMapSize 211073 -parentBuildID 20191030021342 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 6636 "\\.\pipe\gecko-crash-server-pipe.6636" 2744 tabc1a8461f26a7aa5baefcc2926fc2f989Mozilla Corporationn'c\фAtie+M3 xn'cbn'cbS-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exe-contentproc --channel="6636.12.1110350882\854582113" -childID 3 -isForBrowser -prefsHandle 2368 -prefMapHandle 2364 -prefsLen 218 -prefMapSize 211073 -parentBuildID 20191030021342 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 6636 "\\.\pipe\gecko-crash-server-pipe.6636" 2380 tabc1a8461f26a7aa5baefcc2926fc2f989Mozilla Corporationn'c\ф?sie'M3hn'can'caS-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exe-contentproc --channel="6636.6.576105437\1701585990" -childID 2 -isForBrowser -prefsHandle 1956 -prefMapHandle 1952 -prefsLen 62 -prefMapSize 211073 -parentBuildID 20191030021342 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 6636 "\\.\pipe\gecko-crash-server-pipe.6636" 1960 tabc1a8461f26a7aa5baefcc2926fc2f989Mozilla Corporationn'c\ф=rie#M3 n'can'caS-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exe-contentproc --channel="6636.0.519932394\193174698" -childID 1 -isForBrowser -prefsHandle 1592 -prefMapHandle 1572 -prefsLen 1 -prefMapSize 211073 -parentBuildID 20191030021342 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 6636 "\\.\pipe\gecko-crash-server-pipe.6636" 1680 tabc1a8461f26a7aa5baefcc2926fc2f989Mozilla Corporationn'c\ n s U  9F(CnD   M  dn'dn'd!s00000000000000000000000000000000n'c\D   M tn'c-!n'd"00000000000000000000000000000000 n'9D   M n'd^n'd00000000000000000000000000000000n'9 i; M/n'd^n'd^S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\explorer.exe38ae1b3c38faef56fe4907922f0385baMicrosoft Windowsn'9D   M n'c\n'd00000000000000000000000000000000n'cZzS iKoM/ n'dn'dS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\DllHost.exe/Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$D   M n'cln'd00000000000000000000000000000000@n$o iK%M/dn'dOn'dOS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\conhost.exe"168137769-62141664-585441507200779582285340597722843668-638759320626712768"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$XD ik+M3n'd#n'd#S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\pingsender.exehttps://incoming.telemetry.mozilla.org/submit/telemetry/cdf46fe7-32ba-4eb0-bf16-049961f517eb/main/Firefox/70.0.1/release/20191030021342?v=4 C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2de66b35.default\saved-telemetry-pings\cdf46fe7-32ba-4eb0-bf16-049961f517eb0b1b03ed9634f5be4571255777b019d1Mozilla Corporationn'c\сr iK+M/n'd n'd S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\conhost.exe"3197178921363503863575853867170923942853185636453723781-1142822547-1341220749"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$XFik/M3 dn'dn'dS-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\pingsender.exehttps://incoming.telemetry.mozilla.org/submit/telemetry/ca261bcb-94ec-4a73-993c-90accc841296/health/Firefox/70.0.1/release/20191030021342?v=4 C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2de66b35.default\saved-telemetry-pings\ca261bcb-94ec-4a73-993c-90accc8412960b1b03ed9634f5be4571255777b019d1Mozilla Corporationn'c\сriK+M/dn'dn'dS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\conhost.exe"1962126283742443626876773351517069716571059371558782630-2065571418-1317798878"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$XEik-M3`n'dn'dS-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\pingsender.exehttps://incoming.telemetry.mozilla.org/submit/telemetry/eac6d90a-de62-4663-b0a8-059d073f2668/event/Firefox/70.0.1/release/20191030021342?v=4 C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2de66b35.default\saved-telemetry-pings\eac6d90a-de62-4663-b0a8-059d073f26680b1b03ed9634f5be4571255777b019d1Mozilla Corporationn'c\D   M  xn'cbn'd 00000000000000000000000000000000n'c\D   M  n'can'd 00000000000000000000000000000000n'c\D   M hn'can'd 00000000000000000000000000000000n'c\D   M n'c n'd i00000000000000000000000000000000n'c\сS iKoM/ n'd n'd S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\DllHost.exe/Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$D   M n'cd^n'd E00000000000000000000000000000000n'c\фCie/M3n'c n'c S-1-5-21-2732810954-1700855356-1339776706-1000C:\Program Files\Mozilla Firefox\firefox.exe-contentproc --channel="6636.24.1367069292\1101799717" -childID 5 -isForBrowser -prefsHandle 7440 -prefMapHandle 7444 -prefsLen 9378 -prefMapSize 211073 -parentBuildID 20191030021342 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 6636 "\\.\pipe\gecko-crash-server-pipe.6636" 7428 tabc1a8461f26a7aa5baefcc2926fc2f989Mozilla Corporationn'c\ r+V  1 9  {42[S*%K1M/ n'dn'dS-1-5-32-544C:\Windows\system32\conhost.exe"-814587321-12735378416307907008073388361050985515-2056371012241405004-1750048984"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$XS)%s_MYn'd~hn'd~hS-1-5-32-544C:\Program Files (x86)\CheckPoint\Install\dltel.exeunique_client=6eba36b03a91496e9aab82904feda55a client_version=15.6.121.18102 type=211117 list_of_files="/s uninstall" meta_data1=20191101T143527 meta_data2= int_field1= int_field2= int_field3= int_field4= int_field5=0 int_field6=1 int_field7=0 int_field8=0 int_field9=0 int_field10=0 str_field1="Install-Start" str_field2="{OS_BITNESS}" str_field3="{OS_INFO}" str_field4="1001" str_field5="15.6.121.18102" str_field6="/s uninstall" str_field7="15.6.121.18102" str_field8="{OS_VERSION}" str_field9="Install" str_field10="6eba36b03a91496e9aab82904feda55a"d50ce1a748d1a749ca7948011db44740Check Point Software Technologies Ltd.hn'd| 7( %w%MYhn'd| n'd| S-1-5-32-544C:\Program Files (x86)\CheckPoint\Install\Install.exe/s uninstalla4c87b8bbecf406dbc9ad18f65cd9d45Check Point Software Technologies Ltd.@n'dF=D'   M n'dEn'dY00000000000000000000000000000000@n$D&   M Ln'dEn'dYk00000000000000000000000000000000@n$D%   M n'd:n'dR00000000000000000000000000000000@n$D$   M n'dFn'dI00000000000000000000000000000000n'9<#%? M1@n'dF=n'dF=S-1-5-32-544C:\Users\Admin\Downloads\RevoUninstaller_Portable\RevoUninstaller_Portable\x64\RevoUn.exe9bd1b74d8ab4cab72f7c8c66b32ee787VS Revo Group Ltd.n'dF;"%= M1n'dFn'dFS-1-5-32-544C:\Users\Admin\Downloads\RevoUninstaller_Portable\RevoUninstaller_Portable\RevoUPort.exe2f814a927d097a09911111dbf0fc2e93VS Revo Group Ltd.n'9-! KoM/n'dEn'dES-1-5-18C:\Windows\system32\DllHost.exe/Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$D   M  n'dAn'dE00000000000000000000000000000000Pn$6- KoM/Ln'dEn'dES-1-5-18C:\Windows\system32\DllHost.exe/Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$ K=M/ n'dAn'dAS-1-5-18C:\Windows\system32\consent.exe848 646 0000000007A19F90c33ec7fa308bdaeb37546973865350d1Microsoft WindowsPn$6D   M dn'd?n'dA00000000000000000000000000000000n'9]i= M1dn'd?n'd?S-1-5-21-2732810954-1700855356-1339776706-1000C:\Users\Admin\Downloads\RevoUninstaller_Portable\RevoUninstaller_Portable\RevoUPort.exe2f814a927d097a09911111dbf0fc2e93VS Revo Group Ltd.n'9S iKoM/n'd:n'd:S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\DllHost.exe/Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$D   M  n'cn'd9]00000000000000000000000000000000 n'9D   M  n'd n'd200000000000000000000000000000000@n$D   M dn'dn'd$00000000000000000000000000000000n$XD   M `n'dn'd$00000000000000000000000000000000n'c\D   M  n'dn'd$00000000000000000000000000000000@n$D   M dn'dOn'd$00000000000000000000000000000000n$XD   M n'd#n'd$00000000000000000000000000000000n'c\D   M n'd n'd!z00000000000000000000000000000000n$X w  Do(@k$,wBOwT>%K3M/n'dn'dS-1-5-32-544C:\Windows\system32\conhost.exe"731058308-1049825634-16327359321320947173-51225509-766513202-779487343-1647967812"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$Xo=%_MYxn'dn'dS-1-5-32-544C:\Program Files (x86)\CheckPoint\ZoneAlarm\drivers\win70_64\vsdrinst.exe-u {AC30BFB5-834B-46d2-B912-6CE71684EB2D}71b8e082c64cde2455ea2a094f3fcc04Check Point Software Technologies Inc.hn'd| D<   M n'dn'd00000000000000000000000000000000n$XD;   M n'd_n'd00000000000000000000000000000000hn'd| U:%K5M/n'dn'dS-1-5-32-544C:\Windows\system32\conhost.exe"813999563-14964789911023483158-1582522499-96475764919343181281516291149-1998230326"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$XJ9%MM/n'd_n'd_S-1-5-32-544C:\Windows\SysWOW64\wevtutil.exeum C:\Program Files (x86)\CheckPoint\ZoneAlarm\VSMonEventLogProvider.man81538b795f922b8da6fd897efb04b5eeMicrosoft Windowshn'd| 18 %KoM/n'dn'dS-1-5-32-544C:\Windows\SysWOW64\DllHost.exe/Processid:{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}a63dc5c2ea944e6657203e0c8edeaf61Microsoft Windows@n$-7 KoM/n'dn'dS-1-5-18C:\Windows\system32\DllHost.exe/Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}a8edb86fc2a4d6d1285e4c70384ac35aMicrosoft Windows@n$D6   M n'dn'd 00000000000000000000000000000000n$XD5   M n'dn'd00000000000000000000000000000000hn'd| D4   M n'dn'd 00000000000000000000000000000000n$XD3   M n'den'd00000000000000000000000000000000hn'd| D2   M  n'dn'd 00000000000000000000000000000000n$XD1   M n'd~hn'd00000000000000000000000000000000hn'd| 0 ]=M/ |n'dn'dS-1-5-18C:\Windows\system32\SearchFilterHost.exe0 516 520 528 65536 524 d629a0630899e2f12213ae27de454c12Microsoft Windows n$ېD/   M n'bn'd00000000000000000000000000000000 n$ېQ.%K-M/n'dn'dS-1-5-32-544C:\Windows\system32\conhost.exe"2244224368770086631150888213-409294564-2025898294979669378-9349863521620253845"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$XR-%K/M/n'dn'dS-1-5-32-544C:\Windows\system32\conhost.exe"260238366-182582689-1682902333219747939-10768973721172460008-311174718289194346"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$Xl,%sMYn'den'deS-1-5-32-544C:\Program Files (x86)\CheckPoint\Install\dltel.exeunique_client=6eba36b03a91496e9aab82904feda55a client_version=15.6.121.18102 type=211117 list_of_files="/s uninstall" meta_data1=20191101T143530 meta_data2= int_field1=60 int_field2=0 int_field3=1001 int_field4= int_field5=0 int_field6=165 int_field7=2313 int_field8=0 int_field9=0 int_field10=10 str_field1="Uninstall-UninstallPage" str_field2="{OS_BITNESS}" str_field3="{OS_INFO}" str_field4="1001" str_field5="15.6.121.18102" str_field6="/s uninstall" str_field7="15.6.121.18102" str_field8="{OS_VERSION}" str_field9="Uninstall" str_field10="6eba36b03a91496e9aab82904feda55a"d50ce1a748d1a749ca7948011db44740Check Point Software Technologies Ltd.hn'd| r+%sMYn'dn'dS-1-5-32-544C:\Program Files (x86)\CheckPoint\Install\dltel.exeunique_client=6eba36b03a91496e9aab82904feda55a client_version=15.6.121.18102 type=211117 list_of_files="/s uninstall" meta_data1=20191101T143528 meta_data2= int_field1=60 int_field2=0 int_field3=1001 int_field4= int_field5=0 int_field6=166 int_field7=326 int_field8=0 int_field9=0 int_field10=10 str_field1="Uninstall-ChatPageOnInitDialog" str_field2="{OS_BITNESS}" str_field3="{OS_INFO}" str_field4="1001" str_field5="15.6.121.18102" str_field6="/s uninstall" str_field7="15.6.121.18102" str_field8="{OS_VERSION}" str_field9="Uninstall" str_field10="6eba36b03a91496e9aab82904feda55a"d50ce1a748d1a749ca7948011db44740Check Point Software Technologies Ltd.hn'd| U^' Z  # @m&U|5dHU(X %mMYHn'd,n'd,S-1-5-32-544C:\Program Files (x86)\CheckPoint\ICM\uninst.exe/Sb215ea40c70da834afdbe41c580ba663Check Point Software Technologies Ltd.n'dDW   M  n'dn'd00000000000000000000000000000000n$XDV   M Pn'dn'd00000000000000000000000000000000n'dQU%K-M/ n'dn'dS-1-5-32-544C:\Windows\system32\conhost.exe"-53956170460899094012426390352134919685-3516138-1957938522-4684031801506698772"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$XT %A#M/Pn'dn'dS-1-5-32-544C:\Windows\SysWOW64\sc.exequery vsmond2f7a0adc2ee0f65ab1f19d2e00c16b8Microsoft Windowsn'dDS   M  dn'dAn'dp00000000000000000000000000000000n$XDR   M 0n'd"n'dp00000000000000000000000000000000n'dUQ%K5M/ dn'dAn'dAS-1-5-32-544C:\Windows\system32\conhost.exe"-140820672013220953731528145848-2083340016-708044800140755229812381658212104789743"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$XP %A#M/0n'd"n'd"S-1-5-32-544C:\Windows\SysWOW64\sc.exestop cposfwd2f7a0adc2ee0f65ab1f19d2e00c16b8Microsoft Windowsn'dDO   M ,n'dn'd00000000000000000000000000000000n$XDN   M Dn'dn'd00000000000000000000000000000000n'dOM%K)M/,n'dn'dS-1-5-32-544C:\Windows\system32\conhost.exe"1990196159951052801720805307560396385-64974582213213804441891875048-40094333"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$Xn'dC00000000000000000000000000000000n$XDk   M n'dn'dC00000000000000000000000000000000n'd,j iK!M/hn'd7n'd7S-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\System32\mobsync.exe-Embedding509e88ff7b257885775791faf0965d6aMicrosoft Windows@n$Di   M  n'T6n'd 00000000000000000000000000000000n$Dh   M n'd?n'd00000000000000000000000000000000@n$Ug%K5M/pn'd>n'd>S-1-5-32-544C:\Windows\system32\conhost.exe"-1943364063-11479525851160336335526473028-1428643956121233298120785833661138083981"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$Xbf% M7n'dn'dS-1-5-32-544C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe/u "C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exe"af862061889f5b9b956e9469dcdae773Microsoft Corporationn'dDe   M n'dn'd00000000000000000000000000000000n$XDd   M  Ln'dn'd00000000000000000000000000000000n'dTc%K3M/n'dn'dS-1-5-32-544C:\Windows\system32\conhost.exe"402223650-11626073177645436711919708647-20951762612079939429-18368455681006695700"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$Xb %A?M/ Ln'dn'dS-1-5-32-544C:\Windows\SysWOW64\sc.exestop "ZA NET ICM Service"d2f7a0adc2ee0f65ab1f19d2e00c16b8Microsoft Windowsn'dDa   M n'dn'd00000000000000000000000000000000@n$D`   M n'dn'd\00000000000000000000000000000000@n$D_   M n'ddn'd00000000000000000000000000000000n$XD^   M (n'd&n'd00000000000000000000000000000000n'dR]%K/M/n'ddn'ddS-1-5-32-544C:\Windows\system32\conhost.exe"-7919624517276226901014283326420527770-17036639911298480511-926594234-223701284"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$X\ %A#M/(n'd&n'd&S-1-5-32-544C:\Windows\SysWOW64\sc.exestop cposfwd2f7a0adc2ee0f65ab1f19d2e00c16b8Microsoft Windowsn'dL[%'MY Hn'dn'dS-1-5-32-544C:\Program Files (x86)\CheckPoint\Endpoint Security\TPCommon\Cipolla\ZAAR.exeshutdown4d6519074a55560a59deb27d799b2906Check Point Software Technologies Ltd.n'dDZ   M Hn'd,n'd00000000000000000000000000000000n'dWY %ugMYn'dn'dS-1-5-32-544C:\Users\Admin\AppData\Local\Temp\~nsuA.tmp\Un_A.exe /S _?=C:\Program Files (x86)\CheckPoint\ICM\b215ea40c70da834afdbe41c580ba663Check Point Software Technologies Ltd.Hn'd,  - * U ' : D   M n'Vn'e00000000000000000000000000000000n$D   M pn'en'e3^00000000000000000000000000000000@n$D   M 0n'en'eL00000000000000000000000000000000n$!" iK M/0n'en'eS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\rdpclip.exe03b4d0081aeaa944546226ece4e68605Microsoft Windowsn$!{ %M M/n$n$S-1-5-32-544C:\Windows\system32\winlogon.execa0e2df49879c57652531331ef5ae632Microsoft Windows`, iK!M/pn'en'eS-1-5-21-2732810954-1700855356-1339776706-1000C:\Windows\system32\TSTheme.exe-Embedding2b3349dd9922cbe08cc84791ae4b96e8Microsoft Windows@n$D~   M n'Upn'e"00000000000000000000000000000000n$D}   M n'e n'e00000000000000000000000000000000n$XD|   M n'en'e00000000000000000000000000000000xn'eoN{K/M/n'e n'e S-1-5-18C:\Windows\system32\conhost.exe"1488101374212670313-627953753-1552003108756393503-726141722339981179-2060161226"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$Xz A]M/n'en'eS-1-5-18C:\Windows\syswow64\sc.exefailure CpSbaCipolla reset= 0 actions= /d2f7a0adc2ee0f65ab1f19d2e00c16b8Microsoft Windowsxn'eoDy   M Tn'en'e00000000000000000000000000000000n$XDx   M n'en'e00000000000000000000000000000000xn'eoOwK1M/Tn'en'eS-1-5-18C:\Windows\system32\conhost.exe"-354158342-771951619-100807162887317112813929377165449735631484842235-1095703093"11e8d2206380a09e80487baa7475519cMicrosoft Windowsn$X