Sei sulla pagina 1di 103

SpyHolesList Version:7.7 Build:6.9.7.70 14.06.

2011 6:12:41 PM WinDir=C:\WINDOWS Startup=C:\Documents and Settings\hans\Start Menu\Programs\Startup\ Common Startup=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Microsoft Windows XP Service Pack 2 (5.1.2600) Internet Explorer 8.0.6001.18702 [Internet Explorer] [Default Home Page] :HKLM Default_Page_URL=http://go.microsoft.com/fwlink/?Lin kId=69157 [Current Home Page] :HKCU Start Page=http://start.facemoods.com/?a=ddrnw [Current Home Page] :HKCU HOMEOldSP="" [Search URL Template] :HKLM 1=www.%s.com [Search URL Template] :HKLM 2=www.%s.org [Search URL Template] :HKLM 3=www.%s.net [Search URL Template] :HKLM 4=www.%s.edu [All Users Search] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?Li nkId=54896 [All Users Search] :HKLM Search Page=http://go.microsoft.com/fwlink/?LinkId=54 896 [Current Users Search] :HKCU Search Page=http://www.google.com [Current Users Search] :HKCU Search Bar=http://www.google.com/ie [IE Local Blank Page] :HKCU Local Page=C:\WINDOWS\system32\blank.htm [IE Local Blank Page] :HKLM Local Page=C:\WINDOWS\system32\blank.htm [Browser Helper Objects] {0055C089-8582-441B-A0BF-17B458C2A3A8}=C:\PROGRAM FIL ES\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL ### IDM Browser Helper Object Internet Download Manager, Tonec Inc. Internet D ownload Manager Module 6, 4, 2, 1 [Auto Search URL] :HKCU provider="" [Auto Search URL] :HKCU "Default Value"=http://www.google.com/search?q=%s [Search Assistant] :HKCU SearchAssistant=http://www.google.com/ie [Search Assistant] :HKLM SearchAssistant=http://start.facemoods.com/?a=ddrnw&s ={searchTerms}&f=4 [Search Assistant] :HKCU CustomizeSearch="" [Search Assistant] :HKLM CustomizeSearch=http://ie.search.msn.com/{SUB_RFC1766 }/srchasst/srchcust.htm [CustomizeSearch] :HKLM CustomizeSearch="" [URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-00C04FD64497}=C:\WINDOWS\SYSTEM 32\IEFRAME.DLL ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .18702 [URLSearchHook] :HKCU {EF99BD32-C1FB-11D2-892F-0090271D4F88}=C:\PROGRA~1\Yahoo !\Companion\Installs\cpn0\yt.dll ### File is deleted or hidden by rootkit or could not be located. [Default Prefix] :HKLM "Default Value"=http:// [URL Default Prefixes] :HKLM ftp=ftp:// [URL Default Prefixes] :HKLM gopher=gopher:// [URL Default Prefixes] :HKLM home=http:// [URL Default Prefixes] :HKLM mosaic=http:// [URL Default Prefixes] :HKLM www=http:// [Safe Sites] :HKLM ie.search.msn.com=http://ie.search.msn.com/* [AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM OfflineInformation=res://ieframe.dll/offcancl.htm [AboutURLs] :HKLM Home=270 [AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm [AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm [AboutURLs] :HKLM Tabs=res://ieframe.dll/tabswelcome.htm [AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate.htm

[AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm [AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm [AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm [User Style Sheet] :HKCU User Stylesheet="" [User Style Sheet] :HKUS User Stylesheet="" [User Style Sheet] :HKCU Use My Stylesheet=0 [User Style Sheet] :HKUS Use My Stylesheet=0 [Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=1 [Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1 [Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=3 [Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3 [Execute unsigned ActiveX in Internet Zone] :HKCU 1201=3 [Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3 [Links Toolbar] :HKCU LinksFolderName=Links [Explorer Bars] :HKLM {4D5C8C25-D075-11d0-B416-00C04FB90376}=C:\WINDOWS\SYSTEM 32\SHDOCVW.DLL ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.2987 [Context menu items] :HKCU Download all links with IDM=C:\PROGRAM FILES\INTERN ET DOWNLOAD MANAGER\IEGETALL.HTM [Context menu items] :HKCU Download FLV video content with IDM=C:\PROGRAM FILE S\INTERNET DOWNLOAD MANAGER\IEGETVL.HTM [Context menu items] :HKCU Download with IDM=C:\PROGRAM FILES\INTERNET DOWNLOA D MANAGER\IEEXT.HTM [Active Desktop Components] :HKCU 0=About:Home ### Source=About:Home SubscribedURL=About:Home [Protocols Filter] :HKLM application/octet-stream=C:\WINDOWS\system32\MSCOREE. DLL ### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE T Framework 2.0.50727.42 [Protocols Filter] :HKLM application/x-complus=C:\WINDOWS\system32\MSCOREE.DLL ### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE T Framework 2.0.50727.42 [Protocols Filter] :HKLM application/x-msdownload=C:\WINDOWS\system32\MSCOREE. DLL ### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE T Framework 2.0.50727.42 [Protocols Filter] :HKLM Class Install Handler=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Filter] :HKLM deflate=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Filter] :HKLM gzip=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Filter] :HKLM lzdhtml=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Filter] :HKLM text/webviewhtml=C:\WINDOWS\SYSTEM32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Protocols Filter] :HKLM text/xml=C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXM LMF.DLL ### Microsoft Office XML MIME Filter Microsoft Corporation Microsoft Office In foPath 12.0.4518.1014 [Protocols Handler] :HKLM about=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.18702 [Protocols Handler] :HKLM cdl=C:\WINDOWS\SYSTEM32\URLMON.DLL

### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Handler] :HKLM dvd=C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL ### ActiveX control for streaming video Microsoft Corporation DirectShow 6.05. 2600.2180 [Protocols Handler] :HKLM file=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Handler] :HKLM ftp=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Handler] :HKLM gopher=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Handler] :HKLM http=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Handler] :HKLM https=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Handler] :HKLM ipp [Protocols Handler] :HKLM its=C:\WINDOWS\SYSTEM32\ITSS.DLL ### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi ndows Operating System 5.2.3790.1221 [Protocols Handler] :HKLM javascript=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.18702 [Protocols Handler] :HKLM local=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Handler] :HKLM mailto=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.18702 [Protocols Handler] :HKLM mhtml=C:\WINDOWS\SYSTEM32\INETCOMM.DLL ### Microsoft Internet Messaging API Microsoft Corporation Microsoft Windows Ope rating System 6.00.2900.2180 [Protocols Handler] :HKLM mk=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Protocols Handler] :HKLM ms-help=C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHAR ED\HELP\HXDS.DLL ### Microsoft Help Data Services Module Microsoft Corporation Microsoft Help 2. 5 2.05.50727.198 [Protocols Handler] :HKLM ms-its=C:\WINDOWS\SYSTEM32\ITSS.DLL ### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi ndows Operating System 5.2.3790.1221 [Protocols Handler] :HKLM msdaipp [Protocols Handler] :HKLM res=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.18702 [Protocols Handler] :HKLM sysimage=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.18702 [Protocols Handler] :HKLM tv=C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL ### ActiveX control for streaming video Microsoft Corporation DirectShow 6.05. 2600.2180 [Protocols Handler] :HKLM vbscript=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.18702 [Protocols Handler] :HKLM wia=C:\WINDOWS\SYSTEM32\WIASCR.DLL

### WIA Scripting Layer Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Proxy] :HKCU ProxyServer="" [Proxy] :HKCU ProxyEnable=0 [Network Settings] [Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc [Hosts File Contents] :HKLM 127.0.0.1 localhost [Hosts File Contents] :HKLM 127.0.0.1 activate.adobe.com [Hosts File Contents] :HKLM 127.0.0.1 localhost [Domain Name] :HKLM Domain="" [Name Server] {1F755A1B-F859-446A-B563-B3210FABFE71}=192.168.1.1 ### Network Card:WL230USB Wireless B+G USB 2.0 Adapter DHCPNameServer:192.168. 1.1 DhcpDefaultGateway:192.168.1.1 DhcpServer:192.168.1.1 [WinSock2 Components] :HKLM mswsock.dll=C:\WINDOWS\SYSTEM32\MSWSOCK.DLL ### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [WinSock2 Components] :HKLM winrnr.dll=C:\WINDOWS\SYSTEM32\WINRNR.DLL ### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [WinSock2 Components] :HKLM rsvpsp.dll=C:\WINDOWS\SYSTEM32\RSVPSP.DLL ### Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation Microsof t Windows Operating System 5.1.2600.0 [Windows Shell] [Display Scrap's Extensions] :HKLM NeverShowExt="" [ScreenSaver] :HKCU SCRNSAVE.EXE=C:\WINDOWS\SYSTEM32\LOGON.SCR ### Logon Screen Saver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [System.ini] shell=Explorer.exe [User Shell] :HKCU shell="" [Main File Extensions] :HKLM .exe="%1" %* [Main File Extensions] :HKLM .com="%1" %* [Main File Extensions] :HKLM .pif="%1" %* [Main File Extensions] :HKLM .bat="%1" %* [Main File Extensions] :HKLM .cmd="%1" %* [Main File Extensions] :HKLM .scr="%1" /S [Main File Extensions] :HKLM .txt=%SystemRoot%\system32\NOTEPAD.EXE %1 [Main File Extensions] :HKLM .reg=regedit.exe "%1" [Main File Extensions] :HKLM .inf=%SystemRoot%\System32\NOTEPAD.EXE %1 [Main File Extensions] :HKLM .ini=%SystemRoot%\System32\NOTEPAD.EXE %1 [Main File Extensions] :HKLM .js=%SystemRoot%\System32\WScript.exe "%1" %* [Main File Extensions] :HKLM .vbs=%SystemRoot%\System32\WScript.exe "%1" %* [Main File Extensions] :HKLM .vbe=%SystemRoot%\System32\WScript.exe "%1" %* [Main File Extensions] :HKLM .msc=%SystemRoot%\system32\mmc.exe "%1" %* [Main File Extensions] :HKLM .jpg=rundll32.exe C:\WINDOWS\system32\shimgvw.dll ,ImageView_Fullscreen %1 [Main File Extensions] :HKLM .jpeg=rundll32.exe C:\WINDOWS\system32\shimgvw.dl l,ImageView_Fullscreen %1 [Shell Execute Hooks] :HKLM {AEB6717E-7E19-11d0-97EE-00C04FD91972}=C:\WINDOWS\ system32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Shell Execute Hooks] :HKLM {B5A7F190-DDA6-4420-B3BA-52453494E6CD}=C:\PROGRA~1 \MICROS~2\OFFICE12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [UserInit Value] :HKLM UserInit=C:\WINDOWS\system32\userinit.exe, [Winlogon Notification] :HKLM crypt32chain=C:\WINDOWS\system32\CRYPT32.DLL ### crypt32chain Crypto API32 Microsoft Corporation Microsoft Windows Operating System 5.131.2600.2180

[Winlogon Notification] :HKLM cryptnet=C:\WINDOWS\system32\CRYPTNET.DLL ### cryptnet Crypto Network Related API Microsoft Corporation Microsoft Windows Operating System 5.131.2600.2180 [Winlogon Notification] :HKLM cscdll=C:\WINDOWS\system32\CSCDLL.DLL ### cscdll Offline Network Agent Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Winlogon Notification] :HKLM ScCertProp=C:\WINDOWS\system32\WLNOTIFY.DLL ### ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.2180 [Winlogon Notification] :HKLM Schedule=C:\WINDOWS\system32\WLNOTIFY.DLL ### Schedule Common DLL to receive Winlogon notifications Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.2180 [Winlogon Notification] :HKLM sclgntfy=C:\WINDOWS\system32\SCLGNTFY.DLL ### sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.2180 [Winlogon Notification] :HKLM SensLogn=C:\WINDOWS\system32\WLNOTIFY.DLL ### SensLogn Common DLL to receive Winlogon notifications Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.2180 [Winlogon Notification] :HKLM termsrv=C:\WINDOWS\system32\WLNOTIFY.DLL ### termsrv Common DLL to receive Winlogon notifications Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Winlogon Notification] :HKLM wlballoon=C:\WINDOWS\system32\WLNOTIFY.DLL ### wlballoon Common DLL to receive Winlogon notifications Microsoft Corporati on Microsoft Windows Operating System 5.1.2600.2180 [Shell Services DelayLoad] :HKLM PostBootReminder=C:\WINDOWS\SYSTEM32\SHELL32. DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Shell Services DelayLoad] :HKLM CDBurn=C:\WINDOWS\SYSTEM32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Shell Services DelayLoad] :HKLM WebCheck=C:\WINDOWS\SYSTEM32\WEBCHECK.DLL ### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001. 18702 [Shell Services DelayLoad] :HKLM SysTray=C:\WINDOWS\SYSTEM32\STOBJECT.DLL ### Systray shell service object Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [App Paths] :HKLM AcroRd32.exe=C:\Program Files\Adobe\Reader 10.0\Reader\AcroR d32.exe ### AcroRd32.exe Adobe Reader Adobe Systems Incorporated Adobe Reader 10.0.0. 396 [App Paths] :HKLM AVGSE.DLL=C:\Program Files\AVG\AVG10\avgse.dll ### AVGSE.DLL AVG Shell Extension AVG Technologies CZ, s.r.o. AVG Internet Sec urity 10.0.0.1295 [App Paths] :HKLM bckgzm.exe=C:\Program Files\MSN Gaming Zone\Windows\bckgzm.e xe ### bckgzm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1 [App Paths] :HKLM bridge.exe=C:\Program Files\Adobe\Adobe Bridge CS4\bridge.ex e ### bridge.exe Adobe Bridge Adobe Systems, Inc. Bridge 3.0.0.464 [App Paths] :HKLM chkrzm.exe=C:\Program Files\MSN Gaming Zone\Windows\chkrzm.e xe ### chkrzm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1 [App Paths] :HKLM chrome.exe=C:\Documents and Settings\hans\Local Settings\App lication Data\Google\Chrome\Application\chrome.exe ### chrome.exe Google Chrome Google Inc. Google Chrome 0.0.0.0 [App Paths] :HKLM cmmgr32.exe=C:\WINDOWS\system32\cmmgr32.exe ### cmmgr32.exe [App Paths] :HKLM CONF.EXE=C:\Program Files\NetMeeting\conf.exe ### CONF.EXE Windows NetMeeting Microsoft Corporation Windows NetMeeting 3.01

[App Paths] :HKLM CRInstall.exe=C:\Program Files\USB 2.0 Card Reader\MassStora ge\CRInstall.exe ### CRInstall.exe [App Paths] :HKLM dialer.exe=C:\Program Files\Windows NT\dialer.exe ### dialer.exe TAPI 3.0 Dialer and IP Multicast Conference Viewer Microsoft Co rporation Microsoft Windows Operating System 5.1.2600.2180 [App Paths] :HKLM excel.exe=C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE ### excel.exe Microsoft Office Excel Microsoft Corporation 2007 Microsoft Offi ce system 12.0.4518.1014 [App Paths] :HKLM firefox.exe=C:\Program Files\Mozilla Firefox 4.0 Beta 1\fire fox.exe ### firefox.exe Firefox Mozilla Corporation Firefox 4.0b1 [App Paths] :HKLM GROOVE.EXE=C:\PROGRA~1\MICROS~2\Office12\GROOVE.EXE ### GROOVE.EXE Microsoft Office Groove Microsoft Corporation Microsoft Office Groove 4.2.0.2623 [App Paths] :HKLM HELPCTR.EXE=C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HELPCTR.EXE ### HELPCTR.EXE Microsoft Help and Support Center Microsoft Corporation Micros oft Windows Operating System 5.1.2600.2180 [App Paths] :HKLM hrtzzm.exe=C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.e xe ### hrtzzm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1 [App Paths] :HKLM hypertrm.exe="C:\Program Files\Windows NT\hypertrm.exe" ### hypertrm.exe HyperTerminal Applet Hilgraeve, Inc. Microsoft Windows Operatin g System 5.1.2600.0 [App Paths] :HKLM ICWCONN1.EXE="C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE" ### ICWCONN1.EXE Internet Connection Wizard Microsoft Corporation Microsoft Win dows Operating System 6.00.2900.2180 [App Paths] :HKLM ICWCONN2.EXE="C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE" ### ICWCONN2.EXE Internet Connection Wizard Microsoft Corporation Microsoft Win dows Operating System 6.00.2900.2180 [App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE ### IEXPLORE.EXE Internet Explorer Microsoft Corporation Windows Internet Explo rer 8.00.6001.18702 [App Paths] :HKLM INETWIZ.EXE="C:\Program Files\Internet Explorer\Connection W izard\INETWIZ.EXE" ### INETWIZ.EXE Internet Connection Wizard Microsoft Corporation Microsoft Wind ows Operating System 6.00.2900.2180 [App Paths] :HKLM infopath.exe=C:\PROGRA~1\MICROS~2\Office12\INFOPATH.EXE ### infopath.exe Microsoft Office InfoPath 2007 Microsoft Corporation Microsof t Office InfoPath 12.0.4518.1014 [App Paths] :HKLM install.exe ### install.exe [App Paths] :HKLM Installer.exe=C:\Program Files\Atheros\Installer.exe ### Installer.exe [App Paths] :HKLM ISIGNUP.EXE="C:\Program Files\Internet Explorer\Connection W izard\ISIGNUP.EXE" ### ISIGNUP.EXE Internet Signup Microsoft Corporation Microsoft Windows Operatin g System 6.00.2600.0000 [App Paths] :HKLM javaws.exe=C:\Program Files\Java\jre6\bin\javaws.exe ### javaws.exe Java(TM) Web Start Launcher Sun Microsystems, Inc. Java(TM) Pla tform SE 6 U25 6.0.250.6 [App Paths] :HKLM LManager.EXE=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE ### LManager.EXE Launch Manager Dritek System Inc. Launch Manager 1, 0, 17, 60 5 [App Paths] :HKLM migwiz.exe=%SystemRoot%\system32\usmt\migwiz.exe ### migwiz.exe [App Paths] :HKLM moviemk.exe=C:\Program Files\Movie Maker\moviemk.exe ### moviemk.exe Windows Movie Maker Microsoft Corporation Windows Movie Maker

2.1.4026.0 [App Paths] :HKLM mplayer2.exe="C:\Program Files\Windows Media Player\mplayer2 .exe" ### mplayer2.exe [App Paths] :HKLM MSACCESS.EXE=C:\PROGRA~1\MICROS~2\Office12\MSACCESS.EXE ### MSACCESS.EXE Microsoft Office Access Microsoft Corporation 2007 Microsoft Office system 12.0.4518.1014 [App Paths] :HKLM MSCONFIG.EXE=C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.E XE ### MSCONFIG.EXE System Configuration Utility Microsoft Corporation Microsoft W indows Operating System 5.1.2600.2180 [App Paths] :HKLM msimn.exe=%ProgramFiles%\Outlook Express\msimn.exe ### msimn.exe [App Paths] :HKLM msinfo32.exe=C:\Program Files\Common Files\Microsoft Shared\ MSInfo\MSInfo32.exe ### msinfo32.exe System Information Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.0 [App Paths] :HKLM MSMSGS.EXE=C:\Program Files\Messenger\msmsgs.exe ### MSMSGS.EXE Windows Messenger Microsoft Corporation Messenger Version 4.7.3 000 [App Paths] :HKLM MsoHtmEd.exe ### MsoHtmEd.exe [App Paths] :HKLM msoxmled.exe=C:\Program Files\Common Files\Microsoft Shared\ OFFICE12\MSOXMLED.EXE ### msoxmled.exe XML Editor Microsoft Corporation Microsoft Office InfoPath 12 .0.4518.1014 [App Paths] :HKLM MSPUB.EXE=C:\PROGRA~1\MICROS~2\Office12\MSPUB.EXE ### MSPUB.EXE Microsoft Office Publisher Microsoft Corporation 2007 Microsoft Office system 12.0.4518.1014 [App Paths] :HKLM notepad++.exe=C:\Program Files\Notepad++\notepad++.exe ### notepad++.exe Notepad++ : a free (GNU) source code editor Don HO don.h@fre e.fr Notepad++ 5.9 [App Paths] :HKLM ois.exe=C:\PROGRA~1\MICROS~2\Office12\OIS.EXE ### ois.exe Microsoft Office Picture Manager Microsoft Corporation Microsoft O ffice Picture Manager 12.0.4518.1014 [App Paths] :HKLM OneNote.exe=C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE ### OneNote.exe Microsoft Office OneNote Microsoft Corporation Microsoft Offic e OneNote 12.0.4518.1014 [App Paths] :HKLM OUTLOOK.EXE=C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE ### OUTLOOK.EXE Microsoft Office Outlook Microsoft Corporation Microsoft Offic e Outlook 12.0.4518.1014 [App Paths] :HKLM pbrush.exe=%SystemRoot%\system32\mspaint.exe ### pbrush.exe [App Paths] :HKLM Photoshop.exe=C:\Program Files\Adobe\Adobe Photoshop CS4\Pho toshop.exe ### Photoshop.exe Adobe Photoshop CS4 Adobe Systems, Incorporated Adobe Photos hop CS4 CS4 [App Paths] :HKLM PictureViewer.exe=C:\Program Files\QuickTime\PictureViewer.e xe ### PictureViewer.exe PictureViewer Apple Inc. QuickTime QuickTime 7.6.9 (1680 .9) [App Paths] :HKLM pinball.exe=C:\Program Files\Windows NT\Pinball\pinball.exe ### pinball.exe 3D Pinball Cinematronics 3D Pinball 5.1.2600.2180 [App Paths] :HKLM powerpnt.exe=C:\PROGRA~1\MICROS~2\Office12\POWERPNT.EXE ### powerpnt.exe Microsoft Office PowerPoint Microsoft Corporation 2007 Micros oft Office system 12.0.4518.1014 [App Paths] :HKLM QuickTimePlayer.exe=C:\Program Files\QuickTime\QuickTimePlay er.exe ### QuickTimePlayer.exe QuickTime Player Apple Inc. QuickTime QuickTime 7.6.9 (1680.9)

[App Paths] :HKLM rvsezm.exe=C:\Program Files\MSN Gaming Zone\Windows\rvsezm.e xe ### rvsezm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1 [App Paths] :HKLM setup.exe ### setup.exe [App Paths] :HKLM shvlzm.exe=C:\Program Files\MSN Gaming Zone\Windows\shvlzm.e xe ### shvlzm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1 [App Paths] :HKLM table30.exe ### table30.exe [App Paths] :HKLM wab.exe=%ProgramFiles%\Outlook Express\wab.exe ### wab.exe [App Paths] :HKLM wabmig.exe=%ProgramFiles%\Outlook Express\wabmig.exe ### wabmig.exe [App Paths] :HKLM winnt32.exe ### winnt32.exe [App Paths] :HKLM WinRAR.exe=C:\Program Files\WinRAR\WinRAR.exe ### WinRAR.exe [App Paths] :HKLM Winword.exe=C:\PROGRA~1\MICROS~2\Office12\WINWORD.EXE ### Winword.exe Microsoft Office Word Microsoft Corporation 2007 Microsoft Off ice system 12.0.4518.1014 [App Paths] :HKLM wmplayer.exe=C:\Program Files\Windows Media Player\wmplayer. exe ### wmplayer.exe Windows Media Player Microsoft Corporation Microsoft(R) Windo ws Media Player 9.00.00.3250 [App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD. EXE ### WORDPAD.EXE WordPad MFC Application Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE " ### WRITE.EXE [Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0 [Disable Registry Tools] :HKCU DisableRegistryTools =0 [Print Monitors] :HKLM BJ Language Monitor=C:\WINDOWS\system32\CNBJMON.DLL ### Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation Microso ft Windows Operating System 5.1.2600.2082 [Print Monitors] :HKLM Bluetooth Printer Port=C:\WINDOWS\system32\BTHCRP.DLL ### bthcrp DLL Broadcom Corporation. Bluetooth Software 5.1.0.4200 [Print Monitors] :HKLM Local Port=C:\WINDOWS\system32\LOCALSPL.DLL ### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Print Monitors] :HKLM PJL Language Monitor=C:\WINDOWS\system32\PJLMON.DLL ### PJL Language monitor Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Print Monitors] :HKLM Send To Microsoft OneNote Monitor=C:\WINDOWS\system32\M SONPMON.DLL ### Microsoft Office OneNote 2007 Printer Driver Microsoft Corporation Microso ft Office OneNote 2007 Printer Driver 12.3.4518.1014 [Print Monitors] :HKLM Standard TCP/IP Port=C:\WINDOWS\system32\TCPMON.DLL ### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Print Monitors] :HKLM USB Monitor=C:\WINDOWS\system32\USBMON.DLL ### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 1 (GFS Unread Stub)=C:\PROGRA~1\MICROS~2\OFFICE12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 2 (GFS Stub)=

C:\PROGRA~1\MICROS~2\OFFICE12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 2.5 (GFS Unre ad Folder)=C:\PROGRA~1\MICROS~2\OFFICE12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 3 (GFS Folder )=C:\PROGRA~1\MICROS~2\OFFICE12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 4 (GFS Unread Mark)=C:\PROGRA~1\MICROS~2\OFFICE12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Shell Icon Overlay Handlers] :HKLM IDM Shell Extension=C:\PROGRAM FILES\INTER NET DOWNLOAD MANAGER\IDMSHELLEXT.DLL ### Internet Download Manager module Tonec Inc. Internet Download Manager modu le 6,0,4,10 [Shell Icon Overlay Handlers] :HKLM Offline Files=C:\WINDOWS\SYSTEM32\CSCUI.DL L ### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Context Menu Handlers] :HKLM AVG9 Shell Extension=C:\PROGRAM FILES\AVG\AVG10\ AVGSE.DLL ### AVG Shell Extension AVG Technologies CZ, s.r.o. AVG Internet Security 10.0 .0.1295 [Context Menu Handlers] :HKLM MD5ToolShlExt=C:\PROGRAM FILES\MD5 TOOL\DLLREG.D LL ### DllReg Module DllReg Module 1, 0, 0, 1 [Context Menu Handlers] :HKLM Notepad++=C:\PROGRAM FILES\NOTEPAD++\NPPSHELL_04 .DLL ### ShellHandler for Notepad++ (64 bit) 0.1 [Context Menu Handlers] :HKLM Offline Files=C:\WINDOWS\SYSTEM32\CSCUI.DLL ### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Context Menu Handlers] :HKLM Open With EncryptionMenu=C:\WINDOWS\SYSTEM32\SHE LL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Context Menu Handlers] :HKLM WinRAR=C:\PROGRAM FILES\WINRAR\RAREXT.DLL [Context Menu Handlers] :HKLM XXX Groove GFS Context Menu Handler XXX=C:\PROGR A~1\MICROS~2\OFFICE12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}=C:\WINDOW S\SYSTEM32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Kernel Auto Boot] [ActiveSetup] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}=C:\WINDOWS\INF\UNREGMP2. EXE ### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microso ft(R) Windows Media Player 9.00.00.3250 [ActiveSetup] >{26923b43-4d38-484f-9b9e-de460746276c}=C:\WINDOWS\SYSTEM32\IE4U INIT.EXE ### IE Per-User Initialization Utility Microsoft Corporation Windows Internet E

xplorer 8.00.6001.18702 [Svchost DLLs] :HKLM HTTPFilter=C:\WINDOWS\SYSTEM32\W3SSL.DLL ### SSL service for HTTP Microsoft Corporation Internet Information Services 6 .0.2600.2180 [Svchost DLLs] :HKLM Alerter=C:\WINDOWS\SYSTEM32\ALRSVC.DLL ### Alerter Service DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM WebClient=C:\WINDOWS\SYSTEM32\WEBCLNT.DLL ### Web DAV Service DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL ### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft Window s Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\REGSVC.DLL ### Remote Registry Service Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL ### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL ### SSDP Service DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Svchost DLLs] :HKLM DnsCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL ### DNS Caching Resolver Service Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Svchost DLLs] :HKLM 6to4 [Svchost DLLs] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL ### Software installation Service Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL ### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Svchost DLLs] :HKLM Browser=C:\WINDOWS\SYSTEM32\BROWSER.DLL ### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL ### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Svchost DLLs] :HKLM DMServer=C:\WINDOWS\SYSTEM32\DMSERVER.DLL ### Logical Disk Manager service dll Microsoft Corp. Logical Disk Manager for Windows NT 1.0 [Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCSVC.DLL ### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM ERSvc=C:\WINDOWS\SYSTEM32\ERSVC.DLL ### Windows Error Reporting Service Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL ### Microsoft Corporation COM Services 03.00.00.4414 [Svchost DLLs] :HKLM FastUserSwitchingCompatibility=C:\WINDOWS\SYSTEM32\SHSVCS .DLL ### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Svchost DLLs] :HKLM HidServ=%SystemRoot%\System32\hidserv.dll [Svchost DLLs] :HKLM Ias [Svchost DLLs] :HKLM Iprip [Svchost DLLs] :HKLM Irmon [Svchost DLLs] :HKLM LanmanServer=C:\WINDOWS\SYSTEM32\SRVSVC.DLL ### Server Service DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180

[Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\SYSTEM32\WKSSVC.DLL ### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Svchost DLLs] :HKLM Messenger=C:\WINDOWS\SYSTEM32\MSGSVC.DLL ### NT Messenger Service Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Svchost DLLs] :HKLM Netman=C:\WINDOWS\SYSTEM32\NETMAN.DLL ### Network Connections Manager Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Svchost DLLs] :HKLM Nla=C:\WINDOWS\SYSTEM32\MSWSOCK.DLL ### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM Ntmssvc=C:\WINDOWS\SYSTEM32\NTMSSVC.DLL ### Removable Storage Manager Microsoft Corporation Microsoft Windows Whistler O perating System 5.1.2400.2180 [Svchost DLLs] :HKLM NWCWorkstation [Svchost DLLs] :HKLM Nwsapagent [Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\SYSTEM32\RASAUTO.DLL ### Remote Access AutoDial Manager Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Svchost DLLs] :HKLM Rasman=C:\WINDOWS\SYSTEM32\RASMANS.DLL ### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\SYSTEM32\MPRDIM.DLL ### Dynamic Interface Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Svchost DLLs] :HKLM Schedule=C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL ### Task Scheduler Engine Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Svchost DLLs] :HKLM Seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL ### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Svchost DLLs] :HKLM SENS=C:\WINDOWS\SYSTEM32\SENS.DLL ### System Event Notification Service (SENS) Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\SYSTEM32\IPNATHLP.DLL ### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Svchost DLLs] :HKLM SRService=C:\WINDOWS\SYSTEM32\SRSVC.DLL ### System Restore Service Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\SYSTEM32\TAPISRV.DLL ### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM Themes=C:\WINDOWS\SYSTEM32\SHSVCS.DLL ### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\TRKWKS.DLL ### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Svchost DLLs] :HKLM W32Time=C:\WINDOWS\SYSTEM32\W32TIME.DLL ### Windows Time Service Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Svchost DLLs] :HKLM WZCSVC=C:\WINDOWS\SYSTEM32\WZCSVC.DLL ### Wireless Zero Configuration Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM Wmi=C:\WINDOWS\SYSTEM32\ADVAPI32.DLL ### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Svchost DLLs] :HKLM WmdmPmSp

[Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\WSCSVC.DLL ### Windows Security Center Service Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Svchost DLLs] :HKLM xmlprov=C:\WINDOWS\SYSTEM32\XMLPROV.DLL ### Network Provisioning Service Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Svchost DLLs] :HKLM BITS=C:\WINDOWS\SYSTEM32\QMGR.DLL ### Background Intelligent Transfer Service Microsoft Corporation Microsoft Win dows Operating System 6.6.2600.2180 [Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\WUAUSERV.DLL ### Windows Update AutoUpdate Service Microsoft Corporation Microsoft Windows Op erating System 5.4.3790.2180 [Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SHSVCS.DLL ### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Svchost DLLs] :HKLM helpsvc=C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\PCHSVC.DLL ### Microsoft PCHealth Service Holder Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.2180 [Svchost DLLs] :HKLM WmdmPmSN=C:\WINDOWS\SYSTEM32\MSPMSNSV.DLL ### Microsoft Media Device Service Provider Microsoft Corporation Windows Medi a Device Manager 9.0.1.56 [Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL ### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Svchost DLLs] :HKLM TermService=C:\WINDOWS\SYSTEM32\TERMSRV.DLL ### Terminal Server Service Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL ### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL ### Still Image Devices Service Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Bootexecute] :HKLM BootExecute=autocheck autochk * Partizan [Winlogon System] :HKLM system="" ### File is deleted or hidden by rootkit or could not be located. [Winlogon System] :HKLM taskman="" ### File is deleted or hidden by rootkit or could not be located. [Winlogon System] :HKLM UIHost=C:\WINDOWS\system32\LOGONUI.EXE ### Windows Logon UI Microsoft Corporation Microsoft Windows Operating System 6. 00.2900.2180 [Winlogon Autostart] :HKLM VmApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl " [Winlogon Autostart] :HKLM AppSetup="" [KnownDLLs] :HKLM advapi32=advapi32.dll [KnownDLLs] :HKLM comdlg32=comdlg32.dll [KnownDLLs] :HKLM DllDirectory=%SystemRoot%\system32 [KnownDLLs] :HKLM gdi32=gdi32.dll [KnownDLLs] :HKLM imagehlp=imagehlp.dll [KnownDLLs] :HKLM kernel32=kernel32.dll [KnownDLLs] :HKLM lz32=lz32.dll [KnownDLLs] :HKLM ole32=ole32.dll [KnownDLLs] :HKLM oleaut32=oleaut32.dll [KnownDLLs] :HKLM olecli32=olecli32.dll [KnownDLLs] :HKLM olecnv32=olecnv32.dll [KnownDLLs] :HKLM olesvr32=olesvr32.dll [KnownDLLs] :HKLM olethk32=olethk32.dll

[KnownDLLs] :HKLM rpcrt4=rpcrt4.dll [KnownDLLs] :HKLM shell32=shell32.dll [KnownDLLs] :HKLM url=url.dll [KnownDLLs] :HKLM urlmon=urlmon.dll [KnownDLLs] :HKLM user32=user32.dll [KnownDLLs] :HKLM version=version.dll [KnownDLLs] :HKLM wininet=wininet.dll [KnownDLLs] :HKLM wldap32=wldap32.dll [Environment - Path] :HKLM Path=C:\Program Files\PC Connectivity Solution\;%Sy stemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Quic kTime\QTSystem\ [List of Injected DLLs] :HKLM AppInit_DLLs="" [LSA Notification Packages] :HKLM scecli=C:\WINDOWS\system32\SCECLI.DLL ### scecli Windows Security Configuration Editor Client Engine Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.2180 [LSA Security Packages] :HKLM kerberos=C:\WINDOWS\system32\KERBEROS.DLL ### kerberos Kerberos Security Package Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [LSA Security Packages] :HKLM msv1_0=C:\WINDOWS\system32\MSV1_0.DLL ### msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation Microso ft Windows Operating System 5.1.2600.2180 [LSA Security Packages] :HKLM schannel=C:\WINDOWS\system32\SCHANNEL.DLL ### schannel TLS / SSL Security Provider Microsoft Corporation Microsoft Window s Operating System 5.1.2600.2180 [LSA Security Packages] :HKLM wdigest=C:\WINDOWS\system32\WDIGEST.DLL ### wdigest Microsoft Digest Access Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Auto Services] AudioSrv ### Internal Name: AudioSrv. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Manages audio devices for Windows-based pro grams. If this service is stopped, audio devices and effects will not function p roperly. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] avgfws ### Internal Name: avgfws. Status: service is running. Actual File: "C:\Progra m Files\AVG\AVG10\avgfws.exe" * AVG Firewall Service AVG Firewall Service AVG Te chnologies CZ, s.r.o. AVG Internet Security 10.0.0.1350 [Auto Services] avgwd ### Internal Name: avgwd. Status: service is running. Actual File: "C:\Program Files\AVG\AVG10\avgwdsvc.exe" * AVG Watchdog Service AVG Watchdog Service AVG T echnologies CZ, s.r.o. AVG Internet Security 10.0.0.1295 [Auto Services] Browser ### Internal Name: Browser. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k netsvcs * Maintains an updated list of computers on th e network and supplies this list to computers designated as browsers. If this se rvice is stopped, this list will not be updated or maintained. If this service i s disabled, any services that explicitly depend on it will fail to start. Generi c Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Auto Services] btwdins ### Internal Name: btwdins. Status: service is running. Actual File: C:\Progra m Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe * Handles installation and re moval of Bluetooth devices. Bluetooth Support Server Broadcom Corporation. Bluet ooth Software 5.1.0.4200 [Auto Services] CryptSvc ### Internal Name: CryptSvc. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k netsvcs * Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Roo t Service, which adds and removes Trusted Root Certification Authority certifica

tes from this computer; and Key Service, which helps enroll this computer for ce rtificates. If this service is stopped, these management services will not funct ion properly. If this service is disabled, any services that explicitly depend o n it will fail to start. Generic Host Process for Win32 Services Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] DcomLaunch ### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\WIN DOWS\system32\svchost -k DcomLaunch * Provides launch functionality for DCOM ser vices. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Auto Services] Dhcp ### Internal Name: Dhcp. Status: service is running. Actual File: C:\WINDOWS\s ystem32\svchost.exe -k netsvcs * Manages network configuration by registering an d updating IP addresses and DNS names. Generic Host Process for Win32 Services M icrosoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] dmserver ### Internal Name: dmserver. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Detects and monitors new hard disk drives a nd sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configura tion information may become out of date. If this service is disabled, any servic es that explicitly depend on it will fail to start. Generic Host Process for Win 32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] Dnscache ### Internal Name: Dnscache. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k NetworkService * Resolves and caches Domain Name Syst em (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers . If this service is disabled, any services that explicitly depend on it will fa il to start. Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [Auto Services] ERSvc ### Internal Name: ERSvc. Status: service is running. Actual File: C:\WINDOWS\ System32\svchost.exe -k netsvcs * Allows error reporting for services and applic tions running in non-standard environments. Generic Host Process for Win32 Servi ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] Eventlog ### Internal Name: Eventlog. Status: service is running. Actual File: C:\WINDO WS\system32\services.exe * Enables event log messages issued by Windows-based pr ograms and components to be viewed in Event Viewer. This service cannot be stopp ed. Services and Controller app Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] helpsvc ### Internal Name: helpsvc. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Enables Help and Support Center to run on th is computer. If this service is stopped, Help and Support Center will be unavail able. If this service is disabled, any services that explicitly depend on it wil l fail to start. Generic Host Process for Win32 Services Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.2180 [Auto Services] HidServ ### Internal Name: HidServ. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Enables generic input access to Human Interf ace Devices (HID), which activates and maintains the use of predefined hot butto ns on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If t his service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Auto Services] JavaQuickStarterService

### Internal Name: JavaQuickStarterService. Status: service is running. Actual File: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Fil es\Java\jre6\lib\deploy\jqs\jqs.conf" * Prefetches JRE files for faster startup of Java applets and applications Java(TM) Quick Starter Service Sun Microsystems , Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Auto Services] lanmanserver ### Internal Name: lanmanserver. Status: service is running. Actual File: C:\W INDOWS\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh aring over the network for this computer. If this service is stopped, these func tions will be unavailable. If this service is disabled, any services that explic itly depend on it will fail to start. Generic Host Process for Win32 Services Mi crosoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] lanmanworkstation ### Internal Name: lanmanworkstation. Status: service is running. Actual File: C:\WINDOWS\system32\svchost.exe -k netsvcs * Creates and maintains client netwo rk connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly d epend on it will fail to start. Generic Host Process for Win32 Services Microsof t Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] LmHosts ### Internal Name: LmHosts. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k LocalService * Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Generic Host Process for Win32 Ser vices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] NVSvc ### Internal Name: NVSvc. Status: service is running. Actual File: C:\WINDOWS\ system32\nvsvc32.exe * Provides system and desktop level support to the NVIDIA d isplay driver NVIDIA Driver Helper Service, Version 175.90 NVIDIA Corporation NV IDIA Driver Helper Service, Version 175.90 6.14.11.7590 [Auto Services] PlugPlay ### Internal Name: PlugPlay. Status: service is running. Actual File: C:\WINDO WS\system32\services.exe * Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will r esult in system instability. Services and Controller app Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.2180 [Auto Services] PolicyAgent ### Internal Name: PolicyAgent. Status: service is running. Actual File: C:\WI NDOWS\system32\lsass.exe * Manages IP security policy and starts the ISAKMP/Oakl ey (IKE) and the IP security driver. LSA Shell (Export Version) Microsoft Corpor ation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] ProtectedStorage ### Internal Name: ProtectedStorage. Status: service is running. Actual File: C:\WINDOWS\system32\lsass.exe * Provides protected storage for sensitive data, s uch as private keys, to prevent access by unauthorized services, processes, or u sers. LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] RemoteRegistry ### Internal Name: RemoteRegistry. Status: service is running. Actual File: C: \WINDOWS\system32\svchost.exe -k LocalService * Enables remote users to modify r egistry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any ser vices that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2 180 [Auto Services] RpcSs ### Internal Name: RpcSs. Status: service is running. Actual File: C:\WINDOWS\ system32\svchost -k rpcss * Provides the endpoint mapper and other miscellaneous RPC services. Generic Host Process for Win32 Services Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.2180 [Auto Services] SamSs

### Internal Name: SamSs. Status: service is running. Actual File: C:\WINDOWS\ system32\lsass.exe * Stores security information for local user accounts. LSA Sh ell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.2180 [Auto Services] Schedule ### Internal Name: Schedule. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Enables a user to configure and schedule au tomated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Serv ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] seclogon ### Internal Name: seclogon. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unava ilable. If this service is disabled, any services that explicitly depend on it w ill fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] SENS ### Internal Name: SENS. Status: service is running. Actual File: C:\WINDOWS\s ystem32\svchost.exe -k netsvcs * Tracks system events such as Windows logon, net work, and power events. Notifies COM+ Event System subscribers of these events. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Auto Services] SharedAccess ### Internal Name: SharedAccess. Status: service is running. Actual File: C:\W INDOWS\system32\svchost.exe -k netsvcs * Provides network address translation, a ddressing, name resolution and/or intrusion prevention services for a home or sm all office network. Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] ShellHWDetection ### Internal Name: ShellHWDetection. Status: service is running. Actual File: C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay hardware events. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] Spooler ### Internal Name: Spooler. Status: service is running. Actual File: C:\WINDOW S\system32\spoolsv.exe * Loads files to memory for later printing. Spooler SubSy stem App Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] srservice ### Internal Name: srservice. Status: service is running. Actual File: C:\WIND OWS\system32\svchost.exe -k netsvcs * Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Pr operties Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] Themes ### Internal Name: Themes. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Provides user experience theme management. Ge neric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Auto Services] TrkWks ### Internal Name: TrkWks. Status: service is running. Actual File: C:\WINDOWS \system32\svchost.exe -k netsvcs * Maintains links between NTFS files within a c omputer or across computers in a network domain. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] W32Time ### Internal Name: W32Time. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Maintains date and time synchronization on a ll clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services

that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Auto Services] WebClient ### Internal Name: WebClient. Status: service is running. Actual File: C:\WIND OWS\system32\svchost.exe -k LocalService * Enables Windows-based programs to cre ate, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Servi ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] winmgmt ### Internal Name: winmgmt. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k netsvcs * Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not f unction properly. If this service is disabled, any services that explicitly depe nd on it will fail to start. Generic Host Process for Win32 Services Microsoft C orporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] wscsvc ### Internal Name: wscsvc. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Monitors system security settings and configu rations. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Auto Services] wuauserv ### Internal Name: wuauserv. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k netsvcs * Enables the download and installation of Wi ndows updates. If this service is disabled, this computer will not be able to us e the Automatic Updates feature or the Windows Update Web site. Generic Host Pro cess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Auto Services] WZCSVC ### Internal Name: WZCSVC. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Provides automatic configuration for the 802. 11 adapters Generic Host Process for Win32 Services Microsoft Corporation Micros oft Windows Operating System 5.1.2600.2180 [Auto Services] YahooAUService ### Internal Name: YahooAUService. Status: service is running. Actual File: "C :\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe" * Keeps your favorite Yahoo! software up-to-date with the latest features, tools, and enhancements. Au toUpater Service Module Yahoo! Inc. Yahoo! AutoUpdater 1.0.0.53 [Drivers] ntkrnlpa.exe=C:\WINDOWS\SYSTEM32\NTKRNLPA.EXE ### NT Kernel & System Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] hal.dll=C:\WINDOWS\SYSTEM32\HAL.DLL ### Hardware Abstraction Layer DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Drivers] KDCOM.DLL=C:\WINDOWS\SYSTEM32\KDCOM.DLL ### Kernel Debugger HW Extension DLL Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.0 [Drivers] BOOTVID.dll=C:\WINDOWS\SYSTEM32\BOOTVID.DLL ### VGA Boot Driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.0 [Drivers] ACPI.sys=C:\WINDOWS\system32\DRIVERS\ACPI.sys ### ACPI Driver for NT Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] WMILIB.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\WMILIB.SYS ### WMILIB WMI support library Dll Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.0 [Drivers] Partizan.sys=C:\WINDOWS\system32\DRIVERS\Partizan.sys ### Partizan - Rootkit detector Greatis Software RegRun Security Suite 6, 8, 0

, 0 [Drivers] pci.sys=C:\WINDOWS\system32\DRIVERS\pci.sys ### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Drivers] isapnp.sys=C:\WINDOWS\system32\DRIVERS\isapnp.sys ### PNP ISA Bus Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] compbatt.sys=C:\WINDOWS\system32\DRIVERS\compbatt.sys ### Composite Battery Driver Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.0 [Drivers] BATTC.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\BATTC.SYS ### Battery Class Driver Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.0 [Drivers] pciide.sys=C:\WINDOWS\system32\DRIVERS\pciide.sys ### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] PCIIDEX.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDEX.SYS ### PCI IDE Bus Driver Extension Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Drivers] MountMgr.sys=C:\WINDOWS\system32\DRIVERS\MountMgr.sys ### Mount Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.2180 [Drivers] ftdisk.sys=C:\WINDOWS\system32\DRIVERS\ftdisk.sys ### FT Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.0 [Drivers] dmload.sys=C:\WINDOWS\system32\DRIVERS\dmload.sys ### NT Disk Manager Startup Driver Microsoft Corp., Veritas Software. Logical Disk Manager for Windows NT 1.0 [Drivers] dmio.sys=C:\WINDOWS\system32\DRIVERS\dmio.sys ### NT Disk Manager I/O Driver Microsoft Corp., Veritas Software VERITAS NT Dis k Manager 1.0 [Drivers] ACPIEC.sys=C:\WINDOWS\system32\DRIVERS\ACPIEC.sys ### ACPI Embedded Controller Driver Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.0 [Drivers] OPRGHDLR.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\OPRGHDLR.SYS ### ACPI Operation Registration Driver Microsoft Corporation Microsoft Windows O perating System 5.1.2600.0 [Drivers] PartMgr.sys=C:\WINDOWS\system32\DRIVERS\PartMgr.sys ### Partition Manager Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.0 [Drivers] VolSnap.sys=C:\WINDOWS\system32\DRIVERS\VolSnap.sys ### Volume Shadow Copy Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] atapi.sys=C:\WINDOWS\system32\DRIVERS\atapi.sys ### IDE/ATAPI Port Driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Drivers] disk.sys=C:\WINDOWS\system32\DRIVERS\disk.sys ### PnP Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180 [Drivers] CLASSPNP.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\CLASSPNP.SYS ### SCSI Class System Dll Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Drivers] fltMgr.sys=C:\WINDOWS\system32\DRIVERS\fltMgr.sys ### Microsoft Filesystem Filter Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] sr.sys=C:\WINDOWS\system32\DRIVERS\sr.sys ### System Restore Filesystem Filter Driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Drivers] KSecDD.sys=C:\WINDOWS\system32\DRIVERS\KSecDD.sys ### Kernel Security Support Provider Interface Microsoft Corporation Microsoft

Windows Operating System 5.1.2600.2180 [Drivers] Ntfs.sys=C:\WINDOWS\system32\DRIVERS\Ntfs.sys ### NT File System Driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Drivers] NDIS.sys=C:\WINDOWS\system32\DRIVERS\NDIS.sys ### NDIS 5.1 wrapper driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Drivers] Mup.sys=C:\WINDOWS\system32\DRIVERS\Mup.sys ### Multiple UNC Provider driver Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Drivers] avgrkx86.sys=C:\WINDOWS\system32\DRIVERS\avgrkx86.sys ### AVG Anti-Rootkit Driver AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1352 [Drivers] AVGIDSEH.Sys=C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys ### IDS Application Activity Monitor Helper Driver. AVG Technologies CZ, s.r.o . AVG IDS 10.1.0.1306 [Drivers] processr.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS ### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Drivers] i8042prt.sys=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS ### i8042 Port Driver Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Drivers] DKbFltr.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DKBFLTR.SYS ### Dritek PS2 Keyboard Filter Driver Dritek System Inc. Dritek Keyboard Filte r 1, 3, 0, 0 [Drivers] kbdclass.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS ### Keyboard Class Driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Drivers] mouclass.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS ### Mouse Class Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] nvsmu.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NVSMU.SYS ### NVIDIA nForce(TM) SMU Microcontroller Driver NVIDIA Corporation NVIDIA nFo rce(TM) PCA Driver 5.10.2600.0150 [Drivers] usbohci.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS ### OHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Drivers] USBPORT.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\USBPORT.SYS ### USB 1.1 & 2.0 Port Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] usbehci.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS ### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] HDAudBus.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS ### High Definition Audio Bus Driver v1.0a Windows (R) Server 2003 DDK provide r Microsoft Windows Operating System 5.10.01.5013 [Drivers] imapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS ### IMAPI Kernel Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] cdrom.sys=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS ### SCSI CD-ROM Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.3126 [Drivers] redbook.sys=C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS ### Redbook Audio Filter Driver Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Drivers] ks.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KS.SYS ### Kernel CSA Library Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.2180 [Drivers] nv4_mini.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS ### NVIDIA Compatible Windows 2000 Miniport Driver, Version 175.90 NVIDIA Cor

poration NVIDIA Compatible Windows 2000 Miniport Driver, Version 175.90 6.14.11 .7590 [Drivers] VIDEOPRT.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\VIDEOPRT.SYS ### Video Port Driver Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Drivers] CmBatt.sys=C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS ### Control Method Battery Driver Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Drivers] wmiacpi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS ### Windows Management Interface for ACPI Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Drivers] btkrnl.sys=C:\WINDOWS\SYSTEM32\DRIVERS\BTKRNL.SYS ### Bluetooth Bus Enumerator Broadcom Corporation. Bluetooth Software 5.1.0.42 00 [Drivers] avgfwdx.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVGFWDX.SYS ### AVG Firewall intermediate miniport driver AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1044 [Drivers] audstub.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS ### AudStub Driver Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.0 [Drivers] rasl2tp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS ### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.2180 [Drivers] ndistapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS ### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft Windows O perating System 5.1.2600.0 [Drivers] ndiswan.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS ### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft W indows Operating System 5.1.2600.2180 [Drivers] raspppoe.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS ### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Drivers] raspptp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS ### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Drivers] TDI.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\TDI.SYS ### TDI Wrapper Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.2180 [Drivers] psched.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS ### MS QoS Packet Scheduler Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Drivers] msgpc.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS ### MS General Packet Classifier Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Drivers] ptilink.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS ### Parallel Technologies DirectParallel IO Library Parallel Technologies, Inc . Microsoft Windows Operating System 5.1.2600.0 [Drivers] raspti.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS ### PTI DirectParallel(R) mini-port/call-manager driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] rdpdr.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS ### Microsoft RDP Device redirector Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Drivers] termdd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS ### Terminal Server Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Drivers] swenum.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS ### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft(R ) Windows(R) Operating System 5.3.2600.2180 [Drivers] update.sys=C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS

### Update Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.2180 [Drivers] mssmbios.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS ### System Management BIOS Driver Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Drivers] btport.sys=C:\WINDOWS\SYSTEM32\DRIVERS\BTPORT.SYS ### Bluetooth BTPORT Driver for Windows 2000 Broadcom Corporation. Bluetooth S oftware 5.1.0.3200 [Drivers] NDProxy.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS ### NDIS Proxy Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .0 [Drivers] usbhub.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS ### Default Hub Driver for USB Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] USBD.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\USBD.SYS ### Universal Serial Bus Driver Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.0 [Drivers] RtkHDAud.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RTKHDAUD.SYS ### Realtek(r) High Definition Audio Function Driver Realtek Semiconductor Cor p. Realtek(r) High Definition Audio Function Driver (HRTF data Copyright 1994 by MIT Media Lab) 5.10.0.5624 [Drivers] portcls.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PORTCLS.SYS ### Port Class (Class Driver for Port/Miniport Devices) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.1364 [Drivers] drmk.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DRMK.SYS ### Microsoft Kernel DRM Descrambler Filter Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Drivers] HSFHWAZL.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWAZL.SYS ### HSF_HWAZL WDM driver Conexant Systems, Inc. SoftK56 Modem Driver 7.73.00 [Drivers] HSF_DPV.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DPV.SYS ### HSF_DP driver Conexant Systems, Inc. SoftK56 Modem Driver 7.73.00 [Drivers] HSF_CNXT.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.SYS ### HSF_CNXT driver Conexant Systems, Inc. SoftK56 Modem Driver 7.73.00 [Drivers] Modem.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS ### Modem Device Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] avgmfx86.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVGMFX86.SYS ### AVG Resident Shield Minifilter Driver AVG Technologies CZ, s.r.o. AVG Inte rnet Security 10.0.0.1309 [Drivers] Fs_Rec.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\FS_REC.SYS ### File System Recognizer Driver Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.0 [Drivers] Null.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NULL.SYS ### NULL Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.0 [Drivers] Beep.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS ### BEEP Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.0 [Drivers] vga.sys=C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS ### VGA/Super VGA Video Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] mnmdd.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MNMDD.SYS ### Frame buffer simulator Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.0 [Drivers] RDPCDD.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS ### RDP Miniport Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.0 [Drivers] Msfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MSFS.SYS ### Mailslot driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180

[Drivers] Npfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NPFS.SYS ### NPFS Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.2180 [Drivers] rasacd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS ### RAS Automatic Connection Driver Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.0 [Drivers] ipsec.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS ### IPSec Driver Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.2180 [Drivers] tcpip.sys=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS ### TCP/IP Protocol Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Drivers] avgtdix.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVGTDIX.SYS ### AVG Network connection watcher AVG Technologies CZ, s.r.o. AVG Internet Se curity 10.0.0.1357 [Drivers] ipnat.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS ### IP Network Address Translator Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Drivers] wanarp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS ### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Drivers] netbt.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS ### MBT Transport driver Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Drivers] afd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS ### Ancillary Function Driver for WinSock Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Drivers] netbios.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS ### NetBIOS interface driver Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Drivers] rdbss.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS ### Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsof t Windows Operating System 5.1.2600.2180 [Drivers] mrxsmb.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS ### Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Drivers] idmtdi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IDMTDI.SYS ### Internet Download Manager TDI Driver Tonec Inc. Internet Download Manager 6.0.4.10 [Drivers] Fips.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\FIPS.SYS ### FIPS Crypto Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] avgldx86.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AVGLDX86.SYS ### AVG AVI Loader Driver AVG Technologies CZ, s.r.o. AVG Internet Security 10 .0.0.1266 [Drivers] Cdfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS ### CD-ROM File System Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] atapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DUMP_ATAPI.SYS [Drivers] WMILIB.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\DUMP_WMILIB.SYS [Drivers] win32k.sys=C:\WINDOWS\SYSTEM32\WIN32K.SYS ### Multi-User Win32 Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Drivers] watchdog.sys=C:\WINDOWS\SYSTEM32\WATCHDOG.SYS ### Watchdog Driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180 [Drivers] Dxapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXAPI.SYS ### DirectX API Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] dxg.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXG.SYS

### DirectX Graphics Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Drivers] dxgthk.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXGTHK.SYS ### DirectX Graphics Driver Thunk Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.0 [Drivers] nv4_disp.dll=C:\WINDOWS\SYSTEM32\NV4_DISP.DLL ### NVIDIA Compatible Windows 2000 Display driver, Version 175.90 NVIDIA Corp oration NVIDIA Compatible Windows 2000 Display driver, Version 175.90 6.14.11.7 590 [Drivers] ndisuio.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS ### NDIS User mode I/O Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] mrxdav.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS ### Windows NT WebDav Minirdr Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] wdmaud.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS ### MMSYSTEM Wave/Midi API mapper Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Drivers] sysaudio.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS ### System Audio WDM Filter Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Drivers] mdmxsdk.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MDMXSDK.SYS ### Diagnostic Interface x86 Driver Conexant Diagnostic Interface x86 Driver 1 .0.2.012 [Drivers] srv.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS ### Server driver Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.2180 [Drivers] HTTP.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS ### HTTP Protocol Stack Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Drivers] UnHackMeDrv.sys=C:\WINDOWS\SYSTEM32\DRIVERS\UNHACKMEDRV.SYS ### UnHackMe Kernel Driver Greatis Software, LLC. UnHackme 5.00.2195.1620 [Drivers] ALSysIO.sys=C:\DOCUME~1\HANS\LOCALS~1\TEMP\ALSYSIO.SYS [Drivers] WlanUZXP.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WLANUZXP.SYS ### ZD1211B 802.11 b+g USB LAN Driver ZyDAS Technology Corporation ZD1211B 802 .11 b+g USB LAN Adapter 1, 2, 1, 1 [Drivers] kmixer.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS ### Kernel Mode Audio Mixer Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Drivers] ntdll.dll=C:\WINDOWS\SYSTEM32\NTDLL.DLL ### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.2180 [Services detected by Partizan] :HKLM .NET CLR Data [Services detected by Partizan] :HKLM .NET CLR Networking [Services detected by Partizan] :HKLM .NET Data Provider for Oracle [Services detected by Partizan] :HKLM .NET Data Provider for SqlServer [Services detected by Partizan] :HKLM .NETFramework [Services detected by Partizan] :HKLM Abiosdsk ### Driver Start Type: disabled [Services detected by Partizan] :HKLM abp480n5 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SY S ### Driver Microsoft ACPI Driver Start Type: loaded automatically by the Boot Loader ACPI Driver for NT Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM ACPIEC=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIE C.SYS ### Driver Microsoft Embedded Controller Driver Start Type: loaded automatical ly by the Boot Loader ACPI Embedded Controller Driver Microsoft Corporation Micr

osoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM adpu160m ### Driver Start Type: disabled [Services detected by Partizan] :HKLM aec=C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS ### Driver Microsoft Kernel Acoustic Echo Canceller Start Type: loaded manuall y on demand Microsoft Acoustic Echo Canceller Microsoft Corporation Microsoft Win dows Operating System 5.1.2601.2078 [Services detected by Partizan] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS ### Driver AFD AFD Networking Support Environment Start Type: loaded automatic ally at Kernel initialization Ancillary Function Driver for WinSock Microsoft Co rporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Aha154x ### Driver Start Type: disabled [Services detected by Partizan] :HKLM aic78u2 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM aic78xx ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Alerter=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Alerter Notifies selected users and computers of administrative al erts. If the service is stopped, programs that use administrative alerts will no t receive them. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: disabled Generic Host Process for Win32 S ervices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM ALG=C:\WINDOWS\SYSTEM32\ALG.EXE ### Service Application Layer Gateway Service Provides support for 3rd party p rotocol plug-ins for Internet Connection Sharing and the Windows Firewall. Start Type: loaded manually on demand Application Layer Gateway Service Microsoft Cor poration Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM AliIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ALSysIO=\??\C:\DOCUME~1\hans\LOCALS~1\Te mp\ALSysIO.sys ### Driver ALSysIO Start Type: loaded manually on demand File is deleted or hi dden by rootkit or could not be located. [Services detected by Partizan] :HKLM amsint ### Driver Start Type: disabled [Services detected by Partizan] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Application Management Provides software installation services suc h as Assign, Publish, and Remove. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM asc ### Driver Start Type: disabled [Services detected by Partizan] :HKLM asc3350p ### Driver Start Type: disabled [Services detected by Partizan] :HKLM asc3550 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ASP.NET [Services detected by Partizan] :HKLM ASP.NET_2.0.50727 [Services detected by Partizan] :HKLM aspnet_state=C:\WINDOWS\MICROSOFT.NET\FR AMEWORK\V2.0.50727\ASPNET_STATE.EXE ### Service ASP.NET State Service Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded manually on demand Microsoft ASP.NE T State Server Microsoft Corporation Microsoft .NET Framework 2.0.50727.42 [Services detected by Partizan] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASY NCMAC.SYS ### Driver RAS Asynchronous Media Driver RAS Asynchronous Media Driver Start T ype: loaded manually on demand MS Remote Access serial network driver Microsoft

Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI. SYS ### Driver Standard IDE/ESDI Hard Disk Controller Start Type: loaded automatic ally by the Boot Loader IDE/ATAPI Port Driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Atdisk ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Atmarpc=C:\WINDOWS\SYSTEM32\DRIVERS\ATMA RPC.SYS ### Driver ATM ARP Client Protocol ATM ARP Client Protocol Start Type: loaded manually on demand IP/ATM Arp Client Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Services detected by Partizan] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Audio Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Proce ss for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180 [Services detected by Partizan] :HKLM audstub=C:\WINDOWS\SYSTEM32\DRIVERS\AUDS TUB.SYS ### Driver Audio Stub Driver Start Type: loaded manually on demand AudStub Dri ver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM Avg [Services detected by Partizan] :HKLM Avgfwdx=C:\WINDOWS\SYSTEM32\DRIVERS\AVGF WDX.SYS ### Driver Start Type: loaded manually on demand AVG Firewall intermediate min iport driver AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1044 [Services detected by Partizan] :HKLM Avgfwfd=C:\WINDOWS\SYSTEM32\DRIVERS\AVGF WDX.SYS ### Driver AVG network filter service Start Type: loaded manually on demand AV G Firewall intermediate miniport driver AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1044 [Services detected by Partizan] :HKLM avgfws=C:\PROGRAM FILES\AVG\AVG10\AVGFWS .EXE ### Service AVG Firewall AVG Firewall Service Start Type: loaded automatically by Server Manager AVG Firewall Service AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1350 [Services detected by Partizan] :HKLM AVGIDSAgent=C:\PROGRAM FILES\AVG\AVG10\I DENTITY PROTECTION\AGENT\BIN\AVGIDSAGENT.EXE ### Service AVGIDSAgent Provides Identity Protection Against Cyber Crime. Star t Type: loaded manually on demand AVG Identity Protection Service AVG Technologi es CZ, s.r.o. AVG Internet Security 10.1.0.1367 [Services detected by Partizan] :HKLM AVGIDSDriver=C:\WINDOWS\SYSTEM32\DRIVERS \AVGIDSDRIVER.SYS ### Driver AVGIDSDriver AVG Technologies IDS Application Activity Monitor Driv er Start Type: loaded manually on demand IDS Application Activity Monitor Driver . AVG Technologies CZ, s.r.o. AVG IDS 10.1.0.1365 [Services detected by Partizan] :HKLM AVGIDSEH=C:\WINDOWS\SYSTEM32\DRIVERS\AVG IDSEH.SYS ### Driver AVGIDSEH AVG Technologies IDS Application Activity Monitor Helper D river Start Type: loaded automatically by the Boot Loader IDS Application Activi ty Monitor Helper Driver. AVG Technologies CZ, s.r.o. AVG IDS 10.1.0.1306 [Services detected by Partizan] :HKLM AVGIDSFilter=C:\WINDOWS\SYSTEM32\DRIVERS \AVGIDSFILTER.SYS ### Driver AVGIDSFilter AVG Technologies IDS Application Activity Monitor Filt er Driver Start Type: loaded manually on demand IDS Application Activity Monitor Filter Driver. AVG Technologies CZ, s.r.o. AVG IDS 10.1.0.1297 [Services detected by Partizan] :HKLM AVGIDSShim=C:\WINDOWS\SYSTEM32\DRIVERS\A

VGIDSSHIM.SYS ### Driver AVGIDSShim AVG Technologies IDS Application Activity Monitor Shim L oader Driver Start Type: loaded manually on demand IDS Application Activity Moni tor Loader Driver. AVG Technologies CZ, s.r.o. AVG IDS 10.1.0.1297 [Services detected by Partizan] :HKLM Avgldx86=C:\WINDOWS\SYSTEM32\DRIVERS\AVG LDX86.SYS ### Driver AVG AVI Loader Driver Start Type: loaded automatically at Kernel in itialization AVG AVI Loader Driver AVG Technologies CZ, s.r.o. AVG Internet Secu rity 10.0.0.1266 [Services detected by Partizan] :HKLM Avgmfx86=C:\WINDOWS\SYSTEM32\DRIVERS\AVG MFX86.SYS ### Driver AVG Mini-Filter Resident Anti-Virus Shield Start Type: loaded autom atically at Kernel initialization AVG Resident Shield Minifilter Driver AVG Tech nologies CZ, s.r.o. AVG Internet Security 10.0.0.1309 [Services detected by Partizan] :HKLM Avgrkx86=C:\WINDOWS\SYSTEM32\DRIVERS\AVG RKX86.SYS ### Driver AVG Anti-Rootkit Driver Start Type: loaded automatically by the Boo t Loader AVG Anti-Rootkit Driver AVG Technologies CZ, s.r.o. AVG Internet Securi ty 10.0.0.1352 [Services detected by Partizan] :HKLM Avgtdix=C:\WINDOWS\SYSTEM32\DRIVERS\AVGT DIX.SYS ### Driver AVG TDI Driver Start Type: loaded automatically at Kernel initializ ation AVG Network connection watcher AVG Technologies CZ, s.r.o. AVG Internet Se curity 10.0.0.1357 [Services detected by Partizan] :HKLM avgwd=C:\PROGRAM FILES\AVG\AVG10\AVGWDSV C.EXE ### Service AVG WatchDog AVG Watchdog Service Start Type: loaded automatically by Server Manager AVG Watchdog Service AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1295 [Services detected by Partizan] :HKLM BattC [Services detected by Partizan] :HKLM Beep ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM BITS=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Background Intelligent Transfer Service Transfers data between cli ents and servers in the background. If BITS is disabled, features such as Window s Update will not work correctly. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Browser=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Computer Browser Maintains an updated list of computers on the net work and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is dis abled, any services that explicitly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM btaudio=C:\WINDOWS\SYSTEM32\DRIVERS\BTAU DIO.SYS ### Driver Bluetooth Audio Device Start Type: loaded manually on demand Blueto oth Audio Device Broadcom Corporation. Bluetooth Software 5.1.0.4000 [Services detected by Partizan] :HKLM BTDriver=C:\WINDOWS\SYSTEM32\DRIVERS\BTP ORT.SYS ### Driver Bluetooth Virtual Communications Driver Start Type: loaded manually on demand Bluetooth BTPORT Driver for Windows 2000 Broadcom Corporation. Blueto oth Software 5.1.0.3200 [Services detected by Partizan] :HKLM BTKRNL=C:\WINDOWS\SYSTEM32\DRIVERS\BTKRN L.SYS ### Driver Bluetooth Bus Enumerator Start Type: loaded manually on demand Blue tooth Bus Enumerator Broadcom Corporation. Bluetooth Software 5.1.0.4200 [Services detected by Partizan] :HKLM btwdins=C:\PROGRAM FILES\WIDCOMM\BLUETOO TH SOFTWARE\BIN\BTWDINS.EXE

### Service Bluetooth Service Handles installation and removal of Bluetooth de vices. Start Type: loaded automatically by Server Manager Bluetooth Support Serv er Broadcom Corporation. Bluetooth Software 5.1.0.4200 [Services detected by Partizan] :HKLM BTWDNDIS=C:\WINDOWS\SYSTEM32\DRIVERS\BTW DNDIS.SYS ### Driver Bluetooth LAN Access Server Start Type: loaded manually on demand B luetooth LAN Access Server Driver Broadcom Corporation. Bluetooth Software 5.1.0 .3500 [Services detected by Partizan] :HKLM btwhid=C:\WINDOWS\SYSTEM32\DRIVERS\BTWHI D.SYS ### Driver Start Type: loaded manually on demand Bluetooth Virtual HID Minidri ver Broadcom Corporation. Bluetooth Software 5.1.0.3300 [Services detected by Partizan] :HKLM cbidf2k ### Driver Start Type: disabled [Services detected by Partizan] :HKLM cd20xrnt ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Cdaudio ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM Cdfs ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM. SYS ### Driver CD-ROM Driver Start Type: loaded automatically at Kernel initializa tion SCSI CD-ROM Driver Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.3126 [Services detected by Partizan] :HKLM Changer ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM CiSvc=C:\WINDOWS\SYSTEM32\CISVC.EXE ### Service Indexing Service Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language. Start Type: loaded manually on demand Content Index service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM ClipSrv=C:\WINDOWS\SYSTEM32\CLIPSRV.EXE ### Service ClipBook Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be a ble to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: disabled Windows NT DDE Server Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180 [Services detected by Partizan] :HKLM clr_optimization_v2.0.50727_32=C:\WINDOW S\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE ### Service .NET Runtime Optimization Service v2.0.50727_X86 Microsoft .NET Fr amework NGEN Start Type: loaded manually on demand .NET Runtime Optimization Ser vice Microsoft Corporation Microsoft .NET Framework 2.0.50727.42 [Services detected by Partizan] :HKLM CmBatt=C:\WINDOWS\SYSTEM32\DRIVERS\CMBAT T.SYS ### Driver Microsoft ACPI Control Method Battery Driver Start Type: loaded man ually on demand Control Method Battery Driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM CmdIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Compbatt=C:\WINDOWS\SYSTEM32\DRIVERS\COM PBATT.SYS ### Driver Microsoft Composite Battery Driver Start Type: loaded automatically by the Boot Loader Composite Battery Driver Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM COMSysApp=C:\WINDOWS\SYSTEM32\DLLHOST.EX E ### Service COM+ System Application Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most

COM+-based components will not function properly. If this service is disabled, a ny services that explicitly depend on it will fail to start. Start Type: loaded manually on demand COM Surrogate Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM ContentFilter [Services detected by Partizan] :HKLM ContentIndex [Services detected by Partizan] :HKLM Cpqarray ### Driver Start Type: disabled [Services detected by Partizan] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Cryptographic Services Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Roo t Service, which adds and removes Trusted Root Certification Authority certifica tes from this computer; and Key Service, which helps enroll this computer for ce rtificates. If this service is stopped, these management services will not funct ion properly. If this service is disabled, any services that explicitly depend o n it will fail to start. Start Type: loaded automatically by Server Manager Gene ric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Services detected by Partizan] :HKLM dac2w2k ### Driver Start Type: disabled [Services detected by Partizan] :HKLM dac960nt ### Driver Start Type: disabled [Services detected by Partizan] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\SVCHOST.e xe ### Service DCOM Server Process Launcher Provides launch functionality for DCO M services. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Services detected by Partizan] :HKLM Dhcp=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service DHCP Client Manages network configuration by registering and updat ing IP addresses and DNS names. Start Type: loaded automatically by Server Manag er Generic Host Process for Win32 Services Microsoft Corporation Microsoft Window s Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SY S ### Driver Disk Driver Start Type: loaded automatically by the Boot Loader PnP Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.218 0 [Services detected by Partizan] :HKLM DKbFltr=C:\WINDOWS\SYSTEM32\DRIVERS\DKBF LTR.SYS ### Driver Dritek Keyboard Filter Driver Start Type: loaded manually on demand Dritek PS2 Keyboard Filter Driver Dritek System Inc. Dritek Keyboard Filter 1, 3, 0, 0 [Services detected by Partizan] :HKLM dmadmin=C:\WINDOWS\SYSTEM32\DMADMIN.EXE ### Service Logical Disk Manager Administrative Service Configures hard disk d rives and volumes. The service only runs for configuration processes and then st ops. Start Type: loaded manually on demand Logical Disk Manager service process Microsoft Corp., Veritas Software Logical Disk Manager for Windows NT 1.0 [Services detected by Partizan] :HKLM dmboot=C:\WINDOWS\SYSTEM32\DRIVERS\DMBOO T.SYS ### Driver Start Type: disabled NT Disk Manager Startup Driver Microsoft Corp. , Veritas Software VERITAS NT Disk Manager 1.0 [Services detected by Partizan] :HKLM dmio=C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SY S ### Driver Logical Disk Manager Driver Start Type: loaded automatically by the Boot Loader NT Disk Manager I/O Driver Microsoft Corp., Veritas Software VERITA S NT Disk Manager 1.0 [Services detected by Partizan] :HKLM dmload=C:\WINDOWS\SYSTEM32\DRIVERS\DMLOA D.SYS ### Driver Start Type: loaded automatically by the Boot Loader NT Disk Manager

Startup Driver Microsoft Corp., Veritas Software. Logical Disk Manager for Wind ows NT 1.0 [Services detected by Partizan] :HKLM dmserver=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Logical Disk Manager Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service fo r configuration. If this service is stopped, dynamic disk status and configurati on information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded automatical ly by Server Manager Generic Host Process for Win32 Services Microsoft Corporati on Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM DMusic=C:\WINDOWS\SYSTEM32\DRIVERS\DMUSI C.SYS ### Driver Microsoft Kernel DLS Syntheiszer Start Type: loaded manually on dem and Microsoft Kernel DLS Synthesizer Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Services detected by Partizan] :HKLM Dnscache=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service DNS Client Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to res olve DNS names and locate Active Directory domain controllers. If this service i s disabled, any services that explicitly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Serv ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM dpti2o ### Driver Start Type: disabled [Services detected by Partizan] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMK AUD.SYS ### Driver Microsoft Kernel DRM Audio Descrambler Start Type: loaded manually on demand Microsoft Kernel DRM Audio Descrambler Filter Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM ERSvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Error Reporting Service Allows error reporting for services and ap plictions running in non-standard environments. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Eventlog=C:\WINDOWS\SYSTEM32\SERVICES.EX E ### Service Event Log Enables event log messages issued by Windows-based progr ams and components to be viewed in Event Viewer. This service cannot be stopped. Start Type: loaded automatically by Server Manager Services and Controller app Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\SVCHOST. EXE ### Service COM+ Event System Supports System Event Notification Service (SENS ), which provides automatic distribution of events to subscribing Component Obje ct Model (COM) components. If the service is stopped, SENS will close and will n ot be able to provide logon and logoff notifications. If this service is disable d, any services that explicitly depend on it will fail to start. Start Type: loa ded manually on demand Generic Host Process for Win32 Services Microsoft Corpora tion Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Fastfat ### Driver Start Type: disabled [Services detected by Partizan] :HKLM FastUserSwitchingCompatibility=C:\WINDOW S\SYSTEM32\SVCHOST.EXE ### Service Fast User Switching Compatibility Provides management for applicat ions that require assistance in a multiple user environment. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Fdc ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM Fips

### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM FLEXnet Licensing Service=C:\PROGRAM FIL ES\COMMON FILES\MACROVISION SHARED\FLEXNET PUBLISHER\FNPLICENSINGSERVICE.EXE ### Service FLEXnet Licensing Service This service performs licensing function s on behalf of FLEXnet enabled products. Start Type: disabled Activation Licensi ng Service Acresso Software Inc. FLEXnet Publisher (32 bit) [Services detected by Partizan] :HKLM Flpydisk ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMG R.SYS ### Driver FltMgr File System Filter Manager Driver Start Type: loaded automat ically by the Boot Loader Microsoft Filesystem Filter Manager Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Fs_Rec ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM Ftdisk=C:\WINDOWS\SYSTEM32\DRIVERS\FTDIS K.SYS ### Driver Volume Manager Driver Start Type: loaded automatically by the Boot Loader FT Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.0 [Services detected by Partizan] :HKLM Gpc=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SY S ### Driver Generic Packet Classifier Generic Packet Classifier Start Type: loa ded manually on demand MS General Packet Classifier Microsoft Corporation Micros oft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM gusvc=C:\PROGRAM FILES\GOOGLE\COMMON\GOO GLE UPDATER\GOOGLEUPDATERSERVICE.EXE ### Service Google Updater Service Start Type: loaded manually on demand gusvc Google Google Updater 2.0.711.37800.beta [Services detected by Partizan] :HKLM HDAudBus=C:\WINDOWS\SYSTEM32\DRIVERS\HDA UDBUS.SYS ### Driver Microsoft UAA Bus Driver for High Definition Audio Start Type: load ed manually on demand High Definition Audio Bus Driver v1.0a Windows (R) Server 2003 DDK provider Microsoft Windows Operating System 5.10.01.5013 [Services detected by Partizan] :HKLM helpsvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Help and Support Enables Help and Support Center to run on this co mputer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fai l to start. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Services detected by Partizan] :HKLM HidServ=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service HID Input Service Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons o n keyboards, remote controls, and other multimedia devices. If this service is s topped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to star t. Start Type: loaded automatically by Server Manager Generic Host Process for W in32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.21 80 [Services detected by Partizan] :HKLM HidUsb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUS B.SYS ### Driver Microsoft HID Class Driver Start Type: loaded manually on demand US B Miniport Driver for Input Devices Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.0 [Services detected by Partizan] :HKLM hpn ### Driver Start Type: disabled [Services detected by Partizan] :HKLM HSFHWAZL=C:\WINDOWS\SYSTEM32\DRIVERS\HSF HWAZL.SYS ### Driver Start Type: loaded manually on demand HSF_HWAZL WDM driver Conexant

Systems, Inc. SoftK56 Modem Driver 7.73.00 [Services detected by Partizan] :HKLM HSF_DPV=C:\WINDOWS\SYSTEM32\DRIVERS\HSF_ DPV.SYS ### Driver Start Type: loaded manually on demand HSF_DP driver Conexant System s, Inc. SoftK56 Modem Driver 7.73.00 [Services detected by Partizan] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SY S ### Driver HTTP This service implements the hypertext transfer protocol (HTTP) . If this service is disabled, any services that explicitly depend on it will fa il to start. Start Type: loaded manually on demand HTTP Protocol Stack Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM HTTPFilter=C:\WINDOWS\SYSTEM32\SVCHOST.E XE ### Service HTTP SSL This service implements the secure hypertext transfer pro tocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If th is service is disabled, any services that explicitly depend on it will fail to s tart. Start Type: loaded manually on demand Generic Host Process for Win32 Servi ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM i2omgmt ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM i2omp ### Driver Start Type: disabled [Services detected by Partizan] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I80 42PRT.SYS ### Driver i8042 Keyboard and PS/2 Mouse Port Driver Start Type: loaded automa tically at Kernel initialization i8042 Port Driver Microsoft Corporation Microso ft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM IDMTDI=C:\WINDOWS\SYSTEM32\DRIVERS\IDMTD I.SYS ### Driver IDMTDI Internet Download Manager TDI Driver Start Type: loaded auto matically at Kernel initialization Internet Download Manager TDI Driver Tonec In c. Internet Download Manager 6.0.4.10 [Services detected by Partizan] :HKLM Imapi=C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI. SYS ### Driver CD-Burning Filter Driver Start Type: loaded automatically at Kernel initialization IMAPI Kernel Driver Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Services detected by Partizan] :HKLM ImapiService=C:\WINDOWS\SYSTEM32\IMAPI.E XE ### Service IMAPI CD-Burning COM Service Manages CD recording using Image Mast ering Applications Programming Interface (IMAPI). If this service is stopped, th is computer will be unable to record CDs. If this service is disabled, any servi ces that explicitly depend on it will fail to start. Start Type: loaded manually on demand Image Mastering API Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Services detected by Partizan] :HKLM inetaccs [Services detected by Partizan] :HKLM ini910u ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Inport [Services detected by Partizan] :HKLM IntcAzAudAddService=C:\WINDOWS\SYSTEM32\ DRIVERS\RTKHDAUD.SYS ### Driver Service for Realtek HD Audio (WDM) Start Type: loaded manually on d emand Realtek(r) High Definition Audio Function Driver Realtek Semiconductor Cor p. Realtek(r) High Definition Audio Function Driver (HRTF data Copyright 1994 by MIT Media Lab) 5.10.0.5624 [Services detected by Partizan] :HKLM IntelIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Ip6Fw=C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW. SYS ### Driver IPv6 Windows Firewall Driver Provides intrusion prevention service

for a home or small office network. Start Type: loaded manually on demand IPv6 W indows Firewall Driver Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Services detected by Partizan] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVE RS\IPFLTDRV.SYS ### Driver IP Traffic Filter Driver IP Traffic Filter Driver Start Type: loade d manually on demand IP FILTER DRIVER Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.0 [Services detected by Partizan] :HKLM IpInIp=C:\WINDOWS\SYSTEM32\DRIVERS\IPINI P.SYS ### Driver IP in IP Tunnel Driver IP in IP Tunnel Driver Start Type: loaded ma nually on demand IP in IP Encapsulation Driver Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM IpNat=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT. SYS ### Driver IP Network Address Translator IP Network Address Translator Start T ype: loaded manually on demand IP Network Address Translator Microsoft Corporati on Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM IPSec=C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC. SYS ### Driver IPSEC driver IPSEC driver Start Type: loaded automatically at Kerne l initialization IPSec Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Services detected by Partizan] :HKLM IRENUM=C:\WINDOWS\SYSTEM32\DRIVERS\IRENU M.SYS ### Driver IR Enumerator Service Start Type: loaded manually on demand Infra-R ed Bus Enumerator Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.2180 [Services detected by Partizan] :HKLM ISAPISearch [Services detected by Partizan] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPN P.SYS ### Driver PnP ISA/EISA Bus Driver Start Type: loaded automatically by the Boo t Loader PNP ISA Bus Driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.0 [Services detected by Partizan] :HKLM JavaQuickStarterService=C:\PROGRAM FILES \JAVA\JRE6\BIN\JQS.EXE ### Service Java Quick Starter Prefetches JRE files for faster startup of Java applets and applications Start Type: loaded automatically by Server Manager Jav a(TM) Quick Starter Service Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6. 0.250.6 [Services detected by Partizan] :HKLM Kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBD CLASS.SYS ### Driver Keyboard Class Driver Start Type: loaded automatically at Kernel in itialization Keyboard Class Driver Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Services detected by Partizan] :HKLM kmixer=C:\WINDOWS\SYSTEM32\DRIVERS\KMIXE R.SYS ### Driver Microsoft Kernel Wave Audio Mixer Start Type: loaded manually on de mand Kernel Mode Audio Mixer Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Services detected by Partizan] :HKLM KSecDD ### Driver Start Type: loaded automatically by the Boot Loader [Services detected by Partizan] :HKLM lanmanserver=C:\WINDOWS\SYSTEM32\SVCHOST .EXE ### Service Server Supports file, print, and named-pipe sharing over the netwo rk for this computer. If this service is stopped, these functions will be unavai lable. If this service is disabled, any services that explicitly depend on it wi ll fail to start. Start Type: loaded automatically by Server Manager Generic Hos t Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180

[Services detected by Partizan] :HKLM lanmanworkstation=C:\WINDOWS\SYSTEM32\SV CHOST.EXE ### Service Workstation Creates and maintains client network connections to re mote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fai l to start. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Services detected by Partizan] :HKLM lbrtfdc ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM ldap [Services detected by Partizan] :HKLM LicenseService [Services detected by Partizan] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service TCP/IP NetBIOS Helper Enables support for NetBIOS over TCP/IP (Net BT) service and NetBIOS name resolution. Start Type: loaded automatically by Ser ver Manager Generic Host Process for Win32 Services Microsoft Corporation Micros oft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM mdmxsdk=C:\WINDOWS\SYSTEM32\DRIVERS\MDMX SDK.SYS ### Driver Start Type: loaded automatically by Server Manager Diagnostic Inter face x86 Driver Conexant Diagnostic Interface x86 Driver 1.0.2.012 [Services detected by Partizan] :HKLM Messenger=C:\WINDOWS\SYSTEM32\SVCHOST.EX E ### Service Messenger Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this s ervice is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start. Start Ty pe: disabled Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Microsoft Office Groove Audit Service=C: \PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVEAUDITSERVICE.EXE ### Service Microsoft Office Groove Audit Service Start Type: loaded manually on demand Groove Audit Service Microsoft Corporation Groove Audit Service 4.2.0. 2623 [Services detected by Partizan] :HKLM mnmdd ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM mnmsrvc=C:\WINDOWS\SYSTEM32\MNMSRVC.EXE ### Service NetMeeting Remote Desktop Sharing Enables an authorized user to ac cess this computer remotely by using NetMeeting over a corporate intranet. If th is service is stopped, remote desktop sharing will be unavailable. If this servi ce is disabled, any services that explicitly depend on it will fail to start. St art Type: loaded manually on demand NetMeeting Remote Desktop Sharing Microsoft Corporation Windows NetMeeting 3.01 [Services detected by Partizan] :HKLM Modem ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM Mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOU CLASS.SYS ### Driver Mouse Class Driver Start Type: loaded automatically at Kernel initi alization Mouse Class Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Services detected by Partizan] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHI D.SYS ### Driver Mouse HID Driver Start Type: loaded manually on demand HID Mouse Fi lter Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM MountMgr ### Driver Start Type: loaded automatically by the Boot Loader [Services detected by Partizan] :HKLM mraid35x ### Driver Start Type: disabled [Services detected by Partizan] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDA V.SYS

### Driver WebDav Client Redirector WebDav Client Redirector Start Type: loade d manually on demand Windows NT WebDav Minirdr Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM MRxSmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSM B.SYS ### Driver MRXSMB MRXSMB Start Type: loaded automatically at Kernel initializa tion Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Services detected by Partizan] :HKLM MSDTC=C:\WINDOWS\SYSTEM32\MSDTC.EXE ### Service Distributed Transaction Coordinator Coordinates transactions that span multiple resource managers, such as databases, message queues, and file sys tems. If this service is stopped, these transactions will not occur. If this ser vice is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded manually on demand MS DTC console program Microsoft Corporat ion Microsoft Distributed Transaction Coordinator 03.01.00.4414 [Services detected by Partizan] :HKLM Msfs ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM MSIServer=C:\WINDOWS\SYSTEM32\MSIEXEC.EX E ### Service Windows Installer Adds, modifies, and removes applications provide d as a Windows Installer (*.msi) package. If this service is disabled, any servi ces that explicitly depend on it will fail to start. Start Type: loaded manually on demand Windows installer Microsoft Corporation Windows Installer - Unicode 3. 1.4000.1823 [Services detected by Partizan] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKS SRV.SYS ### Driver Microsoft Streaming Service Proxy Start Type: loaded manually on de mand MS KS Server Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.2180 [Services detected by Partizan] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSP CLOCK.SYS ### Driver Microsoft Streaming Clock Proxy Start Type: loaded manually on dema nd MS Proxy Clock Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.2180 [Services detected by Partizan] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM. SYS ### Driver Microsoft Streaming Quality Manager Proxy Start Type: loaded manual ly on demand MS Proxy Quality Manager Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Services detected by Partizan] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSS MBIOS.SYS ### Driver Microsoft System Management BIOS Driver Start Type: loaded manually on demand System Management BIOS Driver Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Mup ### Driver Mup Start Type: loaded automatically by the Boot Loader [Services detected by Partizan] :HKLM NDIS ### Driver NDIS System Driver Start Type: loaded automatically by the Boot Loa der [Services detected by Partizan] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDI STAPI.SYS ### Driver Remote Access NDIS TAPI Driver Remote Access NDIS TAPI Driver Start Type: loaded manually on demand NDIS 3.0 connection wrapper driver Microsoft Co rporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS UIO.SYS ### Driver NDIS Usermode I/O Protocol NDIS Usermode I/O Protocol Start Type: l oaded manually on demand NDIS User mode I/O Driver Microsoft Corporation Microso ft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS

WAN.SYS ### Driver Remote Access NDIS WAN Driver Remote Access NDIS WAN Driver Start T ype: loaded manually on demand MS PPP Framing Driver (Strong Encryption) Microso ft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM NDProxy [Services detected by Partizan] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETB IOS.SYS ### Driver NetBIOS Interface NetBIOS Interface Start Type: loaded automaticall y at Kernel initialization NetBIOS interface driver Microsoft Corporation Micros oft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT. SYS ### Driver NetBios over Tcpip NetBios over Tcpip Start Type: loaded automatica lly at Kernel initialization MBT Transport driver Microsoft Corporation Microsof t Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM NetDDE=C:\WINDOWS\SYSTEM32\NETDDE.EXE ### Service Network DDE Provides network transport and security for Dynamic Da ta Exchange (DDE) for programs running on the same computer or on different comp uters. If this service is stopped, DDE transport and security will be unavailabl e. If this service is disabled, any services that explicitly depend on it will f ail to start. Start Type: disabled Network DDE - DDE Communication Microsoft Cor poration Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM NetDDEdsdm=C:\WINDOWS\SYSTEM32\NETDDE.EX E ### Service Network DDE DSDM Manages Dynamic Data Exchange (DDE) network share s. If this service is stopped, DDE network shares will be unavailable. If this s ervice is disabled, any services that explicitly depend on it will fail to start . Start Type: disabled Network DDE - DDE Communication Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Netlogon=C:\WINDOWS\SYSTEM32\LSASS.EXE ### Service Net Logon Supports pass-through authentication of account logon ev ents for computers in a domain. Start Type: loaded manually on demand LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .2180 [Services detected by Partizan] :HKLM Netman=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Network Connections Manages objects in the Network and Dial-Up Con nections folder, in which you can view both local area network and remote connec tions. Start Type: loaded manually on demand Generic Host Process for Win32 Serv ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Nla=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Network Location Awareness (NLA) Collects and stores network confi guration and location information, and notifies applications when this informati on changes. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Npfs ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM Ntfs ### Driver Start Type: disabled [Services detected by Partizan] :HKLM NtLmSsp=C:\WINDOWS\SYSTEM32\LSASS.EXE ### Service NT LM Security Support Provider Provides security to remote proced ure call (RPC) programs that use transports other than named pipes. Start Type: loaded manually on demand LSA Shell (Export Version) Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM NtmsSvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Removable Storage Start Type: loaded manually on demand Generic Ho st Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Services detected by Partizan] :HKLM Null ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM nv=C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.

SYS ### Driver Start Type: loaded manually on demand NVIDIA Compatible Windows 200 0 Miniport Driver, Version 175.90 NVIDIA Corporation NVIDIA Compatible Windows 2000 Miniport Driver, Version 175.90 6.14.11.7590 [Services detected by Partizan] :HKLM nvsmu=C:\WINDOWS\SYSTEM32\DRIVERS\NVSMU. SYS ### Driver Start Type: loaded manually on demand NVIDIA nForce(TM) SMU Microco ntroller Driver NVIDIA Corporation NVIDIA nForce(TM) PCA Driver 5.10.2600.0150 [Services detected by Partizan] :HKLM NVSvc=C:\WINDOWS\SYSTEM32\NVSVC32.EXE ### Service NVIDIA Display Driver Service Provides system and desktop level su pport to the NVIDIA display driver Start Type: loaded automatically by Server Ma nager NVIDIA Driver Helper Service, Version 175.90 NVIDIA Corporation NVIDIA Dri ver Helper Service, Version 175.90 6.14.11.7590 [Services detected by Partizan] :HKLM NwlnkFlt=C:\WINDOWS\SYSTEM32\DRIVERS\NWL NKFLT.SYS ### Driver IPX Traffic Filter Driver IPX Traffic Filter Driver Start Type: loa ded manually on demand NWLINK2 Traffic Filter Driver Microsoft Corporation Micro soft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM NwlnkFwd=C:\WINDOWS\SYSTEM32\DRIVERS\NWL NKFWD.SYS ### Driver IPX Traffic Forwarder Driver IPX Traffic Forwarder Driver Start Typ e: loaded manually on demand NWLINK2 Forwarder Driver Microsoft Corporation Micr osoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM odserv=C:\PROGRAM FILES\COMMON FILES\MIC ROSOFT SHARED\OFFICE12\ODSERV.EXE ### Service Microsoft Office Diagnostics Service Run portions of Microsoft Off ice Diagnostics. Start Type: loaded manually on demand Microsoft Office Diagnost ics Microsoft Corporation Office Diagnostics Service 12.0.4518.1014 [Services detected by Partizan] :HKLM ose=C:\PROGRAM FILES\COMMON FILES\MICROS OFT SHARED\SOURCE ENGINE\OSE.EXE ### Service Office Source Engine Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error r eports. Start Type: loaded manually on demand Office Source Engine Microsoft Cor poration Office Source Engine 12.0.4518.1014 [Services detected by Partizan] :HKLM Outlook [Services detected by Partizan] :HKLM Parport ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM Partizan=C:\WINDOWS\SYSTEM32\DRIVERS\PAR TIZAN.SYS ### Driver Partizan Start Type: loaded automatically by the Boot Loader Partiz an - Rootkit detector Greatis Software RegRun Security Suite 6, 8, 0, 0 [Services detected by Partizan] :HKLM PartMgr ### Driver Start Type: loaded automatically by the Boot Loader [Services detected by Partizan] :HKLM ParVdm ### Driver Start Type: loaded automatically by Server Manager [Services detected by Partizan] :HKLM pccsmcfd=C:\WINDOWS\SYSTEM32\DRIVERS\PCC SMCFD.SYS ### Driver PCCS Mode Change Filter Driver Start Type: loaded manually on deman d PCCS Mode Change Filter Driver Nokia [Services detected by Partizan] :HKLM PCI=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS ### Driver PCI Bus Driver Start Type: loaded automatically by the Boot Loader NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM PCIDump ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM PCIIde=C:\WINDOWS\SYSTEM32\DRIVERS\PCIID E.SYS ### Driver Start Type: loaded automatically by the Boot Loader Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM Pcmcia

### Driver Start Type: disabled [Services detected by Partizan] :HKLM PDCOMP ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM PDFRAME ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM PDRELI ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM PDRFRAME ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM perc2 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM perc2hib ### Driver Start Type: disabled [Services detected by Partizan] :HKLM PerfDisk [Services detected by Partizan] :HKLM PerfNet [Services detected by Partizan] :HKLM PerfOS [Services detected by Partizan] :HKLM PerfProc [Services detected by Partizan] :HKLM PlugPlay=C:\WINDOWS\SYSTEM32\SERVICES.EX E ### Service Plug and Play Enables a computer to recognize and adapt to hardwar e changes with little or no user input. Stopping or disabling this service will result in system instability. Start Type: loaded automatically by Server Manager Services and Controller app Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Services detected by Partizan] :HKLM PolicyAgent=C:\WINDOWS\SYSTEM32\LSASS.EX E ### Service IPSEC Services Manages IP security policy and starts the ISAKMP/Oa kley (IKE) and the IP security driver. Start Type: loaded automatically by Serve r Manager LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Services detected by Partizan] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS \RASPPTP.SYS ### Driver WAN Miniport (PPTP) WAN Miniport (PPTP) Start Type: loaded manually on demand Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Window s Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Processor=C:\WINDOWS\SYSTEM32\DRIVERS\PR OCESSR.SYS ### Driver Processor Driver Start Type: loaded automatically at Kernel initial ization Processor Device Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM ProtectedStorage=C:\WINDOWS\SYSTEM32\LSA SS.EXE ### Service Protected Storage Provides protected storage for sensitive data, s uch as private keys, to prevent access by unauthorized services, processes, or u sers. Start Type: loaded automatically by Server Manager LSA Shell (Export Versi on) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM PSched=C:\WINDOWS\SYSTEM32\DRIVERS\PSCHE D.SYS ### Driver QoS Packet Scheduler QoS Packet Scheduler Start Type: loaded manual ly on demand MS QoS Packet Scheduler Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Services detected by Partizan] :HKLM Ptilink=C:\WINDOWS\SYSTEM32\DRIVERS\PTIL INK.SYS ### Driver Direct Parallel Link Driver Direct Parallel Link Driver Start Type: loaded manually on demand Parallel Technologies DirectParallel IO Library Paral lel Technologies, Inc. Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM ql1080 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Ql10wnt ### Driver Start Type: disabled

[Services detected by Partizan] :HKLM ql12160 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ql1240 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ql1280 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASAC D.SYS ### Driver Remote Access Auto Connection Driver Remote Access Auto Connection Driver Start Type: loaded automatically at Kernel initialization RAS Automatic C onnection Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .0 [Services detected by Partizan] :HKLM RasAuto=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Remote Access Auto Connection Manager Creates a connection to a re mote network whenever a program references a remote DNS or NetBIOS name or addre ss. Start Type: loaded manually on demand Generic Host Process for Win32 Service s Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL 2TP.SYS ### Driver WAN Miniport (L2TP) WAN Miniport (L2TP) Start Type: loaded manually on demand RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsof t Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM RasMan=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Remote Access Connection Manager Creates a network connection. Sta rt Type: loaded manually on demand Generic Host Process for Win32 Services Micro soft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RAS PPPOE.SYS ### Driver Remote Access PPPOE Driver Remote Access PPPOE Driver Start Type: l oaded manually on demand RAS PPPoE mini-port/call-manager driver Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Raspti=C:\WINDOWS\SYSTEM32\DRIVERS\RASPT I.SYS ### Driver Direct Parallel Direct Parallel Start Type: loaded manually on dema nd PTI DirectParallel(R) mini-port/call-manager driver Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM Rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS. SYS ### Driver Rdbss Rdbss Start Type: loaded automatically at Kernel initializati on Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM RDPCDD=C:\WINDOWS\SYSTEM32\DRIVERS\RDPCD D.SYS ### Driver Start Type: loaded automatically at Kernel initialization RDP Minip ort Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM RDPDD [Services detected by Partizan] :HKLM rdpdr=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR. SYS ### Driver Terminal Server Device Redirector Driver Start Type: loaded manuall y on demand Microsoft RDP Device redirector Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM RDPNP [Services detected by Partizan] :HKLM RDPWD ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM RDSessMgr=C:\WINDOWS\SYSTEM32\SESSMGR.EX E ### Service Remote Desktop Help Session Manager Manages and controls Remote As sistance. If this service is stopped, Remote Assistance will be unavailable. Bef ore stopping this service, see the Dependencies tab of the Properties dialog box . Start Type: loaded manually on demand Microsoft Remote Desktop Help Session Man

ager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM redbook=C:\WINDOWS\SYSTEM32\DRIVERS\REDB OOK.SYS ### Driver Digital CD Audio Playback Filter Driver Start Type: loaded automati cally at Kernel initialization Redbook Audio Filter Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM RegGuard=C:\WINDOWS\SYSTEM32\DRIVERS\REG GUARD.SYS ### Driver RegGuard Start Type: loaded manually on demand Registry Guard - reg istry keys protection driver for Windows NT/2000/XP/2003/Vista/Windows7 Greatis Software RegRun Security Suite 6.50 [Services detected by Partizan] :HKLM RemoteAccess=C:\WINDOWS\SYSTEM32\SVCHOST .EXE ### Service Routing and Remote Access Offers routing services to businesses in local area and wide area network environments. Start Type: disabled Generic Hos t Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Services detected by Partizan] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\SVCHO ST.EXE ### Service Remote Registry Enables remote users to modify registry settings o n this computer. If this service is stopped, the registry can be modified only b y users on this computer. If this service is disabled, any services that explici tly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft W indows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM RpcLocator=C:\WINDOWS\SYSTEM32\LOCATOR.E XE ### Service Remote Procedure Call (RPC) Locator Manages the RPC name service d atabase. Start Type: loaded manually on demand Rpc Locator Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\SVCHOST.exe ### Service Remote Procedure Call (RPC) Provides the endpoint mapper and other miscellaneous RPC services. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.2180 [Services detected by Partizan] :HKLM RSUSBSTOR=System32\Drivers\RTS5121.sys ### Driver RTS5121.Sys Realtek USB Card Reader Start Type: loaded manually on demand File is deleted or hidden by rootkit or could not be located. [Services detected by Partizan] :HKLM RSVP=C:\WINDOWS\SYSTEM32\RSVP.EXE ### Service QoS RSVP Provides network signaling and local traffic control setu p functionality for QoS-aware programs and control applets. Start Type: loaded m anually on demand Microsoft RSVP Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM SamSs=C:\WINDOWS\SYSTEM32\LSASS.EXE ### Service Security Accounts Manager Stores security information for local us er accounts. Start Type: loaded automatically by Server Manager LSA Shell (Expor t Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM SCardSvr=C:\WINDOWS\SYSTEM32\SCARDSVR.EX E ### Service Smart Card Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If t his service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded manually on demand Smart Card Resource Management Serv er Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Schedule=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Task Scheduler Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explici tly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft W

indows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Secdrv=C:\WINDOWS\SYSTEM32\DRIVERS\SECDR V.SYS ### Driver Secdrv SafeDisc driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM seclogon=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Secondary Logon Enables starting processes under alternate credent ials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fai l to start. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Services detected by Partizan] :HKLM SENS=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service System Event Notification Tracks system events such as Windows log on, network, and power events. Notifies COM+ Event System subscribers of these events. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.2180 [Services detected by Partizan] :HKLM Serial ### Driver Start Type: loaded automatically by Server Manager [Services detected by Partizan] :HKLM ServiceLayer=C:\PROGRAM FILES\PC CONNECT IVITY SOLUTION\SERVICELAYER.EXE ### Service ServiceLayer Start Type: loaded manually on demand ServiceLayer Mo dule Nokia PC Connectivity Solution 3.12 [Services detected by Partizan] :HKLM Sfloppy ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM SharedAccess=C:\WINDOWS\SYSTEM32\SVCHOST .EXE ### Service Windows Firewall/Internet Connection Sharing (ICS) Provides networ k address translation, addressing, name resolution and/or intrusion prevention s ervices for a home or small office network. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SVC HOST.EXE ### Service Shell Hardware Detection Provides notifications for AutoPlay hardw are events. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Services detected by Partizan] :HKLM Simbad ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Sparrow ### Driver Start Type: disabled [Services detected by Partizan] :HKLM splitter=C:\WINDOWS\SYSTEM32\DRIVERS\SPL ITTER.SYS ### Driver Microsoft Kernel Audio Splitter Start Type: loaded manually on dema nd Microsoft Kernel Audio Splitter Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Services detected by Partizan] :HKLM Spooler=C:\WINDOWS\SYSTEM32\SPOOLSV.EXE ### Service Print Spooler Loads files to memory for later printing. Start Type : loaded automatically by Server Manager Spooler SubSystem App Microsoft Corpora tion Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM sr=C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS ### Driver System Restore Filter Driver Start Type: loaded automatically by th e Boot Loader System Restore Filesystem Filter Driver Microsoft Corporation Micr osoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM srservice=C:\WINDOWS\SYSTEM32\SVCHOST.EX E ### Service System Restore Service Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Pro perties Start Type: loaded automatically by Server Manager Generic Host Process

for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.2180 [Services detected by Partizan] :HKLM Srv=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS ### Driver Srv Srv Start Type: loaded manually on demand Server driver Microso ft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service SSDP Discovery Service Enables discovery of UPnP devices on your h ome network. Start Type: loaded manually on demand Generic Host Process for Win3 2 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM stisvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Image Acquisition (WIA) Provides image acquisition service s for scanners and cameras. Start Type: loaded manually on demand Generic Host P rocess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM swenum=C:\WINDOWS\SYSTEM32\DRIVERS\SWENU M.SYS ### Driver Software Bus Driver Start Type: loaded manually on demand Plug and Play Software Device Enumerator Microsoft Corporation Microsoft(R) Windows(R) Op erating System 5.3.2600.2180 [Services detected by Partizan] :HKLM swmidi=C:\WINDOWS\SYSTEM32\DRIVERS\SWMID I.SYS ### Driver Microsoft Kernel GS Wavetable Synthesizer Start Type: loaded manual ly on demand Microsoft GS Wavetable Synthesizer Microsoft Corporation Microsoft W indows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM SwPrv=C:\WINDOWS\SYSTEM32\DLLHOST.EXE ### Service MS Software Shadow Copy Provider Manages software-based volume sha dow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabl ed, any services that explicitly depend on it will fail to start. Start Type: lo aded manually on demand COM Surrogate Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Services detected by Partizan] :HKLM symc810 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM symc8xx ### Driver Start Type: disabled [Services detected by Partizan] :HKLM sym_hi ### Driver Start Type: disabled [Services detected by Partizan] :HKLM sym_u3 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM sysaudio=C:\WINDOWS\SYSTEM32\DRIVERS\SYS AUDIO.SYS ### Driver Microsoft Kernel System Audio Device Start Type: loaded manually on demand System Audio WDM Filter Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM SysmonLog=C:\WINDOWS\SYSTEM32\SMLOGSVC.E XE ### Service Performance Logs and Alerts Collects performance data from local o r remote computers based on preconfigured schedule parameters, then writes the d ata to a log or triggers an alert. If this service is stopped, performance infor mation will not be collected. If this service is disabled, any services that exp licitly depend on it will fail to start. Start Type: loaded manually on demand P erformance Logs and Alerts Service Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Services detected by Partizan] :HKLM TapiSrv=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Telephony Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer a nd, through the LAN, on servers that are also running the service. Start Type: l oaded manually on demand Generic Host Process for Win32 Services Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.

SYS ### Driver TCP/IP Protocol Driver TCP/IP Protocol Driver Start Type: loaded au tomatically at Kernel initialization TCP/IP Protocol Driver Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM TDPIPE ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM TDTCP ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM TermDD=C:\WINDOWS\SYSTEM32\DRIVERS\TERMD D.SYS ### Driver Terminal Device Driver Start Type: loaded automatically at Kernel i nitialization Terminal Server Driver Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Services detected by Partizan] :HKLM TermService=C:\WINDOWS\SYSTEM32\SVCHOST. exe ### Service Terminal Services Allows multiple users to be connected interactiv ely to a machine as well as the display of desktops and applications to remote c omputers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Themes=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Themes Provides user experience theme management. Start Type: load ed automatically by Server Manager Generic Host Process for Win32 Services Micro soft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM TlntSvr=C:\WINDOWS\SYSTEM32\TLNTSVR.EXE ### Service Telnet Enables a remote user to log on to this computer and run pr ograms, and supports various TCP/IP Telnet clients, including UNIX-based and Win dows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: disabled Telnet Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM TosIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Distributed Link Tracking Client Maintains links between NTFS file s within a computer or across computers in a network domain. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsof t Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM TSDDD [Services detected by Partizan] :HKLM Udfs ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ultra ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Update=C:\WINDOWS\SYSTEM32\DRIVERS\UPDAT E.SYS ### Driver Microcode Update Driver Start Type: loaded manually on demand Updat e Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM upnphost=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Universal Plug and Play Device Host Provides support to host Unive rsal Plug and Play devices. Start Type: loaded manually on demand Generic Host P rocess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM UPS=C:\WINDOWS\SYSTEM32\UPS.EXE ### Service Uninterruptible Power Supply Manages an uninterruptible power supp ly (UPS) connected to the computer. Start Type: loaded manually on demand UPS Se rvice Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBE HCI.SYS ### Driver Microsoft USB 2.0 Enhanced Host Controller Miniport Driver Start Ty

pe: loaded manually on demand EHCI eUSB Miniport Driver Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHU B.SYS ### Driver USB2 Enabled Hub Start Type: loaded manually on demand Default Hub Driver for USB Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2 180 [Services detected by Partizan] :HKLM usbohci=C:\WINDOWS\SYSTEM32\DRIVERS\USBO HCI.SYS ### Driver Microsoft USB Open Host Controller Miniport Driver Start Type: load ed manually on demand OHCI USB Miniport Driver Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM USBSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\USBS TOR.SYS ### Driver USB Mass Storage Driver Start Type: loaded manually on demand USB M ass Storage Class Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM VgaSave=C:\WINDOWS\SYSTEM32\DRIVERS\VGA. SYS ### Driver Start Type: loaded automatically at Kernel initialization VGA/Super VGA Video Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.2180 [Services detected by Partizan] :HKLM ViaIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM VolSnap ### Driver Start Type: loaded automatically by the Boot Loader [Services detected by Partizan] :HKLM VSS=C:\WINDOWS\SYSTEM32\VSSVC.EXE ### Service Volume Shadow Copy Manages and implements Volume Shadow Copies use d for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded manually on demand Microsoft Volume Shadow Copy Service Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM W32Time=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Time Maintains date and time synchronization on all client s and servers in the network. If this service is stopped, date and time synchron ization will be unavailable. If this service is disabled, any services that expl icitly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win 32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM W3SVC [Services detected by Partizan] :HKLM wampapache=C:\WAMP\BIN\APACHE\APACHE2.2. 8\BIN\HTTPD.EXE ### Service wampapache Apache/2.2.8 (Win32) PHP/5.2.6 Start Type: disabled Apa che HTTP Server Apache Software Foundation Apache HTTP Server 2.2.8 [Services detected by Partizan] :HKLM wampmysqld=C:\WAMP\BIN\MYSQL\MYSQL5.0.51 B\BIN\MYSQLD-NT.EXE ### Service wampmysqld Start Type: disabled [Services detected by Partizan] :HKLM Wanarp=C:\WINDOWS\SYSTEM32\DRIVERS\WANAR P.SYS ### Driver Remote Access IP ARP Driver Remote Access IP ARP Driver Start Type: loaded manually on demand MS Remote Access and Routing ARP Driver Microsoft Cor poration Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM WDICA ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM wdmaud=C:\WINDOWS\SYSTEM32\DRIVERS\WDMAU D.SYS ### Driver Microsoft WINMM WDM Audio Compatibility Driver Start Type: loaded m anually on demand MMSYSTEM Wave/Midi API mapper Microsoft Corporation Microsoft W

indows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM WebClient=C:\WINDOWS\SYSTEM32\SVCHOST.EX E ### Service WebClient Enables Windows-based programs to create, access, and mo dify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend o n it will fail to start. Start Type: loaded automatically by Server Manager Gene ric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Services detected by Partizan] :HKLM winachsf=C:\WINDOWS\SYSTEM32\DRIVERS\HSF _CNXT.SYS ### Driver Start Type: loaded manually on demand HSF_CNXT driver Conexant Syst ems, Inc. SoftK56 Modem Driver 7.73.00 [Services detected by Partizan] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Management Instrumentation Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based softwa re will not function properly. If this service is disabled, any services that ex plicitly depend on it will fail to start. Start Type: loaded automatically by Se rver Manager Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Winsock ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM WinSock2 [Services detected by Partizan] :HKLM WinTrust [Services detected by Partizan] :HKLM WL230_XP=C:\WINDOWS\SYSTEM32\DRIVERS\WLA NUZXP.SYS ### Driver Aztech 802.11g WL230 1211B Driver Start Type: loaded manually on de mand ZD1211B 802.11 b+g USB LAN Driver ZyDAS Technology Corporation ZD1211B 802. 11 b+g USB LAN Adapter 1, 2, 1, 1 [Services detected by Partizan] :HKLM WmdmPmSN=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Portable Media Serial Number Service Retrieves the serial number o f any portable media player connected to this computer. If this service is stopp ed, protected content might not be down loaded to the device. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM Wmi=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Management Instrumentation Driver Extensions Provides syst ems management information to and from drivers. Start Type: loaded manually on d emand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM WmiAcpi=C:\WINDOWS\SYSTEM32\DRIVERS\WMIA CPI.SYS ### Driver Microsoft Windows Management Interface for ACPI Start Type: loaded automatically at Kernel initialization Windows Management Interface for ACPI Mic rosoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM WmiApRpl [Services detected by Partizan] :HKLM WmiApSrv=C:\WINDOWS\SYSTEM32\WBEM\WMIAPS RV.EXE ### Service WMI Performance Adapter Provides performance library information f rom WMI HiPerf providers. Start Type: loaded manually on demand WMI Performance Adapter Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600. 2180 [Services detected by Partizan] :HKLM WS2IFSL ### Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Security Center Monitors system security settings and configuratio ns. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2 180

[Services detected by Partizan] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Automatic Updates Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Start Type: loaded au tomatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM WZCSVC=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Wireless Zero Configuration Provides automatic configuration for t he 802.11 adapters Start Type: loaded automatically by Server Manager Generic Ho st Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Services detected by Partizan] :HKLM xmlprov=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Network Provisioning Service Manages XML configuration files on a domain basis for automatic network provisioning. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Services detected by Partizan] :HKLM YahooAUService=C:\PROGRAM FILES\YAHOO!\S OFTWAREUPDATE\YAHOOAUSERVICE.EXE ### Service Yahoo! Updater Keeps your favorite Yahoo! software up-to-date with the latest features, tools, and enhancements. Start Type: loaded automatically by Server Manager AutoUpater Service Module Yahoo! Inc. Yahoo! AutoUpdater 1.0.0 .53 [Services detected by Partizan] :HKLM {07171AC2-0D2A-427d-BCE5-B6C2D6C7058B} [Services detected by Partizan] :HKLM {1F755A1B-F859-446A-B563-B3210FABFE71} [Services detected by Partizan] :HKLM {2DDF0727-1C8A-4851-8097-C46824FC072F} [Services detected by Partizan] :HKLM {859E586F-C6D0-47CA-B798-B9865607951E} [Codecs] :HKLM midimapper=C:\WINDOWS\system32\MIDIMAP.DLL ### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Codecs] :HKLM msacm.imaadpcm=C:\WINDOWS\system32\IMAADP32.ACM ### IMA ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Codecs] :HKLM msacm.msadpcm=C:\WINDOWS\system32\MSADP32.ACM ### Microsoft ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Codecs] :HKLM msacm.msg711=C:\WINDOWS\system32\MSG711.ACM ### Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.0 [Codecs] :HKLM msacm.msgsm610=C:\WINDOWS\system32\MSGSM32.ACM ### Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.0 [Codecs] :HKLM msacm.trspch=C:\WINDOWS\system32\TSSOFT32.ACM ### DSP Group TrueSpeech(TM) Audio Codec for MSACM V3.50 DSP GROUP, INC. DSP G ROUP Windows NT(TM) TrueSpeech CODEC 1.01 [Codecs] :HKLM vidc.cvid=C:\WINDOWS\system32\ICCVID.DLL ### Cinepak Codec Radius Inc. Cinepak for Windows 32 1.10.0.0 [Codecs] :HKLM vidc.I420=C:\WINDOWS\system32\MSH263.DRV ### Microsoft H.263 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 [Codecs] :HKLM vidc.iv31=C:\WINDOWS\system32\IR32_32.DLL [Codecs] :HKLM vidc.iv32=C:\WINDOWS\system32\IR32_32.DLL [Codecs] :HKLM vidc.iv41=C:\WINDOWS\system32\IR41_32.AX ### Intel Indeo Video 4.5 Intel Corporation Intel Indeo Video 4.5 4.51.16.03 [Codecs] :HKLM vidc.iyuv=C:\WINDOWS\system32\IYUV_32.DLL ### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Codecs] :HKLM vidc.mrle=C:\WINDOWS\system32\MSRLE32.DLL ### Microsoft RLE Compressor Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Codecs] :HKLM vidc.msvc=C:\WINDOWS\system32\MSVIDC32.DLL ### Microsoft Video 1 Compressor Microsoft Corporation Microsoft Windows Operati

ng System 5.1.2600.0 [Codecs] :HKLM vidc.uyvy=C:\WINDOWS\system32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo ws(R) Operating System 5.3.2600.2180 [Codecs] :HKLM vidc.yuy2=C:\WINDOWS\system32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo ws(R) Operating System 5.3.2600.2180 [Codecs] :HKLM vidc.yvu9=C:\WINDOWS\system32\TSBYUV.DLL ### Toshiba Video Codec Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Codecs] :HKLM vidc.yvyu=C:\WINDOWS\system32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo ws(R) Operating System 5.3.2600.2180 [Codecs] :HKLM wavemapper=C:\WINDOWS\system32\MSACM32.DRV ### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.0 [Codecs] :HKLM msacm.msg723=C:\WINDOWS\system32\MSG723.ACM ### Microsoft G.723.1 CODEC for MSACM Microsoft Corporation Windows NetMeeting 3 .01 [Codecs] :HKLM vidc.M263=C:\WINDOWS\system32\MSH263.DRV ### Microsoft H.263 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 [Codecs] :HKLM vidc.M261=C:\WINDOWS\system32\MSH261.DRV ### Microsoft H.261 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 [Codecs] :HKLM msacm.msaudio1=C:\WINDOWS\system32\MSAUD32.ACM ### Windows Media Audio Microsoft Corporation Windows Media Audio 8.00.00.4487 [Codecs] :HKLM msacm.sl_anet=C:\WINDOWS\system32\SL_ANET.ACM ### Audio codec for MS ACM Sipro Lab Telecom Inc. ACELP.net Audio Codec 3.02 [Codecs] :HKLM msacm.iac2=C:\WINDOWS\SYSTEM32\IAC25_32.AX ### Indeo audio software Intel Corporation Indeo audio software 2.05.53 [Codecs] :HKLM vidc.iv50=C:\WINDOWS\system32\IR50_32.DLL ### Intel Indeo video 5.10 Intel Corporation Intel Indeo video 5.10 R.5.10.15.2. 55 [Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSTEM32\L3CODECA.ACM ### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltu ngen IIS MPEG Layer-3 Audio Codec for MSACM 1, 0, 0, 0 [Codecs] :HKLM wave=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating stem 5.1.2600.2180 [Codecs] :HKLM midi=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating stem 5.1.2600.2180 [Codecs] :HKLM mixer=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating stem 5.1.2600.2180 [Codecs] :HKLM aux=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating stem 5.1.2600.2180 [Codecs] :HKLM wave1=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating stem 5.1.2600.2180 [Codecs] :HKLM midi1=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating stem 5.1.2600.2180 [Codecs] :HKLM mixer1=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating stem 5.1.2600.2180 [Codecs] :HKLM wave2=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating stem 5.1.2600.2180

Sy Sy Sy Sy Sy Sy Sy Sy

[Codecs] :HKLM midi2=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Codecs] :HKLM mixer2=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Codecs] :HKLM wave3=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Codecs] :HKLM midi3=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Codecs] :HKLM mixer3=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Detected using Heuristic Algorithm] :HKLM Desktop_.ini=C:\WINDOWS\SYSTEM32\DE SKTOP_.INI [Auto Start Apps] [Registry Run] :HKCU ctfmon.exe=C:\WINDOWS\SYSTEM32\CTFMON.EXE ### CTF Loader Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .2180 [Registry Run] :HKCU IDMan=C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EX E ### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6, 5, 1, 1 [Registry Run] :HKCU uTorrent=C:\PROGRAM FILES\UTORRENT\UTORRENT.EXE ### Torrent BitTorrent, Inc. Torrent 2.2.1.25302 [Registry Run] :HKCU UnHackMe Monitor=C:\PROGRAM FILES\UNHACKME\HACKMON.EXE ### Detects Rootkits in background Greatis Software UnHackMe 5.9 [Registry Run] :HKLM SM?RT-Protection [Registry Run] :HKLM Adobe ARM=C:\PROGRAM FILES\COMMON FILES\ADOBE\ARM\1.0\ADO BEARM.EXE ### Adobe Reader and Acrobat Manager Adobe Systems Incorporated Adobe Reader a nd Acrobat Manager 1.4.7.0 [Registry Run] :HKLM NvCplDaemon=C:\WINDOWS\SYSTEM32\NVCPL.DLL ### NVIDIA Display Properties Extension NVIDIA Corporation NVIDIA Compatible W indows 2000 Display driver, Version 175.90 6.14.11.7590 [Registry RunOnceEx] :HKLM @UnHackMe=C:\PROGRA~1\UnHackMe\UnHackMe.exe /p Part izan ### 1=C:\PROGRA~1\UnHackMe\UnHackMe.exe /p Partizan [Win.ini] load="" [Win.ini] run="" [Startup Folder] OneNote 2007 Screen Clipper and Launcher.lnk=C:\PROGRAM FILES \MICROSOFT OFFICE\OFFICE12\ONENOTEM.EXE ### Microsoft Office OneNote Quick Launcher Microsoft Corporation Microsoft Of fice OneNote 12.0.4518.1014 [Scheduled Tasks] AppleSoftwareUpdate=C:\PROGRAM FILES\APPLE SOFTWARE UPDATE\S OFTWAREUPDATE.EXE ### Apple Software Update Apple Inc. Apple Software Update 2.1.1.116 [In memory] [Running Processes] C:\WINDOWS\SYSTEM32\SMSS.EXE ### Windows NT Session Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Processes] C:\WINDOWS\SYSTEM32\WINLOGON.EXE ### Windows NT Logon Application Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Running Processes] C:\WINDOWS\SYSTEM32\SERVICES.EXE ### Services and Controller app Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Running Processes] C:\WINDOWS\SYSTEM32\LSASS.EXE

### LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Running Processes] C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EX E ### Bluetooth Support Server Broadcom Corporation. Bluetooth Software 5.1.0.42 00 [Running Processes] C:\WINDOWS\SYSTEM32\SPOOLSV.EXE ### Spooler SubSystem App Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Running Processes] C:\PROGRAM FILES\AVG\AVG10\AVGFWS.EXE ### AVG Firewall Service AVG Technologies CZ, s.r.o. AVG Internet Security 10. 0.0.1350 [Running Processes] C:\PROGRAM FILES\AVG\AVG10\AVGWDSVC.EXE ### AVG Watchdog Service AVG Technologies CZ, s.r.o. AVG Internet Security 10. 0.0.1295 [Running Processes] C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE ### Java(TM) Quick Starter Service Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Running Processes] C:\WINDOWS\EXPLORER.EXE ### Windows Explorer Microsoft Corporation Microsoft Windows Operating System 6. 00.2900.2180 [Running Processes] C:\WINDOWS\SYSTEM32\NVSVC32.EXE ### NVIDIA Driver Helper Service, Version 175.90 NVIDIA Corporation NVIDIA Dri ver Helper Service, Version 175.90 6.14.11.7590 [Running Processes] C:\PROGRAM FILES\YAHOO!\SOFTWAREUPDATE\YAHOOAUSERVICE.EXE ### AutoUpater Service Module Yahoo! Inc. Yahoo! AutoUpdater 1.0.0.53 [Running Processes] C:\PROGRAM FILES\AVG\AVG10\AVGAM.EXE ### AVG Alert Manager AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0 .1295 [Running Processes] C:\PROGRAM FILES\AVG\AVG10\AVGNSX.EXE ### AVG Online Shield Service AVG Technologies CZ, s.r.o. AVG Internet Securit y 10.0.0.1364 [Running Processes] C:\PROGRAM FILES\AVG\AVG10\AVGRSX.EXE ### AVG Resident Shield Service AVG Technologies CZ, s.r.o. AVG Internet Secur ity 10.0.0.1295 [Running Processes] C:\PROGRAM FILES\AVG\AVG10\AVGCHSVX.EXE ### AVG Cache Server AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0. 1352 [Running Processes] C:\PROGRAM FILES\AVG\AVG10\AVGCSRVX.EXE ### AVG Scanning Core Module - Server Part AVG Technologies CZ, s.r.o. AVG Int ernet Security 10.0.0.1355 [Running Processes] C:\PROGRAM FILES\SMADAV\SM?RTP.EXE ### File is deleted or hidden by rootkit or could not be located. [Running Processes] C:\PROGRAM FILES\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE ### Adobe Reader and Acrobat Manager Adobe Systems Incorporated Adobe Reader a nd Acrobat Manager 1.4.7.0 [Running Processes] C:\WINDOWS\SYSTEM32\CTFMON.EXE ### CTF Loader Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .2180 [Running Processes] C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EXE ### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM) 6, 5, 1, 1 [Running Processes] C:\PROGRAM FILES\UTORRENT\UTORRENT.EXE ### Torrent BitTorrent, Inc. Torrent 2.2.1.25302

[Running Processes] C:\PROGRAM FILES\UNHACKME\HACKMON.EXE ### Detects Rootkits in background Greatis Software UnHackMe 5.9 [Running Processes] C:\PROGRAM FILES\UNHACKME\UNHACKME.EXE ### Detects and removes rootkits Greatis Software UnHackMe 5.99 [Running Processes] C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\ONENOTEM.EXE ### Microsoft Office OneNote Quick Launcher Microsoft Corporation Microsoft Of fice OneNote 12.0.4518.1014 [Running Processes] C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEMONITOR.EXE ### Internet Download Manager agent for click monitoring in IE-based browsers Tonec Inc. IEMonitor Application 5, 19, 3, 1 [Running Processes] C:\WINDOWS\SYSTEM32\WUAUCLT.EXE ### Automatic Updates Microsoft Corporation Microsoft Windows Operating System 5 .4.3790.2180 [Running Processes] C:\WINDOWS\SYSTEM32\WSCNTFY.EXE ### Windows Security Center Notification App Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Running Processes] C:\PROGRA~1\UNHACKME\REGRUNINFO.EXE ### Module for retrieving file info from Internet Greatis Software RegRun Secu rity Suite 6.99 [Running Processes] C:\PROGRAM FILES\JAVA\JRE6\BIN\JAVAW.EXE ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Running Processes] C:\PROGRAM FILES\VIDEOLAN\VLC\VLC.EXE [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Running Processes] C:\WINDOWS\SYSTEM32\NOTEPAD.EXE ### Notepad Microsoft Corporation Microsoft Windows Operating System 5.1.2600.21 80 [Running Processes] C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 0.0.0.0 [Running Processes] C:\PROGRAM FILES\UNHACKME\REANIMATOR.EXE

### RegRun Start Control Greatis Software RegRun Security Suite 6.99 release [Loaded DLLs] C:\WINDOWS\System32\Wbem\framedyn.dll ### WMI SDK Provider Framework Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\srclient.dll ### SR CLIENT DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.2180 [Loaded DLLs] C:\WINDOWS\system32\mstask.dll ### Task Scheduler interface DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\sti.dll ### Still Image Devices client DLL Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\CFGMGR32.dll ### Configuration Manager Forwarder DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\wiaservc.dll ### Still Image Devices Service Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Loaded DLLs] C:\Program Files\Internet Download Manager\idmmkb.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager 6, 0 , 3, 4 [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\gcswf32.dll [Loaded DLLs] C:\WINDOWS\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40 00.2435 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgcslx.dll ### AVG Common Client Library AVG Technologies CZ, s.r.o. AVG Internet Securit y 10.0.0.1375 [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0. 0.1374_0\plugins\avgxpl.dll ### LinkScanner SDK AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1 374 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0. 0.1374_0\plugins\avgnpss.dll ### avgnpss AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1374 [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\avformat-52.dll [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\avutil-50.dll [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\avcodec-52.dll [Loaded DLLs] C:\WINDOWS\system32\LPK.DLL ### Language Pack Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.2180 [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\ppGoogleNaClPluginChrome.dll [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\pdf.dll ### Chrome PDF Viewer Chrome PDF Viewer 1, 0, 0, 1 [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\locales\en-US.dll [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\icudt.dll

### ICU Data DLL The ICU Project International Components for Unicode 4, 6, 0, 0 [Loaded DLLs] C:\WINDOWS\system32\USP10.dll ### Uniscribe Unicode script processor Microsoft Corporation Microsoft(R) Unis cribe Unicode script processor 1.0420.2600.2180 [Loaded DLLs] C:\Documents and Settings\hans\Local Settings\Application Data\G oogle\Chrome\Application\12.0.742.53\chrome.dll ### Google Chrome Google Inc. Google Chrome 12.0.742.53 [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libscaletempo_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libfloat32_mixer_plugin.dl l [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libaudio_format_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libtrivial_channel_mixer_p lugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libmono_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libugly_resampler_plugin.d ll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdolby_surround_decoder_ plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\liba52tospdif_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libsimple_channel_mixer_pl ugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdtstospdif_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libconverter_fixed_plugin. dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libbandlimited_resampler_p lugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\liba52tofloat32_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdtstofloat32_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libmpgatofixed32_plugin.dl l [Loaded DLLs] C:\WINDOWS\system32\KsUser.dll ### User CSA Library Microsoft Corporation Microsoft(R) Windows(R) Operating S ystem 5.3.2600.2180 [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libblend_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdrawable_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdirect3d_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libvout_wrapper_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libyuvp_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libscale_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi422_i420_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libyuy2_i422_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi420_yuy2_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libgrey_yuv_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi420_rgb_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libyuy2_i420_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi422_yuy2_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi420_rgb_mmx_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi422_yuy2_mmx_plugin.dl l [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi420_rgb_sse2_plugin.dl l [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi422_yuy2_sse2_plugin.d ll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libswscale_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi420_yuy2_mmx_plugin.dl l [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libi420_yuy2_sse2_plugin.d ll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libfreetype_plugin.dll

[Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libavcodec_plugin.dll [Loaded DLLs] C:\WINDOWS\system32\dsound.dll ### DirectSound Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.2180 [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libfluidsynth_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\liba52_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\liblpcm_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libmpeg_audio_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libtheora_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libfaad_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdts_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libaes3_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libaraw_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\liblibass_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libspeex_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libvorbis_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libflac_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libschroedinger_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libpng_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libcdg_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libfake_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libfolder_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libasf_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libqt4_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libavi_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libglobalhotkeys_plugin.dl l [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libmp4_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libhotkeys_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libxml_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\liblua_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libtaglib_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libplaylist_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libstream_filter_record_pl ugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libzip_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libstream_filter_rar_plugi n.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libfilesystem_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdvdnav_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libaccess_bd_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libmemcpymmxext_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libwaveout_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libskins2_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdshow_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libdirectx_plugin.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\plugins\libaout_directx_plugin.dll [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\Program Files\VideoLAN\VLC\libvlccore.dll [Loaded DLLs] C:\Program Files\VideoLAN\VLC\libvlc.dll [Loaded DLLs] C:\Program Files\Java\jre6\bin\jpeg.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Internet Download Manager\IDMShellExt.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager modu le 6,0,4,10 [Loaded DLLs] C:\WINDOWS\system32\urlmon.dll ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer

8.00.6001.18702 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Loaded DLLs] C:\Program Files\Java\jre6\bin\sunmscapi.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\dcpr.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\mlib_image.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\fontmanager.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\awt.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\nio.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\net.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\zip.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\java.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\verify.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\client\jvm.dll ### Java HotSpot(TM) Client VM Sun Microsystems, Inc. Java(TM) Platform SE 6u2 5 6.0.250.6 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\wuaucpl.cpl ### Automatic Updates Control Panel Microsoft Corporation Microsoft Windows Oper ating System 5.4.3790.2180 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\1033\ONINTL.DLL ### Microsoft Office OneNote International Resources Microsoft Corporation Mic rosoft Office OneNote 12.0.4518.1014 [Loaded DLLs] C:\WINDOWS\system32\ieframe.dll ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .18702 [Loaded DLLs] C:\Program Files\Internet Download Manager\IDMShellExt.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager modu le 6,0,4,10 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\Program Files\Internet Download Manager\idmmkb.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager 6, 0

, 3, 4 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40 00.2435 [Loaded DLLs] C:\WINDOWS\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40 00.2435 [Loaded DLLs] C:\Program Files\Internet Download Manager\idmmkb.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager 6, 0 , 3, 4 [Loaded DLLs] C:\WINDOWS\system32\hnetcfg.dll ### Home Networking Configuration Manager Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\RICHED20.dll ### Rich Text Edit Control, v3.0 Microsoft Corporation Microsoft RichEdit Cont rol, version 3.0 3.0 [Loaded DLLs] C:\WINDOWS\system32\RichEd32.Dll ### Wrapper Dll for Richedit 1.0 Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.0 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\cryptnet.dll ### Crypto Network Related API Microsoft Corporation Microsoft Windows Operating System 5.131.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\MSCTF.dll ### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.3319 [Loaded DLLs] C:\WINDOWS\system32\oledlg.dll ### Microsoft Windows(TM) OLE 2.0 User Interface Support Microsoft Corporation Microsoft Windows(TM) OLE 2.0 User Interface Support 2.01 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40 00.2435 [Loaded DLLs] C:\WINDOWS\system32\ieframe.dll ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .18702 [Loaded DLLs] C:\WINDOWS\system32\asycfilt.dll ### Microsoft Corporation 5.1.2600.2180 [Loaded DLLs] C:\Program Files\Smadav\SmadEngine.dll ### Smadav Virus Scanner Engine Smadsoft SmadEngine 1, 0, 0, 1 [Loaded DLLs] C:\WINDOWS\system32\MSVBVM60.DLL ### Visual Basic Virtual Machine Microsoft Corporation Visual Basic 6.00.9690 [Loaded DLLs] C:\WINDOWS\system32\OLEPRO32.DLL ### Microsoft Corporation 5.1.2600.2180 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgchclx.dll ### AVG Cache Manager Module - Client Part AVG Technologies CZ, s.r.o. AVG Int ernet Security 10.0.0.1295 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgcorex.dll ### AVG Scanning Core Module AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1513 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgcertx.dll ### AVG Cert SDK AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1295

[Loaded DLLs] C:\Program Files\AVG\AVG10\avgchjwx.dll ### AVG Scanning Cache Module AVG Technologies CZ, s.r.o. AVG Internet Securit y 10.0.0.1352 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgcclix.dll ### AVG Scanning Core Module - Client Part AVG Technologies CZ, s.r.o. AVG Int ernet Security 10.0.0.1355 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgxpl.dll ### LinkScanner SDK AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1 368 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgamnot.dll ### AVG Event Notification Library AVG Technologies CZ, s.r.o. AVG Internet Se curity 10.0.0.1295 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgameh.dll ### AVG Alert Manager Library AVG Technologies CZ, s.r.o. AVG Internet Securit y 10.0.0.1295 [Loaded DLLs] C:\Program Files\AVG\AVG10\avglngx.dll ### AVG Language Module AVG Technologies CZ, s.r.o. AVG Internet Security 10.0 .0.1367 [Loaded DLLs] C:\WINDOWS\system32\nvapi.dll ### NVIDIA NVAPI Library, Version 175.90 NVIDIA Corporation NVIDIA Windows dr ivers 6.14.11.7590 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgse.dll ### AVG Shell Extension AVG Technologies CZ, s.r.o. AVG Internet Security 10.0 .0.1295 [Loaded DLLs] C:\Program Files\MD5 Tool\DLLReg.dll ### DllReg Module DllReg Module 1, 0, 0, 1 [Loaded DLLs] C:\Program Files\Notepad++\NppShell_04.dll ### ShellHandler for Notepad++ (64 bit) 0.1 [Loaded DLLs] C:\Program Files\WinRAR\rarext.dll [Loaded DLLs] C:\Program Files\Smadav\SmadExtc.dll ### Smadav shell extension Smadsoft SmadExt 1.1.0.0 [Loaded DLLs] C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll ### Microsoft Office Shell Extension Handlers Microsoft Corporation Microsoft Office 12.0.4518.1014 [Loaded DLLs] C:\Program Files\Common Files\Microsoft Shared\OFFICE11\msxml5.d ll ### MSXML 5.0 Microsoft Corporation Microsoft(R) MSXML 5.0 5.20.1072.0 [Loaded DLLs] C:\WINDOWS\system32\actxprxy.dll ### ActiveX Interface Marshaling Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\wzcdlg.dll ### Wireless Zero Configuration Service UI Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\AVIFIL32.dll ### Microsoft AVI File support library Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\shmedia.dll ### Media File Property Extractor Shell Extension Microsoft Corporation Micros oft Windows Operating System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\DRMClien.DLL ### DRM Client DLL Microsoft Corporation Microsoft DRM 9.00.00.3250 [Loaded DLLs] C:\WINDOWS\system32\dxmasf.dll [Loaded DLLs] C:\WINDOWS\system32\msdmo.dll [Loaded DLLs] C:\WINDOWS\system32\MSVFW32.dll ### Microsoft Video for Windows DLL Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\shimgvw.dll

### Windows Picture and Fax Viewer Microsoft Corporation Microsoft Windows Opera ting System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\shdoclc.dll ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\icm32.dll ### Microsoft Color Management Module (CMM) Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\mscms.dll ### Microsoft Color Matching System DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df _1.0.2600.2180_x-ww_522f9f82\gdiplus.dll ### Microsoft GDI+ Microsoft Corporation Microsoft Windows Operating System 5.1. 3102.2180 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\msohevi.dll ### 2007 Microsoft Office component Microsoft Corporation 2007 Microsoft Offic e system 12.0.4518.1014 [Loaded DLLs] C:\Program Files\Internet Download Manager\IDMIECC.dll ### IDM Browser Helper Object Internet Download Manager, Tonec Inc. Internet D ownload Manager Module 6, 4, 2, 1 [Loaded DLLs] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll ### PDF Shell Extension Adobe Systems, Inc. Adobe PDF Shell Extension 10.0.0.3 96 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResour ce.dll ### GrooveIntlResource Module Microsoft Corporation GrooveIntlResource Module 4.2.0.2623 [Loaded DLLs] C:\WINDOWS\system32\Oleacc.dll ### Active Accessibility Core Component Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Loaded DLLs] C:\WINDOWS\system32\odbcint.dll ### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat a Access Components 3.525.1117.0 [Loaded DLLs] C:\WINDOWS\system32\DUSER.dll ### Windows DirectUser Engine Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\browselc.dll ### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\System32\davclnt.dll ### Web DAV Client DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\NETUI1.dll ### NT LM UI Common Code - Networking classes Microsoft Corporation Microsoft W indows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\NETUI0.dll ### NT LM UI Common Code - GUI Classes Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\ntlanman.dll ### Microsoft Lan Manager Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\drprov.dll ### Microsoft Terminal Server Network Provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\Program Files\Internet Download Manager\idmmkb.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager 6, 0 , 3, 4 [Loaded DLLs] C:\WINDOWS\system32\BatMeter.dll ### Battery Meter Helper DLL Microsoft Corporation Microsoft Windows Operating S

ystem 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\stobject.dll ### Systray shell service object Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\webcheck.dll ### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001. 18702 [Loaded DLLs] C:\PROGRA~1\MICROS~2\Office12\GR326C~1.DLL ### GrooveMisc Module Microsoft Corporation GrooveMisc Module 4.2.0.2623 [Loaded DLLs] C:\WINDOWS\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40 00.2435 [Loaded DLLs] C:\WINDOWS\system32\ieframe.dll ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .18702 [Loaded DLLs] C:\WINDOWS\system32\ntshrui.dll ### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\LINKINFO.dll ### Windows Volume Tracking Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\msxml3.dll ### MSXML 3.0 SP 5 Microsoft Corporation Microsoft(R) MSXML 3.0 SP 5 8.50.2162 .0 [Loaded DLLs] C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL ### GrooveSystemServices Module Microsoft Corporation GrooveSystemServices Mod ule 4.2.0.2623 [Loaded DLLs] C:\WINDOWS\system32\MSCTF.dll ### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.3319 [Loaded DLLs] C:\WINDOWS\system32\msutb.dll ### MSUTB Server DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\themeui.dll ### Windows Theme API Microsoft Corporation Microsoft Windows Operating System 6 .00.2900.2180 [Loaded DLLs] C:\Program Files\Internet Download Manager\IDMShellExt.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager modu le 6,0,4,10 [Loaded DLLs] C:\WINDOWS\system32\MSImg32.dll ### GDIEXT Client DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50 727.4053_x-ww_473666fd\ATL80.DLL ### ATL Module for Windows (Unicode) Microsoft Corporation Microsoft Visual Stu dio 2005 8.00.50727.4053 [Loaded DLLs] C:\PROGRA~1\MICROS~2\Office12\GrooveNew.DLL ### GrooveNew Module Microsoft Corporation GrooveNew Module 4.2.0.2623 [Loaded DLLs] C:\PROGRA~1\MICROS~2\Office12\GrooveUtil.DLL ### GrooveUtil Module Microsoft Corporation GrooveUtil Module 4.2.0.2623 [Loaded DLLs] C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\SHDOCVW.dll ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.2987 [Loaded DLLs] C:\WINDOWS\system32\BROWSEUI.dll

### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2995 [Loaded DLLs] C:\WINDOWS\system32\perfdisk.dll ### Windows Disk Performance Objects DLL Microsoft Corporation Microsoft Window s Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\perfos.dll ### Windows System Performance Objects DLL Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\odbcbcp.dll ### Microsoft BCP for ODBC Microsoft Corporation Microsoft SQL Server 3.85.111 7 [Loaded DLLs] C:\WINDOWS\system32\pdh.dll ### Windows Performance Data Helper DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\Program Files\Java\jre6\bin\MSVCR71.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio .N ET 7.10.3052.4 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgwdwsc.dll ### AVG Windows Security Center Module AVG Technologies CZ, s.r.o. AVG Interne t Security 10.0.0.1295 [Loaded DLLs] C:\WINDOWS\system32\SensAPI.DLL ### SENS Connectivity API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgsched.dll ### AVG Scheduler Module AVG Technologies CZ, s.r.o. AVG Internet Security 10. 0.0.1300 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgidpsdkx.dll ### AVG Identity Protection Library AVG Technologies CZ, s.r.o. AVG Internet S ecurity 10.1.0.1297 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgcslx.dll ### AVG Common Client Library AVG Technologies CZ, s.r.o. AVG Internet Securit y 10.0.0.1375 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgwd.dll ### AVG Watchdog Module AVG Technologies CZ, s.r.o. AVG Internet Security 10.0 .0.1370 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgclitx.dll ### AVG Scanning Core Module - Lite Version AVG Technologies CZ, s.r.o. AVG In ternet Security 10.0.0.1295 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgmtrapx.dll ### AVG M-TRAP Reporting Library AVG Technologies CZ, s.r.o. AVG Internet Secu rity 10.0.0.1295 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30 729.4148_x-ww_d495ac4e\MSVCP90.dll ### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio 2 008 9.00.30729.4148 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgidpsdkx.dll ### AVG Identity Protection Library AVG Technologies CZ, s.r.o. AVG Internet S ecurity 10.1.0.1297 [Loaded DLLs] C:\Program Files\AVG\AVG10\avgcfgx.dll ### AVG Configuration Module AVG Technologies CZ, s.r.o. AVG Internet Security 10.0.0.1363 [Loaded DLLs] C:\Program Files\AVG\AVG10\avglogx.dll ### AVG Logging Library AVG Technologies CZ, s.r.o. AVG Internet Security 10.0 .0.1304 [Loaded DLLs] C:\WINDOWS\system32\snmpapi.dll ### SNMP Utility Library Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180

[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30 729.4148_x-ww_d495ac4e\MSVCR90.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 8 9.00.30729.4148 [Loaded DLLs] C:\WINDOWS\system32\inetpp.dll ### Internet Print Provider DLL Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\NETRAP.dll ### Net Remote Admin Protocol DLL Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\win32spl.dll ### 32-bit Spooler API DLL Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\spool\PRTPROCS\W32X86\msonpppr.dll ### Microsoft Office OneNote 2007 Printer Driver Microsoft Corporation Microso ft Office OneNote 2007 Printer Driver 12.3.4518.1014 [Loaded DLLs] C:\WINDOWS\system32\usbmon.dll ### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\tcpmon.dll ### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50 727.4053_x-ww_e6967989\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.4053 [Loaded DLLs] C:\WINDOWS\system32\msonpmon.dll ### Microsoft Office OneNote 2007 Printer Driver Microsoft Corporation Microso ft Office OneNote 2007 Printer Driver 12.3.4518.1014 [Loaded DLLs] C:\WINDOWS\system32\pjlmon.dll ### PJL Language monitor Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\MFC42.DLL ### MFCDLL Shared Library - Retail Version Microsoft Corporation Microsoft (R) Visual C++ 6.02.400 [Loaded DLLs] C:\WINDOWS\system32\wbtapi.dll ### WBTApi DLL Broadcom Corporation. Bluetooth Software 5.1.0.4200 [Loaded DLLs] C:\WINDOWS\system32\WidcommSdk.dll ### WidcommSdk DLL Broadcom Corporation. Bluetooth Software 5.1.0.4200 [Loaded DLLs] C:\WINDOWS\system32\bthcrp.dll ### bthcrp DLL Broadcom Corporation. Bluetooth Software 5.1.0.4200 [Loaded DLLs] C:\WINDOWS\system32\cnbjmon.dll ### Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation Microso ft Windows Operating System 5.1.2600.2082 [Loaded DLLs] C:\WINDOWS\system32\localspl.dll ### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\SPOOLSS.DLL ### Spooler SubSystem DLL Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\xmlprovi.dll ### Network Provisioning Service Client API Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\mlang.dll ### Multi Language Support DLL Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\System32\catsrv.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\System32\MfcSubs.dll ### Microsoft Corporation COM Services 03.00.00.4414

[Loaded DLLs] C:\WINDOWS\System32\catsrvut.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\System32\RASDLG.dll ### Remote Access Common Dialog API Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\winrnr.dll ### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\qmgr.dll ### Background Intelligent Transfer Service Microsoft Corporation Microsoft Win dows Operating System 6.6.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wups.dll ### Windows Update client proxy stub Microsoft Corporation Microsoft Windows Ope rating System 5.4.3790.2180 [Loaded DLLs] C:\WINDOWS\System32\ntlsapi.dll ### Microsoft License Server Interface DLL Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\rasppp.dll ### Remote Access PPP Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\hidphone.tsp ### Microsoft HID Phone TSP Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\h323.tsp ### Microsoft H.323 Telephony Service Provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\ipconf.tsp ### Microsoft Multicast Conference TAPI Service Provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\ndptsp.tsp ### NDIS Proxy TAPI Service Provider Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\kmddsp.tsp ### TAPI Kernel-Mode Service Provider Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\modemui.dll ### Windows Modem Properties Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\unimdmat.dll ### Unimodem Service Provider AT Mini Driver Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\uniplat.dll ### Unimodem AT Mini Driver Platform Driver for Windows NT Microsoft Corporati on Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\unimdm.tsp ### Unimodem 5 Service Provider Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\rastapi.dll ### Remote Access TAPI Compliance Layer Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\rasadhlp.dll ### Remote Access AutoDial Helper Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\tapisrv.dll ### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\rasmans.dll ### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\netcfgx.dll

### Network Configuration Objects Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\SSDPAPI.dll ### SSDP Client API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\upnp.dll ### Universal Plug and Play API Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wbem\ncprov.dll ### Non-COM WMI Event Provision APIs Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\RESUTILS.DLL ### Microsoft Cluster Resource Utility DLL Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\CLUSAPI.DLL ### Cluster API Library Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\colbact.DLL ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\system32\WSOCK32.dll ### Windows Socket 32-Bit DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\MTXCLU.DLL ### MS DTC amd MTS clustering support DLL Microsoft Corporation COM Services 0 3.01.00.4414 [Loaded DLLs] C:\WINDOWS\system32\comsvcs.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\system32\wbem\wbemess.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wbem\wmiprvsd.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wbem\repdrvfs.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wbem\wmiutils.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\Wbem\esscli.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\Wbem\wbemcore.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\ipnathlp.dll ### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40 00.2435 [Loaded DLLs] c:\windows\system32\wscsvc.dll ### Windows Security Center Service Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\browser.dll ### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\mspatcha.dll ### Microsoft(R) Patch Engine Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\Cabinet.dll ### Microsoft Cabinet File API Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\WINHTTP.dll ### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180

[Loaded DLLs] C:\WINDOWS\System32\SHFOLDER.dll ### Shell Folder Service Microsoft Corporation Microsoft Windows Operating Syste m 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\System32\ADVPACK.dll ### ADVPACK Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Loaded DLLs] C:\WINDOWS\system32\wuaueng.dll ### Windows Update AutoUpdate Engine Microsoft Corporation Microsoft Windows Ope rating System 5.4.3790.2180 [Loaded DLLs] c:\windows\system32\wuauserv.dll ### Windows Update AutoUpdate Service Microsoft Corporation Microsoft Windows Op erating System 5.4.3790.2180 [Loaded DLLs] C:\WINDOWS\system32\VSSAPI.DLL ### Microsoft Volume Shadow Copy Requestor/Writer Services API DLL Microsoft Co rporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\wbem\wmisvc.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\trkwks.dll ### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\POWRPROF.dll ### Power Profile Helper DLL Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Loaded DLLs] c:\windows\system32\srsvc.dll ### System Restore Service Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\sens.dll ### System Event Notification Service (SENS) Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\seclogon.dll ### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\credui.dll ### Credential Manager User Interface Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\netshell.dll ### Network Connections Shell Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\netman.dll ### Network Connections Manager Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\srvsvc.dll ### Server Service DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\HID.DLL ### Hid User Library Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Loaded DLLs] c:\windows\system32\hidserv.dll ### HID Audio Service Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Loaded DLLs] c:\windows\pchealth\helpctr\binaries\pchsvc.dll ### Microsoft PCHealth Service Holder Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\es.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] c:\windows\system32\ersvc.dll ### Windows Error Reporting Service Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\dmserver.dll ### Logical Disk Manager service dll Microsoft Corp. Logical Disk Manager for Windows NT 1.0

[Loaded DLLs] c:\windows\system32\certcli.dll ### Microsoft Certificate Services Client Microsoft Corporation Microsoft Window s Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\cryptsvc.dll ### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\wkssvc.dll ### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\audiosrv.dll ### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\MSIDLE.DLL ### User Idle Monitor Microsoft Corporation Microsoft Windows Operating System 6 .00.2900.2180 [Loaded DLLs] c:\windows\system32\schedsvc.dll ### Task Scheduler Engine Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\WZCSAPI.DLL ### Wireless Zero Configuration service API Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\raschap.dll ### Remote Access PPP CHAP Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\TAPI32.dll ### Microsoft Windows(TM) Telephony API Client DLL Microsoft Corporation Micros oft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\rasman.dll ### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\RASAPI32.dll ### Remote Access API Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\MPRAPI.dll ### Windows NT MP Router Administration DLL Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\iertutil.dll ### Run time utility for Internet Explorer Microsoft Corporation Windows Intern et Explorer 8.00.6001.18702 [Loaded DLLs] C:\WINDOWS\system32\urlmon.dll ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\WININET.dll ### Internet Extensions for Win32 Microsoft Corporation Windows Internet Explor er 8.00.6001.18702 [Loaded DLLs] C:\WINDOWS\System32\CRYPTUI.dll ### Microsoft Trust UI Provider Microsoft Corporation Microsoft Windows Operatin g System 5.131.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\rastls.dll ### Remote Access PPP EAP-TLS Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\ESENT.dll ### Server Database Storage Engine Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\WMI.dll ### WMI DC and DP functionality Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180

[Loaded DLLs] c:\windows\system32\rtutils.dll ### Routing Utilities Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Loaded DLLs] c:\windows\system32\wzcsvc.dll ### Wireless Zero Configuration Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\dhcpcsvc.dll ### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\ATL.DLL ### ATL Module for Windows XP (Unicode) Microsoft Corporation Microsoft (R) Vi sual C++ 6.05.2284 [Loaded DLLs] c:\windows\system32\adsldpc.dll ### ADs LDAP Provider C DLL Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\ACTIVEDS.dll ### ADs Router Layer DLL Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\mstlsapi.dll ### Microsoft Terminal Server Licensing Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\ICAAPI.dll ### DLL Interface to TermDD Device Driver Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\termsrv.dll ### Terminal Server Service Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] c:\windows\system32\rpcss.dll ### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\dssenh.dll ### Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2133 [Loaded DLLs] C:\WINDOWS\system32\psbase.dll ### Protected Storage default provider Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\pstorsvc.dll ### Protected storage server Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\System32\wshtcpip.dll ### Windows Sockets Helper DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\hnetcfg.dll ### Home Networking Configuration Manager Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\mswsock.dll ### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WINIPSEC.DLL ### Windows IPSec SPD Client DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\oakley.DLL ### Oakley Key Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\ipsecsvc.dll ### Windows IPSec SPD Server DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180

[Loaded DLLs] C:\WINDOWS\system32\scecli.dll ### Windows Security Configuration Editor Client Engine Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wdigest.dll ### Microsoft Digest Access Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\schannel.dll ### TLS / SSL Security Provider Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\w32time.dll ### Windows Time Service Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\netlogon.dll ### Net Logon Services DLL Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\kerberos.dll ### Kerberos Security Package Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\msprivs.dll ### Microsoft Privilege Translations Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\cryptdll.dll ### Cryptography Manager Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\SAMSRV.dll ### SAM Server DLL Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.2180 [Loaded DLLs] C:\WINDOWS\system32\LSASRV.dll ### LSA Server DLL Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.2180 [Loaded DLLs] C:\WINDOWS\system32\eventlog.dll ### Event Logging Service Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\AppPatch\AcGenral.DLL ### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\ShimEng.dll ### Shim Engine DLL Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180 [Loaded DLLs] C:\WINDOWS\system32\NCObjAPI.DLL ### Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\umpnpmgr.dll ### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\SCESRV.dll ### Windows Security Configuration Editor Engine Microsoft Corporation Microso ft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\DNSAPI.dll ### DNS Client API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\NTDSAPI.dll ### NT5DS Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\MSVCP60.dll ### Microsoft (R) C++ Runtime Library Microsoft Corporation Microsoft (R) Visu al C++ 6.02.3104.0 [Loaded DLLs] C:\WINDOWS\system32\wbem\fastprox.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wbem\wbemsvc.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180

[Loaded DLLs] C:\WINDOWS\system32\wbem\wbemcomn.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wbem\wbemprox.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\CLBCATQ.DLL ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\system32\OLEAUT32.dll ### Microsoft Corporation 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\COMRes.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\system32\midimap.dll ### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\MSACM32.dll ### Microsoft ACM Audio Filter Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\msacm32.drv ### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.0 [Loaded DLLs] C:\WINDOWS\system32\NTMARTA.DLL ### Windows NT MARTA provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wldap32.dll ### Win32 LDAP API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\wdmaud.drv ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\cscui.dll ### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\iphlpapi.dll ### IP Helper API Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.2180 [Loaded DLLs] C:\WINDOWS\system32\msv1_0.dll ### Microsoft Authentication Package v1.0 Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\SAMLIB.dll ### SAM Library DLL Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180 [Loaded DLLs] C:\WINDOWS\system32\rsaenh.dll ### Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft W indows Operating System 5.1.2600.2161 [Loaded DLLs] C:\WINDOWS\system32\MPR.dll ### Multiple Provider Router DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WINSPOOL.DRV ### Windows Spooler Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WlNotify.dll ### Common DLL to receive Winlogon notifications Microsoft Corporation Microso ft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\cscdll.dll ### Offline Network Agent Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WINMM.dll ### MCI API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.260

0.2180 [Loaded DLLs] C:\WINDOWS\system32\uxtheme.dll ### Microsoft UxTheme Library Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\sxs.dll ### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .2180 [Loaded DLLs] C:\WINDOWS\system32\WTSAPI32.dll ### Windows Terminal Server SDK APIs Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WINSCARD.DLL ### Microsoft Smart Card API Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\msctfime.ime ### Microsoft Text Frame Work Service IME Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\Apphelp.dll ### Application Compatibility Client Library Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\ole32.dll ### Microsoft OLE for Windows Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\sfc_os.dll ### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\sfc.dll ### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\SHSVCS.dll ### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\odbcint.dll ### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat a Access Components 3.525.1117.0 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b641 44ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll ### User Experience Controls Library Microsoft Corporation Microsoft Windows Ope rating System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\comdlg32.dll ### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\ODBC32.dll ### Microsoft Data Access - ODBC Driver Manager Microsoft Corporation Microsof t Data Access Components 3.525.1117.0 [Loaded DLLs] C:\WINDOWS\system32\COMCTL32.dll ### Common Controls Library Microsoft Corporation Microsoft Windows Operating Sy stem 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\SHLWAPI.dll ### Shell Light-weight Utility Library Microsoft Corporation Microsoft Windows O perating System 6.00.2900.2995 [Loaded DLLs] C:\WINDOWS\system32\SHELL32.dll ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Loaded DLLs] C:\WINDOWS\system32\MSGINA.dll ### Windows NT Logon GINA DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\IMM32.DLL ### Windows XP IMM32 API Client DLL Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WS2HELP.dll

### Windows Socket 2.0 Helper for Windows NT Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WS2_32.dll ### Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\IMAGEHLP.dll ### Windows NT Image Helper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WINTRUST.dll ### Microsoft Trust Verification APIs Microsoft Corporation Microsoft Windows Op erating System 5.131.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\WINSTA.dll ### Winstation Library Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\VERSION.dll ### Version Checking and File Installation Libraries Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\SETUPAPI.dll ### Windows Setup API Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\Secur32.dll ### Security Support Provider Interface Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\REGAPI.dll ### Registry Configuration APIs Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\PSAPI.DLL ### Process Status Helper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\USERENV.dll ### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.21 80 [Loaded DLLs] C:\WINDOWS\system32\NETAPI32.dll ### Net Win32 API DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\PROFMAP.dll ### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.21 80 [Loaded DLLs] C:\WINDOWS\system32\NDdeApi.dll ### Network DDE Share Management APIs Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\MSASN1.dll ### ASN.1 Runtime APIs Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\GDI32.dll ### GDI Client DLL Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.2180 [Loaded DLLs] C:\WINDOWS\system32\USER32.dll ### Windows XP USER API Client DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\CRYPT32.dll ### Crypto API32 Microsoft Corporation Microsoft Windows Operating System 5.131. 2600.2180 [Loaded DLLs] C:\WINDOWS\system32\msvcrt.dll ### Windows NT CRT DLL Microsoft Corporation Microsoft Windows Operating System 7.0.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\AUTHZ.dll ### Authorization Framework Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\RPCRT4.dll

### Remote Procedure Call Runtime Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\ADVAPI32.dll ### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\kernel32.dll ### Windows NT BASE API Client DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Loaded DLLs] C:\WINDOWS\system32\ntdll.dll ### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.2180 [Explorer's DLLs] C:\Program Files\AVG\AVG10\avgse.dll ### AVG Shell Extension AVG Technologies CZ, s.r.o. AVG Internet Security 10.0 .0.1295 [Explorer's DLLs] C:\Program Files\MD5 Tool\DLLReg.dll ### DllReg Module DllReg Module 1, 0, 0, 1 [Explorer's DLLs] C:\Program Files\Notepad++\NppShell_04.dll ### ShellHandler for Notepad++ (64 bit) 0.1 [Explorer's DLLs] C:\Program Files\WinRAR\rarext.dll [Explorer's DLLs] C:\Program Files\Smadav\SmadExtc.dll ### Smadav shell extension Smadsoft SmadExt 1.1.0.0 [Explorer's DLLs] C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll ### Microsoft Office Shell Extension Handlers Microsoft Corporation Microsoft Office 12.0.4518.1014 [Explorer's DLLs] C:\Program Files\Common Files\Microsoft Shared\OFFICE11\msxm l5.dll ### MSXML 5.0 Microsoft Corporation Microsoft(R) MSXML 5.0 5.20.1072.0 [Explorer's DLLs] C:\WINDOWS\system32\actxprxy.dll ### ActiveX Interface Marshaling Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\wzcdlg.dll ### Wireless Zero Configuration Service UI Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\AVIFIL32.dll ### Microsoft AVI File support library Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\shmedia.dll ### Media File Property Extractor Shell Extension Microsoft Corporation Micros oft Windows Operating System 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\DRMClien.DLL ### DRM Client DLL Microsoft Corporation Microsoft DRM 9.00.00.3250 [Explorer's DLLs] C:\WINDOWS\system32\dxmasf.dll [Explorer's DLLs] C:\WINDOWS\system32\msdmo.dll [Explorer's DLLs] C:\WINDOWS\system32\MSVFW32.dll ### Microsoft Video for Windows DLL Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\shimgvw.dll ### Windows Picture and Fax Viewer Microsoft Corporation Microsoft Windows Opera ting System 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\shdoclc.dll ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\icm32.dll ### Microsoft Color Management Module (CMM) Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\mscms.dll ### Microsoft Color Matching System DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144cc f1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll

### Microsoft GDI+ Microsoft Corporation Microsoft Windows Operating System 5.1. 3102.2180 [Explorer's DLLs] C:\Program Files\Microsoft Office\Office12\msohevi.dll ### 2007 Microsoft Office component Microsoft Corporation 2007 Microsoft Offic e system 12.0.4518.1014 [Explorer's DLLs] C:\Program Files\Internet Download Manager\IDMIECC.dll ### IDM Browser Helper Object Internet Download Manager, Tonec Inc. Internet D ownload Manager Module 6, 4, 2, 1 [Explorer's DLLs] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell .dll ### PDF Shell Extension Adobe Systems, Inc. Adobe PDF Shell Extension 10.0.0.3 96 [Explorer's DLLs] C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlRe source.dll ### GrooveIntlResource Module Microsoft Corporation GrooveIntlResource Module 4.2.0.2623 [Explorer's DLLs] C:\WINDOWS\system32\Oleacc.dll ### Active Accessibility Core Component Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Explorer's DLLs] C:\WINDOWS\system32\odbcint.dll ### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat a Access Components 3.525.1117.0 [Explorer's DLLs] C:\WINDOWS\system32\DUSER.dll ### Windows DirectUser Engine Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\browselc.dll ### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\System32\davclnt.dll ### Web DAV Client DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\System32\NETUI1.dll ### NT LM UI Common Code - Networking classes Microsoft Corporation Microsoft W indows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\System32\NETUI0.dll ### NT LM UI Common Code - GUI Classes Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\System32\ntlanman.dll ### Microsoft Lan Manager Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\System32\drprov.dll ### Microsoft Terminal Server Network Provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\Program Files\Internet Download Manager\idmmkb.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager 6, 0 , 3, 4 [Explorer's DLLs] C:\WINDOWS\system32\BatMeter.dll ### Battery Meter Helper DLL Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\stobject.dll ### Systray shell service object Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\webcheck.dll ### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001. 18702 [Explorer's DLLs] C:\PROGRA~1\MICROS~2\Office12\GR326C~1.DLL ### GrooveMisc Module Microsoft Corporation GrooveMisc Module 4.2.0.2623 [Explorer's DLLs] C:\WINDOWS\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40 00.2435

[Explorer's DLLs] C:\WINDOWS\system32\ieframe.dll ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .18702 [Explorer's DLLs] C:\WINDOWS\system32\ntshrui.dll ### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\LINKINFO.dll ### Windows Volume Tracking Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\msxml3.dll ### MSXML 3.0 SP 5 Microsoft Corporation Microsoft(R) MSXML 3.0 SP 5 8.50.2162 .0 [Explorer's DLLs] C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL ### GrooveSystemServices Module Microsoft Corporation GrooveSystemServices Mod ule 4.2.0.2623 [Explorer's DLLs] C:\WINDOWS\system32\MSCTF.dll ### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.3319 [Explorer's DLLs] C:\WINDOWS\system32\msutb.dll ### MSUTB Server DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\themeui.dll ### Windows Theme API Microsoft Corporation Microsoft Windows Operating System 6 .00.2900.2180 [Explorer's DLLs] C:\Program Files\Internet Download Manager\IDMShellExt.dll ### Internet Download Manager module Tonec Inc. Internet Download Manager modu le 6,0,4,10 [Explorer's DLLs] C:\WINDOWS\system32\MSImg32.dll ### GDIEXT Client DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8. 0.50727.4053_x-ww_473666fd\ATL80.DLL ### ATL Module for Windows (Unicode) Microsoft Corporation Microsoft Visual Stu dio 2005 8.00.50727.4053 [Explorer's DLLs] C:\PROGRA~1\MICROS~2\Office12\GrooveNew.DLL ### GrooveNew Module Microsoft Corporation GrooveNew Module 4.2.0.2623 [Explorer's DLLs] C:\PROGRA~1\MICROS~2\Office12\GrooveUtil.DLL ### GrooveUtil Module Microsoft Corporation GrooveUtil Module 4.2.0.2623 [Explorer's DLLs] C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.0.2623 [Explorer's DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Explorer's DLLs] C:\WINDOWS\system32\SHDOCVW.dll ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.2987 [Explorer's DLLs] C:\WINDOWS\system32\BROWSEUI.dll ### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2995 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9. 0.30729.4148_x-ww_d495ac4e\MSVCP90.dll ### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio 2 008 9.00.30729.4148 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9. 0.30729.4148_x-ww_d495ac4e\MSVCR90.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 8 9.00.30729.4148 [Explorer's DLLs] C:\WINDOWS\system32\NETRAP.dll ### Net Remote Admin Protocol DLL Microsoft Corporation Microsoft Windows Operat

ing System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8. 0.50727.4053_x-ww_e6967989\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.4053 [Explorer's DLLs] C:\WINDOWS\system32\mlang.dll ### Multi Language Support DLL Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\System32\WINHTTP.dll ### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Explorer's DLLs] c:\windows\system32\POWRPROF.dll ### Power Profile Helper DLL Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Explorer's DLLs] c:\windows\system32\credui.dll ### Credential Manager User Interface Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.2180 [Explorer's DLLs] c:\windows\system32\netshell.dll ### Network Connections Shell Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\System32\WZCSAPI.DLL ### Wireless Zero Configuration service API Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\iertutil.dll ### Run time utility for Internet Explorer Microsoft Corporation Windows Intern et Explorer 8.00.6001.18702 [Explorer's DLLs] C:\WINDOWS\system32\urlmon.dll ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Explorer's DLLs] C:\WINDOWS\system32\WININET.dll ### Internet Extensions for Win32 Microsoft Corporation Windows Internet Explor er 8.00.6001.18702 [Explorer's DLLs] C:\WINDOWS\System32\CRYPTUI.dll ### Microsoft Trust UI Provider Microsoft Corporation Microsoft Windows Operatin g System 5.131.2600.2180 [Explorer's DLLs] c:\windows\system32\rtutils.dll ### Routing Utilities Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Explorer's DLLs] c:\windows\system32\ATL.DLL ### ATL Module for Windows XP (Unicode) Microsoft Corporation Microsoft (R) Vi sual C++ 6.05.2284 [Explorer's DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\AppPatch\AcGenral.DLL ### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\ShimEng.dll ### Shim Engine DLL Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\MSVCP60.dll ### Microsoft (R) C++ Runtime Library Microsoft Corporation Microsoft (R) Visu al C++ 6.02.3104.0 [Explorer's DLLs] C:\WINDOWS\system32\CLBCATQ.DLL ### Microsoft Corporation COM Services 03.00.00.4414 [Explorer's DLLs] C:\WINDOWS\system32\OLEAUT32.dll ### Microsoft Corporation 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\COMRes.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Explorer's DLLs] C:\WINDOWS\system32\midimap.dll

### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\MSACM32.dll ### Microsoft ACM Audio Filter Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\msacm32.drv ### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.0 [Explorer's DLLs] C:\WINDOWS\system32\NTMARTA.DLL ### Windows NT MARTA provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\wldap32.dll ### Win32 LDAP API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\wdmaud.drv ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\cscui.dll ### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\iphlpapi.dll ### IP Helper API Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.2180 [Explorer's DLLs] C:\WINDOWS\system32\SAMLIB.dll ### SAM Library DLL Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\rsaenh.dll ### Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft W indows Operating System 5.1.2600.2161 [Explorer's DLLs] C:\WINDOWS\system32\MPR.dll ### Multiple Provider Router DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\WINSPOOL.DRV ### Windows Spooler Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\cscdll.dll ### Offline Network Agent Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\WINMM.dll ### MCI API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.2180 [Explorer's DLLs] C:\WINDOWS\system32\uxtheme.dll ### Microsoft UxTheme Library Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\sxs.dll ### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .2180 [Explorer's DLLs] C:\WINDOWS\system32\WTSAPI32.dll ### Windows Terminal Server SDK APIs Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\msctfime.ime ### Microsoft Text Frame Work Service IME Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\Apphelp.dll ### Application Compatibility Client Library Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\ole32.dll ### Microsoft OLE for Windows Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595

b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll ### User Experience Controls Library Microsoft Corporation Microsoft Windows Ope rating System 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\comdlg32.dll ### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\ODBC32.dll ### Microsoft Data Access - ODBC Driver Manager Microsoft Corporation Microsof t Data Access Components 3.525.1117.0 [Explorer's DLLs] C:\WINDOWS\system32\COMCTL32.dll ### Common Controls Library Microsoft Corporation Microsoft Windows Operating Sy stem 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\SHLWAPI.dll ### Shell Light-weight Utility Library Microsoft Corporation Microsoft Windows O perating System 6.00.2900.2995 [Explorer's DLLs] C:\WINDOWS\system32\SHELL32.dll ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.2180 [Explorer's DLLs] C:\WINDOWS\system32\MSGINA.dll ### Windows NT Logon GINA DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\IMM32.DLL ### Windows XP IMM32 API Client DLL Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\WS2HELP.dll ### Windows Socket 2.0 Helper for Windows NT Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\WS2_32.dll ### Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\IMAGEHLP.dll ### Windows NT Image Helper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\WINTRUST.dll ### Microsoft Trust Verification APIs Microsoft Corporation Microsoft Windows Op erating System 5.131.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\WINSTA.dll ### Winstation Library Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\VERSION.dll ### Version Checking and File Installation Libraries Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\SETUPAPI.dll ### Windows Setup API Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\Secur32.dll ### Security Support Provider Interface Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\PSAPI.DLL ### Process Status Helper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\USERENV.dll ### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.21 80 [Explorer's DLLs] C:\WINDOWS\system32\NETAPI32.dll ### Net Win32 API DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\MSASN1.dll ### ASN.1 Runtime APIs Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180

[Explorer's DLLs] C:\WINDOWS\system32\GDI32.dll ### GDI Client DLL Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\USER32.dll ### Windows XP USER API Client DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\CRYPT32.dll ### Crypto API32 Microsoft Corporation Microsoft Windows Operating System 5.131. 2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\msvcrt.dll ### Windows NT CRT DLL Microsoft Corporation Microsoft Windows Operating System 7.0.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\RPCRT4.dll ### Remote Procedure Call Runtime Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\ADVAPI32.dll ### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\kernel32.dll ### Windows NT BASE API Client DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Explorer's DLLs] C:\WINDOWS\system32\ntdll.dll ### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.2180 [Running Services] ALG ### Internal Name: ALG. Status: service is running. Actual File: C:\WINDOWS\Sy stem32\alg.exe * Provides support for 3rd party protocol plug-ins for Internet C onnection Sharing and the Windows Firewall. Application Layer Gateway Service Mi crosoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] AudioSrv ### Internal Name: AudioSrv. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Manages audio devices for Windows-based pro grams. If this service is stopped, audio devices and effects will not function p roperly. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.2180 [Running Services] avgfws ### Internal Name: avgfws. Status: service is running. Actual File: "C:\Progra m Files\AVG\AVG10\avgfws.exe" * AVG Firewall Service AVG Firewall Service AVG Te chnologies CZ, s.r.o. AVG Internet Security 10.0.0.1350 [Running Services] avgwd ### Internal Name: avgwd. Status: service is running. Actual File: "C:\Program Files\AVG\AVG10\avgwdsvc.exe" * AVG Watchdog Service AVG Watchdog Service AVG T echnologies CZ, s.r.o. AVG Internet Security 10.0.0.1295 [Running Services] BITS ### Internal Name: BITS. Status: service is running. Actual File: C:\WINDOWS\s ystem32\svchost.exe -k netsvcs * Transfers data between clients and servers in t he background. If BITS is disabled, features such as Windows Update will not wor k correctly. Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [Running Services] Browser ### Internal Name: Browser. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k netsvcs * Maintains an updated list of computers on th e network and supplies this list to computers designated as browsers. If this se rvice is stopped, this list will not be updated or maintained. If this service i s disabled, any services that explicitly depend on it will fail to start. Generi c Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.2180 [Running Services] btwdins ### Internal Name: btwdins. Status: service is running. Actual File: C:\Progra

m Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe * Handles installation and re moval of Bluetooth devices. Bluetooth Support Server Broadcom Corporation. Bluet ooth Software 5.1.0.4200 [Running Services] CryptSvc ### Internal Name: CryptSvc. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k netsvcs * Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Roo t Service, which adds and removes Trusted Root Certification Authority certifica tes from this computer; and Key Service, which helps enroll this computer for ce rtificates. If this service is stopped, these management services will not funct ion properly. If this service is disabled, any services that explicitly depend o n it will fail to start. Generic Host Process for Win32 Services Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.2180 [Running Services] DcomLaunch ### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\WIN DOWS\system32\svchost -k DcomLaunch * Provides launch functionality for DCOM ser vices. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Running Services] Dhcp ### Internal Name: Dhcp. Status: service is running. Actual File: C:\WINDOWS\s ystem32\svchost.exe -k netsvcs * Manages network configuration by registering an d updating IP addresses and DNS names. Generic Host Process for Win32 Services M icrosoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] dmserver ### Internal Name: dmserver. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Detects and monitors new hard disk drives a nd sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configura tion information may become out of date. If this service is disabled, any servic es that explicitly depend on it will fail to start. Generic Host Process for Win 32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] Dnscache ### Internal Name: Dnscache. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k NetworkService * Resolves and caches Domain Name Syst em (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers . If this service is disabled, any services that explicitly depend on it will fa il to start. Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.2180 [Running Services] ERSvc ### Internal Name: ERSvc. Status: service is running. Actual File: C:\WINDOWS\ System32\svchost.exe -k netsvcs * Allows error reporting for services and applic tions running in non-standard environments. Generic Host Process for Win32 Servi ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] Eventlog ### Internal Name: Eventlog. Status: service is running. Actual File: C:\WINDO WS\system32\services.exe * Enables event log messages issued by Windows-based pr ograms and components to be viewed in Event Viewer. This service cannot be stopp ed. Services and Controller app Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] EventSystem ### Internal Name: EventSystem. Status: service is running. Actual File: C:\WI NDOWS\system32\svchost.exe -k netsvcs * Supports System Event Notification Servi ce (SENS), which provides automatic distribution of events to subscribing Compon ent Object Model (COM) components. If the service is stopped, SENS will close an d will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180

[Running Services] FastUserSwitchingCompatibility ### Internal Name: FastUserSwitchingCompatibility. Status: service is running. Actual File: C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides management f or applications that require assistance in a multiple user environment. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] helpsvc ### Internal Name: helpsvc. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Enables Help and Support Center to run on th is computer. If this service is stopped, Help and Support Center will be unavail able. If this service is disabled, any services that explicitly depend on it wil l fail to start. Generic Host Process for Win32 Services Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.2180 [Running Services] HidServ ### Internal Name: HidServ. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Enables generic input access to Human Interf ace Devices (HID), which activates and maintains the use of predefined hot butto ns on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If t his service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.2180 [Running Services] JavaQuickStarterService ### Internal Name: JavaQuickStarterService. Status: service is running. Actual File: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Fil es\Java\jre6\lib\deploy\jqs\jqs.conf" * Prefetches JRE files for faster startup of Java applets and applications Java(TM) Quick Starter Service Sun Microsystems , Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Running Services] lanmanserver ### Internal Name: lanmanserver. Status: service is running. Actual File: C:\W INDOWS\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh aring over the network for this computer. If this service is stopped, these func tions will be unavailable. If this service is disabled, any services that explic itly depend on it will fail to start. Generic Host Process for Win32 Services Mi crosoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] lanmanworkstation ### Internal Name: lanmanworkstation. Status: service is running. Actual File: C:\WINDOWS\system32\svchost.exe -k netsvcs * Creates and maintains client netwo rk connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly d epend on it will fail to start. Generic Host Process for Win32 Services Microsof t Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] LmHosts ### Internal Name: LmHosts. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k LocalService * Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Generic Host Process for Win32 Ser vices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] Netman ### Internal Name: Netman. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Manages objects in the Network and Dial-Up Co nnections folder, in which you can view both local area network and remote conne ctions. Generic Host Process for Win32 Services Microsoft Corporation Microsoft W indows Operating System 5.1.2600.2180 [Running Services] Nla ### Internal Name: Nla. Status: service is running. Actual File: C:\WINDOWS\sy stem32\svchost.exe -k netsvcs * Collects and stores network configuration and lo cation information, and notifies applications when this information changes. Gen eric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.2180 [Running Services] NVSvc

### Internal Name: NVSvc. Status: service is running. Actual File: C:\WINDOWS\ system32\nvsvc32.exe * Provides system and desktop level support to the NVIDIA d isplay driver NVIDIA Driver Helper Service, Version 175.90 NVIDIA Corporation NV IDIA Driver Helper Service, Version 175.90 6.14.11.7590 [Running Services] PlugPlay ### Internal Name: PlugPlay. Status: service is running. Actual File: C:\WINDO WS\system32\services.exe * Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will r esult in system instability. Services and Controller app Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.2180 [Running Services] PolicyAgent ### Internal Name: PolicyAgent. Status: service is running. Actual File: C:\WI NDOWS\system32\lsass.exe * Manages IP security policy and starts the ISAKMP/Oakl ey (IKE) and the IP security driver. LSA Shell (Export Version) Microsoft Corpor ation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] ProtectedStorage ### Internal Name: ProtectedStorage. Status: service is running. Actual File: C:\WINDOWS\system32\lsass.exe * Provides protected storage for sensitive data, s uch as private keys, to prevent access by unauthorized services, processes, or u sers. LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] RasMan ### Internal Name: RasMan. Status: service is running. Actual File: C:\WINDOWS \system32\svchost.exe -k netsvcs * Creates a network connection. Generic Host Pr ocess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] RemoteRegistry ### Internal Name: RemoteRegistry. Status: service is running. Actual File: C: \WINDOWS\system32\svchost.exe -k LocalService * Enables remote users to modify r egistry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any ser vices that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2 180 [Running Services] RpcSs ### Internal Name: RpcSs. Status: service is running. Actual File: C:\WINDOWS\ system32\svchost -k rpcss * Provides the endpoint mapper and other miscellaneous RPC services. Generic Host Process for Win32 Services Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.2180 [Running Services] SamSs ### Internal Name: SamSs. Status: service is running. Actual File: C:\WINDOWS\ system32\lsass.exe * Stores security information for local user accounts. LSA Sh ell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.2180 [Running Services] Schedule ### Internal Name: Schedule. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Enables a user to configure and schedule au tomated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Serv ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] seclogon ### Internal Name: seclogon. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unava ilable. If this service is disabled, any services that explicitly depend on it w ill fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] SENS ### Internal Name: SENS. Status: service is running. Actual File: C:\WINDOWS\s

ystem32\svchost.exe -k netsvcs * Tracks system events such as Windows logon, net work, and power events. Notifies COM+ Event System subscribers of these events. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Running Services] SharedAccess ### Internal Name: SharedAccess. Status: service is running. Actual File: C:\W INDOWS\system32\svchost.exe -k netsvcs * Provides network address translation, a ddressing, name resolution and/or intrusion prevention services for a home or sm all office network. Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.2180 [Running Services] ShellHWDetection ### Internal Name: ShellHWDetection. Status: service is running. Actual File: C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay hardware events. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] Spooler ### Internal Name: Spooler. Status: service is running. Actual File: C:\WINDOW S\system32\spoolsv.exe * Loads files to memory for later printing. Spooler SubSy stem App Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] srservice ### Internal Name: srservice. Status: service is running. Actual File: C:\WIND OWS\system32\svchost.exe -k netsvcs * Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Pr operties Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] SSDPSRV ### Internal Name: SSDPSRV. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k LocalService * Enables discovery of UPnP devices on yo ur home network. Generic Host Process for Win32 Services Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.2180 [Running Services] stisvc ### Internal Name: stisvc. Status: service is running. Actual File: C:\WINDOWS \system32\svchost.exe -k imgsvc * Provides image acquisition services for scanne rs and cameras. Generic Host Process for Win32 Services Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.2180 [Running Services] TapiSrv ### Internal Name: TapiSrv. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Provides Telephony API (TAPI) support for pr ograms that control telephony devices and IP based voice connections on the loca l computer and, through the LAN, on servers that are also running the service. G eneric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.2180 [Running Services] TermService ### Internal Name: TermService. Status: service is running. Actual File: C:\WI NDOWS\System32\svchost -k DComLaunch * Allows multiple users to be connected int eractively to a machine as well as the display of desktops and applications to r emote computers. The underpinning of Remote Desktop (including RD for Administra tors), Fast User Switching, Remote Assistance, and Terminal Server. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.2180 [Running Services] Themes ### Internal Name: Themes. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Provides user experience theme management. Ge neric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.2180 [Running Services] TrkWks ### Internal Name: TrkWks. Status: service is running. Actual File: C:\WINDOWS \system32\svchost.exe -k netsvcs * Maintains links between NTFS files within a c omputer or across computers in a network domain. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180

[Running Services] W32Time ### Internal Name: W32Time. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Maintains date and time synchronization on a ll clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O perating System 5.1.2600.2180 [Running Services] WebClient ### Internal Name: WebClient. Status: service is running. Actual File: C:\WIND OWS\system32\svchost.exe -k LocalService * Enables Windows-based programs to cre ate, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Servi ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] winmgmt ### Internal Name: winmgmt. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k netsvcs * Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not f unction properly. If this service is disabled, any services that explicitly depe nd on it will fail to start. Generic Host Process for Win32 Services Microsoft C orporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] wscsvc ### Internal Name: wscsvc. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Monitors system security settings and configu rations. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.2180 [Running Services] wuauserv ### Internal Name: wuauserv. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k netsvcs * Enables the download and installation of Wi ndows updates. If this service is disabled, this computer will not be able to us e the Automatic Updates feature or the Windows Update Web site. Generic Host Pro cess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.2180 [Running Services] WZCSVC ### Internal Name: WZCSVC. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Provides automatic configuration for the 802. 11 adapters Generic Host Process for Win32 Services Microsoft Corporation Micros oft Windows Operating System 5.1.2600.2180 [Running Services] YahooAUService ### Internal Name: YahooAUService. Status: service is running. Actual File: "C :\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe" * Keeps your favorite Yahoo! software up-to-date with the latest features, tools, and enhancements. Au toUpater Service Module Yahoo! Inc. Yahoo! AutoUpdater 1.0.0.53 [Uninstall] [Applications] :HKLM JDownloader 0.9=C:\Program Files\JDownloader\JDUninstall. exe ### 1489-3350-5074-6281 JDownloader AppWork GmbH JDownloader Uninstaller 0.9 [Applications] :HKLM Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0. 0.0)=C:\PROGRA~1\DIFX\B4723E9A0713E5B1\dpinst.exe /u C:\WINDOWS\system32\DRVSTOR E\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf ### 504244733D18C8F63FF584AEB290E3904E791693 Driver Package Installer Microsof t Corporation Driver Package Installer (DPInst) 2.1.1 [Applications] :HKLM Windows Driver Package - Nokia Modem (10/07/2010 4.6)=C: \PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia _blue_0E737C5DBBFCF603DB03D27D4DE0E55B5A00309C\nokia_bluetooth.inf ### 6DA48AFDE796708D5A4C9121A83E7617A63A9A15 Driver Package Installer Microsof t Corporation Driver Package Installer (DPInst) 2.1 [Applications] :HKLM AddressBook

### AddressBook [Applications] :HKLM Adobe Flash Player 10 ActiveX=C:\WINDOWS\system32\Macrome d\Flash\FlashUtil10p_ActiveX.exe -maintain activex ### Adobe Flash Player ActiveX Adobe Flash Player Installer/Uninstaller 10.2 r15 9 Adobe Systems, Inc. Flash Player Installer/Uninstaller 10,2,159,1 [Applications] :HKLM Adobe Flash Player 10 Plugin=C:\WINDOWS\system32\Macromed \Flash\FlashUtil10q_Plugin.exe -maintain plugin ### Adobe Flash Player Plugin Adobe Flash Player Installer/Uninstaller 10.3 r181 Adobe Systems, Inc. Flash Player Installer/Uninstaller 10,3,181,14 [Applications] :HKLM Adobe Photoshop CS4=C:\Program Files\Common Files\Adobe\I nstallers\faf656ef605427ee2f42989c3ad31b8\Setup.exe --uninstall=1 ### Adobe_faf656ef605427ee2f42989c3ad31b8 Adobe Setup Adobe Systems, Copyright 2005-2008 Adobe Setup 2,0,133,0 [Applications] :HKLM AlwaysUnloadDll ### AlwaysUnloadDll [Applications] :HKLM AVG 2011="C:\Program Files\AVG\AVG10\avgmfapx.exe" /AppMo de=SETUP /Uninstall ### AVG AVG Installer Application AVG Technologies CZ, s.r.o. AVG Internet Sec urity 10.0.0.1380 [Applications] :HKLM Branding ### Branding [Applications] :HKLM HDAUDIO Soft Data Fax Modem with SmartCP=C:\Program Files \CONEXANT\CNXT_MODEM_HDA_HSF\UIU32m.exe -U -IAcZUnM5k.INF ### CNXT_MODEM_HDA_HSF Conexant Universal Device Install/Uninstall x86 Applica tion Conexant Systems, Inc. Conexant Universal Device Install/Uninstall x86 Appl ication 4.0.42.0 [Applications] :HKLM Connection Manager ### Connection Manager [Applications] :HKLM DirectAnimation ### DirectAnimation [Applications] :HKLM DirectDrawEx ### DirectDrawEx [Applications] :HKLM DXM_Runtime ### DXM_Runtime [Applications] :HKLM Windows Driver Package - Nokia Modem (06/09/2010 7.01.0. 8)=C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\ nokbtmdm_A6F4DB5C7B968742C0CEC6C3D94F498B3F04B319\nokbtmdm.inf ### E5372C32E8562C76C24DBA6525002B1031495F34 Driver Package Installer Microsof t Corporation Driver Package Installer (DPInst) 2.1 [Applications] :HKLM Microsoft Office Enterprise 2007="C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall E NTERPRISE /dll OSETUP.DLL ### ENTERPRISE Microsoft Setup Bootstrapper Microsoft Corporation Microsoft Se tup Bootstrapper 12.0.4518.1014 [Applications] :HKLM Facemoods Toolbar="C:\Program Files\facemoods.com\facemoo ds\1.4.17.7\uninstall.exe" ### facemoods facemoods.com facemoods [Applications] :HKLM FileZilla Client 3.5.0=C:\Program Files\FileZilla FTP Cli ent\uninstall.exe ### FileZilla Client [Applications] :HKLM Fontcore ### Fontcore [Applications] :HKLM ICW ### ICW [Applications] :HKLM IDNMitigationAPIs ### IDNMitigationAPIs [Applications] :HKLM IE40 ### IE40 [Applications] :HKLM IE4Data ### IE4Data

[Applications] :HKLM IE5BAKEX ### IE5BAKEX [Applications] :HKLM ie7 ### ie7 [Applications] :HKLM Windows Internet Explorer 8="C:\WINDOWS\ie8\spuninst\spun inst.exe" ### ie8 Windows Service Pack Uninstall Microsoft Corporation Microsoft Windows O perating System 6.3.0015.0 [Applications] :HKLM IEData ### IEData [Applications] :HKLM Internet Download Manager=C:\Program Files\Internet Downl oad Manager\Uninstall.exe ### Internet Download Manager Internet Download Manager installer Tonec Inc. I nternet Download Manager installer 6, 4, 3, 1 [Applications] :HKLM KB884016 ### KB884016 [Applications] :HKLM High Definition Audio Driver Package - KB888111="C:\WINDO WS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe" ### KB888111WXPSP2 Windows Service Pack Uninstall Microsoft Corporation Micros oft Windows Operating System 6.1.0022.0 [Applications] :HKLM KB893803 ### KB893803 [Applications] :HKLM Windows Installer 3.1 (KB893803)="C:\WINDOWS\$MSI31Uninst all_KB893803v2$\spuninst\spuninst.exe" ### KB893803v2 Windows Service Pack Uninstall Microsoft Corporation Microsoft W indows Operating System 6.1.0022.4 [Applications] :HKLM Update for Windows XP (KB932823-v3)="C:\WINDOWS\$NtUninst allKB932823-v3$\spuninst\spuninst.exe" ### KB932823-v3 Windows Service Pack Uninstall Microsoft Corporation Microsoft Windows Operating System 6.2.0029.0 [Applications] :HKLM Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray="C:\WINDOWS\$NtUninstallKB952011$\spuninst\spuninst.exe" ### KB952011 Windows Service Pack Uninstall Microsoft Corporation Microsoft Win dows Operating System 6.3.0004.1 [Applications] :HKLM Launch Manager=C:\WINDOWS\UnInst32.exe QtZgAcer.UNI ### LManager Uninstall Application Dritek System Inc. Dritek System Inc. Unins tall Application 1, 5, 0, 1803 [Applications] :HKLM MD5 Tool=C:\Program Files\MD5 Tool\Uninstall.exe ### MD5 Tool [Applications] :HKLM Microsoft .NET Framework 2.0=C:\WINDOWS\Microsoft.NET\Fra mework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe ### Microsoft .NET Framework 2.0 External Installer Microsoft Corporation Micr osoft Visual Studio 2005 8.0.50727.42 [Applications] :HKLM MobileOptionPack ### MobileOptionPack [Applications] :HKLM Mozilla Firefox (4.0b1)=C:\Program Files\Mozilla Firefox 4.0 Beta 1\uninstall\helper.exe ### Mozilla Firefox (4.0b1) Firefox Helper Mozilla Corporation Firefox 4.0b1 [Applications] :HKLM MPlayer2 ### MPlayer2 [Applications] :HKLM MSI30-Beta1 ### MSI30-Beta1 [Applications] :HKLM MSI30-Beta2 ### MSI30-Beta2 [Applications] :HKLM MSI30-KB884016 ### MSI30-KB884016 [Applications] :HKLM MSI30-RC1 ### MSI30-RC1 [Applications] :HKLM MSI30-RC2 ### MSI30-RC2

[Applications] :HKLM MSI30a-KB884016 ### MSI30a-KB884016 [Applications] :HKLM MSI31-Beta ### MSI31-Beta [Applications] :HKLM MSI31-RC1 ### MSI31-RC1 [Applications] :HKLM NetMeeting ### NetMeeting [Applications] :HKLM NLSDownlevelMapping ### NLSDownlevelMapping [Applications] :HKLM Nokia PC Suite=C:\Documents and Settings\All Users\Applic ation Data\Installations\{F38FD0E4-B991-462B-873D-F2115EADD093}\Nokia_PC_Suite_e ng_web.exe ### Nokia PC Suite Installer Application Installer Application 2, 2, 0, 0 [Applications] :HKLM Notepad++=C:\Program Files\Notepad++\uninstall.exe ### Notepad++ [Applications] :HKLM NVIDIA Drivers=C:\WINDOWS\system32\nvuninst.exe Uninstall GUI ### NVIDIA Drivers NVIDIA Uninstaller Utility NVIDIA Corporation NVIDIA Corpor ation 1 , 3 , 21 , 2 [Applications] :HKLM OutlookExpress ### OutlookExpress [Applications] :HKLM PCHealth=rundll32.exe setupapi.dll,InstallHinfSection Def aultUninstall 132 C:\WINDOWS\INF\PCHealth.inf ### PCHealth [Applications] :HKLM Picasa 3="C:\Program Files\Google\Picasa3\Uninstall.exe" ### Picasa 3 [Applications] :HKLM Player="C:/\uninstall.exe" "/U:C:/\Uninstall\uninstall.xm l" ### Player1.0 Setup Application Indigo Rose Corporation Setup Factory 8.0 Runt ime 8.2.1.0 [Applications] :HKLM SchedulingAgent ### SchedulingAgent [Applications] :HKLM UnHackMe 5.99 release="C:\Program Files\UnHackMe\unins000 .exe" ### UnHackMe_is1 Setup/Uninstall Inno Setup 0.0.0.0 [Applications] :HKLM Torrent="C:\Program Files\uTorrent\uTorrent.exe" /UNINSTAL L ### uTorrent Torrent BitTorrent, Inc. Torrent 2.2.1.25302 [Applications] :HKLM VLC media player 1.1.9=C:\Program Files\VideoLAN\VLC\unin stall.exe ### VLC media player [Applications] :HKLM WampServer 2.1="c:\wamp\unins000.exe" ### WampServer 2_is1 Setup/Uninstall [Applications] :HKLM WinRAR 4.00 (32-bit)=C:\Program Files\WinRAR\uninstall.ex e ### WinRAR archiver [Applications] :HKLM Yahoo! Toolbar=C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE ### Yahoo! Companion Yahoo! Toolbar Uninstall Setup Yahoo! Inc. [Applications] :HKLM Yahoo! Messenger=C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE / U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG ### Yahoo! Messenger [Applications] :HKLM Yahoo! Software Update=C:\PROGRA~1\Yahoo!\SOFTWA~1\UNINST ~1.EXE ### Yahoo! Software Update Yahoo! Software Update Setup Yahoo! Inc. [Applications] :HKLM Yahoo! Toolbar=C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE ### Yahoo! Toolbar Yahoo! Toolbar Uninstall Setup Yahoo! Inc. [Applications] :HKLM Adobe Color NA Recommended Settings CS4=MsiExec.exe /I{00 ADFB20-AE75-46F4-AD2C-F48B15AC3100} ### {00ADFB20-AE75-46F4-AD2C-F48B15AC3100} Windows installer Microsoft Corporat

ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Update Manager CS4=MsiExec.exe /I{05308C4E-7285-406 6-BAE3-6B50DA6ED755} ### {05308C4E-7285-4066-BAE3-6B50DA6ED755} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Extension Manager CS4=MsiExec.exe /I{054EFA56-2AC148F4-A883-0AB89874B972} ### {054EFA56-2AC1-48F4-A883-0AB89874B972} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Core Temp version 0.99.8="C:\Program Files\Core Temp\unin s000.exe" ### {086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1 Setup/Uninstall [Applications] :HKLM kuler=MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243 } ### {098727E1-775A-4450-B573-3F441F1CA243} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Color JA Extra Settings CS4=MsiExec.exe /I{0D6013AB -A0C7-41DC-973C-E93129C9A29F} ### {0D6013AB-A0C7-41DC-973C-E93129C9A29F} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Setup=MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B 433F23} ### {0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe CSI CS4=MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80 AD292DAF} ### {0F723FC1-7606-4867-866C-CE80AD292DAF} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Anchor Service CS4=MsiExec.exe /I{1618734A-3957-4AD D-8199-F973763109A8} ### {1618734A-3957-4ADD-8199-F973763109A8} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM AdobeColorCommonSetRGB=MsiExec.exe /I{16E6D2C1-7C90-43098EC4-D2212690AAA4} ### {16E6D2C1-7C90-4309-8EC4-D2212690AAA4} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 .4148=MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989} ### {1F1C2DFC-2D24-3E06-BCB8-725134ADF989} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM AVG 2011=MsiExec.exe /I{23DA4222-E517-42B3-8F97-9CFD49E2A 732} ### {23DA4222-E517-42B3-8F97-9CFD49E2A732} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Java(TM) 6 Update 25=MsiExec.exe /X{26A24AE4-039D-4CA4-87 B4-2F83216025FF} ### {26A24AE4-039D-4CA4-87B4-2F83216025FF} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM WebFldrs XP ### {350C97B0-3D7C-4EE8-BAA9-00BCB3D54227} [Applications] :HKLM PDF Settings CS4=MsiExec.exe /I{35D94F92-1D3A-43C5-8605-E A268B1A7BD9} ### {35D94F92-1D3A-43C5-8605-EA268B1A7BD9} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM WL230USB Wireless B+G USB 2.0 Adapter=C:\Program Files\In stallShield Installation Information\{3660D4AD-6874-4684-A0D5-179482650B86}\setu p.exe -runfromtemp -l0x0009 -removeonly ### {3660D4AD-6874-4684-A0D5-179482650B86} Setup.exe Macrovision Corporation I nstallShield 12.0 [Applications] :HKLM Adobe XMP Panels CS4=MsiExec.exe /I{3A4E8896-C2E7-4084-A4

A4-B8FD1894E739} ### {3A4E8896-C2E7-4084-A4A4-B8FD1894E739} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Color - Photoshop Specific CS4=MsiExec.exe /I{3D2C9 DE6-9ADE-4252-A241-E43723B0CE02} ### {3D2C9DE6-9ADE-4252-A241-E43723B0CE02} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe WinSoft Linguistics Plugin=MsiExec.exe /I{3DA8DF9A044E-46C4-8531-DEDBB0EE37FF} ### {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Nokia Connectivity Cable Driver=MsiExec.exe /I{4216D328-0 FE8-48B8-85B8-BD300E6F080F} ### {4216D328-0FE8-48B8-85B8-BD300E6F080F} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM HiJackThis=MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4 883D7} ### {45A66726-69BC-466B-A7A4-12FCBA4883D7} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Service Manager Extension=MsiExec.exe /I{4943EFF5-2 29F-435D-BEA9-BE3CAEA783A7} ### {4943EFF5-229F-435D-BEA9-BE3CAEA783A7} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Java Auto Updater ### {4A03706F-666A-4037-7777-5F2748764D10} [Applications] :HKLM Adobe Color EU Extra Settings CS4=MsiExec.exe /I{5570C7F0 -43D0-4916-8A9E-AEDD52FA86F4} ### {5570C7F0-43D0-4916-8A9E-AEDD52FA86F4} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM QuickTime=MsiExec.exe /I{57752979-A1C9-4C02-856B-FBB27AC4 E02C} ### {57752979-A1C9-4C02-856B-FBB27AC4E02C} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Color Video Profiles CS CS4=MsiExec.exe /I{63C24A08 -70F3-4C8E-B9FB-9F21A903801D} ### {63C24A08-70F3-4C8E-B9FB-9F21A903801D} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Photoshop CS4 Support=MsiExec.exe /I{63E5CDBF-82144F03-84F8-CD3CE48639AD} ### {63E5CDBF-8214-4F03-84F8-CD3CE48639AD} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM AdobeColorCommonSetCMYK=MsiExec.exe /I{68243FF8-83CA-466B -B2B8-9F99DA5479C4} ### {68243FF8-83CA-466B-B2B8-9F99DA5479C4} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Apple Software Update=MsiExec.exe /I{6956856F-B6B3-4BE0-B A0B-8F495BE32033} ### {6956856F-B6B3-4BE0-BA0B-8F495BE32033} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM MSVC80_x86_v2=MsiExec.exe /I{6D3245B1-8DB8-4A23-9CD2-2C90 F40ABAF6} ### {6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft .NET Framework 2.0 ### {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} [Applications] :HKLM Adobe Type Support CS4=MsiExec.exe /I{820D3F45-F6EE-4AAF81EF-CE21FF21D230} ### {820D3F45-F6EE-4AAF-81EF-CE21FF21D230} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Visual C++ 2005 Redistributable=MsiExec.exe /X{

837b34e3-7c30-493c-8f6a-2b0f04e2912c} ### {837b34e3-7c30-493c-8f6a-2b0f04e2912c} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Bridge CS4=MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2 BAC22E093E0} ### {83877DB1-8B77-45BC-AB43-2BAC22E093E0} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Suite Shared Configuration CS4=MsiExec.exe /I{842B4B72-9E 8F-4962-B3C1-1C422A5C4434} ### {842B4B72-9E8F-4962-B3C1-1C422A5C4434} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM WIDCOMM Bluetooth Software=MsiExec.exe /X{84814E6B-2581-4 6EC-926A-823BD1C670F6} ### {84814E6B-2581-46EC-926A-823BD1C670F6} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Software Update for Web Folders (English) 12 ### {90120000-0010-0409-0000-0000000FF1CE} [Applications] :HKLM Microsoft Office Access MUI (English) 2007=MsiExec.exe /X {90120000-0015-0409-0000-0000000FF1CE} ### {90120000-0015-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Excel MUI (English) 2007=MsiExec.exe /X{ 90120000-0016-0409-0000-0000000FF1CE} ### {90120000-0016-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office PowerPoint MUI (English) 2007=MsiExec.ex e /X{90120000-0018-0409-0000-0000000FF1CE} ### {90120000-0018-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Publisher MUI (English) 2007=MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE} ### {90120000-0019-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Outlook MUI (English) 2007=MsiExec.exe / X{90120000-001A-0409-0000-0000000FF1CE} ### {90120000-001A-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Word MUI (English) 2007=MsiExec.exe /X{9 0120000-001B-0409-0000-0000000FF1CE} ### {90120000-001B-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Proof (English) 2007=MsiExec.exe /X{9012 0000-001F-0409-0000-0000000FF1CE} ### {90120000-001F-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Proof (French) 2007=MsiExec.exe /X{90120 000-001F-040C-0000-0000000FF1CE} ### {90120000-001F-040C-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Proof (Spanish) 2007=MsiExec.exe /X{9012 0000-001F-0C0A-0000-0000000FF1CE} ### {90120000-001F-0C0A-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Proofing (English) 2007=MsiExec.exe /X{9 0120000-002C-0409-0000-0000000FF1CE} ### {90120000-002C-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Enterprise 2007=MsiExec.exe /X{901200000030-0000-0000-0000000FF1CE} ### {90120000-0030-0000-0000-0000000FF1CE} Windows installer Microsoft Corporat

ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office InfoPath MUI (English) 2007=MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE} ### {90120000-0044-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Shared MUI (English) 2007=MsiExec.exe /X {90120000-006E-0409-0000-0000000FF1CE} ### {90120000-006E-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office OneNote MUI (English) 2007=MsiExec.exe / X{90120000-00A1-0409-0000-0000000FF1CE} ### {90120000-00A1-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Of fice programs=MsiExec.exe /X{90120000-00B2-0409-0000-0000000FF1CE} ### {90120000-00B2-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Groove MUI (English) 2007=MsiExec.exe /X {90120000-00BA-0409-0000-0000000FF1CE} ### {90120000-00BA-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Groove Setup Metadata MUI (English) 2007 =MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE} ### {90120000-0114-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Shared Setup Metadata MUI (English) 2007 =MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE} ### {90120000-0115-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Microsoft Office Access Setup Metadata MUI (English) 2007 =MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE} ### {90120000-0117-0409-0000-0000000FF1CE} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM AVG 2011=MsiExec.exe /I{91D2C605-AD2B-44C8-A0A1-9B116B3C9 1CB} ### {91D2C605-AD2B-44C8-A0A1-9B116B3C91CB} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Linguistics CS4=MsiExec.exe /I{931AB7EA-3656-4BB7-8 64D-022B09E3DD67} ### {931AB7EA-3656-4BB7-864D-022B09E3DD67} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe CMaps CS4=MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-59 2635E8A191} ### {94D398EB-D2FD-4FD1-B8C4-592635E8A191} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Reader X=MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-AA0 000000001} ### {AC76BA86-7AD7-1033-7B44-AA0000000001} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Connect=MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C61 8D} ### {B29AD377-CC12-490A-A480-1452337C618D} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Photoshop CS4=MsiExec.exe /I{B65BA85C-0A27-4BC0-A22 D-A66F0E5B9494} ### {B65BA85C-0A27-4BC0-A22D-A66F0E5B9494} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Output Module=MsiExec.exe /I{BB4E33EC-8181-4685-96F 7-8554293DEC6A} ### {BB4E33EC-8181-4685-96F7-8554293DEC6A} Windows installer Microsoft Corporat

ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Default Language CS4=MsiExec.exe /I{C52E3EC1-048C-4 5E1-8D53-10B0C6509683} ### {C52E3EC1-048C-45E1-8D53-10B0C6509683} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Photoshop Camera Raw=MsiExec.exe /I{CC75AB5C-2110-4A7F-AF 52-708680D22FE8} ### {CC75AB5C-2110-4A7F-AF52-708680D22FE8} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM USB 2.0 Card Reader=C:\Program Files\InstallShield Instal lation Information\{D10CB652-9332-4242-B7A9-2D61570144F7}\setup.exe -runfromtemp -l0x0009 -removeonly ### {D10CB652-9332-4242-B7A9-2D61570144F7} Setup.exe Macrovision Corporation I nstallShield 12.0 [Applications] :HKLM PC Connectivity Solution=MsiExec.exe /I{D4AEC53C-1720-41D 9-B6D7-6A60DE62D444} ### {D4AEC53C-1720-41D9-B6D7-6A60DE62D444} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Photoshop CS4=MsiExec.exe /I{E4848436-0345-47E2-B64 8-8B522FCDA623} ### {E4848436-0345-47E2-B648-8B522FCDA623} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Apple Application Support=MsiExec.exe /I{EE6097DD-05F4-41 78-9719-D3170BF098E8} ### {EE6097DD-05F4-4178-9719-D3170BF098E8} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Search for Help=MsiExec.exe /I{F0E64E2E-3A60-40D8-A 55D-92F6831875DA} ### {F0E64E2E-3A60-40D8-A55D-92F6831875DA} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Realtek High Definition Audio Driver=RunDll32 C:\PROGRA~1 \COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Progr am Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108F E7DBC}\Setup.exe" -l0x9 -removeonly ### {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} InstallShield (R) Ctor DLL Macrovis ion Corporation InstallShield 11.50 [Applications] :HKLM Nokia PC Suite=MsiExec.exe /I{F38FD0E4-B991-462B-873D-F21 15EADD093} ### {F38FD0E4-B991-462B-873D-F2115EADD093} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Atheros for Acer Driver 5.3.0.67_Foxconn Installation Pro gram=C:\Program Files\InstallShield Installation Information\{F70D5D8C-C1AF-40B3 -9E47-3BB5F19EEA3A}\Setup.exe -runfromtemp -l0x0009 -removeonly ### {F70D5D8C-C1AF-40B3-9E47-3BB5F19EEA3A} Setup.exe Macrovision Corporation I nstallShield 12.0 [Applications] :HKLM Adobe ExtendScript Toolkit CS4=MsiExec.exe /I{F8EF2B3F-C3 45-4F20-8FE4-791A20333CD5} ### {F8EF2B3F-C345-4F20-8FE4-791A20333CD5} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe PDF Library Files CS4=MsiExec.exe /I{F93C84A6-0DC642AF-89FA-776F7C377353} ### {F93C84A6-0DC6-42AF-89FA-776F7C377353} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [Applications] :HKLM Adobe Fonts All=MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE 86D1032794} ### {FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794} Windows installer Microsoft Corporat ion Windows Installer - Unicode 3.1.4000.1823 [MD5] [ -2][0 -1 ]C:\DOCUME~1\HANS\LOCALS~1\TEMP\ALSYSIO.SYS

[89F299B3A7A436665A2BEF8B9AB849DA][1 1011768 CD16669115F713D6972CD2AA5B3 BAA7AE120B651 ]C:\DOCUMENTS AND SETTINGS\HANS\LOCAL SETTINGS\APPLICATION DATA \GOOGLE\CHROME\APPLICATION\CHROME.EXE [1264F787E46DC572FA274CA09B446E01][1 44344 ]C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL [786DD1892B553EFE5A004AC39775C851][1 2210608 ]C:\PROGRA~1\MICROS~2\OFFICE12\GRA8E1~1.DLL [9FE614353486E73D75B75985D33C2040][1 2573080 B7D01D85941894C403762A286F8 D37CCC06C8E05 ]C:\PROGRA~1\UNHACKME\REGRUNINFO.EXE [ -2][0 -1 ]C:\PROGRA~1\YAHOO!\COMPANION\INSTALLS\CPN0\YT.DLL [7B43567B4C32AD7ADED537CD3B1342B9][1 566592 ]C:\PROGRAM FILES\APPLE SOFTWARE UPDATE\SOFTWAREUPDATE.EXE [61B1A2BBFC9BF4AE7FC5C6D845FCD87F][1 750432 393639F51CF8C2B20287F826B82 1D5EF4CE2B1B5 ]C:\PROGRAM FILES\AVG\AVG10\AVGAM.EXE [9EFAD1ACC1F1E7CB3F495161F94854FF][1 656736 4B86F7322F2D7610E34A7B52B02 D4266B411E108 ]C:\PROGRAM FILES\AVG\AVG10\AVGCHSVX.EXE [2FE694541C5D0D2A874CCC222BBFC7D0][1 351072 D62BC7AD7F29C3243A1DFAEE00E 4588915FDD3E2 ]C:\PROGRAM FILES\AVG\AVG10\AVGCSRVX.EXE [2F0C5AE2352F22B587EDC2829C971262][1 2708024 126C7F590F349DDEE4562FF9F4A 745C8DB3146F8 ]C:\PROGRAM FILES\AVG\AVG10\AVGFWS.EXE [0DA06277AA7F458211DFC59329949193][1 1080672 5FCA9E909B64576530978424CEF A1333775767D1 ]C:\PROGRAM FILES\AVG\AVG10\AVGNSX.EXE [A5F0605634DD7F3A1B1564DB021BC7C6][1 658784 0BB6AE2A7DBC6E13AC8800775C9 8DBB24213F401 ]C:\PROGRAM FILES\AVG\AVG10\AVGRSX.EXE [6FBFA21869A09EDE8F3A2427BAEBCBDB][1 207200 C1DA2F7B3DAD29F5543EB552D52 A358D7ECD3FC5 ]C:\PROGRAM FILES\AVG\AVG10\AVGSE.DLL [FC2BC51120A945F7C70376495E4E7737][1 269520 4A20A001B5C801C30A2CAF7E892 B69083DA7A934 ]C:\PROGRAM FILES\AVG\AVG10\AVGWDSVC.EXE [37DFF4CEE590B6D081EFE18FB2C377DB][1 7398752 54844AEA2E6E0545D027038A62E 1929765FC2A73 ]C:\PROGRAM FILES\AVG\AVG10\IDENTITY PROTECTION\AGENT\BIN\AVGID SAGENT.EXE [BAD6BEA0DE1F69C82BDB74378CE0C20A][1 932288 ]C:\PROGRAM FILES\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE [1F63900E2EB00101B9ACA2B7A870704E][1 655624 ]C:\PROGRAM FILES\COMMON FILES\MACROVISION SHARED\FLEXNET PUBLI SHER\FNPLICENSINGSERVICE.EXE [9E7370CC3D6A43942433F85D0E2BBDD8][1 873216 ]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\HELP\HXDS.DLL [84DE1DD996B48B05ACE31AD015FA108A][1 441136 ]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE12\ODSERV .EXE [5A432A042DAE460ABE7199B758E8606C][1 145184 ]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SOURCE ENGINE\O SE.EXE [C1B577B2169900F4CF7190C39F085794][1 136120 ]C:\PROGRAM FILES\GOOGLE\COMMON\GOOGLE UPDATER\GOOGLEUPDATERSER VICE.EXE [0CB4DEF075F810EA1E98DD30B79DB435][2 3289088 9361BF60E3CB956FB8BEB07F0C7 31B50E2C04175 ]C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EXE [19C7EF6C70A60EA8B2A1A7C4EAD30E06][1 202160 ]C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL [C2752CFFB1418B0B2174EFF338414934][1 67680 ]C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMSHELLEXT.DLL [207B16FA69F61D1895F8D8532F587E4B][1 263600 ]C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEMONITOR.EXE [B60DDDD2D63CE41CB8C487FCFBB6419E][1 638816 ]C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE [364F7A2B4B535659F3B50DE5E5C20123][1 145184 A1D964E6A4BE9082F35DE78BF4F 566DCDD40DF6A ]C:\PROGRAM FILES\JAVA\JRE6\BIN\JAVAW.EXE

[11C3EFB4BAC41175D03B1595DB1A4A4F][1 153376 B8F35D861F7A171D7D3659F7623 9C4C81F412220 ]C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE [1DB3F0391EB3253BE17D2451CDA725B9][1 135384 93088A285963BDE479D53DAD067 3D9353603ED92 ]C:\PROGRAM FILES\MD5 TOOL\DLLREG.DLL [FAFE367D032ED82E9332B4C741A20216][1 65824 ]C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVEAUDITSERVICE. EXE [D91AFB6D2A0DA7539B74FB5838775D94][1 98632 ]C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\ONENOTEM.EXE [86A591473178AA6B6400A8DA225DF04F][2 296448 ]C:\PROGRAM FILES\NOTEPAD++\NPPSHELL_04.DLL [7D3903AF48E6C1DC2704EAFCB608D031][2 628736 ]C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\SERVICELAYER.EXE [ -1][2 1511458 ]C:\PROGRAM FILES\SMADAV\SM?RTP.EXE [AD25E399AD035C98B32D32CD745A3313][1 594200 34A42F3B967273D0719CE78224C 05C2D9D32B6E6 ]C:\PROGRAM FILES\UNHACKME\HACKMON.EXE [09840ED501636847343E9FD77B059CBE][1 8137536 C5E71E287F85EDDF241A708BB1D B23E12B48F262 ]C:\PROGRAM FILES\UNHACKME\REANIMATOR.EXE [1A5655B327C5FCD0ECD992D603283679][1 1397528 596F0AEC5A14F11E4715DA618BD AF1AAD0C33F2A ]C:\PROGRAM FILES\UNHACKME\UNHACKME.EXE [BB2FCFA2415D0F08653157D8E998D342][1 399736 76CB0DEF3EE130F4BDDB6893ACB CD6A7284F336B ]C:\PROGRAM FILES\UTORRENT\UTORRENT.EXE [89984415BF772D2C8595EEBC475BCFDB][2 107520 403F073F194AABB7A8DC4A37778 0CE14A3CDCAD2 ]C:\PROGRAM FILES\VIDEOLAN\VLC\VLC.EXE [E88D7C9F4C4F9DE849D9E5C59954812F][1 264800 ]C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE [F0543ACEEB5CD8821469958C9F3DD9A4][1 214528 ]C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.EXE [8DA7DE8B3AC78C784BE73DD9C20C786C][2 140288 32C15505953C4110E1B5E0FE104 81E55F00C151A ]C:\PROGRAM FILES\WINRAR\RAREXT.DLL [DD0042F0C3B606A6A8B92D49AFB18AD6][1 602392 ]C:\PROGRAM FILES\YAHOO!\SOFTWAREUPDATE\YAHOOAUSERVICE.EXE [97ED5AA5FBAA105EF614B8C240B62BA1][2 24635 ]C:\WAMP\BIN\APACHE\APACHE2.2.8\BIN\HTTPD.EXE [6D9C3B76768D5B2E72F0CB9E237A9D82][2 5750784 ]C:\WAMP\BIN\MYSQL\MYSQL5.0.51B\BIN\MYSQLD-NT.EXE [A0732187050030AE399B241436565E64][1 1032192 ]C:\WINDOWS\EXPLORER.EXE [95F11851AA8794B9716CB1EA39D00FB5][1 208896 ]C:\WINDOWS\INF\UNREGMP2.EXE [D33C507942299753868204CC7642FA27][1 29896 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\ASPNET_STATE.EXE [3C4D595E7F9B747325AEF28B4ADCAAE5][1 66240 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE [3BA608F5B5EB81B972E047FCC1813BFE][1 768512 ]C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HELPCTR.EXE [4FD22142F54692463A7B98B7DE175573][1 158208 ]C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.EXE [8827911A8C37E40C027CBFC88E69D967][1 38912 ]C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\PCHSVC.DLL [1AFF244CA134956C54474F4E2433E4CE][1 616960 ]C:\WINDOWS\SYSTEM32\ADVAPI32.DLL [F1958FBF86D5C004CF19A5951A9514B7][1 44544 ]C:\WINDOWS\SYSTEM32\ALG.EXE [C7AE0FD3867DB0D42B03B73C18F3D671][1 17408 ]C:\WINDOWS\SYSTEM32\ALRSVC.DLL [9C3C12975C97119412802B181FBEEFFE][1 167936 ]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL [DB66DB626E4882EBEF55F136F12C1829][1 42496

]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL [CC306BF581446D5E443EAE5B3BB900F0][6 12288 ]C:\WINDOWS\SYSTEM32\BOOTVID.DLL [E3CFCCDDA4EDD1D0DC9168B2E18F27B8][1 77312 ]C:\WINDOWS\SYSTEM32\BROWSER.DLL [09ECDBADCFA1E4AEE002F480B2CB54ED][2 106496 ]C:\WINDOWS\SYSTEM32\BTHCRP.DLL [3192BD04D032A9C4A85A3278C268A13A][1 5632 ]C:\WINDOWS\SYSTEM32\CISVC.EXE [C8DEC22C4137D7A90F8BDF41CA4B82AE][1 33280 ]C:\WINDOWS\SYSTEM32\CLIPSRV.EXE [7105749E78925FDFFD078DD54A8C2B70][1 47104 ]C:\WINDOWS\SYSTEM32\CNBJMON.DLL [6728270CB7DBB776ED086F5AC4C82310][1 792064 ]C:\WINDOWS\SYSTEM32\COMRES.DLL [EFC958396A7A7EF7E6D4A52B97512E18][1 597504 ]C:\WINDOWS\SYSTEM32\CRYPT32.DLL [CAD4AA32E7ECA00C23CC39C0EB833F9D][1 63488 ]C:\WINDOWS\SYSTEM32\CRYPTNET.DLL [10654F9DDCEA9C46CFB77554231BE73B][1 60416 ]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL [587729679B4FE04CE06A5C61D6C56DCD][1 101888 ]C:\WINDOWS\SYSTEM32\CSCDLL.DLL [51230212AE7F8159A90F06A7EA30DD8A][1 326656 ]C:\WINDOWS\SYSTEM32\CSCUI.DLL [24232996A38C0B0CF151C2140AE29FC8][1 15360 ]C:\WINDOWS\SYSTEM32\CTFMON.EXE [42803EC60803C1A0754671E9183458F1][1 1179648 ]C:\WINDOWS\SYSTEM32\D3D8.DLL [8D9210E9858D525646251DFA1FE37EBE][1 8192 ]C:\WINDOWS\SYSTEM32\D3D8THK.DLL [7ED462F353B3D915A418A689FA881F96][1 266240 ]C:\WINDOWS\SYSTEM32\DDRAW.DLL [D22495C64B312AD1FDDD9832BE6052BE][6 8 ]C:\WINDOWS\SYSTEM32\DESKTOP_.INI [CB6CA3E5261D65F6F809EED23BF167AA][1 111104 ]C:\WINDOWS\SYSTEM32\DHCPCSVC.DLL [DD87DB7387B9EB441C5674888A0D840C][1 5120 ]C:\WINDOWS\SYSTEM32\DLLHOST.EXE [554C7CB178FE3BD12450B81AD63ADBC3][1 224768 ]C:\WINDOWS\SYSTEM32\DMADMIN.EXE [1639D9964C9E1B2ECCA95C8217D3E70D][1 23552 ]C:\WINDOWS\SYSTEM32\DMSERVER.DLL [7379DE06FD196E396A00AA97B990C00D][1 45568 ]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL [A10C7534F7223F4A73A948967D00E69B][1 187776 ]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS [9859C0F6936E723E4892D7141B1327D5][6 11648 ]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEC.SYS [841F385C6CFAF66B58FBD898722BB4F0][1 142464 ]C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS [5AC495F4CB807B2B98AD2AD591E6D92E][1 138496 ]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS [DAD16A9D5C873E7219E6B43802ED316A][1 36992 ]C:\WINDOWS\SYSTEM32\DRIVERS\amdk6.sys [680AD1C1BB16239E28D8F33A54A7A3C7][1 37376 ]C:\WINDOWS\SYSTEM32\DRIVERS\amdk7.sys [F0D692B0BFFB46E30EB3CEA168BBC49F][1 60800 ]C:\WINDOWS\SYSTEM32\DRIVERS\arp1394.sys [02000ABF34AF4C218C35D257024807D6][1 14336

]C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS [CDFE4411A69C224BD1D11B2DA92DAC51][1 95360 ]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS [EC88DA854AB7D7752EC8BE11A741BB7F][1 59904 ]C:\WINDOWS\SYSTEM32\DRIVERS\ATMARPC.SYS [39A0A59180F19946374275745B21AEBA][6 31360 ]C:\WINDOWS\SYSTEM32\DRIVERS\atmepvc.sys [0128E78FE835F074E469F03DB681CA9E][1 55936 ]C:\WINDOWS\SYSTEM32\DRIVERS\atmlane.sys [E7EF69B38D17BA01F914AE8F66216A38][6 352256 ]C:\WINDOWS\SYSTEM32\DRIVERS\atmuni.sys [D9F724AA26C010A217C97606B160ED68][6 3072 ]C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS [0C5941AF0B6BF2FDF378937392865217][1 30432 ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGFWDX.SYS [C403E7F715BB0A851A9DFAE16EC4AE42][1 134480 B9FBA97D1956288D80A6EEEC563 2F223811B063A ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGIDSDRIVER.SYS [1AF676DB3F3D4CC709CFAB2571CF5FC3][1 22992 6B82E32F1C2EF50DBED2B687028 2AF3C136A91C8 ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGIDSEH.SYS [4C51E233C87F9EC7598551DE554BC99D][1 24144 B9A84D87ABC85291FD373E1C04C 2A4BA97762CF2 ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGIDSFILTER.SYS [C3FC426E54F55C1CC3219E415B88E10C][1 27216 7180F07D8FA975E2C0A6769FEC2 7FAC2562C5AA5 ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGIDSSHIM.SYS [4E796D3D2C3182B13B3E3B5A2AD4EF0A][1 248656 5F9716073970870A377A1F6750D 8E99D84BB39BF ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGLDX86.SYS [5639DE66B37D02BD22DF4CF3155FBA60][1 34896 9F453CD0A192E4ECF49C490701F 2AB3C10B5C208 ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGMFX86.SYS [D1BAF652EDA0AE70896276A1FB32C2D4][1 32592 BE451F47B6432995FD6D5FEADFB 04A1BFC49162E ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGRKX86.SYS [AAF0EBCAD95F2164CFFB544E00392498][1 297168 515B1A7980416B43A612F9EDF1E 94508A7F2C0F1 ]C:\WINDOWS\SYSTEM32\DRIVERS\AVGTDIX.SYS [EA22EDADF90C0ABA8319454B2A07B700][1 14080 ]C:\WINDOWS\SYSTEM32\DRIVERS\BATTC.SYS [DA1F27D85E0D1525F6621372E7B685E9][6 4224 ]C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS [EE0F41FA0466189A2C8B9CAF7D1CDDD5][2 20608 ]C:\WINDOWS\SYSTEM32\DRIVERS\BRGSp50.sys [E4E6A0922E3D983728C9AD4E8D466954][1 71552 ]C:\WINDOWS\SYSTEM32\DRIVERS\bridge.sys [B0A533AA6C5CE5F51CF738BF7E5CB5C4][1 539432 ]C:\WINDOWS\SYSTEM32\DRIVERS\BTAUDIO.SYS [9BA609D995F7B708C62E53168DF3ED2A][1 879496 ]C:\WINDOWS\SYSTEM32\DRIVERS\BTKRNL.SYS [58A49BD10E08D3D4333A60DEDCB1CED8][1 37424 ]C:\WINDOWS\SYSTEM32\DRIVERS\BTPORT.SYS [80F61DE965C116051614AC2F04222FF7][1 156392 ]C:\WINDOWS\SYSTEM32\DRIVERS\BTWDNDIS.SYS [E48668B4A6A5CF68B33AECAD18EE8E1E][1 55352 ]C:\WINDOWS\SYSTEM32\DRIVERS\BTWHID.SYS [90A673FC8E12A79AFBED2576F6A7AAF9][6 13952 ]C:\WINDOWS\SYSTEM32\DRIVERS\cbidf2k.sys [C1B486A7658353D33A10CC15211A873B][6 18688 ]C:\WINDOWS\SYSTEM32\DRIVERS\cdaudio.sys [CD7D5152DF32B47F4E36F710B35AAE02][1 63744 ]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS [7B53584D94E9D8716B2DE91D5F1CB42D][1 62592 ]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS [B562592B7F5759C99E179CA467ECFB4C][6 262528 ]C:\WINDOWS\SYSTEM32\DRIVERS\cinemst2.sys [D86173B401470F06D9810F7962969DDF][1 49664

]C:\WINDOWS\SYSTEM32\DRIVERS\CLASSPNP.SYS [4266BE808F85826AEDF3C64C1E240203][1 14080 ]C:\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS [DF1B1A24BF52D0EBC01ED4ECE8979F50][1 9344 ]C:\WINDOWS\SYSTEM32\DRIVERS\COMPBATT.SYS [9624293E55AD405415862B504CA95B73][6 11776 ]C:\WINDOWS\SYSTEM32\DRIVERS\cpqdap01.sys [6AF1684CCAAC3F7EF4EE9BA65EB0677A][1 36480 ]C:\WINDOWS\SYSTEM32\DRIVERS\crusoe.sys [00CA44E4534865F8A3B64F7C0984BFF0][1 36352 ]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS [D16C81677A9BE399C63CD2EA486472A5][1 14208 ]C:\WINDOWS\SYSTEM32\DRIVERS\diskdump.sys [08D30AF92C270F2E76787C81589DBAD6][1 16896 ]C:\WINDOWS\SYSTEM32\DRIVERS\DKBFLTR.SYS [C0FBB516E06E243F0CF31F597E7EBF7D][1 799744 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS [F5E7B358A732D09F4BCF2824B88B9E28][1 153344 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS [E9317282A63CA4D188C0DF5E09C6AC5F][6 5888 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS [A6F881284AC1150E37D9AE47FF601267][1 52864 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMUSIC.SYS [FF86422268DE771D571E123EB7092C6A][1 60288 ]C:\WINDOWS\SYSTEM32\DRIVERS\DRMK.SYS [1ED4DBBAE9F5D558DBBA4CC450E3EB2E][1 2944 ]C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS [FE97D0343ACFDEBDD578FC67CC91FA87][6 10496 ]C:\WINDOWS\SYSTEM32\DRIVERS\DXAPI.SYS [D3DAC8432110AAD0B02A58B4459AB835][1 71040 ]C:\WINDOWS\SYSTEM32\DRIVERS\DXG.SYS [A73F5D6705B1D820C19B18782E176EFD][6 3328 ]C:\WINDOWS\SYSTEM32\DRIVERS\DXGTHK.SYS [3117F595E9615E04F05A54FC15A03B20][1 143360 ]C:\WINDOWS\SYSTEM32\DRIVERS\fastfat.sys [CED2E8396A8838E59D8FD529C680E02C][1 27392 ]C:\WINDOWS\SYSTEM32\DRIVERS\fdc.sys [E153AB8A11DE5452BCF5AC7652DBF3ED][1 34944 ]C:\WINDOWS\SYSTEM32\DRIVERS\FIPS.SYS [0DD1DE43115B93F4D85E889D7A86F548][1 20480 ]C:\WINDOWS\SYSTEM32\DRIVERS\flpydisk.sys [157754F0DF355A9E0A6F54721914F9C6][1 124800 ]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS [3E1E2BD4F39B0E2B7DC4F4D2BCC2779A][6 7936 ]C:\WINDOWS\SYSTEM32\DRIVERS\FS_REC.SYS [455F778EE14368468560BD7CB8C854D0][6 12160 ]C:\WINDOWS\SYSTEM32\DRIVERS\fsvga.sys [6AC26732762483366C3969C9E4D2259D][6 125056 ]C:\WINDOWS\SYSTEM32\DRIVERS\FTDISK.SYS [3FCC124B6E08EE0E9351F717DD136939][1 138752 ]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS [2A013E7530BEAB6E569FAA83F517E836][1 145920 ]C:\WINDOWS\SYSTEM32\DRIVERS\Hdaudio.sys [378055AB8DDA86228683C697C4E11685][1 36224 ]C:\WINDOWS\SYSTEM32\DRIVERS\hidclass.sys [5FFF41CD5108E9051D255C37825AF697][1 24960 ]C:\WINDOWS\SYSTEM32\DRIVERS\hidparse.sys [1DE6783B918F540149AA69943BDFEBA8][1 9600 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS [ED10A3D367DD5596506022D5E2A3CBA0][1 731264

]C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.SYS [D92272A376BBA4A0ED61F92280D71A10][1 985472 ]C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DPV.SYS [03A51D7D5666DF3D4331581B3A3109DC][1 210560 ]C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWAZL.SYS [C19B522A9AE0BBC3293397F3055E80A1][1 263040 ]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS [5502B58EEF7486EE6F93F3F164DCB808][1 52736 ]C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS [0DED5397F34F5B4AE61674D7303557D9][1 97112 ]C:\WINDOWS\SYSTEM32\DRIVERS\IDMTDI.SYS [F8AA320C6A0409C0380E5D8A99D76EC6][1 41856 ]C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS [279FB78702454DFF2BB445F238C048D2][1 36096 ]C:\WINDOWS\SYSTEM32\DRIVERS\intelppm.sys [4448006B6BC60E6C027932CFC38D6855][1 29056 ]C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW.SYS [731F22BA402EE4B62748ADAF6363C182][6 32896 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS [E1EC7F5DA720B640CD8FB8424F1B14BB][1 20992 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS [B5A8E215AC29D24D60B4D1250EF05ACE][1 134912 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS [64537AA5C003A6AFEEE1DF819062D0D1][1 74752 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS [50708DAA1B1CBB7D6AC1CF8F56A24410][1 11264 ]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS [E504F706CCB699C2596E9A3DA1596E87][1 35840 ]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS [EBDEE8A2EE5393890A1ACEE971C4C246][1 24576 ]C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS [D93CAD07C5683DB066B0B2D2D3790EAD][1 171776 ]C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS [B9540E258F952650DE8DEC68719A5C97][1 140928 ]C:\WINDOWS\SYSTEM32\DRIVERS\KS.SYS [EB7FFE87FD367EA8FCA0506F74A87FBB][1 92032 ]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS [D1F8BE91ED4DDB671D42E473E3FE71AB][6 7680 ]C:\WINDOWS\SYSTEM32\DRIVERS\mcd.sys [0CEA2D0D3FA284B85ED5B68365114F76][1 12672 ]C:\WINDOWS\SYSTEM32\DRIVERS\MDMXSDK.SYS [729D83E56C29C510258A6E9E79FFDDC3][1 63744 ]C:\WINDOWS\SYSTEM32\DRIVERS\mf.sys [4AE068242760A1FB6E1A44BF4E16AFA6][6 4224 ]C:\WINDOWS\SYSTEM32\DRIVERS\MNMDD.SYS [6FC6F9D7ACC36DCA9B914565A3AEDA05][1 30080 ]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS [34E1F0031153E491910E12551400192C][1 23040 ]C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS [B1C303E17FB9D46E87A98E4BA6769685][1 12160 ]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS [65653F3B4477F3C63E68A9659F85EE2E][1 42240 ]C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS [DB07B0088CDFD20C2A22E675120EDE34][1 72960 ]C:\WINDOWS\SYSTEM32\DRIVERS\mqac.sys [46EDCC8F2DB2F322C24F48785CB46366][1 181248 ]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS [1FD607FC67F7F7C633C3DA65BFC53D18][1 451456 ]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS [561B3A4333CA2DBDBA28B5B956822519][1 19072

]C:\WINDOWS\SYSTEM32\DRIVERS\MSFS.SYS [C0F1D4A21DE5A415DF8170616703DEBF][1 35072 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS [AE431A8DD3C1D0D0610CDBAC16057AD0][1 7552 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS [13E75FEF9DFEB08EEDED9D0246E1F448][1 5376 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS [1988A33FF19242576C3D0EF9CE785DA7][1 4992 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS [469541F8BFD2B32659D5D463A6714BCE][1 15488 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS [82035E0F41C2DD05AE41D27FE6CF7DE1][1 107904 ]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS [558635D3AF1C7546D26067D5D9B6959E][1 182912 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS [08D43BBDACDF23F34D79E44ED35C1B4C][1 9600 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS [34D6CD56409DA9A7ED573E1C90A308BF][1 12928 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS [0B90E255A9490166AB368CD55A529893][1 91776 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS [59FC3FB44D2669BC144FD87826BB571F][1 38016 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS [3A2ACA8FC1D7786902CA434998D7CEB4][1 34560 ]C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS [0C80E410CD2F47134407EE7DD19CC86B][1 162816 ]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS [5C5C53DB4FEF16CF87B9911C7E8C6FBC][1 61824 ]C:\WINDOWS\SYSTEM32\DRIVERS\nic1394.sys [BE984D604D91C217355CDD3737AAD25D][6 12032 ]C:\WINDOWS\SYSTEM32\DRIVERS\nikedrv.sys [60CF8C7192B3614F240838DDBAA4A245][1 40320 ]C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys [4F601BCB8F64EA3AC0994F98FED03F8E][1 30848 ]C:\WINDOWS\SYSTEM32\DRIVERS\NPFS.SYS [B78BE402C3F63DD55521F73876951CDD][1 574592 ]C:\WINDOWS\SYSTEM32\DRIVERS\NTFS.SYS [73C1E1F395918BC2C6DD67AF7591A3AD][6 2944 ]C:\WINDOWS\SYSTEM32\DRIVERS\NULL.SYS [FBFFC978C457A96EAFB066637E42FCA8][1 6563136 ]C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS [0FB6BF3AB170FC5BD403D25E134EAFDE][1 14848 ]C:\WINDOWS\SYSTEM32\DRIVERS\NVSMU.SYS [B305F3FAD35083837EF46A0BBCE2FC57][6 12416 ]C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFLT.SYS [C99B3415198D1AAB7227F2C88FD664B9][6 32512 ]C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFWD.SYS [79EA3FCDA7067977625B3363A2657C80][1 88448 ]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys [56D34A67C05E94E16377C60609741FF8][6 63232 ]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnknb.sys [C0BB7D1615E1ACBDC99757F6CEAF8CF0][6 55936 ]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkspx.sys [03373A79440473062C6F3AEDEC6A49C8][1 163584 ]C:\WINDOWS\SYSTEM32\DRIVERS\nwrdr.sys [4BB30DDC53EBC76895E38694580CDFE9][6 3456 ]C:\WINDOWS\SYSTEM32\DRIVERS\OPRGHDLR.SYS [3E16EFF2A6FED2D8D7F5A66DFE65D183][1 42496 ]C:\WINDOWS\SYSTEM32\DRIVERS\p3.sys [29744EB4CE659DFE3B4122DEB45BC478][1 80128

]C:\WINDOWS\SYSTEM32\DRIVERS\parport.sys [6DDCF3F801EC15FE698F6A215CF30A1F][1 35816 ]C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS [3334430C29DC338092F79C38EF7B4CD0][1 18688 ]C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS [70E98B3FD8E963A6A46A2E6247E0BEA1][6 6784 ]C:\WINDOWS\SYSTEM32\DRIVERS\parvdm.sys [FD2041E9BA03DB7764B2248F02475079][1 18816 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCCSMCFD.SYS [8086D9979234B603AD5BC2F5D890B234][1 68224 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS [CCF5F451BB1A5A2A522A76E670000FF0][1 3328 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS [520B91AB011456B940D9B05FC91108FF][1 25088 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDEX.SYS [82A087207DECEC8456FBE8537947D579][1 119936 ]C:\WINDOWS\SYSTEM32\DRIVERS\pcmcia.sys [BC6B2BC69C1E009443E8B1FE2DB96101][1 136960 ]C:\WINDOWS\SYSTEM32\DRIVERS\PORTCLS.SYS [0D97D88720A4087EC93AF7DBB303B30A][1 35328 ]C:\WINDOWS\SYSTEM32\DRIVERS\PROCESSR.SYS [48671F327553DCF1D27F6197F622A668][1 69120 ]C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS [80D317BD1C3DBC5D4FE7B1678C60CADD][6 17792 ]C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS [FE0D99D6F31E4FAD8159F690D68DED9C][6 8832 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS [98FAEB4A4DCF812BA1C6FCA4AA3E115C][1 51328 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS [7306EEED8895454CBED4669BE9F79FAA][1 41472 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS [1C5CC65AAC0783C344F16353E60B72AC][1 48384 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS [FDBB1D60066FCFBB7452FD8F9829B242][6 16512 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS [01524CD237223B18ADBB48F70083F101][6 34432 ]C:\WINDOWS\SYSTEM32\DRIVERS\rawwan.sys [29D66245ADBA878FFF574CD66ABD2884][1 176512 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS [4912D5B403614CE99C28420F75353332][6 4224 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS [A2CAE2C60BC37E0751EF9DDA7CEAF4AD][1 196864 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS [D4F5643D7714EF499AE9527FDCD50894][1 139400 ]C:\WINDOWS\SYSTEM32\DRIVERS\rdpwd.sys [B31B4588E4086D8D84ADBF9845C2402B][1 57472 ]C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS [37ECEBDD930395A9C399FB18A3C236D3][1 24416 ]C:\WINDOWS\SYSTEM32\DRIVERS\REGGUARD.SYS [A56FE08EC7473E8580A390BB1081CDD7][6 12032 ]C:\WINDOWS\SYSTEM32\DRIVERS\rio8drv.sys [0A854DF84C77A0BE205BFEAB2AE4F0EC][6 12032 ]C:\WINDOWS\SYSTEM32\DRIVERS\riodrv.sys [35E81B908AE4E97FC7BDF4607C516FF4][1 200064 ]C:\WINDOWS\SYSTEM32\DRIVERS\RMCast.sys [7CE8B277F3207EA82D7D22AD348BEFC6][1 30080 ]C:\WINDOWS\SYSTEM32\DRIVERS\rndismp.sys [D8B0B4ADE32574B2D9C5CC34DC0DBBE7][6 5888 ]C:\WINDOWS\SYSTEM32\DRIVERS\rootmdm.sys [7FFE2751AE9B3082CD55BFCC2E9BECDB][1 4742144

]C:\WINDOWS\SYSTEM32\DRIVERS\RTKHDAUD.SYS -2][0 -1 ]C:\WINDOWS\SYSTEM32\DRIVERS\RTS5121.SYS [D7FD0FF761E28AC0EA35AD71E0CD67E9][1 96256 ]C:\WINDOWS\SYSTEM32\DRIVERS\scsiport.sys [02FC71B020EC8700EE8A46C58BC6F276][1 67584 ]C:\WINDOWS\SYSTEM32\DRIVERS\sdbus.sys [D26E26EA516450AF9D072635C60387F4][1 27440 ]C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS [A2D868AEEFF612E70E213C451A70CAFB][1 15488 ]C:\WINDOWS\SYSTEM32\DRIVERS\serenum.sys [CD9404D115A00D249F70A371B46D5A26][1 64896 ]C:\WINDOWS\SYSTEM32\DRIVERS\serial.sys [1D9F1BEC651815741F088A8FB88E17EE][1 11136 ]C:\WINDOWS\SYSTEM32\DRIVERS\sffdisk.sys [586499FD312FFD7F78553F408E71682E][1 10240 ]C:\WINDOWS\SYSTEM32\DRIVERS\sffp_sd.sys [0D13B6DF6E9E101013A7AFB0CE629FE0][1 11392 ]C:\WINDOWS\SYSTEM32\DRIVERS\sfloppy.sys [017DAECF0ED3AA731313433601EC40FA][6 14592 ]C:\WINDOWS\SYSTEM32\DRIVERS\smclib.sys [ADDC9E4757A68AB60562AD3CB9C288D6][1 25472 ]C:\WINDOWS\SYSTEM32\DRIVERS\sonydcam.sys [8E186B8F23295D1E42C573B82B80D548][1 6400 ]C:\WINDOWS\SYSTEM32\DRIVERS\SPLITTER.SYS [E41B6D037D6CD08461470AF04500DC24][1 73472 ]C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS [20B7E396720353E4117D64D9DCB926CA][1 336256 ]C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS [C43356072EB3E88CD62958DB10CEAD47][1 48640 ]C:\WINDOWS\SYSTEM32\DRIVERS\stream.sys [03C1BAE4766E2450219D20B993D6E046][1 4352 ]C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS [94ABC808FC4B6D7D2BBF42B85E25BB4D][1 54272 ]C:\WINDOWS\SYSTEM32\DRIVERS\SWMIDI.SYS [650AD082D46BAC0E64C9C0E0928492FD][1 60800 ]C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS [A2A9CA0D1A9AC1FF54220AA0789FE5CF][1 14976 ]C:\WINDOWS\SYSTEM32\DRIVERS\tape.sys [9F4B36614A0FC234525BA224957DE55C][1 359040 ]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS [4D58BB1AE8841AAFD8790AD7E1E3B8EA][1 223616 ]C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys [6891B74AB9A016064E82A419388D0601][1 18560 ]C:\WINDOWS\SYSTEM32\DRIVERS\TDI.SYS [38D437CF2D98965F239B0ABCD66DCB0F][1 12040 ]C:\WINDOWS\SYSTEM32\DRIVERS\tdpipe.sys [ED0580AF02502D00AD8C4C066B156BE9][1 21896 ]C:\WINDOWS\SYSTEM32\DRIVERS\tdtcp.sys [A540A99C281D933F3D69D55E48727F47][1 40840 ]C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS [699450901C5CCFD82357CBC531CEDD23][6 51712 ]C:\WINDOWS\SYSTEM32\DRIVERS\tosdvd.sys [D74A8EC75305F1D3CFDE7C7FC1BD62A9][6 21376 ]C:\WINDOWS\SYSTEM32\DRIVERS\tsbvcap.sys [87A0E9E18C10A9E454238E3330E2A26D][1 12416 ]C:\WINDOWS\SYSTEM32\DRIVERS\tunmp.sys [12F70256F140CD7D52C58C7048FDE657][1 66176 ]C:\WINDOWS\SYSTEM32\DRIVERS\udfs.sys [819DE2D0F9EC99698DF659E2DE6B6A2B][1 12808 254A2B1D571AC13F4742A3BE44F [

BF040E9EAB943 ]C:\WINDOWS\SYSTEM32\DRIVERS\UNHACKMEDRV.SYS [AFF2E5045961BBC0A602BB6F95EB1345][1 209408 ]C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS [AF090265EC388BAB320F1FF7E7A7D5EA][1 12672 ]C:\WINDOWS\SYSTEM32\DRIVERS\usb8023.sys [2654EECC6FB13603EBDDCD5C8EA943D1][1 23808 ]C:\WINDOWS\SYSTEM32\DRIVERS\usbcamd.sys [61018BA9DF6B63E51D9753C980E73EC2][1 23936 ]C:\WINDOWS\SYSTEM32\DRIVERS\usbcamd2.sys [596EB39B50D6EBD9B734DC4AE0544693][1 4736 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBD.SYS [15E993BA2F6946B2BFBBFCD30398621E][1 26624 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS [C72F40947F92CEA56A8FB532EDF025F1][1 57600 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS [2853FD4C4489E0F8BFCF78EFCDB7E998][1 16000 ]C:\WINDOWS\SYSTEM32\DRIVERS\usbintel.sys [BDFE799A8531BAD8A5A985821FE78760][1 17024 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS [2034CA78F9C6E787B4B76D81AC888351][1 142976 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBPORT.SYS [6CD7B22193718F1D17A47A1CD6D37E75][1 26496 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS [55E01061C74A8CEFFF58DC36114A8D3F][6 58112 ]C:\WINDOWS\SYSTEM32\DRIVERS\vdmindvd.sys [8A60EDD72B4EA5AEA8202DAF0E427925][1 20992 ]C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS [D5A9D123F5ED7C9965A481BD20CF66D8][1 79744 ]C:\WINDOWS\SYSTEM32\DRIVERS\VIDEOPRT.SYS [EE4660083DEBA849FF6C485D944B379B][1 52352 ]C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS [984EF0B9788ABF89974CFED4BFBAACBC][1 34560 ]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS [2797F33EBF50466020C430EE4F037933][1 82944 ]C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS [6D0B121FE665626D266678EA97C75622][2 437760 62EB3708916AF833FDDD8118B4C E6432E36932C6 ]C:\WINDOWS\SYSTEM32\DRIVERS\WLANUZXP.SYS [AE2C8544E747C20062DB27456EA2D67A][1 8832 ]C:\WINDOWS\SYSTEM32\DRIVERS\WMIACPI.SYS [2F31B7F954BED437F2C75026C65CAF7B][6 4352 ]C:\WINDOWS\SYSTEM32\DRIVERS\WMILIB.SYS [6ABE6E225ADB5A751622A9CC3BC19CE8][6 12032 ]C:\WINDOWS\SYSTEM32\DRIVERS\ws2ifsl.sys [00AE175B903D45ED4A62384D3315DC2A][2 17664 ]C:\WINDOWS\SYSTEM32\DRIVERS\ZDPSp50.sys [55E148C01296696588EAFA425782C3E8][1 367616 ]C:\WINDOWS\SYSTEM32\DSOUND.DLL [67DFF7BBBD0E80AAB7B3CF061448DB8A][1 23040 ]C:\WINDOWS\SYSTEM32\ERSVC.DLL [ACD36A2DD7D1E9D8A060AA651DC07E63][1 243200 ]C:\WINDOWS\SYSTEM32\ES.DLL [DFCE51FD96909D1B97D4A1A72D060D77][1 134400 ]C:\WINDOWS\SYSTEM32\HAL.DLL [765B30C776A1780B46B479FE614F707C][1 344064 ]C:\WINDOWS\SYSTEM32\HNETCFG.DLL [6580E3EC7593C0621A91387AAB419524][1 199680 ]C:\WINDOWS\SYSTEM32\IAC25_32.AX [F263E68AF3B8ACE47DDB70F075B20782][1 80384 ]C:\WINDOWS\SYSTEM32\ICCVID.DLL [670709F5BC284AABF4E1B603FA1B3095][1 173056

]C:\WINDOWS\SYSTEM32\IE4UINIT.EXE [729DA5D23A9AD20A6AA353156A126420][1 11063808 ]C:\WINDOWS\SYSTEM32\IEFRAME.DLL [AE01989028765DE3B3F3750DC3E7A1B6][1 16384 ]C:\WINDOWS\SYSTEM32\IMAADP32.ACM [FA788520BCAC0F5D9D5CDE5615C0D931][1 150016 ]C:\WINDOWS\SYSTEM32\IMAPI.EXE [87CA7CE6469577F059297B9D6556D66D][1 110080 ]C:\WINDOWS\SYSTEM32\IMM32.DLL [64528CDF39D8BC19D800BE60039BB7E4][1 678400 ]C:\WINDOWS\SYSTEM32\INETCOMM.DLL [36CC8C01B5E50163037BEF56CB96DEFF][1 331264 ]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL [43ECA1576906BA76FB3E329A338A3CAE][6 199168 ]C:\WINDOWS\SYSTEM32\IR32_32.DLL [B106530542C5920EDB040A288BD300AB][1 848384 ]C:\WINDOWS\SYSTEM32\IR41_32.AX [603CC77B5E5F7977DE2ABFBA50CD6854][1 755200 ]C:\WINDOWS\SYSTEM32\IR50_32.DLL [A00B287BB6F78BDD3589B7E75A86A6FA][1 134144 ]C:\WINDOWS\SYSTEM32\ITSS.DLL [A82F57744B5633E4BE8AFD6ADC2D0C14][1 47616 ]C:\WINDOWS\SYSTEM32\IYUV_32.DLL [945FBB881AE927A44DFD96440F2F4F44][6 7040 ]C:\WINDOWS\SYSTEM32\KDCOM.DLL [940813D4CA9193D6C1A0BA10E0ED9B4E][1 294400 ]C:\WINDOWS\SYSTEM32\KERBEROS.DLL [3A4C25B718268D8C18757312FCA936A7][1 290816 ]C:\WINDOWS\SYSTEM32\L3CODECA.ACM [B3EFF6D938C572E90A07B3D87A3C7657][1 13824 ]C:\WINDOWS\SYSTEM32\LMHSVC.DLL [71D3D970127D939A4BB062B5040B6EBA][1 341504 ]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL [793F04A09B15E7C6C11DBDFFAF06C0AB][1 75264 ]C:\WINDOWS\SYSTEM32\LOCATOR.EXE [43FCEEF75FD6208925DDD4FFF8C36723][1 220672 ]C:\WINDOWS\SYSTEM32\LOGON.SCR [7DB59FFF2AF32C27EB2276424FA5EDDB][1 514560 ]C:\WINDOWS\SYSTEM32\LOGONUI.EXE [74D66B3DE265E8789153414E75175F26][1 22016 ]C:\WINDOWS\SYSTEM32\LPK.DLL [84885F9B82F4D55C6146EBF6065D75D2][1 13312 ]C:\WINDOWS\SYSTEM32\LSASS.EXE [3B4702155BB2AE9DC00C06A68834BDFA][1 18944 ]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL [F6415361201915B9FE3896B0E4E724FF][1 32768 ]C:\WINDOWS\SYSTEM32\MNMSRVC.EXE [3046DB917E3CFA040632799DD9B14865][1 49152 ]C:\WINDOWS\SYSTEM32\MPRDIM.DLL [9A3BD5F55AADFF859539142F6328A66E][1 20480 ]C:\WINDOWS\SYSTEM32\MSACM32.DRV [5637038012870FDA20650E07D6476D02][1 14848 ]C:\WINDOWS\SYSTEM32\MSADP32.ACM [C893918956D43F84FBBB54B7553DBEE8][1 294912 ]C:\WINDOWS\SYSTEM32\MSAUD32.ACM [19D02521959829A39820512DCED78C5C][2 270848 ]C:\WINDOWS\SYSTEM32\MSCOREE.DLL [C7C3D89EB0A6F3DBA622EA737FA335B1][1 6144 ]C:\WINDOWS\SYSTEM32\MSDTC.EXE [33271A2667334B9A8842C65A079EF375][1 9216

]C:\WINDOWS\SYSTEM32\MSG711.ACM [B87F759738C52E8D6FBCDAAA84C6486F][1 118784 ]C:\WINDOWS\SYSTEM32\MSG723.ACM [3A9846E207DAFC13009C048A2F6F8C2A][1 19968 ]C:\WINDOWS\SYSTEM32\MSGSM32.ACM [95FD808E4AC22ABA025A7B3EAC0375D2][1 33792 ]C:\WINDOWS\SYSTEM32\MSGSVC.DLL [B60C4EC848567309CC0172D3F3FADD9E][1 188416 ]C:\WINDOWS\SYSTEM32\MSH261.DRV [28B2EEA9060D18BD0F13017749803E33][1 294912 ]C:\WINDOWS\SYSTEM32\MSH263.DRV [D469A0EBA2EF5C6BEE8065B7E3196E5E][1 5937152 ]C:\WINDOWS\SYSTEM32\MSHTML.DLL [F5F0146580E7023ADB963879840777F8][1 78848 ]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE [B9B3F6D8B8F1E0029C58B304632A729B][1 32592 ]C:\WINDOWS\SYSTEM32\MSONPMON.DLL [C086483E3DBA8C1C0A687EC8D5B3D4C1][1 52224 ]C:\WINDOWS\SYSTEM32\MSPMSNSV.DLL [C8444ACDF4CA2B1CB2D6C607DB20C68E][1 11264 ]C:\WINDOWS\SYSTEM32\MSRLE32.DLL [77C41F9146450C89534704A75836CE56][1 129536 ]C:\WINDOWS\SYSTEM32\MSV1_0.DLL [6EF2B7676E92B9452AAB164339B69084][6 25600 ]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL [7B5BA7CB7CF42B557C17D08015BE8A14][1 1428480 ]C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL [4E74AF063C3271FBEA20DD940CFD1184][1 245248 ]C:\WINDOWS\SYSTEM32\MSWSOCK.DLL [9D124E6A01DBCBEEEAE60DD19ABAC5F0][1 17408 ]C:\WINDOWS\SYSTEM32\MSYUV.DLL [05AFB5AD06462257BEA7495283C86D50][1 111104 ]C:\WINDOWS\SYSTEM32\NETDDE.EXE [DAB9E6C7105D2EF49876FE92C524F565][1 198144 ]C:\WINDOWS\SYSTEM32\NETMAN.DLL [388B8FBC36A8558587AFC90FB23A3B99][1 69120 ]C:\WINDOWS\SYSTEM32\NOTEPAD.EXE [BB5CBFFC096497506167BCE1D9690EF2][1 708096 ]C:\WINDOWS\SYSTEM32\NTDLL.DLL [FB142B7007CA2EEA76966C6C5CC12150][1 2015232 ]C:\WINDOWS\SYSTEM32\NTKRNLPA.EXE [B62F29C00AC55A761B2E45877D85EA0F][1 435200 ]C:\WINDOWS\SYSTEM32\NTMSSVC.DLL [A83C91F69EA6B4982F73FA47C93AB44B][1 6249344 ]C:\WINDOWS\SYSTEM32\NV4_DISP.DLL [EEDA687B6CE7D40B3DFFD28031FB1D51][1 13537280 ]C:\WINDOWS\SYSTEM32\NVCPL.DLL [C0AD0D8FA3C29188C2E9537C6995F465][1 159812 ]C:\WINDOWS\SYSTEM32\NVSVC32.EXE [B48D3193DD1474DCBCC32BF4779AC698][1 83456 ]C:\WINDOWS\SYSTEM32\OLEPRO32.DLL [C44BC10BA73575C91FF50CDAF4D8E370][1 15360 ]C:\WINDOWS\SYSTEM32\PJLMON.DLL [2C69EC7E5A311334D10DD95F338FCCEA][1 382464 ]C:\WINDOWS\SYSTEM32\QMGR.DLL [4CAEC028C1E21C75E17877D4522D3DB4][1 8192 ]C:\WINDOWS\SYSTEM32\RASADHLP.DLL [44DB7A9BDD2FB58747D123FBF1D35ADB][1 89088 ]C:\WINDOWS\SYSTEM32\RASAUTO.DLL [41A3C11E3517C962C9B44893BCEC3B34][1 174080

]C:\WINDOWS\SYSTEM32\RASMANS.DLL [3151427DB7D87107D1C5BE58FAC53960][1 59904 ]C:\WINDOWS\SYSTEM32\REGSVC.DLL [5C83A4408604F737717AB96371201680][1 395776 ]C:\WINDOWS\SYSTEM32\RPCSS.DLL [471B3F9741D762ABE75E9DEEA4787E47][6 132608 ]C:\WINDOWS\SYSTEM32\RSVP.EXE [90491683ABD587C702B16F181AB0D99D][1 90112 ]C:\WINDOWS\SYSTEM32\RSVPSP.DLL [DA285490BBD8A1D0CE6623577D5BA1FF][1 33280 ]C:\WINDOWS\SYSTEM32\RUNDLL32.EXE [25D8DE134DF108E3DBC8D7D23B1AA58E][1 95744 ]C:\WINDOWS\SYSTEM32\SCARDSVR.EXE [0F78E27F563F2AAF74B91A49E2ABF19A][1 180224 ]C:\WINDOWS\SYSTEM32\SCECLI.DLL [29632E787DCFC0085A555C681EB82693][1 144896 ]C:\WINDOWS\SYSTEM32\SCHANNEL.DLL [92360854316611F6CC471612213C3D92][1 190976 ]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL [D636FA41E50671160D838EA2DACE3330][1 20992 ]C:\WINDOWS\SYSTEM32\SCLGNTFY.DLL [B1E0CE09895376871746F36DC5773B4F][1 18944 ]C:\WINDOWS\SYSTEM32\SECLOGON.DLL [DFD9870CF39C791D86C4C209DA9FA919][1 38912 ]C:\WINDOWS\SYSTEM32\SENS.DLL [C6CE6EEC82F187615D1002BB3BB50ED4][1 108032 ]C:\WINDOWS\SYSTEM32\SERVICES.EXE [729798E0933076B8FCFCD9934698F164][1 140800 ]C:\WINDOWS\SYSTEM32\SESSMGR.EXE [30A609E00BD1D4FFC49D6B5A432BE7F2][1 1580544 ]C:\WINDOWS\SYSTEM32\SFCFILES.DLL [559B2D22A1EE947A7EAED530C7FF9320][6 1497088 ]C:\WINDOWS\SYSTEM32\SHDOCVW.DLL [D5988A5048E4DC7175BCA9F29FC144AE][1 8384000 ]C:\WINDOWS\SYSTEM32\SHELL32.DLL [E7518DC542D3EBDCB80EDD98462C7821][1 134656 ]C:\WINDOWS\SYSTEM32\SHSVCS.DLL [059FCD11A8F067650ABF6426E1CB43D3][1 86016 ]C:\WINDOWS\SYSTEM32\SL_ANET.ACM [8B54AA346D1B1B113FFAA75501B8B1B2][1 89600 ]C:\WINDOWS\SYSTEM32\SMLOGSVC.EXE [BD7FB0957C716F1A60333AEE04DE2178][1 50688 ]C:\WINDOWS\SYSTEM32\SMSS.EXE [7435B108B935E42EA92CA94F59C8E717][1 57856 ]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE [92BDF74F12D6CBEC43C94D4B7F804838][1 170496 ]C:\WINDOWS\SYSTEM32\SRSVC.DLL [93D32468D34E000CB3407947D1D6E22A][1 96768 ]C:\WINDOWS\SYSTEM32\SRVSVC.DLL [4B8D61792F7175BED48859CC18CE4E38][1 71680 ]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL [297101A925ECFFDCDF7F6341FFBB6C1A][1 121856 ]C:\WINDOWS\SYSTEM32\STOBJECT.DLL [8F078AE4ED187AAABC0A305146DE6716][1 14336 ]C:\WINDOWS\SYSTEM32\SVCHOST.EXE [60881F813BA450A2EC6F0A9C6F42BF63][1 298496 ]C:\WINDOWS\SYSTEM32\SYSDM.CPL [EB4A4187D74A8EFDCBEA3EA2CB1BDFBD][1 246272 ]C:\WINDOWS\SYSTEM32\TAPISRV.DLL [A3F853629F7F2537157EA6EA9857EA56][1 45568

]C:\WINDOWS\SYSTEM32\TCPMON.DLL [B60C877D16D9C880B952FDA04ADF16E6][1 295424 ]C:\WINDOWS\SYSTEM32\TERMSRV.DLL [37DB0A7D097310E8B4DE803FC3119C78][1 73216 ]C:\WINDOWS\SYSTEM32\TLNTSVR.EXE [6D9AC544B30F96C57F8206566C1FB6A1][1 90624 ]C:\WINDOWS\SYSTEM32\TRKWKS.DLL [1A235B74C54F236B7667AB67E8AE3820][6 8192 ]C:\WINDOWS\SYSTEM32\TSBYUV.DLL [E8CD0D7E169ECCE2D4FD829DAAB786ED][1 8192 ]C:\WINDOWS\SYSTEM32\TSSOFT32.ACM [0546477BDE979E33294FE97F6B3DE84A][1 185344 ]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL [3F5DF65B0758675F95A2D43918A740A3][1 18432 ]C:\WINDOWS\SYSTEM32\UPS.EXE [05642AE6A7BDAA7541A7451F5A4C6512][1 1206784 ]C:\WINDOWS\SYSTEM32\URLMON.DLL [242D07D7FC72AD897944BFF932D57C3C][1 16896 ]C:\WINDOWS\SYSTEM32\USBMON.DLL [C72661F8552ACE7C5C85E16A3CF505C4][1 577024 ]C:\WINDOWS\SYSTEM32\USER32.DLL [39B1FFB03C2296323832ACBAE50D2AFF][1 24576 ]C:\WINDOWS\SYSTEM32\USERINIT.EXE [2CDE496666A975A2CE8F969F3042C8DB][5 218624 ]C:\WINDOWS\SYSTEM32\UXTHEME.DLL [3EE00364AE0FD8D604F46CBAF512838A][1 289792 ]C:\WINDOWS\SYSTEM32\VSSVC.EXE [2B281958F5D0CF99ED626E3EF39D5C8D][1 174592 ]C:\WINDOWS\SYSTEM32\W32TIME.DLL [064D8581ADF77C25133E7D751D917D83][1 15872 ]C:\WINDOWS\SYSTEM32\W3SSL.DLL [C9BF2F12C4E6C12F8A85FBA4B6BC6208][1 17664 ]C:\WINDOWS\SYSTEM32\WATCHDOG.SYS [BA8CECC3E813E1F7C441B20393D4F86C][1 126464 ]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE [F399242A80C4066FD155EFA4CF96658E][1 144896 ]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL [A8B82C5D30B7AB937E164AB349478FBA][1 49152 ]C:\WINDOWS\SYSTEM32\WDIGEST.DLL [D6A8DC8C374EEA24744F2D4E87CA0E7E][1 23552 ]C:\WINDOWS\SYSTEM32\WDMAUD.DRV [CC8915DB4E33E8FB29CA0D2DBF75306E][1 236544 ]C:\WINDOWS\SYSTEM32\WEBCHECK.DLL [5D0A442864BFBF3B19DCCA4CD29F6E99][1 67584 ]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL [DD469944B09B032E7C7FE85687C2A399][1 75776 ]C:\WINDOWS\SYSTEM32\WIASCR.DLL [D9F6C4F6B1E188ADAFC42B561D9BC2E6][1 333312 ]C:\WINDOWS\SYSTEM32\WIASERVC.DLL [B74C69A810949E7A54DC688CAE662206][1 1835904 ]C:\WINDOWS\SYSTEM32\WIN32K.SYS [01C3346C241652F43AED8E2149881BFE][1 502272 ]C:\WINDOWS\SYSTEM32\WINLOGON.EXE [2C8FDB176F22629EA5342DB474FAC391][1 16896 ]C:\WINDOWS\SYSTEM32\WINRNR.DLL [2C0A7B2AE9C26F2C163627679B42783C][1 132096 ]C:\WINDOWS\SYSTEM32\WKSSVC.DLL [A599E5E366C1408E48AA5D37882D4E3E][1 92672 ]C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL [49911DD39E023BB6C45E4E436CFBD297][1 13824

]C:\WINDOWS\SYSTEM32\WSCNTFY.EXE [4D59DAA66C60858CDF4F67A900F42D4A][1 81408 ]C:\WINDOWS\SYSTEM32\WSCSVC.DLL [4126D27CECE4471E00E425411F7306B5][1 111104 ]C:\WINDOWS\SYSTEM32\WUAUCLT.EXE [13D72740963CBA12D9FF76A7F218BCD8][1 6656 ]C:\WINDOWS\SYSTEM32\WUAUSERV.DLL [5A91E6FEAB9F901302FA7FF768C0120F][1 359936 ]C:\WINDOWS\SYSTEM32\WZCSVC.DLL [EEF46DAB68229A14DA3D8E73C99E2959][1 129536 ]C:\WINDOWS\SYSTEM32\XMLPROV.DLL === [MBR] [MD5=004BC502E8A0AB7DDDB5C2C67E1CDFEE] M8CO0LwAfI7Ajti+AHy/AAa5AAL886RQaBwGy/u5BAC9vgeAfgAAfAsPhQ4Bg8UQ4vHNGIhW AFXGRhEFxkYQALRBu6pVzRNdcg+B+1WqdQn3wQEAdAP+RhBmYIB+EAB0JmZoAAAAAGb/dgho AABoAHxoAQBoEAC0QopWAIv0zROfg8QQnusUuAECuwB8ilYAinYBik4Cim4DzRNmYXMc/k4R dQyAfgCAD4SKALKA64RVMuSKVgDNE13rnoE+/n1VqnVu/3YA6I0AdRf6sNHmZOiDALDf5mDo fACw/+Zk6HUA+7gAu80aZiPAdTtmgftUQ1BBdTKB+QIBcixmaAe7AABmaAACAABmaAgAAABm U2ZTZlVmaAAAAABmaAB8AABmYWgAAAfNGloy9uoAfAAAzRigtwfrCKC2B+sDoLUHMuQFAAeL 8Kw8AHQJuwcAtA7NEOvy9Ov9K8nkZOsAJALg+CQCw0ludmFsaWQgcGFydGl0aW9uIHRhYmxl AEVycm9yIGxvYWRpbmcgb3BlcmF0aW5nIHN5c3RlbQBNaXNzaW5nIG9wZXJhdGluZyBzeXN0 ZW0AAABje5o= ===

Potrebbero piacerti anche