Sysnative BSOD Dump + File Collection App [Detailed] Output Explained

jcgriff2

Co-Founder / Admin
BSOD Instructor/Expert
Microsoft MVP (Ret.)
Staff member
Joined
Feb 19, 2012
Posts
21,541
Location
New Jersey Shore
Windows8LOGO_200x67.jpg

us_flag_40x24.png

MVPinsiderLogo.jpg

Info


Sysnative BSOD Dump + File Collection App Output Explained

Here at Sysnative Forums as well as TSF Forums, Bleeping Computer and MBAM Forums (and some other forums as well), a BSOD OP attaches a file to their post called SysnativeFileCollectionApp.zip. This is mandatory.

It results from running the app found in the Sysnative BSOD Posting Instructions.

The output contains a treasure trove of information besides the mini kernel memory dump files. I will try my best to explain the contents of the ~30 files below and what the information can be used for.

To date, the output directory contains 29 output system/OS related files plus all BSOD mini-kernel memory dump files.

There is NO personal related information found in any of these files.



Here is a DIR listing of the Sysnative output zip file -
Rich (BB code):
01/01/1980  12:00 AM           448,108 112019-10093-01.dmp
01/01/1980  12:00 AM           460,300 112019-10859-01.dmp
01/01/1980  12:00 AM           495,348 112019-8140-01.dmp
01/01/1980  12:00 AM           569,908 112019-8796-01.dmp
01/01/1980  12:00 AM           569,916 112019-9031-01.dmp
01/01/1980  12:00 AM                 2 Autoruns.txt
01/01/1980  12:00 AM             1,275 BSODPostingInstructions.txt
01/01/1980  12:00 AM            49,208 DriverqFo.txt
01/01/1980  12:00 AM            14,258 DriverqSi.txt
01/01/1980  12:00 AM            97,662 DriverqV.txt
01/01/1980  12:00 AM           107,427 DxDiagx86.txt
01/01/1980  12:00 AM           934,549 EvtxAppDump.txt
01/01/1980  12:00 AM           967,196 EvtxSysDump.txt
01/01/1980  12:00 AM               752 HKCUSoftMSWinCVUninstall.txt
01/01/1980  12:00 AM             7,261 HKLMSoftMSA-SInstalledComponents.txt
01/01/1980  12:00 AM            29,195 HKLMSoftMSWinCVUninstall.txt
01/01/1980  12:00 AM               824 Hosts.txt
01/01/1980  12:00 AM             4,913 IPconfigAll.txt
01/01/1980  12:00 AM            15,986 Jcgriff2Log.txt
01/01/1980  12:00 AM             1,517 KernelDumpList.txt
01/01/1980  12:00 AM         2,115,736 MSInfo32.nfo
01/01/1980  12:00 AM             4,542 NetSHLAN1.txt
01/01/1980  12:00 AM            15,766 NetstatJcgriff2
01/01/1980  12:00 AM                 0 NetstatJcgriff2.StdErr
01/01/1980  12:00 AM            19,556 RAMInfo.html
01/01/1980  12:00 AM             3,914 SetEnvironmentVar.txt
01/01/1980  12:00 AM           302,549 SysList.txt
01/01/1980  12:00 AM             2,955 SystemInfo.txt
01/01/1980  12:00 AM           340,497 TasklistSVCHOST.txt
01/01/1980  12:00 AM             1,191 Tracert.txt
01/01/1980  12:00 AM            13,095 WERALL.txt
01/01/1980  12:00 AM               744 WERLocalAppData
01/01/1980  12:00 AM            13,656 WERProgramData
01/01/1980  12:00 AM             1,318 WMICRecoveros.txt

I wrote the original app that generates the above in 2008 and kept tweaking it through the years. It is now a general troubleshooting tool in addition to a mandatory app for BSOD OPs.

To try it for yourself, Run this app - SysnativeBSODCollectionApp

It comes from step #1 here - Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 + Vista

Tens, if not hundreds of thousands of people have run some form/version of this app over the last 12+ years. It DOES NOT get installed; it is a stand-alone executable; it does NOT write to the Registry; it DOES create a folder in Documents called SysnativeFileCollectionApp, which can be deleted at any time.

Here is a table naming each file, a brief description of it, followed by a spoiler that if clicked on, will reveal a sample of the output file/ report.


Autoruns.txtThe text output of SysInternals Autoruns. It rarely works; not sure why, but we're doing away with it in the next release. The text version of AutoRuns is just too difficult to read. I used to obtain the ARN version, which was fabulous. Will try for that one again.
BSODPostingInstructions.txtInstructions that appear on the OP's screen at the conclusion of the Sysnsative BSOD Dump + File Processing App's execution.
DriverqFo.txtA listing of drivers - basic info - sorted alphabetically
Module Name: 1394ohci
Display Name: 1394 OHCI Compliant Host Controller
Driver Type: Kernel
Link Date: 20/11/2010 8:44:56

Module Name: ACPI
Display Name: Microsoft ACPI Driver
Driver Type: Kernel
Link Date: 10/02/2018 15:21:53

Module Name: AcpiPmi
Display Name: ACPI Power Meter Driver
Driver Type: Kernel
Link Date: 20/11/2010 7:30:42

Module Name: adp94xx
Display Name: adp94xx
Driver Type: Kernel
Link Date: 05/12/2008 21:54:42

Module Name: adpahci
Display Name: adpahci
Driver Type: Kernel
Link Date: 01/05/2007 14:30:09

Module Name: adpu320
Display Name: adpu320
Driver Type: Kernel
Link Date: 27/02/2007 21:04:15

Module Name: AFD
Display Name: Ancillary Function Driver for Winsock
Driver Type: Kernel
Link Date: 04/04/2017 11:53:16

Module Name: agp440
Display Name: Filtro de barramento Intel AGP
Driver Type: Kernel
Link Date: 18/04/2019 23:11:34

Module Name: aliide
Display Name: aliide
Driver Type: Kernel
Link Date: 13/07/2009 20:19:47

Module Name: amdide
Display Name: amdide
Driver Type: Kernel
Link Date: 13/07/2009 20:19:49

Module Name: AmdK8
Display Name: AMD K8 Processor Driver
Driver Type: Kernel
Link Date: 12/06/2019 11:35:08

Module Name: AmdPPM
Display Name: AMD Processor Driver
Driver Type: Kernel
Link Date: 12/06/2019 11:35:08

Module Name: amdsata
Display Name: amdsata
Driver Type: Kernel
Link Date: 18/03/2010 21:45:17

Module Name: amdsbs
Display Name: amdsbs
Driver Type: Kernel
Link Date: 20/03/2009 15:36:03

Module Name: amdxata
Display Name: amdxata
Driver Type: Kernel
Link Date: 19/03/2010 13:18:18
DriverqSi.txtSigned/Non-Signed Device Drivers
Code:
DeviceName InfName IsSigned Manufacturer
============================== ============= ======== =========================
Generic volume volume.inf TRUE Microsoft
Generic volume shadow copy volsnap.inf TRUE Microsoft
Generic volume volume.inf TRUE Microsoft
Generic volume volume.inf TRUE Microsoft
Volume Manager machine.inf TRUE (Standard system devices)
Microsoft Virtual Drive Enumer machine.inf TRUE (Standard system devices)
Fintek(R) 501 oem51.inf TRUE Fintek ,Inc.
DAEMON Tools Lite Virtual USB oem41.inf FALSE Disc Soft Ltd
UMBus Enumerator umbus.inf TRUE Microsoft
UMBus Root Bus Enumerator umbus.inf TRUE Microsoft
HID-compliant consumer control hidserv.inf TRUE Microsoft
HID-compliant mouse msmouse.inf TRUE Microsoft
HID Keyboard Device keyboard.inf TRUE (Standard keyboards)
HID Keyboard Device keyboard.inf TRUE (Standard keyboards)
HID-compliant mouse msmouse.inf TRUE Microsoft
Corsair composite virtual inpu oem18.inf TRUE Corsair
Corsair Bus oem19.inf TRUE Corsair
RAS Async Adapter netrasa.inf TRUE Microsoft
Plug and Play Software Device machine.inf TRUE (Standard system devices)
CD-ROM Drive cdrom.inf TRUE (Standard CD-ROM drives)
DAEMON Tools Lite Virtual SCSI oem40.inf FALSE Disc Soft Ltd
Terminal Server Mouse Driver machine.inf TRUE (Standard system devices)
Terminal Server Keyboard Drive machine.inf TRUE (Standard system devices)
Windscribe VPN oem58.inf FALSE Windscribe.com
WAN Miniport (SSTP) netsstpa.inf TRUE Microsoft
WAN Miniport (PPTP) netrasa.inf TRUE Microsoft
WAN Miniport (PPPOE) netrasa.inf TRUE Microsoft
WAN Miniport (IPv6) netrasa.inf TRUE Microsoft
WAN Miniport (IP) netrasa.inf TRUE Microsoft
WAN Miniport (Network Monitor) netrasa.inf TRUE Microsoft
WAN Miniport (L2TP) netrasa.inf TRUE Microsoft
DriverqV.txtExtremely detailed listing of drivers and execution status
Code:
Module Name Display Name Description Driver Type Start Mode State Status Accept Stop Accept Pause Paged Pool Code(bytes BSS(by Link Date Path Init(bytes
============ ====================== ====================== ============= ========== ========== ========== =========== ============ ========== ========== ====== ====================== ================================================ ==========
1394ohci 1394 OHCI Compliant Ho 1394 OHCI Compliant Ho Kernel Manual Stopped OK FALSE FALSE 4.096 200.704 0 20/11/2010 8:44:56 C:\Windows\system32\drivers\1394ohci.sys 4.096
ACPI Microsoft ACPI Driver Microsoft ACPI Driver Kernel Boot Running OK TRUE FALSE 90.112 176.128 0 10/02/2018 15:21:53 C:\Windows\system32\drivers\ACPI.sys 12.288
AcpiPmi ACPI Power Meter Drive ACPI Power Meter Drive Kernel Manual Stopped OK FALSE FALSE 4.096 4.096 0 20/11/2010 7:30:42 C:\Windows\system32\drivers\acpipmi.sys 4.096
adp94xx adp94xx adp94xx Kernel Manual Stopped OK FALSE FALSE 0 438.272 0 05/12/2008 21:54:42 C:\Windows\system32\drivers\adp94xx.sys 4.096
adpahci adpahci adpahci Kernel Manual Stopped OK FALSE FALSE 0 311.296 0 01/05/2007 14:30:09 C:\Windows\system32\drivers\adpahci.sys 4.096
adpu320 adpu320 adpu320 Kernel Manual Stopped OK FALSE FALSE 0 151.552 0 27/02/2007 21:04:15 C:\Windows\system32\drivers\adpu320.sys 4.096
AFD Ancillary Function Dri Ancillary Function Dri Kernel System Running OK TRUE FALSE 307.200 81.920 0 04/04/2017 11:53:16 C:\Windows\system32\drivers\afd.sys 16.384
agp440 Filtro de barramento I Filtro de barramento I Kernel Manual Stopped OK FALSE FALSE 28.672 16.384 0 18/04/2019 23:11:34 C:\Windows\system32\drivers\agp440.sys 4.096
aliide aliide aliide Kernel Manual Stopped OK FALSE FALSE 0 4.096 0 13/07/2009 20:19:47 C:\Windows\system32\drivers\aliide.sys 4.096
amdide amdide amdide Kernel Manual Stopped OK FALSE FALSE 0 4.096 0 13/07/2009 20:19:49 C:\Windows\system32\drivers\amdide.sys 4.096
AmdK8 AMD K8 Processor Drive AMD K8 Processor Drive Kernel Manual Stopped OK FALSE FALSE 28.672 16.384 0 12/06/2019 11:35:08 C:\Windows\system32\drivers\amdk8.sys 8.192
AmdPPM AMD Processor Driver AMD Processor Driver Kernel Manual Stopped OK FALSE FALSE 28.672 12.288 0 12/06/2019 11:35:08 C:\Windows\system32\drivers\amdppm.sys 4.096
amdsata amdsata amdsata Kernel Manual Stopped OK FALSE FALSE 0 90.112 0 18/03/2010 21:45:17 C:\Windows\system32\drivers\amdsata.sys 4.096
amdsbs amdsbs amdsbs Kernel Manual Stopped OK FALSE FALSE 0 172.032 0 20/03/2009 15:36:03 C:\Windows\system32\drivers\amdsbs.sys 4.096
amdxata amdxata amdxata Kernel Boot Running OK TRUE FALSE 8.192 8.192 0 19/03/2010 13:18:18 C:\Windows\system32\drivers\amdxata.sys 4.096
AppID AppID Driver AppID Driver Kernel Manual Stopped OK FALSE FALSE 40.960 8.192 0 12/06/2019 11:42:51 C:\Windows\system32\drivers\appid.sys 8.192
arc arc arc Kernel Manual Stopped OK FALSE FALSE 0 69.632 0 24/05/2007 18:27:55 C:\Windows\system32\drivers\arc.sys 4.096
arcsas arcsas arcsas Kernel Manual Stopped OK FALSE FALSE 0 77.824 0 14/01/2009 17:27:37 C:\Windows\system32\drivers\arcsas.sys 4.096
ASMMAP64 ASMMAP64 ASMMAP64 Kernel Auto Running OK TRUE FALSE 4.096 4.096 0 02/07/2009 6:13:26 \??\C:\Program Files (x86)\ASUS\ATK Package\ATKG 4.096
AsyncMac RAS Asynchronous Media RAS Asynchronous Media Kernel Manual Stopped OK FALSE FALSE 0 16.384 0 13/07/2009 21:10:13 C:\Windows\system32\DRIVERS\asyncmac.sys 4.096
atapi Canal de IDE Canal de IDE Kernel Boot Running OK TRUE FALSE 0 12.288 0 13/07/2009 20:19:47 C:\Windows\system32\drivers\atapi.sys 4.096
athr Atheros Extensible Wir Atheros Extensible Wir Kernel Manual Running OK TRUE FALSE 0 2.170.880 0 12/06/2012 3:52:12 C:\Windows\system32\DRIVERS\athrx.sys 8.192
ATKWMIACPIIO ATKWMIACPI Driver ATKWMIACPI Driver Kernel System Running OK TRUE FALSE 4.096 8.192 0 06/09/2011 22:44:52 \??\C:\Program Files (x86)\ASUS\ATK Package\ATK 4.096
b06bdrv Broadcom NetXtreme II Broadcom NetXtreme II Kernel Manual Stopped OK FALSE FALSE 0 184.320 0 13/02/2009 20:18:07 C:\Windows\system32\drivers\bxvbda.sys 4.096
b57nd60a Broadcom NetXtreme Gig Broadcom NetXtreme Gig Kernel Manual Stopped OK FALSE FALSE 8.192 212.992 0 26/04/2009 8:14:55 C:\Windows\system32\DRIVERS\b57nd60a.sys 4.096
Beep Beep Beep Kernel System Running OK TRUE FALSE 0 4.096 0 13/07/2009 21:00:13 C:\Windows\system32\drivers\Beep.sys 4.096
blbdrive blbdrive blbdrive Kernel System Running OK TRUE FALSE 4.096 36.864 0 13/07/2009 20:35:59 C:\Windows\system32\DRIVERS\blbdrive.sys 4.096
bowser Browser Support Driver Browser Support Driver File System Manual Running OK TRUE FALSE 65.536 16.384 0 18/07/2018 12:18:04 C:\Windows\system32\DRIVERS\bowser.sys 8.192
DxDiagx86.txtDirectX Kernel Diagnostics/Info Report

NOTE: You can obtain PCI Hardware Device Information from this report as well as device driver info for video, audio, wifi (if applicable), Ethernet, and other device drivers as well.
Code:
------------------
System Information
------------------
Time of this report: 8/13/2019, 15:20:33
Machine name: ABI-PC
Operating System: Windows 7 Ultimate 64-bit (6.1, Build 7601) Service Pack 1 (7601.win7sp1_ldr.190612-0600)
Language: Indonesian (Regional Setting: Indonesian)
System Manufacturer: ASUSTeK COMPUTER INC.
System Model: K46CB
BIOS: BIOS Date: 05/17/13 10:47:14 Ver: 04.06.05
Processor: Intel(R) Core(TM) i3-3217U CPU @ 1.80GHz (4 CPUs), ~1.8GHz
Memory: 4096MB RAM
Available OS Memory: 3982MB RAM
Page File: 3915MB used, 4045MB available
Windows Dir: C:\Windows
DirectX Version: DirectX 11
DX Setup Parameters: Not found
User DPI Setting: Using System DPI
System DPI Setting: 96 DPI (100 percent)
DWM DPI Scaling: Disabled
DxDiag Version: 6.01.7601.17514 32bit Unicode

------------
DxDiag Notes
------------
Display Tab 1: No problems found.
Sound Tab 1: No problems found.
Input Tab: No problems found.

--------------------
DirectX Debug Levels
--------------------
Direct3D: 0/4 (retail)
DirectDraw: 0/4 (retail)
DirectInput: 0/5 (retail)
DirectMusic: 0/5 (retail)
DirectPlay: 0/9 (retail)
DirectSound: 0/5 (retail)
DirectShow: 0/6 (retail)

---------------
Display Devices
---------------
Card name: Intel(R) HD Graphics 4000
Manufacturer: Intel Corporation
Chip type: Intel(R) HD Graphics Family
DAC type: Internal
Device Key: Enum\PCI\VEN_8086&DEV_0166&SUBSYS_100D1043&REV_09
Display Memory: 1696 MB
Dedicated Memory: 64 MB
Shared Memory: 1632 MB
Current Mode: 1366 x 768 (32 bit) (60Hz)
Monitor Name: Monitor Genérico PnP
Monitor Model: unknown
Monitor Id: CMN1472
Native Mode: 1366 x 768(p) (59.989Hz)
Output Type: Internal
Driver Name: igdumd64.dll,igd10umd64.dll,igd10umd64.dll,igdumd32,igd10umd32,igd10umd32
Driver File Version: 9.17.0010.2867 (English)
Driver Version: 9.17.10.2867
DDI Version: 11
Driver Model: WDDM 1.1
Driver Attributes: Final Retail
Driver Date/Size: 8/11/2019 18:46:39, 12604416 bytes
WHQL Logo'd: Yes
WHQL Date Stamp:
Device Identifier: {D7B78E66-4226-11CF-CB6B-0030B4C2C735}
Vendor ID: 0x8086
Device ID: 0x0166
SubSys ID: 0x100D1043
Revision ID: 0x0009
Driver Strong Name: oem5.inf:Intel.Mfg.NTamd64:iIVBM0:9.17.10.2867:pci\ven_8086&dev_0166&subsys_100d1043
Rank Of Driver: 00E00001
Video Accel: ModeMPEG2_A ModeMPEG2_C ModeWMV9_C ModeVC1_C
Deinterlace Caps: {BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
{5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
{BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
{5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
{BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
{5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(YV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
{BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
{5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(NV12,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
{BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
{5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC1,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
{BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
{5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
{BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
{5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC3,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
{BF752EF6-8CC4-457A-BE1B-08BD1CAEEE9F}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,1) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_EdgeFiltering
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend DeinterlaceTech_BOBVerticalStretch
{5A54A0C9-C7EC-4BD9-8EDE-F3C75DC4393B}: Format(In/Out)=(IMC4,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY VideoProcess_AlphaBlend
D3D9 Overlay: Supported
DXVA-HD: Supported
DDraw Status: Enabled
D3D Status: Enabled
AGP Status: Enabled

-------------
Sound Devices
-------------
Description: Alto-falantes (Realtek High Definition Audio)
Default Sound Playback: Yes
Default Voice Playback: Yes
Hardware ID: HDAUDIO\FUNC_01&VEN_10EC&DEV_0270&SUBSYS_1043100D&REV_1001
Manufacturer ID: 1
Product ID: 100
Type: WDM
Driver Name: RTKVHD64.sys
Driver Version: 6.00.0001.6788 (English)
Driver Attributes: Final Retail
WHQL Logo'd: Yes
Date and Size: 11/27/2012 11:52:20, 4222096 bytes
Other Files:
Driver Provider: Realtek Semiconductor Corp.
HW Accel Level: Basic
Cap Flags: 0xF1F
Min/Max Sample Rate: 100, 200000
Static/Strm HW Mix Bufs: 1, 0
Static/Strm HW 3D Bufs: 0, 0
HW Memory: 0
Voice Management: No
EAX(tm) 2.0 Listen/Src: No, No
I3DL2(tm) Listen/Src: No, No
Sensaura(tm) ZoomFX(tm): No

---------------------
Sound Capture Devices
---------------------
Description: Microfone (Realtek High Definition Audio)
Default Sound Capture: Yes
Default Voice Capture: Yes
Driver Name: RTKVHD64.sys
Driver Version: 6.00.0001.6788 (English)
Driver Attributes: Final Retail
Date and Size: 11/27/2012 11:52:20, 4222096 bytes
Cap Flags: 0x1
Format Flags: 0xFFFFF

-------------------
DirectInput Devices
-------------------
Device Name: Mouse
Attached: 1
Controller ID: n/a
Vendor/Product ID: n/a
FF Driver: n/a

Device Name: Keyboard
Attached: 1
Controller ID: n/a
Vendor/Product ID: n/a
FF Driver: n/a

Device Name: USB Receiver
Attached: 1
Controller ID: 0x0
Vendor/Product ID: 0x046D, 0xC534
FF Driver: n/a

Device Name: USB Receiver
Attached: 1
Controller ID: 0x0
Vendor/Product ID: 0x046D, 0xC534
FF Driver: n/a

Device Name: USB Receiver
Attached: 1
Controller ID: 0x0
Vendor/Product ID: 0x046D, 0xC534
FF Driver: n/a

Device Name: USB Receiver
Attached: 1
Controller ID: 0x0
Vendor/Product ID: 0x046D, 0xC534
FF Driver: n/a

Poll w/ Interrupt: No

-----------
USB Devices
-----------
+ USB Root Hub
| Vendor/Product ID: 0x8086, 0x1E2D
| Matching Device ID: usb\root_hub20
| Service: usbhub
|
+-+ Generic USB Hub
| | Vendor/Product ID: 0x8087, 0x0024
| | Location: Port_#0001.Hub_#0001
| | Matching Device ID: usb\class_09
| | Service: usbhub

----------------
Gameport Devices
----------------

------------
PS/2 Devices
------------
+ PC/AT Enhanced PS/2 Keyboard (101/102-Key)
| Matching Device ID: *pnp030b
| Service: i8042prt
|
+ HID Keyboard Device
| Vendor/Product ID: 0x046D, 0xC534
| Matching Device ID: hid_device_system_keyboard
| Service: kbdhid
|
+ Terminal Server Keyboard Driver
| Matching Device ID: root\rdp_kbd
| Upper Filters: kbdclass
| Service: TermDD
|
+ Microsoft PS/2 Mouse
| Matching Device ID: *pnp0f03
| Service: i8042prt
|
+ HID-compliant mouse
| Vendor/Product ID: 0x046D, 0xC534
| Matching Device ID: hid_device_system_mouse
| Service: mouhid
|
+ Terminal Server Mouse Driver
| Matching Device ID: root\rdp_mou
| Upper Filters: mouclass
| Service: TermDD

------------------------
Disk & DVD/CD-ROM Drives
------------------------
Drive: C:
Free Space: 10.8 GB
Total Space: 150.0 GB
File System: NTFS
Model: Hitachi HTS545050A7E380 ATA Device

Drive: D:
Free Space: 40.2 GB
Total Space: 100.0 GB
File System: NTFS
Model: Hitachi HTS545050A7E380 ATA Device

Drive: E:
Free Space: 49.0 GB
Total Space: 176.8 GB
File System: NTFS
Model: Hitachi HTS545050A7E380 ATA Device

Drive: F:
Free Space: 14.5 GB
Total Space: 50.0 GB
File System: NTFS
Model: Hitachi HTS545050A7E380 ATA Device

Drive: G:
Model: MATSHITA DVD-RAM UJ8C2 S ATA Device
Driver: c:\windows\system32\drivers\cdrom.sys, 6.01.7601.17514 (Indonesian), , 0 bytes

--------------
System Devices
--------------
Name: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_1E22&SUBSYS_100D1043&REV_04\3&11583659&0&FB
Driver: n/a

Name: PCI Data Acquisition and Signal Processing Controller
Device ID: PCI\VEN_8086&DEV_0153&SUBSYS_100D1043&REV_09\3&11583659&0&20
Driver: n/a

Name: High Definition Audio Controller
Device ID: PCI\VEN_8086&DEV_1E20&SUBSYS_100D1043&REV_04\3&11583659&0&D8
Driver: n/a

Name: PCI standard PCI-to-PCI bridge
Device ID: PCI\VEN_8086&DEV_0151&SUBSYS_100D1043&REV_09\3&11583659&0&08
Driver: n/a

Name: PCI standard PCI-to-PCI bridge
Device ID: PCI\VEN_8086&DEV_1E16&SUBSYS_100D1043&REV_C4\3&11583659&0&E3
Driver: n/a

Name: Atheros AR9485WB-EG Wireless Network Adapter
Device ID: PCI\VEN_168C&DEV_0032&SUBSYS_662811AD&REV_01\4&11B6214C&0&00E1
Driver: n/a

Name: PCI standard ISA bridge
Device ID: PCI\VEN_8086&DEV_1E59&SUBSYS_100D1043&REV_04\3&11583659&0&F8
Driver: n/a

Name: PCI standard PCI-to-PCI bridge
Device ID: PCI\VEN_8086&DEV_1E12&SUBSYS_100D1043&REV_C4\3&11583659&0&E1
Driver: n/a

Name: Ethernet Controller
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_200F1043&REV_0A\4&41C3870&0&02E3
Driver: n/a

Name: Intel(R) Management Engine Interface
Device ID: PCI\VEN_8086&DEV_1E3A&SUBSYS_100D1043&REV_04\3&11583659&0&B0
Driver: n/a

Name: PCI standard PCI-to-PCI bridge
Device ID: PCI\VEN_8086&DEV_1E10&SUBSYS_100D1043&REV_C4\3&11583659&0&E0
Driver: n/a

Name: Realtek PCIE CardReader
Device ID: PCI\VEN_10EC&DEV_5289&SUBSYS_202F1043&REV_01\4&41C3870&0&00E3
Driver: n/a

Name: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_8086&DEV_1E31&SUBSYS_100D1043&REV_04\3&11583659&0&A0
Driver: n/a

Name: Standard AHCI 1.0 Serial ATA Controller
Device ID: PCI\VEN_8086&DEV_1E03&SUBSYS_100D1043&REV_04\3&11583659&0&FA
Driver: n/a

Name: NVIDIA GeForce GT 740M
Device ID: PCI\VEN_10DE&DEV_0FDF&SUBSYS_100D1043&REV_A1\4&3B13E28A&0&0008
Driver: n/a

Name: Standard Enhanced PCI to USB Host Controller
Device ID: PCI\VEN_8086&DEV_1E2D&SUBSYS_100D1043&REV_04\3&11583659&0&D0
Driver: n/a

Name: Intel(R) HD Graphics 4000
Device ID: PCI\VEN_8086&DEV_0166&SUBSYS_100D1043&REV_09\3&11583659&0&10
Driver: n/a

Name: Standard Enhanced PCI to USB Host Controller
Device ID: PCI\VEN_8086&DEV_1E26&SUBSYS_100D1043&REV_04\3&11583659&0&E8
Driver: n/a

Name: PCI standard host CPU bridge
Device ID: PCI\VEN_8086&DEV_0154&SUBSYS_100D1043&REV_09\3&11583659&0&00
Driver: n/a

------------------
DirectShow Filters
------------------
EvtxAppDump.txtUp to 50,000 Event Viewer Application Log entries are dumped and stored in this file.

Often, the EVTX entries go back to the day when the system was first booted or when Windows was last reinstalled.
Code:
Event[0]:
Log Name: Application
Source: Microsoft-Windows-LoadPerf
Date: 2019-08-13T15:13:23.614
Event ID: 1000
Task: N/A
Level: Information
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: AUTORIDADE NT\SISTEMA
Computer: Abi-PC
Description:
Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.

Event[1]:
Log Name: Application
Source: Microsoft-Windows-LoadPerf
Date: 2019-08-13T15:13:23.481
Event ID: 1001
Task: N/A
Level: Information
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: AUTORIDADE NT\SISTEMA
Computer: Abi-PC
Description:
Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.

Event[2]:
Log Name: Application
Source: Windows Error Reporting
Date: 2019-08-13T15:11:05.000
Event ID: 1001
Task: N/A
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Fault bucket X64_0x3B_c000001d_nt!ObpCloseHandle+14, type 0
Event Name: BlueScreen
Response: Not available
Cab Id: 0

Problem signature:
P1:
P2:
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:

Attached files:
C:\Windows\Minidump\081319-34647-01.dmp
C:\Users\Abi\AppData\Local\Temp\WER-68203-0.sysdata.xml
C:\Users\Abi\AppData\Local\Temp\WER511B.tmp.WERInternalMetadata.xml

These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0bfc73d7

Analysis symbol: X64_0x3B_c000001d_nt!ObpCloseHandle+14
Rechecking for solution: 0
Report Id: 081319-34647-01
Report Status: 0

Event[3]:
Log Name: Application
Source: Microsoft-Windows-Security-SPP
Date: 2019-08-13T15:09:41.000
Event ID: 902
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
The Software Protection service has started.
6.1.7601.17514

Event[4]:
Log Name: Application
Source: Microsoft-Windows-Security-SPP
Date: 2019-08-13T15:09:41.000
Event ID: 1003
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 1], [(?)( 5 0x00000000 30 40200)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)(?)])]
8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]



Event[5]:
Log Name: Application
Source: Microsoft-Windows-Security-SPP
Date: 2019-08-13T15:09:41.000
Event ID: 1066
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000


Event[6]:
Log Name: Application
Source: SecurityCenter
Date: 2019-08-13T15:09:38.000
Event ID: 1
Task: N/A
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
The Windows Security Center Service has started.

Event[7]:
Log Name: Application
Source: Microsoft-Windows-Security-SPP
Date: 2019-08-13T15:09:36.000
Event ID: 900
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
The Software Protection service is starting.


Event[8]:
Log Name: Application
Source: gupdate
Date: 2019-08-13T15:09:36.000
Event ID: 0
Task: None
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
N/A

Event[9]:
Log Name: Application
Source: Microsoft-Windows-WMI
Date: 2019-08-13T15:09:13.000
Event ID: 10
Task: N/A
Level: Error
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Event[10]:
Log Name: Application
Source: Microsoft-Windows-WMI
Date: 2019-08-13T15:09:13.000
Event ID: 5617
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Windows Management Instrumentation Service subsystems initialized successfully

Event[11]:
Log Name: Application
Source: Microsoft-Windows-Search
Date: 2019-08-13T15:07:34.000
Event ID: 1003
Task: Search service
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
The Windows Search Service started.


Event[12]:
Log Name: Application
Source: ESENT
Date: 2019-08-13T15:07:32.000
Event ID: 302
Task: Logging/Recovery
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Windows (3440) Windows: The database engine has successfully completed recovery steps.

Event[13]:
Log Name: Application
Source: ESENT
Date: 2019-08-13T15:07:32.000
Event ID: 301
Task: Logging/Recovery
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Windows (3440) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.

Event[14]:
Log Name: Application
Source: ESENT
Date: 2019-08-13T15:07:32.000
Event ID: 300
Task: Logging/Recovery
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Windows (3440) Windows: The database engine is initiating recovery steps.

Event[15]:
Log Name: Application
Source: ESENT
Date: 2019-08-13T15:07:32.000
Event ID: 102
Task: General
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Windows (3440) Windows: The database engine (6.01.7601.0000) started a new instance (0).

Event[16]:
Log Name: Application
Source: Microsoft-Windows-WMI
Date: 2019-08-13T15:07:20.000
Event ID: 5611
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
The Windows Management Instrumentation service has detected an inconsistent system shutdown.

Event[17]:
Log Name: Application
Source: Microsoft-Windows-WMI
Date: 2019-08-13T15:07:19.000
Event ID: 5615
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Windows Management Instrumentation Service started sucessfully

Event[18]:
Log Name: Application
Source: NvStreamSvc
Date: 2019-08-13T15:07:18.000
Event ID: 2003
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
Expected event (Started [0]).

Event[19]:
Log Name: Application
Source: NVNetworkService
Date: 2019-08-13T15:07:17.000
Event ID: 0
Task: None
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: Abi-PC
Description:
N/A
EvtxSysDump.txtUp to 50,000 Event Viewer System Log entries are dumped and stored in this file.

Often, the EVTX entries go back to the day when the system was first booted or when Windows was last reinstalled.
Code:
Event[0]:
Log Name: System
Source: Microsoft-Windows-Application-Experience
Date: 2019-08-09T21:47:45.949
Event ID: 206
Task: N/A
Level: Information
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: User-PC
Description:
The Program Compatibility Assistant service successfully performed phase two initialization.

Event[1]:
Log Name: System
Source: Microsoft Antimalware
Date: 2019-08-09T21:47:45.000
Event ID: 2010
Task: N/A
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
Microsoft Antimalware used Dynamic Signature Service to retrieve additional signatures to help protect your machine.
Current Signature Version: 1.299.1672.0
Signature Type: AntiSpyware
Current Engine Version: 1.1.16200.1
Dynamic Signature Type: Signature update
Persistence Path: C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\RtSigs\data\a0b32bce52ebf31c374e1c53157eb74cbd13a9bd
Dynamic Signature Version: 0.0.0.0
Dynamic Signature Compilation Timestamp: ?8/?10/?2019 4:47:38 AM
Persistence Limit Type: Duration
Persistence Limit: 288000000

Event[2]:
Log Name: System
Source: Microsoft Antimalware
Date: 2019-08-09T21:47:45.000
Event ID: 2010
Task: N/A
Level: Information
Opcode: Info
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
Microsoft Antimalware used Dynamic Signature Service to retrieve additional signatures to help protect your machine.
Current Signature Version: 1.299.1672.0
Signature Type: AntiVirus
Current Engine Version: 1.1.16200.1
Dynamic Signature Type: Signature update
Persistence Path: C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\RtSigs\data\a0b32bce52ebf31c374e1c53157eb74cbd13a9bd
Dynamic Signature Version: 0.0.0.0
Dynamic Signature Compilation Timestamp: ?8/?10/?2019 4:47:38 AM
Persistence Limit Type: Duration
Persistence Limit: 288000000

Event[3]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:47:44.661
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Multimedia Class Scheduler service entered the running state.

Event[4]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:45:13.071
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Multimedia Class Scheduler service entered the stopped state.

Event[5]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:44:23.085
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Intel(R) SUR QC Software Asset Manager service entered the stopped state.

Event[6]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:43:52.850
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Intel(R) SUR QC Software Asset Manager service entered the running state.

Event[7]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:43:52.828
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Intel(R) SUR QC Software Asset Manager service entered the running state.

Event[8]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:23.146
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The WMI Performance Adapter service entered the stopped state.

Event[9]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:13.626
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Windows Update service entered the running state.

Event[10]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:12.826
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Security Center service entered the running state.

Event[11]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:12.532
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Software Protection service entered the running state.

Event[12]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:12.430
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Intel(R) Rapid Storage Technology service entered the running state.

Event[13]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:12.222
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Portable Device Enumerator Service service entered the stopped state.

Event[14]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:12.158
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Google Update Service (gupdate) service entered the stopped state.

Event[15]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:12.144
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Google Update Service (gupdate) service entered the running state.

Event[16]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:12.087
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Microsoft .NET Framework NGEN v4.0.30319_X64 service entered the running state.

Event[17]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:11.894
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Microsoft .NET Framework NGEN v4.0.30319_X86 service entered the running state.

Event[18]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:42:11.687
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The Background Intelligent Transfer Service service entered the running state.

Event[19]:
Log Name: System
Source: Service Control Manager
Date: 2019-08-09T21:40:22.800
Event ID: 7036
Task: N/A
Level: Information
Opcode: N/A
Keyword: Classic
User: N/A
User Name: N/A
Computer: User-PC
Description:
The WMI Performance Adapter service entered the running state.
HKCUSoftMSWinCVUninstall.txtFrom HKCU Registry - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\

Contains info, including the "uninstall strings" for certain programs/apps
Code:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
DisplayIcon REG_SZ "C:\Users\Abi\AppData\Roaming\uTorrent\uTorrent.exe",0
DisplayName REG_SZ Torrent
DisplayVersion REG_SZ 3.5.5.45311
UninstallString REG_SZ "C:\Users\Abi\AppData\Roaming\uTorrent\uTorrent.exe" /UNINSTALL
InstallLocation REG_SZ C:\Users\Abi\AppData\Roaming\uTorrent
VersionMajor REG_DWORD 0x3
MajorVersion REG_DWORD 0x3
VersionMinor REG_DWORD 0x5
MinorVersion REG_DWORD 0x5
NoModify REG_DWORD 0x1
NoRepair REG_DWORD 0x1
URLInfoAbout REG_SZ http://www.utorrent.com
Publisher REG_SZ BitTorrent Inc.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WhatsApp
DisplayIcon REG_SZ C:\Users\Abi\AppData\Local\WhatsApp\app.ico
DisplayName REG_SZ WhatsApp
DisplayVersion REG_SZ 0.3.4157
InstallDate REG_SZ 20190812
InstallLocation REG_SZ C:\Users\Abi\AppData\Local\WhatsApp
Publisher REG_SZ WhatsApp
QuietUninstallString REG_SZ "C:\Users\Abi\AppData\Local\WhatsApp\Update.exe" --uninstall -s
UninstallString REG_SZ "C:\Users\Abi\AppData\Local\WhatsApp\Update.exe" --uninstall
URLUpdateInfo REG_SZ
EstimatedSize REG_DWORD 0x1d475
NoModify REG_DWORD 0x1
NoRepair REG_DWORD 0x1
Language REG_DWORD 0x409

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1
Inno Setup: Setup Version REG_SZ 5.6.1 (u)
Inno Setup: App Path REG_SZ C:\Users\Abi\AppData\Roaming\Telegram Desktop
InstallLocation REG_SZ C:\Users\Abi\AppData\Roaming\Telegram Desktop\
Inno Setup: Icon Group REG_SZ Telegram Desktop
Inno Setup: User REG_SZ Abi
Inno Setup: Selected Tasks REG_SZ desktopicon
Inno Setup: Deselected Tasks REG_SZ
Inno Setup: Language REG_SZ english
DisplayName REG_SZ Telegram Desktop version 1.8.1
DisplayIcon REG_SZ C:\Users\Abi\AppData\Roaming\Telegram Desktop\Telegram.exe
UninstallString REG_SZ "C:\Users\Abi\AppData\Roaming\Telegram Desktop\unins000.exe"
QuietUninstallString REG_SZ "C:\Users\Abi\AppData\Roaming\Telegram Desktop\unins000.exe" /SILENT
DisplayVersion REG_SZ 1.8.1
Publisher REG_SZ Telegram FZ-LLC
URLInfoAbout REG_SZ https://tdesktop.com
HelpLink REG_SZ https://tdesktop.com
URLUpdateInfo REG_SZ https://tdesktop.com
NoModify REG_DWORD 0x1
NoRepair REG_DWORD 0x1
InstallDate REG_SZ 20190813
MajorVersion REG_DWORD 0x1
MinorVersion REG_DWORD 0x8
VersionMajor REG_DWORD 0x1
VersionMinor REG_DWORD 0x8
EstimatedSize REG_DWORD 0xbce4
HKLMSoftMSA-SInstalledComponents.txtRegistry HKLM Microsoft Installed Components

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\
Code:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
(Default) REG_SZ Microsoft Windows Media Player
Version REG_SZ 12,0,7601,24499
IsInstalled REG_DWORD 0x0
ComponentID REG_SZ WMPACCESS
LocalizedName REG_EXPAND_SZ @%SystemRoot%\system32\wmploc.dll,-128
StubPath REG_EXPAND_SZ %SystemRoot%\system32\unregmp2.exe /ShowWMP
DontAsk REG_DWORD 0x2
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{09CCBE8E-B964-30EF-AE84-6537AB4197F9}
Locale REG_SZ
Version REG_SZ 4,0,30319,0
ComponentID REG_SZ .NETFramework
(Default) REG_SZ .NET Framework

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
(Default) REG_SZ Microsoft Windows Media Player 12.0
IsInstalled REG_DWORD 0x1
Version REG_SZ 12,0,7601,24499
DontAsk REG_DWORD 0x2
Locale REG_SZ EN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
(Default) REG_SZ Themes Setup
LocalizedName REG_EXPAND_SZ @%SystemRoot%\system32\themeui.dll,-2682
ComponentID REG_SZ Theme Component
IsInstalled REG_DWORD 0x1
Locale REG_SZ EN
StubPath REG_EXPAND_SZ %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
Version REG_SZ 1,1,1,9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}
(Default) REG_SZ Offline Browsing Pack
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,19399
ComponentID REG_SZ MobilePk
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
IsInstalled REG_DWORD 0x1
Dontask REG_DWORD 0x2
Locale REG_SZ *
ComponentID REG_SZ MailNews
CloneUser REG_DWORD 0x1
StubPath REG_EXPAND_SZ "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
Version REG_SZ 6,1,7601,17514
(Default) REG_SZ Microsoft Windows

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
(Default) REG_SZ DirectDrawEx
ComponentID REG_SZ DirectDrawEx
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 4,71,1113,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
(Default) REG_SZ Internet Explorer Help
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,19399
ComponentID REG_SZ HelpCont
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}
(Default) REG_SZ Microsoft Windows Script 5.6
ComponentID REG_SZ MSVBScript
IsInstalled REG_DWORD 0x1
Locale REG_SZ EN
Version REG_SZ 5,6,0,8833

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
(Default) REG_SZ Internet Explorer Setup Tools
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,19399
ComponentID REG_SZ GenSetup
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
KeyFileName REG_EXPAND_SZ %SystemRoot%\system32\msieftp.dll
(Default) REG_SZ Browsing Enhancements
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,19399
ComponentID REG_SZ ExtraPack
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{66C64F22-FC60-4E6C-A6B5-F0D580E680CE}
(Default) REG_SZ Enable TLS1.1 and 1.2
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,0
LocalizedName REG_SZ @C:\Windows\System32\ie4uinit.exe,-2000
StubPath REG_SZ C:\Windows\System32\ie4uinit.exe -EnableTLS
Dontask REG_DWORD 0x2
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
(Default) REG_SZ Microsoft Windows Media Player
IsInstalled REG_DWORD 0x1
Version REG_SZ 12,0,7601,24499
ComponentID REG_SZ Microsoft Windows Media Player
LocalizedName REG_EXPAND_SZ @%SystemRoot%\system32\wmploc.dll,-128
StubPath REG_EXPAND_SZ %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
DontAsk REG_DWORD 0x2
Locale REG_SZ EN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
(Default) REG_SZ MSN Site Access
IsInstalled REG_DWORD 0x1
Version REG_SZ 4,9,9,2
ComponentID REG_SZ MSN_Auth
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}
(Default) REG_SZ Address Book 7
Version REG_SZ 6,1,7601,17514
IsInstalled REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7D715857-A67C-4C2F-A929-038448584D63}
(Default) REG_SZ Disable SSL3
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,0
LocalizedName REG_SZ @C:\Windows\System32\ie4uinit.exe,-2000
StubPath REG_SZ C:\Windows\System32\ie4uinit.exe -DisableSSL3
Dontask REG_DWORD 0x2
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}
(Default) REG_SZ Windows Desktop Update
LocalizedName REG_EXPAND_SZ @%SystemRoot%\system32\shell32.dll,-32969
ComponentID REG_SZ IE4_SHELLID
IsInstalled REG_DWORD 0x1
Locale REG_SZ en
StubPath REG_EXPAND_SZ regsvr32.exe /s /n /i:U shell32.dll
Version REG_SZ 6,1,7601,24468

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}
(Default) REG_SZ Web Platform Customizations
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,0
ComponentID REG_SZ BASEIE40_W2K
LocalizedName REG_SZ @C:\Windows\System32\ie4uinit.exe,-2000
StubPath REG_SZ C:\Windows\System32\ie4uinit.exe -UserConfig
Locale REG_SZ *
Dontask REG_DWORD 0x2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
IsInstalled REG_DWORD 0x1
ComponentID REG_SZ DOTNETFRAMEWORKS
StubPath REG_SZ C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
DontAsk REG_DWORD 0x2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
(Default) REG_SZ Google Chrome
StubPath REG_SZ "C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Localized Name REG_SZ Google Chrome
IsInstalled REG_DWORD 0x1
Version REG_SZ 43,0,0,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
(Default) REG_SZ Dynamic HTML Data Binding
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,19399
ComponentID REG_SZ Tridata
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}
(Default) REG_SZ Internet Explorer Core Fonts
IsInstalled REG_DWORD 0x1
Version REG_SZ 11,0,9600,0
ComponentID REG_SZ Fontcore
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
(Default) REG_SZ HTML Help
IsInstalled REG_DWORD 0x1
Version REG_SZ 6,3,9600,19399
ComponentID REG_SZ HTMLHelp
Locale REG_SZ *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
(Default) REG_SZ Active Directory Service Interface
ComponentID REG_SZ ADSI
IsInstalled REG_DWORD 0x1
Locale REG_SZ EN
Version REG_SZ 5,0,00,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}
Locale REG_SZ
Version REG_SZ 2,0,50727,0
(Default) REG_SZ .NET Framework
ComponentID REG_SZ .NETFramework
HKLMSoftMSWinCVUninstall.txtRegistry HKLM Uninstall Strings

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
Code:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
DisplayIcon REG_SZ C:\Program Files\Bitdefender Agent\bdicon.ico
DisplayName REG_SZ Bitdefender Agent
DisplayVersion REG_SZ 1.0.1
InstallLocation REG_SZ C:\Program Files\Bitdefender Agent\
NoModify REG_DWORD 0x1
NoRepair REG_DWORD 0x1
Publisher REG_SZ Bitdefender
UninstallString REG_SZ C:\Program Files\Bitdefender Agent\installer\installer.exe /uninstall
VersionMajor REG_DWORD 0x1
VersionMinor REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager
SystemComponent REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProInst
DisplayName REG_SZ Intel PROSet Wireless
SystemComponent REG_DWORD 0x1
UninstallString REG_SZ Intel PROSet Wireless

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProPlusRetail - en-us
UninstallString REG_SZ "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" scenario=install scenariosubtype=ARP sourcetype=None productstoremove=ProPlusRetail.16_en-us_x-none culture=en-us version.16=16.0
ModifyPath REG_SZ "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" scenario=repair platform=x64 culture=en-us
NoRepair REG_DWORD 0x0
NoRemove REG_DWORD 0x0
NoModify REG_DWORD 0x0
DisplayIcon REG_SZ C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
DisplayName REG_SZ Microsoft Office Professional Plus 2016 - en-us
DisplayVersion REG_SZ 16.0.11901.20176
Publisher REG_SZ Microsoft Corporation
InstallLocation REG_SZ C:\Program Files\Microsoft Office
ClickToRunComponent REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC
NoRemove REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
DisplayName REG_SZ WinRAR 5.71 (64-bit)
DisplayVersion REG_SZ 5.71.0
VersionMajor REG_DWORD 0x5
VersionMinor REG_DWORD 0x47
UninstallString REG_SZ C:\Program Files\WinRAR\Uninstall.exe
DisplayIcon REG_SZ C:\Program Files\WinRAR\WinRAR.exe
InstallLocation REG_SZ C:\Program Files\WinRAR\
NoModify REG_DWORD 0x1
NoRepair REG_DWORD 0x1
Language REG_DWORD 0x0
Publisher REG_SZ win.rar GmbH

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{09CCBE8E-B964-30EF-AE84-6537AB4197F9}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 4.7.03062
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20190812
InstallLocation REG_SZ
InstallSource REG_SZ E:\d4adeac71fc8d292978e91b4c9\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{09CCBE8E-B964-30EF-AE84-6537AB4197F9}
NoModify REG_DWORD 0x1
NoRepair REG_DWORD 0x1
Publisher REG_SZ Microsoft Corporation
Readme REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkId=863282
Size REG_DWORD 0x9b34
EstimatedSize REG_DWORD 0x21b4af
SystemComponent REG_DWORD 0x1
UninstallString REG_EXPAND_SZ MsiExec.exe /X{09CCBE8E-B964-30EF-AE84-6537AB4197F9}
URLInfoAbout REG_SZ http://go.microsoft.com/fwlink/?LinkId=286133
URLUpdateInfo REG_SZ http://go.microsoft.com/fwlink/?LinkId=286134
VersionMajor REG_DWORD 0x4
VersionMinor REG_DWORD 0x7
WindowsInstaller REG_DWORD 0x1
Version REG_DWORD 0x4070bf6
Language REG_DWORD 0x0
DisplayName REG_SZ Microsoft .NET Framework 4.7.2
Hosts.txtWindows HOSTS File

C:\Windows\System32\drivers\etc\hosts
Code:
# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
IPconfigAll.txtWindows IPCONFIG Networking Report

CMD command = ipconfig /all
Code:
Windows IP Configuration

Host Name . . . . . . . . . . . . : Abi-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Wireless LAN adapter Conexao de Rede sem Fio:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Atheros AR9485WB-EG Wireless Network Adapter
Physical Address. . . . . . . . . : 24-FD-52-B5-16-2E
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::917e:45ac:2cf4:f051%14(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.99.135(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.240.0
Lease Obtained. . . . . . . . . . : 13 Agustus 2019 15:07:06
Lease Expires . . . . . . . . . . : 14 Agustus 2019 15:07:09
Default Gateway . . . . . . . . . : 192.168.96.1
DHCP Server . . . . . . . . . . . : 192.168.96.1
DHCPv6 IAID . . . . . . . . . . . : 354745682
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-24-E2-D9-B8-24-FD-52-B5-16-2E
DNS Servers . . . . . . . . . . . : 200.220.136.1
200.220.136.2
NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Conexao de Rede Bluetooth:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Dispositivo Bluetooth (Rede Pessoal)
Physical Address. . . . . . . . . : 24-FD-52-B5-83-8E
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{CB1E3989-A580-43E2-81D3-9810EE708D01}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Adaptador do Microsoft ISATAP
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{8D07F370-8F6F-4DD8-8F51-E71A3A9D08D1}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Adaptador do Microsoft ISATAP #2
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
13/08/2019 15:20:26,39
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨



¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨

Windows IP Configuration


==============================================================================
Network Information for Compartment 1 (ACTIVE)
==============================================================================
Host Name . . . . . . . . . . . . : Abi-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Wireless LAN adapter Conexao de Rede sem Fio:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Atheros AR9485WB-EG Wireless Network Adapter
Physical Address. . . . . . . . . : 24-FD-52-B5-16-2E
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::917e:45ac:2cf4:f051%14(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.99.135(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.240.0
Lease Obtained. . . . . . . . . . : 13 Agustus 2019 15:07:06
Lease Expires . . . . . . . . . . : 14 Agustus 2019 15:07:09
Default Gateway . . . . . . . . . : 192.168.96.1
DHCP Server . . . . . . . . . . . : 192.168.96.1
DHCPv6 IAID . . . . . . . . . . . : 354745682
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-24-E2-D9-B8-24-FD-52-B5-16-2E
DNS Servers . . . . . . . . . . . : 200.220.136.1
200.220.136.2
NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Conexao de Rede Bluetooth:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Dispositivo Bluetooth (Rede Pessoal)
Physical Address. . . . . . . . . : 24-FD-52-B5-83-8E
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{CB1E3989-A580-43E2-81D3-9810EE708D01}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Adaptador do Microsoft ISATAP
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{8D07F370-8F6F-4DD8-8F51-E71A3A9D08D1}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Adaptador do Microsoft ISATAP #2
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨



¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
jcgriff2log.txtA log of the jcgriff2/Sysnative App's execution, including execution time and WHOAMI command; a directory listing of the output (helpful in catching OPs who tamper with the output (and there have been quite a few!))
Code:
13/08/2019 15:20:25,17 Begin Logging

v4.6.0 compiled EXE
v4.6.0 compiled EXE
v4.6.0 compiled EXE
v4.6.0 compiled EXE

13/08/2019 15:20:25,18 Finished set commands - error level - 0


13/08/2019 15:20:25,19 Changed the title of the screen - error level - 0
13/08/2019 15:20:25,20 Did a PushD to HomeDrive:HomePath\Document- error level - 0
13/08/2019 15:20:25,20 Checked for existance of TSE Sub-Dir - error level - 0
13/08/2019 15:20:25,21 Created user Dir - error level - 0
13/08/2019 15:20:25,29 Copying mini-kernel dump files - error level - 0
13/08/2019 15:20:25,34 Copying mini-kernel dump files Done - error level - 1
-
* * * B S O D F I L E C O L L E C T I O N S C R I P T * * *
Authors:
jcgriff2 - J. C. Griffith, Microsoft MVP
TheOutcaste - Jerry Wines, Microsoft MVP
Patrick - Patrick Barker, Microsoft MVP
niemiro - Richard
Tekno Venus - Stephen
© http://www.sysnative.com/
© sysnative.com - MVP
© 2008 - 2014 sysnative.com
Last Update: July 2014
New Jersey, USA; Oregon, USA; New York, USA
ALL RIGHTS RESERVED
-
13/08/2019 15:20:19,58 ----- Actual Start execution time
-
B E G I N jcgriff2 B A T C H E X E C U T I O N
B E G I N jcgriff2 B A T C H E X E C U T I O N
-
-
13/08/2019 15:20:25,37
-
Original home drive = C:
home path = \Users\Abi
current directory = C:\Users\Abi\Documents
-
13/08/2019 15:20:25,38 Running WHOAMI command - error level - 1
-
ALL user SIDs ------

USER INFORMATION
----------------

User Name SID
========== =============================================
abi-pc\abi S-1-5-21-2557094879-178247765-2722095413-1000


GROUP INFORMATION
-----------------

Group Name Type SID Attributes
============================================================== ================ ============ ===============================================================
Todos Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
AUTORIDADE NT\Conta local e membro do grupo de Administradores Well-known group S-1-5-114 Mandatory group, Enabled by default, Enabled group
BUILTIN\Administradores Alias S-1-5-32-544 Mandatory group, Enabled by default, Enabled group, Group owner
BUILTIN\Usu rios Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
AUTORIDADE NT\INTERATIVO Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
LOGON de CONSOLE Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
AUTORIDADE NT\Usu rios autenticados Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
AUTORIDADE NT\Esta organiza‡ao Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
AUTORIDADE NT\Conta local Well-known group S-1-5-113 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
AUTORIDADE NT\Autentica‡ao NTLM Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
R¢tulo Obrigat¢rio\N¡vel Obrigat¢rio Alto Label S-1-16-12288 Mandatory group, Enabled by default, Enabled group


PRIVILEGES INFORMATION
----------------------

Privilege Name Description State
=============================== ========================================= ========
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeSecurityPrivilege Manage auditing and security log Disabled
SeTakeOwnershipPrivilege Take ownership of files or other objects Disabled
SeLoadDriverPrivilege Load and unload device drivers Disabled
SeSystemProfilePrivilege Profile system performance Disabled
SeSystemtimePrivilege Change the system time Disabled
SeProfileSingleProcessPrivilege Profile single process Disabled
SeIncreaseBasePriorityPrivilege Increase scheduling priority Disabled
SeCreatePagefilePrivilege Create a pagefile Disabled
SeBackupPrivilege Back up files and directories Disabled
SeRestorePrivilege Restore files and directories Disabled
SeShutdownPrivilege Shut down the system Disabled
SeDebugPrivilege Debug programs Disabled
SeSystemEnvironmentPrivilege Modify firmware environment values Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeRemoteShutdownPrivilege Force shutdown from a remote system Disabled
SeUndockPrivilege Remove computer from docking station Disabled
SeManageVolumePrivilege Perform volume maintenance tasks Disabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled
SeCreateSymbolicLinkPrivilege Create symbolic links Disabled
-
13/08/2019 15:20:25,55 WHOAMI Command Done - error level - 1
-
-
Get basic system information . . .
Number of processors . . . . 4
PC Brand . . . . . . . . . .
Platform . . . . . . . . . .
Processor Architecture . . . AMD64
Processor Identifier . . . . Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
Processor Level. . . . . . . 6
Processor Revision . . . . . 3a09
Operating system . . . . . . Windows_NT
Windows Dir. . . . . . . . . C:\Windows
User Profile Dir . . . . . . C:\Users\Abi
-
13/08/2019 15:20:25,57 Starting msinfo32 - save in NFO format
-
13/08/2019 15:20:25,63 msinfo32 Started - error level - 0
-
-
13/08/2019 15:20:25,63 Starting dxdiag
-
13/08/2019 15:20:25,65 dxdiag Started - error level - -
-
-
13/08/2019 15:20:25,66 Copy Hosts File
-
13/08/2019 15:20:25,68 Copy Hosts File Done - error level - 0
-
-
13/08/2019 15:20:25,69 Starting Driver Query #1
-
13/08/2019 15:20:25,74 Driver Query #1 Started - error level - 0
-
-
13/08/2019 15:20:25,75 Starting Driver Query #2
-
13/08/2019 15:20:25,78 Driver Query #2 Started - error level - 0
-
-
13/08/2019 15:20:25,79 Starting Driver Query #3
-
13/08/2019 15:20:25,83 Driver Query #3 Started - error level - 0
-
-
D R I V E R Q U E R Y E N D
-
-
13/08/2019 15:20:25,87 Starting Event Viewer log dump - apps
-
13/08/2019 15:20:25,91 Event Viewer log dump - apps - Started - error level - 0
-
-
13/08/2019 15:20:25,92 Starting Event Viewer log dump - System
-
13/08/2019 15:20:25,95 Event Viewer log dump - System - Started - error level - 0
-
-
13/08/2019 15:20:25,96 Starting TRACERT and IPCONFIG
-
-
13/08/2019 15:20:26,03 TRACERT Started - error level - 0
-
13/08/2019 15:20:26,46 Running IPCONFIG Done - error level - 0
-
-
13/08/2019 15:20:26,46 Starting SystemInfo
-
13/08/2019 15:20:26,49 SystemInfo Started - error level - 0
-
-
13/08/2019 15:20:26,50 Starting SysInfo e-mail removing vbs script
-
-)
13/08/2019 15:20:26,53 Export current variables Done - error level - 0
-
-
13/08/2019 15:20:26,54 Starting WHERE *.sys Command
-
-)
13/08/2019 15:20:43,86 NETSH Commands Done - error level - 1
-
-
13/08/2019 15:20:43,87 Running NETSTAT Command
-
13/08/2019 15:22:49,26 NETSTAT Command Done - error level - 0
-
-
13/08/2019 15:22:49,26 Obtaining Windows Error Reporting information
-
13/08/2019 15:22:49,42 Windows Error Reporting Done - error level - 0
-
-
13/08/2019 15:22:49,42 Running Windows Management Instrumentation
-
13/08/2019 15:22:51,72 Windows Management Instrumentation Done - error level - 0
-
-
13/08/2019 15:22:51,72 Listing running Tasks
-
13/08/2019 15:22:53,10 Running executing Tasks Listing . . . DONE

Issue cd cmd - Where are we? . . .
C:\Users\Abi\Documents
13/08/2019 15:22:53,11 cd command issued - error level - 0


13/08/2019 15:22:53,11 Downloading and executing autorunsc.exe. . .


13/08/2019 15:22:55,78 Downloading and executing autorunsc.exe. . . DONE


13/08/2019 15:22:55,79 Copy dumps - 2nd time

13/08/2019 15:22:56,11 Copy dumps - 2nd time . . . Done - error level - 0

13/08/2019 15:22:56,12 Begin registry dump - program un-install strings in case needed

13/08/2019 15:23:00,97 Regquery 1 . . . D O N E - error level - 0

13/08/2019 15:23:01,00 Regquery 2 . . . D O N E - error level - 0

13/08/2019 15:23:01,30 Regquery 3 . . . D O N E - error level - 0

Volume in drive C has no label.
Volume Serial Number is A6D3-2323

Directory of C:\Users\Abi\Documents\SysnativeFileCollectionApp

13/08/2019 15:23 .
13/08/2019 15:23 ..
12/08/2019 23:34 375.560 081219-54085-01.dmp
13/08/2019 15:06 309.640 081319-34647-01.dmp
13/08/2019 15:22 0 Autoruns.txt
13/08/2019 15:20 36.911 DriverqFo.txt
13/08/2019 15:21 14.987 DriverqSi.txt
13/08/2019 15:20 63.930 DriverqV.txt
13/08/2019 15:21 24.168 DxDiagx86.txt
13/08/2019 15:20 984.618 EvtxAppDump.txt
13/08/2019 15:20 2.420.165 EvtxSysDump.txt
13/08/2019 15:23 2.978 HKCUSoftMSWinCVUninstall.txt
13/08/2019 15:23 9.207 HKLMSoftMSA-SInstalledComponents.txt
13/08/2019 15:23 43.212 HKLMSoftMSWinCVUninstall.txt
10/06/2009 18:00 824 Hosts.txt
13/08/2019 15:20 5.551 IPconfigAll.txt
13/08/2019 15:23 10.066 Jcgriff2Log.txt
13/08/2019 15:20 1.020 KernelDumpList.txt
13/08/2019 15:22 2.232.906 MSInfo32.nfo
13/08/2019 15:20 18.946 NetSHLAN1.txt
13/08/2019 15:22 23.219 NetstatJcgriff2
13/08/2019 15:21 0 NetstatJcgriff2.StdErr
13/08/2019 15:22 0 RAMInfo.html
13/08/2019 15:20 3.574 SetEnvironmentVar.txt
13/08/2019 15:20 11.007 SysList.txt
13/08/2019 15:22 10.245 SystemInfo.txt
13/08/2019 15:22 191.352 TasklistSVCHOST.txt
13/08/2019 15:21 1.078 Tracert.txt
13/08/2019 15:22 25 WERALL.txt
13/08/2019 15:22 3.548 WERLocalAppData
13/08/2019 15:22 34.755 WERProgramData
13/08/2019 15:22 1.274 WMICRecoveros.txt
30 File(s) 6.834.766 bytes
2 Dir(s) 11.317.919.744 bytes free

13/08/2019 15:23:01,30 Dir command . . . Done - error level - 0

13/08/2019 15:23:01,31 -- E O J - End of Job . . .
13/08/2019 15:23:01,31 -- E O J - End of Job . . .
13/08/2019 15:23:01,31 -- E O J - End of Job . . .


* * * B S O D F I L E C O L L E C T I O N S C R I P T * * *
Authors:
jcgriff2 - J. C. Griffith, Microsoft MVP
TheOutcaste - Jerry Wines, Microsoft MVP
Patrick - Patrick Barker, Microsoft MVP
niemiro - Richard
Tekno Venus - Stephen
© http://www.sysnative.com/
© sysnative.com - MVP
© 2008 - 2014 sysnative.com
Last Update: July 2014
New Jersey, USA; Oregon, USA; New York, USA
ALL RIGHTS RESERVED

13/08/2019 15:23:01,35 -- E O J - End of Job . . .
13/08/2019 15:23:01,35 -- E O J - End of Job . . .
KernelDumpList.txtThis report performs a DIR command on both the sole file \windows\memory.dmp as well as \windows\minidump sub-directory to allow the BSOD Analyst to check if in fact any dumps were written by a BSOD and are available.

The reason for this file is that occasionally the jcgriff2/Sysnative BSOD App does not properly copy the mini kernel dump files. No idea why this happens on these very rare occasions.

Also, sometimes dumps are listed in this file but not included in the zip file output, it could be because the OP deleted the dump files so that we could not analyze them. This has happened quite a few times.

Most of the OPs involved in this type of activity were trying to cover up the fact that they had a copy of patched Windows (non-genuine) and knew that we would pick up on that fact while processing the dumps. And we have.... :-)
Code:
10/08/2019 21:09:31.09


LISTING OF MINI KERNEL DUMP FILES
LISTING OF MINI KERNEL DUMP FILES

Volume in drive C is OS
Volume Serial Number is D273-1481

Directory of C:\WINDOWS\minidump

10/08/2019 08:43 PM BUILTIN\Administrators .
10/08/2019 08:43 PM NT SERVICE\TrustedInsta..
10/08/2019 08:35 PM 1,178,260 081019~4.DMP BUILTIN\Administrators 081019-33015-01.dmp
10/08/2019 08:44 PM 1,037,988 08C2FD~1.DMP BUILTIN\Administrators 081019-34078-01.dmp
10/08/2019 05:53 PM 3,045,252 081019~1.DMP BUILTIN\Administrators 081019-45390-01.dmp
10/08/2019 08:27 PM 0 081019~3.DMP BUILTIN\Administrators 081019-48046-01.dmp
10/08/2019 08:22 PM 0 081019~2.DMP BUILTIN\Administrators 081019-55187-01.dmp
5 File(s) 5,261,500 bytes
2 Dir(s) 461,436,878,848 bytes free


_______________________________________________________

10/08/2019 21:09:31.10


FULL KERNEL DUMP FILE
FULL KERNEL DUMP FILE

Volume in drive C is OS
Volume Serial Number is D273-1481

Directory of C:\WINDOWS

10/08/2019 08:43 PM 1,148,785,769 BUILTIN\Administrators MEMORY.DMP
1 File(s) 1,148,785,769 bytes
0 Dir(s) 461,436,878,848 bytes free

_______________________________________________________


E O J
E O J

10/08/2019 21:09:31.11
MSInfo32.nfoThis is one of the most comprehensive reports available from Windows and I highly recommend that you spend time getting to know it. The information it contains will definitely come in handy as you continue your learning of BSOD processing.

Bring up your own msinfo32 - bring up a search box or a CMD Prompt screen and type msinfo32.exe and press ENTER. Look over the information carefully.
NetSHLAN1.txtWindows Networking Report showing wifi signal strength and wifi driver name and info.

This is a very helpful while troubleshooting network problems.
Code:
*********************************************************************
*********************************************************************
*********** B E G I N *** N E T W O R K *** I N F O ***********
*********** B E G I N *** N E T W O R K *** I N F O ***********
*********************************************************************
*********************************************************************


by John C. Griffith, Microsoft MVP


***************** WIFI WLAN NETSH WLAN SHOW ALL ******************
***************** WIFI WLAN NETSH WLAN SHOW ALL ******************
Wireless System Information Summary
(Time: 13/08/2019 15:20:34 E. South America Standard Time)


=======================================================================
============================== SHOW DRIVERS ===========================
=======================================================================


Interface name: Conexao de Rede sem Fio

Driver : Atheros AR9485WB-EG Wireless Network Adapter
Vendor : Atheros Communications Inc.
Provider : Atheros Communications Inc.
Date : 11/06/2012
Version : 9.2.0.504
INF file : C:\Windows\INF\oem7.inf
Files : 2 total
C:\Windows\system32\DRIVERS\athrx.sys
C:\Windows\system32\drivers\vwifibus.sys
Type : Native Wi-Fi Driver
Radio types supported : 802.11b 802.11g 802.11n
FIPS 140-2 mode supported : Yes
Hosted network supported : Yes
Authentication and cipher supported in infrastructure mode:
Open None
Open WEP-40bit
Shared WEP-40bit
Open WEP-104bit
Shared WEP-104bit
Open WEP
Shared WEP
WPA-Enterprise TKIP
WPA-Personal TKIP
WPA2-Enterprise TKIP
WPA2-Personal TKIP
Vendor defined TKIP
WPA2-Enterprise Vendor defined
Vendor defined Vendor defined
WPA-Enterprise CCMP
WPA-Personal CCMP
WPA2-Enterprise CCMP
Vendor defined CCMP
WPA2-Enterprise Vendor defined
Vendor defined Vendor defined
WPA2-Personal CCMP
Vendor defined Vendor defined
Authentication and cipher supported in ad-hoc mode:
Open None
Open WEP-40bit
Open WEP-104bit
Open WEP
WPA2-Personal CCMP
Vendor defined Vendor defined
IHV service present : Yes
IHV adapter OUI : [00 03 7f], type: [00]
IHV extensibility DLL path: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll
IHV UI extensibility ClSID: {00000000-0000-0000-0000-000000000000}
IHV diagnostics CLSID : {00000000-0000-0000-0000-000000000000}


=======================================================================
============================= SHOW INTERFACES =========================
=======================================================================


There is 1 interface on the system:

Name : Conexao de Rede sem Fio
Description : Atheros AR9485WB-EG Wireless Network Adapter
GUID : cb1e3989-a580-43e2-81d3-9810ee708d01
Physical address : 24:fd:52:b5:16:2e
State : connected
SSID : Hotel Faro
BSSID : 02:27:22:d5:cc:75
Network type : Infrastructure
Radio type : 802.11n
Authentication : Open
Cipher : None
Connection mode : Auto Connect
Channel : 11
Receive rate (Mbps) : 72.2
Transmit rate (Mbps) : 72.2
Signal : 64%
Profile : Hotel Faro

Hosted network status : Not available


=======================================================================
=========================== SHOW HOSTED NETWORK =======================
=======================================================================


Hosted network settings
-----------------------
Mode : Allowed
Settings :

Hosted network status
---------------------
Status : Not available


=======================================================================
============================= SHOW SETTINGS ===========================
=======================================================================
NetstatJcgriff2Windows NETSTAT file output.

Again, this app and its output is used for much more than BSOD troubleshooting.
Code:
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨ 13/08/2019 15:21:22,13 ¨¨¨¨ NETSTAT ¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨ 13/08/2019 15:21:22,13 ¨¨¨¨ NETSTAT ¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨ 13/08/2019 15:21:22,13 ¨¨¨¨ NETSTAT ¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨

Interface Statistics

Received Sent

Bytes 377518955 27909860
Unicast packets 304690 207090
Non-unicast packets 20560 1010
Discards 0 0
Errors 0 0
Unknown protocols 0

Interface Index = 1
Description = Type = 24
Mtu = 1500
Speed = 1073741824
Physical Address = Administrative Status = 1
Operational Status = 1
Last Changed = 0
Output Queue Length = 0

Interface Index = 2
Description = Type = 131
Mtu = 4091
Speed = 1073741824
Physical Address = Administrative Status = 1
Operational Status = 1
Last Changed = 0
Output Queue Length = 0

Interface Index = 3
Description = Type = 131
Mtu = 1460
Speed = 1073741824
Physical Address = Administrative Status = 1
Operational Status = 1
Last Changed = 0
Output Queue Length = 0

Interface Index = 4
Description = Type = 131
Mtu = 1464
Speed = 1073741824
Physical Address = Administrative Status = 1
Operational Status = 1
Last Changed = 0
Output Queue Length = 0

Interface Index = 5
Description = Type = 23
Mtu = 1494
Speed = 1073741824
Physical Address = Administrative Status = 1
Operational Status = 1
Last Changed = 0
Output Queue Length = 0
NetstatJcgriff2.StdErrNETSTAT Errors
Code:
NO DATA AVAILABLE
RAMInfo.htmlRAM Info is a WMI command that reports on RAM. Unfortunately, it does not work for every OP and the file is sometimes empty.
Code:
NO DATA AVAILABLE
SetEnvironmentVar.txtThe SET command is issued during execution to show the environment variables and their values.
Code:
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Abi\AppData\Roaming
CommonProgramFiles=C:\Program Files\Common Files
CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files
CommonProgramW6432=C:\Program Files\Common Files
COMPUTERNAME=ABI-PC
ComSpec=C:\Windows\system32\cmd.exe
CppWrapperNoDelete=set
CppWrapperPath=C:\Users\Abi\Downloads\SysnativeBSODCollectionApp.exe
CRDate=2008 - 2014 sysnative.com
DllList=DllList.txt
drvq=DrvQuery.txt
drvq_fo=DriverqFo.txt
drvq_si=DriverqSi.txt
drvq_v=DriverqV.txt
EnvirVars=SetEnvironmentVar.txt
ErrFile=C:\Users\Abi\AppData\Local\Temp\errinfotmp.txt
evtx1=EvtxAppDump.txt
evtx2=EvtxSysDump.txt
execdate=13/08/2019
exectime=15:20:19,58
FP_NO_HOST_CHECK=NO
hdrive=C:
HOMEDRIVE=C:
HOMEPATH=\Users\Abi
Indent1=
Indent2=
Indent3=
ipconfg1=IPconfigAll.txt
KrnlDump=KernelDumpList.txt
LastUpdt=July 2014
LOCALAPPDATA=C:\Users\Abi\AppData\Local
Logfile=SysnativeFileCollectionApp\Jcgriff2Log.txt
LOGONSERVER=\\ABI-PC
netsh1=NetSHLAN1.txt
netst1=NetstatJcgriff2
netst1StdErr=NetstatJcgriff2.StdErr
NUMBER_OF_PROCESSORS=4
OFile=Jcgriff2Log.txt
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=AMD64
PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=3a09
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
ProgramFiles(x86)=C:\Program Files (x86)
ProgramW6432=C:\Program Files
ProgVer=v4.6.0
PROMPT=$P$G
PSModulePath=C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
PUBLIC=C:\Users\Public
Reg1=HKLMSoftMSWinCVUninstall.txt
Reg2=HKCUSoftMSWinCVUninstall.txt
Reg3=HKLMSoftMSA-SInstalledComponents.txt
Spacer1=¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
Spacer2=*********************************************************************
SysInfo=SystemInfo.txt
SysInfo1=SystemInfo1.txt
SysList=SysList.txt
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Abi\AppData\Local\Temp
TlSvcHost=TasklistSVCHOST.txt
TMP=C:\Users\Abi\AppData\Local\Temp
tracert1=Tracert.txt
userdir=SysnativeFileCollectionApp
userdir1=C:\Users\Abi\Documents\SysnativeFileCollectionApp
USERDOMAIN=Abi-PC
USERNAME=Abi
USERPROFILE=C:\Users\Abi
usrinstr=BSODPostingInstructions.txt
Wer1=WERProgramData
Wer2=WERLocalAppData
Wer3=WERALL.txt
windir=C:\Windows
windows_tracing_flags=3
windows_tracing_logfile=C:\BVTBin\Tests\installpackage\csilogfile.log
WMICRam=RAMInfo.html
WMICROS=WMICRecoveros.txt
WMIpage=WMICPageCrashdump.txt
WrkDir=C:\Users\Abi\Documents
_Maj=6
_Min=1
_Pad= .
_PadTmp=SystemInfo Started .
_Tab=
_TaskName=SysnativeFileCollectionApp
_TaskNumb=8
_tmpFile1=C:\Users\Abi\AppData\Local\Temp\Jcgriff2Log.txt
_tmpFile2=C:\Users\Abi\AppData\Local\Temp\wmic_dump_info.txt
_tmpFile3=C:\Users\Abi\AppData\Local\Temp\wmic_dump_info1.txt
_tmpFile4=C:\Users\Abi\AppData\Local\Temp\wmic_dump_info2.txt
_tmpFile5=C:\Users\Abi\AppData\Local\Temp\BTF.vbs
_tmpfnumb=5
_Ver=61
_Verchk=1
13/08/2019 15:20:26,52
SysList.txtA system-wide listing of every *.sys file and its location
Code:
13/08/2019 15:20:26,58 -- WHERE *.sys . . .
13/08/2019 15:20:26,58 -- WHERE *.sys . . .
13/08/2019 15:20:26,59 -- WHERE *.sys . . .
-1163722752 13/08/2019 15:06:38 "C:\hiberfil.sys"
-119971840 13/08/2019 15:06:40 "C:\pagefile.sys"
268435456 11/08/2019 12:32:59 "C:\swapfile.sys"
20504 25/02/2009 14:58:58 "C:\HP Universal Print Driver\pcl6-x64-5.8.0.17508\hpfx64bulk.sys"
31256 25/02/2009 14:58:58 "C:\HP Universal Print Driver\pcl6-x64-5.8.0.17508\hpfx64gen.sys"
22040 25/02/2009 14:58:58 "C:\HP Universal Print Driver\pcl6-x64-5.8.0.17508\hppdbulkio.sys"
31768 25/02/2009 14:58:58 "C:\HP Universal Print Driver\pcl6-x64-5.8.0.17508\hppdgenio.sys"
193824 03/12/2013 20:16:28 "C:\HP Universal Print Driver\pcl6-x64-5.8.0.17508\Drivers\Dot4\AMD64\winxp\HPZid412.sys"
55072 03/12/2013 20:16:36 "C:\HP Universal Print Driver\pcl6-x64-5.8.0.17508\Drivers\Dot4\AMD64\winxp\HPZipr12.sys"
36128 03/12/2013 20:16:42 "C:\HP Universal Print Driver\pcl6-x64-5.8.0.17508\Drivers\Dot4\AMD64\winxp\HPZisc12.sys"
57120 03/12/2013 20:16:50 "C:\HP Universal Print Driver\pcl6-x64-5.8.0.17508\Drivers\Dot4\AMD64\winxp\HPZius12.sys"
20504 25/02/2009 14:58:58 "C:\HP Universal Print Driver\pcl6-x64-6.0.0.18849\hpfx64bulk.sys"
31256 25/02/2009 14:58:58 "C:\HP Universal Print Driver\pcl6-x64-6.0.0.18849\hpfx64gen.sys"
22040 25/02/2009 14:58:58 "C:\HP Universal Print Driver\pcl6-x64-6.0.0.18849\hppdbulkio.sys"
31768 25/02/2009 14:58:58 "C:\HP Universal Print Driver\pcl6-x64-6.0.0.18849\hppdgenio.sys"
193776 20/11/2014 4:17:14 "C:\HP Universal Print Driver\pcl6-x64-6.0.0.18849\Drivers\Dot4\AMD64\winxp\HPZid412.sys"
55024 20/11/2014 4:17:22 "C:\HP Universal Print Driver\pcl6-x64-6.0.0.18849\Drivers\Dot4\AMD64\winxp\HPZipr12.sys"
36080 20/11/2014 4:17:30 "C:\HP Universal Print Driver\pcl6-x64-6.0.0.18849\Drivers\Dot4\AMD64\winxp\HPZisc12.sys"
57072 20/11/2014 4:17:38 "C:\HP Universal Print Driver\pcl6-x64-6.0.0.18849\Drivers\Dot4\AMD64\winxp\HPZius12.sys"
19576 26/08/2015 21:37:39 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\amd64\server\NvStreamKms.sys"
18552 26/08/2015 21:37:40 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\x86\server\NvStreamKms.sys"
136624 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\HDAudio\nvhda32.sys"
171352 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\HDAudio\nvhda32v.sys"
171352 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\HDAudio\nvhda64.sys"
204648 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\HDAudio\nvhda64v.sys"
39032 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\Miracast.VirtualAudio\nvvadarm.sys"
454752 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\NV3DVisionUSB.Driver\nvstusb32.sys"
469688 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\NV3DVisionUSB.Driver\nvstusb64.sys"
14456 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\NVI2\NVI2SystemService32.sys"
15664 25/08/2015 15:46:21 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\NVI2\NVI2SystemService64.sys"
44840 11/08/2015 1:55:08 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\NvVAD\nvvad32v.sys"
50472 11/08/2015 1:52:30 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\NvVAD\nvvad64v.sys"
24760 26/08/2015 21:36:15 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\ShieldWirelessController\NVSWCFilter32.sys"
28344 26/08/2015 21:36:15 "C:\NVIDIA\DisplayDriver\355.82\Win8_WinVista_Win7_64\International\ShieldWirelessController\NVSWCFilter64.sys"
26560 23/02/2016 20:58:18 "C:\NVIDIA\DisplayDriver\362.00\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\amd64\server\NvStreamKms.sys"
25536 23/02/2016 20:58:18 "C:\NVIDIA\DisplayDriver\362.00\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\x86\server\NvStreamKms.sys"
138040 23/02/2016 20:58:18 "C:\NVIDIA\DisplayDriver\362.00\Win8_WinVista_Win7_64\International\HDAudio\nvhda32.sys"
170128 23/02/2016 20:58:18 "C:\NVIDIA\DisplayDriver\362.00\Win8_WinVista_Win7_64\International\HDAudio\nvhda32v.sys"
170312 23/02/2016 20:58:18 "C:\NVIDIA\DisplayDriver\362.00\Win8_WinVista_Win7_64\International\HDAudio\nvhda64.sys"
205456 23/02/2016 20:58:18 "C:\NVIDIA\DisplayDriver\362.00\Win8_WinVista_Win7_64\International\HDAudio\nvhda64v.sys"
SystemInfo.txtBasic system info + a full listing of all Windows Updates installed (kb numbers) + active network
Code:
Host Name: ABI-PC
OS Name: Microsoft Windows 7 Ultimate
OS Version: 6.1.7601 Service Pack 1 Build 7601
OS Manufacturer: Microsoft Corporation
OS Configuration: Standalone Workstation
OS Build Type: Multiprocessor Free
Registered Organization:
Product ID: 00426-292-0000007-85267
Original Install Date: 11/08/2019, 14:23:53
System Boot Time: 13/08/2019, 15:06:14
System Manufacturer: ASUSTeK COMPUTER INC.
System Model: K46CB
System Type: x64-based PC
Processor(s): 1 Processor(s) Installed.
[01]: Intel64 Family 6 Model 58 Stepping 9 GenuineIntel ~1801 Mhz
BIOS Version: American Megatrends Inc. K46CB.207, 17/05/2013
Windows Directory: C:\Windows
System Directory: C:\Windows\system32
Boot Device: \Device\HarddiskVolume1
System Locale: en-us;English (United States)
Input Locale: en-us;English (United States)
Time Zone: (UTC-03:00) Brasilia
Total Physical Memory: 3.982 MB
Available Physical Memory: 981 MB
Virtual Memory: Max Size: 7.961 MB
Virtual Memory: Available: 4.067 MB
Virtual Memory: In Use: 3.894 MB
Page File Location(s): C:\pagefile.sys
Domain: WORKGROUP
Logon Server: \\ABI-PC
Hotfix(s): 181 Hotfix(s) Installed.
[01]: KB2849697
[02]: KB2849697
[03]: KB2849696
[04]: KB2849696
[05]: KB2841134
[06]: KB2841134
[07]: KB2670838
[08]: KB971033
[09]: KB2479943
[10]: KB2491683
[11]: KB2506014
[12]: KB2506212
[13]: KB2506928
[14]: KB2532531
[15]: KB2533552

Network Card(s): 2 NIC(s) Installed.
[01]: Dispositivo Bluetooth (Rede Pessoal)
Connection Name: Conexao de Rede Bluetooth
Status: Media disconnected
[02]: Atheros AR9485WB-EG Wireless Network Adapter
Connection Name: Conexao de Rede sem Fio
DHCP Enabled: Yes
DHCP Server: 192.168.96.1
IP address(es)
[01]: 192.168.99.135
[02]: fe80::917e:45ac:2cf4:f051
TasklistSVCHOST.txtWindows current running tasklist detailing all SVCHOST jobs
Code:
Image Name PID Services
========================= ======== ============================================
svchost.exe 772 DcomLaunch, PlugPlay, Power
svchost.exe 880 RpcEptMapper, RpcSs
svchost.exe 976 AudioSrv, Dhcp, eventlog, lmhosts, wscsvc
svchost.exe 1008 AudioEndpointBuilder, CscService, hidserv,
Netman, PcaSvc, TrkWks, UxSms,
WdiSystemHost, Wlansvc, wudfsvc
svchost.exe 128 EventSystem, FontCache, netprofm, nsi,
WdiServiceHost, WinHttpAutoProxySvc
svchost.exe 300 AeLookupSvc, Appinfo, BITS, EapHost, gpsvc,
iphlpsvc, LanmanServer, MMCSS, ProfSvc,
Schedule, SENS, ShellHWDetection, Themes,
Winmgmt, wuauserv
svchost.exe 1092 CryptSvc, Dnscache, LanmanWorkstation,
NlaSvc
svchost.exe 1656 BFE, DPS, MpsSvc
svchost.exe 1116 DiagTrack
svchost.exe 2328 stisvc
svchost.exe 2352 SysMain
svchost.exe 2756 bthserv
svchost.exe 3600 SSDPSRV, upnphost
svchost.exe 4704 WinDefend

Image Name PID Session Name Session# Mem Usage Status User Name CPU Time Window Title
========================= ======== ================ =========== ============ =============== ================================================== ============ ========================================================================
System Idle Process 0 Services 0 24 K Unknown NT AUTHORITY\SYSTEM 0:52:26 N/A
System 4 Services 0 8.792 K Unknown N/A 0:00:46 N/A
smss.exe 284 Services 0 996 K Unknown AUTORIDADE NT\SISTEMA 0:00:00 N/A
csrss.exe 428 Services 0 4.272 K Unknown AUTORIDADE NT\SISTEMA 0:00:00 N/A
csrss.exe 544 Console 1 23.912 K Running AUTORIDADE NT\SISTEMA 0:00:02 N/A
wininit.exe 552 Services 0 4.268 K Unknown AUTORIDADE NT\SISTEMA 0:00:00 N/A
winlogon.exe 600 Console 1 6.104 K Unknown AUTORIDADE NT\SISTEMA 0:00:00 N/A
services.exe 648 Services 0 10.536 K Unknown AUTORIDADE NT\SISTEMA 0:00:02 N/A
Tracert.txtWindows TRACERT command
Code:
Tracing route to sysnative.com [104.247.78.250]
over a maximum of 30 hops:

1 33 ms 36 ms 36 ms 192.168.96.1
2 2 ms 2 ms 2 ms 189.127.3.145.nipcable.com [189.127.3.145]
3 2 ms 2 ms 3 ms 186.236.65.17.nipbr.com [186.236.65.17]
4 47 ms 6 ms 4 ms 100g.200.220.128.45.nipcable.com [200.220.128.45]
5 43 ms 47 ms 47 ms 187-51-232-209.customer.tdatabrasil.net.br [187.51.232.209]
6 8 ms 21 ms 23 ms 152-255-155-218.user.vivozap.com.br [152.255.155.218]
7 56 ms 66 ms 59 ms 213.140.39.93
8 117 ms 115 ms 119 ms 5.53.3.145
9 * * * Request timed out.
10 * * * Request timed out.
11 217 ms 215 ms 243 ms 4.79.22.110
12 * * * Request timed out.
13 * * * Request timed out.
14 220 ms 219 ms 218 ms eccomp4-havp6.inmotionhosting.com [104.193.140.55]
15 219 ms 220 ms 245 ms vps32419.inmotionhosting.com [104.247.78.250]

Trace complete.
WERALL.txtWindows WER Reports, their directory names and locations
Code:
13/08/2019 15:22:49,37
13706 12/08/2019 15:28:30 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_winsat.exe_dccc3dc3a082f06957126a1e9f5df9842bae6df_11dcbb92\Report.wer"
2506 12/08/2019 4:28:48 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_23264e8ae6fb933dcdc18cbb349a0c77e6660ad_04ba89f7\Report.wer"
2156 12/08/2019 20:28:20 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_18798443f5a85347cdacd37beabf47e6935b010_055bb2ab\Report.wer"
2208 12/08/2019 19:11:06 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_00a72f3a\Report.wer"
2208 12/08/2019 19:09:54 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_02b214d7\Report.wer"
2208 12/08/2019 19:12:21 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_05ac53ab\Report.wer"
2208 12/08/2019 19:09:10 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_08c567c7\Report.wer"
2208 12/08/2019 19:11:07 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_096f335f\Report.wer"
2208 12/08/2019 19:11:45 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0bd3c83e\Report.wer"
2208 12/08/2019 19:09:53 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0c36113f\Report.wer"
2208 12/08/2019 19:12:23 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0c805abc\Report.wer"
2208 12/08/2019 19:10:31 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0d02a469\Report.wer"
2208 12/08/2019 19:11:44 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0fd7c429\Report.wer"
2208 12/08/2019 20:26:39 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_7af53ae74dd3aa6ad11bb03d8298c39257519c7d_06ba2a1b\Report.wer"
2208 12/08/2019 19:08:27 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_a31d301a47bebff1e8e5edb710f8e6624f1493b_062cc283\Report.wer"
2216 12/08/2019 4:28:40 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_aad42ea8d73a6654e9f42a86371e79b66762a62c_0ee2695d\Report.wer"
2204 12/08/2019 20:27:49 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_f9b9d5ca396ecaa1b11b5723e1b13ee99f6d4_0acb3c25\Report.wer"
4814 13/08/2019 3:15:42 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0b43a798\Report.wer"
4790 13/08/2019 15:11:05 "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0bfc73d7\Report.wer"
WERLocalAppDataLocal Appdata WER info
Code:
13/08/2019 15:22:49,36
Volume in drive C has no label.
Volume Serial Number is A6D3-2323

Directory of C:\Users\Abi\AppData\Local\Microsoft\Windows\WER

11/08/2019 14:40 ..
11/08/2019 14:40 .
12/08/2019 03:09 REPORT~2 ReportQueue
12/08/2019 08:38 REPORT~1 ReportArchive
13/08/2019 15:09 ERC
0 File(s) 0 bytes

Directory of C:\Users\Abi\AppData\Local\Microsoft\Windows\WER\ERC

13/08/2019 15:09 ..
13/08/2019 15:09 .
0 File(s) 0 bytes

Directory of C:\Users\Abi\AppData\Local\Microsoft\Windows\WER\ReportArchive

12/08/2019 04:29 NONCRI~1 NonCritical_x64_e8a391424a8c4eeda3c73622338914db885e9bf1_0c6750de
12/08/2019 08:38 ..
12/08/2019 08:38 .
12/08/2019 08:38 NONCRI~2 NonCritical_x64_52af0f356e84ce39ec5d7ac36b2cb29138116a4_12aa8b6f
0 File(s) 0 bytes

Directory of C:\Users\Abi\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_x64_52af0f356e84ce39ec5d7ac36b2cb29138116a4_12aa8b6f

12/08/2019 08:38 ..
12/08/2019 08:38 .
12/08/2019 08:38 2.346 Report.wer
1 File(s) 2.346 bytes

Directory of C:\Users\Abi\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_x64_e8a391424a8c4eeda3c73622338914db885e9bf1_0c6750de

12/08/2019 04:29 ..
12/08/2019 04:29 .
12/08/2019 04:29 2.614 Report.wer
1 File(s) 2.614 bytes

Directory of C:\Users\Abi\AppData\Local\Microsoft\Windows\WER\ReportQueue

11/08/2019 14:40 NONCRI~1 NonCritical_x64_627939aa4eaad5f23ff5748fa434d5e2e7b5429_cab_09eba1e9
12/08/2019 03:09 ..
12/08/2019 03:09 .
12/08/2019 03:12 APPCRA~1.EXE AppCrash_Dwm.exe_41641337d5907812dcee9a268b7198c6be76e23_cab_0a3deb3c
0 File(s) 0 bytes

Directory of C:\Users\Abi\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppCrash_Dwm.exe_41641337d5907812dcee9a268b7198c6be76e23_cab_0a3deb3c

12/08/2019 03:09 5.608 WERCB5~1.TXT WERCB5D.tmp.appcompat.txt
12/08/2019 03:09 2.932 WERCFF~1.XML WERCFF0.tmp.WERInternalMetadata.xml
12/08/2019 03:09 1.031.545 WERD01~1.MDM WERD010.tmp.mdmp
12/08/2019 03:09 80 WEREB1~1.TXT WEREB10.tmp.WERDataCollectionFailure.txt
12/08/2019 03:12 8.220 Report.wer
12/08/2019 03:12 ..
12/08/2019 03:12 .
5 File(s) 1.048.385 bytes

Directory of C:\Users\Abi\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_627939aa4eaad5f23ff5748fa434d5e2e7b5429_cab_09eba1e9

11/08/2019 14:40 ..
11/08/2019 14:40 1.600 Report.wer
11/08/2019 14:40 .
1 File(s) 1.600 bytes

Total Files Listed:
8 File(s) 1.054.945 bytes
23 Dir(s) 11.319.353.344 bytes free
WERProgramDataWER data found under \Programdata directory
Code:
13/08/2019 15:22:49,29
Volume in drive C has no label.
Volume Serial Number is A6D3-2323

Directory of C:\ProgramData\Microsoft\Windows\WER

14/07/2009 00:20 ..
14/07/2009 00:20 .
13/08/2019 06:43 REPORT~2 ReportQueue
13/08/2019 15:11 REPORT~1 ReportArchive
0 File(s) 0 bytes

Directory of C:\ProgramData\Microsoft\Windows\WER\ReportArchive

12/08/2019 03:44 NONCRI~1.244 NonCritical_7.6.7601.24436_3426abe03b564928fb65a812e4e3d671c404d_0149cfdc
12/08/2019 04:28 CRITIC~1.760 Critical_6.1.7601_aad42ea8d73a6654e9f42a86371e79b66762a62c_0ee2695d
12/08/2019 04:28 CRITIC~1.175 Critical_6.1.7601.17592_23264e8ae6fb933dcdc18cbb349a0c77e6660ad_04ba89f7
12/08/2019 15:28 APPCRA~1.EXE AppCrash_winsat.exe_dccc3dc3a082f06957126a1e9f5df9842bae6df_11dcbb92
12/08/2019 19:08 CRITIC~2.760 Critical_6.1.7601_a31d301a47bebff1e8e5edb710f8e6624f1493b_062cc283
12/08/2019 19:09 CRITIC~3.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_08c567c7
12/08/2019 19:09 CRITIC~4.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0c36113f
12/08/2019 19:09 CRF245~1.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_02b214d7
12/08/2019 19:10 CRCE0C~1.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0d02a469
12/08/2019 19:11 CR99EE~1.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_00a72f3a
12/08/2019 19:11 CRE302~1.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_096f335f
12/08/2019 19:11 CR1FC5~1.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0fd7c429
12/08/2019 19:11 CR2292~1.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0bd3c83e
12/08/2019 19:12 CRE563~1.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_05ac53ab
12/08/2019 19:12 CRAA11~1.760 Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_0c805abc
12/08/2019 20:26 CR96DE~1.760 Critical_6.1.7601_7af53ae74dd3aa6ad11bb03d8298c39257519c7d_06ba2a1b
12/08/2019 20:27 CR045D~1.760 Critical_6.1.7601_f9b9d5ca396ecaa1b11b5723e1b13ee99f6d4_0acb3c25
12/08/2019 20:28 CRBFA5~1.760 Critical_6.1.7601_18798443f5a85347cdacd37beabf47e6935b010_055bb2ab
13/08/2019 03:15 KERNEL~1 Kernel_0_0_cab_0b43a798
13/08/2019 15:11 .
13/08/2019 15:11 ..
13/08/2019 15:11 KERNEL~2 Kernel_0_0_cab_0bfc73d7
0 File(s) 0 bytes

Directory of C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_winsat.exe_dccc3dc3a082f06957126a1e9f5df9842bae6df_11dcbb92

12/08/2019 15:28 ..
12/08/2019 15:28 .
12/08/2019 15:28 13.706 Report.wer
1 File(s) 13.706 bytes

Directory of C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_23264e8ae6fb933dcdc18cbb349a0c77e6660ad_04ba89f7

12/08/2019 04:28 ..
12/08/2019 04:28 .
12/08/2019 04:28 2.506 Report.wer
1 File(s) 2.506 bytes

Directory of C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_18798443f5a85347cdacd37beabf47e6935b010_055bb2ab

12/08/2019 20:28 ..
12/08/2019 20:28 .
12/08/2019 20:28 2.156 Report.wer
1 File(s) 2.156 bytes

Directory of C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_68fd56bd1ca2b1c3a95e54fb4f563ae9fc5832_00a72f3a

12/08/2019 19:11 ..
12/08/2019 19:11 .
12/08/2019 19:11 2.208 Report.wer
1 File(s) 2.208 bytes
WMICRecoveros.txtDump File Settings + Page File Settings
Code:
AutoReboot=TRUE
Caption=
DebugFilePath=%SystemRoot%\MEMORY.DMP
DebugInfoType=2
Description=
ExpandedDebugFilePath=C:\Windows\MEMORY.DMP
ExpandedMiniDumpDirectory=C:\Windows\Minidump
KernelDumpOnly=FALSE
MiniDumpDirectory=%SystemRoot%\Minidump
Name=Microsoft Windows 7 Ultimate |C:\Windows|
OverwriteExistingDebugFile=TRUE
SendAdminAlert=FALSE
SettingID=
WriteDebugInfo=TRUE
WriteToSystemLog=TRUE


AllocatedBaseSize=3981
Caption=C:\pagefile.sys
CurrentUsage=412
Description=C:\pagefile.sys
InstallDate=20161013223410.334315-180
Name=C:\pagefile.sys
PeakUsage=426
Status=
TempPageFile=FALSE
 
About the jcgriff2log.txt content, what is the difference between the error levels?
 
The text output of SysInternals Autoruns. It rarely works; not sure why, but we're doing away with it in the next release.
No Eula popup visible so it hangs. Back in the day I manually triggered and agreed to the Eula before triggering the file collection app., the file collection included the then-expected .ARN.
 
About the jcgriff2log.txt content, what is the difference between the error levels?
Error levels vary for each command. You would literally have to play (test) with them and check their value based on the output code given to you.
 
Must ask, everything it's collecting along with IP + router versions and a lot more
this just seems way to weird to post on a forum due to the fact that whoever can goes trough these and have malicious intentions.

Do you guys reconcile with this at all? Or do you go by the "the external IP is not shown therefor it's safe"?
 
The files generated aren't specifically for BSOD problems even though that's a main purpose of the tool. The files can also, and have in the past, been used for other problems which include network related problems.

Whether some files are still needed these days, I don't know. I believe updating the tool is on the todo list by those who created it but it's not a priority.

You're not the first to ask about this though, but, as far as I know, there haven't been any incidents with the files that consequently requires updating the tool.
 
The files generated aren't specifically for BSOD problems even though that's a main purpose of the tool. The files can also, and have in the past, been used for other problems which include network related problems.

Whether some files are still needed these days, I don't know. I believe updating the tool is on the todo list by those who created it but it's not a priority.

You're not the first to ask about this though, but, as far as I know, there haven't been any incidents with the files that consequently requires updating the tool.

At least practice good safety for the users who need help, if there is a handler that is deemed trustworthy let him get the files seperately instead of having your entire system details posted on a open forum.
 
Last edited:
There are several other forums besides Sysnative that use this app - originally developed by me in 2007/8.

Other forums - Tech Support Forum (TSF), Bleeping Computer, Malwarebytes, and others.

There has never been a problem with the output of the app and "rogue forces"!
 
There are several other forums besides Sysnative that use this app - originally developed by me in 2007/8.

Other forums - Tech Support Forum (TSF), Bleeping Computer, Malwarebytes, and others.

There has never been a problem with the output of the app and "rogue forces"!
Furthermore, the sheer number of users that are out there using this product, if there were a problem, it would surely crop up.
 
Could you point out the parts that you deem to create a vulnerability that doesn't already exist by simply being connected to the internet?

Examples:
Click click click

Here's All the Data Collected From You as You Browse the Web

Cover Your Tracks

I don't understand your point at all, the reason for the sysnative collection tool to exist is to know your system both hardware and applications and not just that but other things such as net related configuration. This by itself is a reason concern if anyone want to play around and poke around how bad one can mess up your system.

I'm not saying it's a usual thing someone would come here just to do this, I'm simply stating that the load of data that is required to post for specific problems is just stupid.
I have problem with my mouse someone comes in saying "Yeah don't do anything just post me sysnative collection data" and acting like it's not any problem by it.

And again, i think the practice of actually just sending the data to someone who's there to help is fine, but the practice of asking one to upload everything for the entire forum / net to see is honestly weird.
I'm not against the application I'm against the practice of it on help forums like this and others, It would maybe be good to have an anonymized version of it, like a light-scan which exclude your network configuration and things that is making you an easy target.
 
Last edited:
I don't understand your point at all,
It's not a point, it's a question and examples of how one is vulnerable by browsing the internet.

I'm not trying to be contrary either. I appreciate your input.

The thing is, when one is troubleshooting a computer issue, the more info we have, the better to target the issue accurately. Sharing the info on the forum also opens it up to more brains, hence further drilling down to a solution. It also puts it out there for others with similar issues and has helped solve issues in that manner. It also enables learning to others who want to learn.

Sharing this info on the forum is always up to the user posting. We never force anyone to share.

If I had to make a point I guess it would be that the info put out is no more a honeypot for bad actors than the info that already available to a bad actor.

If you look around the plethora of tech sites, it's not weird, it's common practice. Otherwise, no fixes would be found.
 
There is no personal information shared in those files and most - if not all - the network configuration data is trivial and would change upon a reboot. There has been no problems reported by users with the log collection tool and it is used by most of the "big" tech support forums.
 
There is a reference to Geek Police in the script - it would seem that this batch file may be using some of their code which is not something we would want to do.
I have coded the script no one use the script i can remove reference to Geek Police.

What does this do differently to the current log collection tool?
Batch script uses 7-zip to zip archive log files.

Lists running processes.

Displays all current TCP/IP network configuration values.

Collects Group Policy configuration.

Lists drivers.

Creates .nfo file that contain your system information.

Creates event log file for System.

Copies all memory dump files within %SystemRoot%\MiniDump.

Copies windows HOSTS File.

Lists entries in Boot Configuration Data (BCD) store.

Lists installed programs.

Lists Windows services.

Lists device driver status.

List services status.

Lists all installed hotfix updates.

Lists hardware information.

Creates report for DirectX.

Creates report fort energy efficiency and collect power configurations.





 
The current log collection tool provides most of that information though. Do we need all their network configuration? We rarely - if ever - use it in dump file analysis. It's always best to ask for minimum amount of information as possible especially if the user asks for justification.
 
The current log collection tool provides most of that information though. Do we need all their network configuration? We rarely - if ever - use it in dump file analysis. It's always best to ask for minimum amount of information as possible especially if the user asks for justification.
I posted the script so if it's needed, the current script can be enhanced if wanted too.
 
I have coded the script no one use the script i can remove reference to Geek Police.


Batch script uses 7-zip to zip archive log files. We use .zip extension so that Windows can easily open it

Lists running processes.

Displays all current TCP/IP network configuration values. We list all networking info

Collects Group Policy configuration. Most users do ot use Windows XX Pro - so ot much we can do with this

Lists drivers. We obtain drivers from the dumps them match against the DRT

Creates .nfo file that contain your system information. We run msinfo32; output=msinfo32.nfo

Creates event log file for System. We dump both Ststem + Application EVTX logs

Copies all memory dump files within %SystemRoot%\MiniDump. We of course copy minidumps as we process them

Copies windows HOSTS File. We copy it

Lists entries in Boot Configuration Data (BCD) store.

Lists installed programs. We produce all program uninstalls using WMI

Lists Windows services. All system services are listed - Windows + 3rd party

Lists device driver status. Same

List services status. Same

Lists all installed hotfix updates. See systeminfo

Lists hardware information. Found in msinfo32 + dxdiag

Creates report for DirectX. dxdiag

Creates report fort energy efficiency and collect power configurations. Not sure if we do powerconfig or not, but what is its purpose?


Thank you, but we will continue to use ours - originally written by me in 2007/8 and updated by several others since then. We all are very used to it by now.

The Sysnative/jcgriff2 Kernel Dump and System File Collection App has over 1 million downloads to date -- all versions combined and works just fine for us.

Besides, Sysnative Forums being its home base, Bleeping Computers, TechSupportForun (TSF), Malwarebytes (MBAM) and others use it for BSOD threads as well as for general troubleshooting purposes as well.

John


`
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top