Anda di halaman 1dari 100

SpyHolesList Version:8.0 Build:6.9.7.95 22.11.

2011 17:20:27 WinDir=C:\WINDOWS Startup=C:\Documents and Settings\rato OTM\Start Menu\Programs\Startup\ Common Startup=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Microsoft Windows XP Service Pack 3 (5.1.2600) Internet Explorer 8.0.6001.18702 [Internet Explorer] [Default Home Page] :HKLM Default_Page_URL=http://go.microsoft.com/fwlink/?Lin kId=69157 [Current Home Page] :HKCU Start Page=http://www.google.co.id/ [Current Home Page] :HKCU HOMEOldSP="" [Search URL Template] :HKLM 1=www.%s.com [Search URL Template] :HKLM 2=www.%s.org [Search URL Template] :HKLM 3=www.%s.net [Search URL Template] :HKLM 4=www.%s.edu [All Users Search] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?Li nkId=54896 [All Users Search] :HKLM Search Page=http://go.microsoft.com/fwlink/?LinkId=54 896 [Current Users Search] :HKCU Search Page=http://go.microsoft.com/fwlink/?LinkI d=54896 [Current Users Search] :HKCU Search Bar="" [IE Local Blank Page] :HKCU Local Page=C:\WINDOWS\system32\blank.htm [IE Local Blank Page] :HKLM Local Page=C:\WINDOWS\system32\blank.htm [Browser Helper Objects] {18DF081C-E8AD-4283-A596-FA578C2EBDC3}=C:\PROGRAM FIL ES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPERSHIM.DLL ### Adobe PDF Helper for Internet Explorer Adobe Systems Incorporated AcroIEHe lperShim Library 10.0.1.434 [Browser Helper Objects] {72853161-30C5-4D22-B7F9-0BBC1D38A37E}=C:\PROGRAM FIL ES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIONS.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Browser Helper Objects] {DBC80044-A445-435b-BC74-9C25C1C588A9}=C:\PROGRAM FIL ES\JAVA\JRE6\BIN\JP2SSV.DLL ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Browser Helper Objects] {E7E6F031-17CE-4C07-BC86-EABFE594F69C}=C:\PROGRAM FIL ES\JAVA\JRE6\LIB\DEPLOY\JQS\IE\JQS_PLUGIN.DLL ### Java(TM) Quick Starter binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Auto Search URL] :HKCU provider="" [Auto Search URL] :HKCU "Default Value"="" [Search Assistant] :HKCU SearchAssistant="" [Search Assistant] :HKLM SearchAssistant="" [Search Assistant] :HKCU CustomizeSearch="" [Search Assistant] :HKLM CustomizeSearch="" [CustomizeSearch] :HKLM CustomizeSearch="" [URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-00C04FD64497}=C:\WINDOWS\SYSTEM 32\IEFRAME.DLL ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .23227 [Default Prefix] :HKLM "Default Value"=http:// [URL Default Prefixes] :HKLM ftp=ftp:// [URL Default Prefixes] :HKLM home=http:// [URL Default Prefixes] :HKLM mosaic=http:// [URL Default Prefixes] :HKLM www=http:// [AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm [AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM Home=270

[AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate.htm [AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm [AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm [AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm [AboutURLs] :HKLM OfflineInformation=res://ieframe.dll/offcancl.htm [AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm [AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm [AboutURLs] :HKLM Tabs=res://ieframe.dll/tabswelcome.htm [User Style Sheet] :HKCU User Stylesheet="" [User Style Sheet] :HKUS User Stylesheet="" [User Style Sheet] :HKCU Use My Stylesheet=0 [User Style Sheet] :HKUS Use My Stylesheet=0 [Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=0 [Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1 [Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=0 [Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3 [Execute unsigned ActiveX in Internet Zone] :HKCU 1201=0 [Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3 [Links Toolbar] :HKCU LinksFolderName=Links [Explorer Bars] :HKLM {4D5C8C25-D075-11d0-B416-00C04FB90376}=C:\WINDOWS\SYSTEM 32\SHDOCVW.DLL ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.5512 [IE Extensions - All Users] :HKLM {2670000A-7350-4f3c-8081-5663EE0C6C49}=C:\WI NDOWS\SYSTEM32\SHDOCVW.DLL ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.5512 [IE Extensions - All Users] :HKLM {92780B25-18CC-41C8-B9BE-3C9C571A8263}=C:\PR OGRA~1\MICROS~2\OFFICE12\REFIEBAR.DLL ### Allows you to use the Research Library and its collection of information s ervices from Microsoft Internet Explorer Microsoft Corporation Research Library Explorer Bar 12.0.6606.1000 [IE Extensions - All Users] :HKLM {e2e2dd38-d088-4134-82b7-f2ba38496583}=C:\WI NDOWS\NETWORK DIAGNOSTIC\XPNETDIAG.EXE ### Network Diagnostic for Windows XP Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Context menu items] :HKCU E&xport to Microsoft Excel=res://C:\PROGRA~1\MICROS ~2\Office12\EXCEL.EXE/3000 ### File is deleted or hidden by a rootkit or could not be located. [Active Desktop Components] :HKCU 0=About:Home ### Source=About:Home SubscribedURL=About:Home [AutoConfigURL] :HKCU AutoConfigURL="" [Protocols Filter] :HKLM application/octet-stream=C:\WINDOWS\system32\MSCOREE. DLL ### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE T Framework 4.0.31106.0 [Protocols Filter] :HKLM application/x-complus=C:\WINDOWS\system32\MSCOREE.DLL ### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE T Framework 4.0.31106.0 [Protocols Filter] :HKLM application/x-msdownload=C:\WINDOWS\system32\MSCOREE. DLL ### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE T Framework 4.0.31106.0 [Protocols Filter] :HKLM deflate=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Filter] :HKLM gzip=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227

[Protocols Filter] :HKLM text/webviewhtml=C:\WINDOWS\SYSTEM32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.6072 [Protocols Filter] :HKLM text/xml=C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXM LMF.DLL ### Microsoft Office XML MIME Filter Microsoft Corporation Microsoft Office In foPath 12.0.6500.5000 [Protocols Handler] :HKLM about=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.23250 [Protocols Handler] :HKLM cdl=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Handler] :HKLM dvd=C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL ### ActiveX control for streaming video Microsoft Corporation DirectShow 6.05. 2600.5512 [Protocols Handler] :HKLM file=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Handler] :HKLM ftp=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Handler] :HKLM gopher=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Handler] :HKLM grooveLocalGWS=C:\PROGRAM FILES\MICROSOFT OFFICE\OFF ICE12\GROOVESYSTEMSERVICES.DLL ### GrooveSystemServices Module Microsoft Corporation GrooveSystemServices Mod ule 4.2.2.2807 [Protocols Handler] :HKLM http=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Handler] :HKLM https=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Handler] :HKLM ipp [Protocols Handler] :HKLM its=C:\WINDOWS\SYSTEM32\ITSS.DLL ### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi ndows Operating System 5.2.3790.4186 [Protocols Handler] :HKLM javascript=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.23250 [Protocols Handler] :HKLM local=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Handler] :HKLM mailto=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.23250 [Protocols Handler] :HKLM mhtml=C:\WINDOWS\SYSTEM32\INETCOMM.DLL ### Microsoft Internet Messaging API Microsoft Corporation Microsoft Windows Ope rating System 6.00.2900.6157 [Protocols Handler] :HKLM mk=C:\WINDOWS\SYSTEM32\URLMON.DLL ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Protocols Handler] :HKLM ms-help=C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHAR ED\HELP\HXDS.DLL ### Microsoft Help Data Services Module Microsoft Corporation Microsoft Help 2. 5 2.05.50727.198 [Protocols Handler] :HKLM ms-its=C:\WINDOWS\SYSTEM32\ITSS.DLL ### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi

ndows Operating System 5.2.3790.4186 [Protocols Handler] :HKLM msdaipp [Protocols Handler] :HKLM res=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.23250 [Protocols Handler] :HKLM tv=C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL ### ActiveX control for streaming video Microsoft Corporation DirectShow 6.05. 2600.5512 [Protocols Handler] :HKLM vbscript=C:\WINDOWS\SYSTEM32\MSHTML.DLL ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.23250 [Protocols Handler] :HKLM wia=C:\WINDOWS\SYSTEM32\WIASCR.DLL ### WIA Scripting Layer Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Proxy] :HKCU ProxyServer="" [Proxy] :HKCU ProxyEnable=0 [Network Settings] [Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc [Hosts File Contents] :HKLM 127.0.0.1 localhost [Browsers] [Installed Browsers] Avant.Browser=C:\PROGRAM FILES\AVANT BROWSER\AVANT.EXE ### Avant Browser Avant Force 12.0.0.0 [Installed Browsers] chrome.exe=C:\DOCUMENTS AND SETTINGS\RATO OTM\LOCAL SETTI NGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 17.0.938.0 [Installed Browsers] FIREFOX.EXE=C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE ### Firefox Mozilla Corporation Firefox 7.0.1 [Installed Browsers] Google Chrome=C:\DOCUMENTS AND SETTINGS\RATO OTM\LOCAL SE TTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE ### Google Chrome Google Inc. Google Chrome 17.0.938.0 [Installed Browsers] IEXPLORE.EXE=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE. EXE ### Default Browser Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Installed Browsers] Opera=C:\PROGRAM FILES\OPERA\OPERA.EXE ### Opera Internet Browser Opera Software Opera Internet Browser 11.52 [Installed Browsers] Orca.Browser=C:\PROGRAM FILES\ORCA BROWSER\ORCA.EXE ### Orca Browser Avant Force 1.2.0.6 [FireFox Components and Extensions] browsercomps.dll=C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS\BROWSERCOMPS.DLL ### Mozilla Foundation Firefox 7.0.1 [FireFox Components and Extensions] {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}=C:\ Documents and Settings\rato OTM\Application Data\Mozilla\Firefox\Profiles\r9xude bx.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi ### {46551EC9-40F0-4e47-8E18-8E5CF550CFB8} Stylish [FireFox Components and Extensions] {E10A6337-382E-4FE6-96DE-936ADC34DD04}=C:\ Documents and Settings\rato OTM\Application Data\Mozilla\Firefox\Profiles\r9xude bx.default\extensions\{E10A6337-382E-4FE6-96DE-936ADC34DD04}.xpi ### {E10A6337-382E-4FE6-96DE-936ADC34DD04} Thumbnail Zoom [FireFox Components and Extensions] {e4a8a97b-f2ed-450b-b12d-ee082ba24781}=C:\ Documents and Settings\rato OTM\Application Data\Mozilla\Firefox\Profiles\r9xude bx.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}\ ### {e4a8a97b-f2ed-450b-b12d-ee082ba24781} Greasemonkey Files greasemonkey.jar gmIGreasemonkeyService.xpt greasemonkey.js greasemonkey.js addons4.js [FireFox Components and Extensions] {e9ad55ab-4d1c-42d2-a40c-a5563a9ad5e6}=C:\ Documents and Settings\rato OTM\Application Data\Mozilla\Firefox\Profiles\r9xude bx.default\extensions\{e9ad55ab-4d1c-42d2-a40c-a5563a9ad5e6}.xpi ### {e9ad55ab-4d1c-42d2-a40c-a5563a9ad5e6} Facebook zoom picture [FireFox Settings] :HKLM browser.startup.homepage=""

[FireFox Settings] :HKLM network.proxy.http="" [FireFox Settings] :HKLM network.proxy.http_port="" [FireFox Settings] :HKLM browser.search.selectedEngine="" [FireFox Settings] :HKLM keyword.URL="" [FireFox Settings] :HKLM network.proxy.autoconfig_url="" [Network Settings] [Domain Name] :HKLM Domain="" [Name Server] {C139FED1-07B2-43D2-AEBE-806A898B5653}=10.0.18.38 10.0.18.42 ### Network Card:HUAWEI Mobile Connect - 3G Network Card DHCPNameServer:10.0.1 8.38 10.0.18.42 DhcpDefaultGateway:10.44.95.41 DhcpServer:10.44.95.41 [WinSock2 Components] :HKLM mswsock.dll=C:\WINDOWS\SYSTEM32\MSWSOCK.DLL ### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro soft Windows Operating System 5.1.2600.5649 [WinSock2 Components] :HKLM winrnr.dll=C:\WINDOWS\SYSTEM32\WINRNR.DLL ### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [WinSock2 Components] :HKLM rsvpsp.dll=C:\WINDOWS\SYSTEM32\RSVPSP.DLL ### Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation Microsof t Windows Operating System 5.1.2600.5512 [Windows Shell] [Display Scrap's Extensions] :HKLM NeverShowExt="" [ScreenSaver] :HKCU SCRNSAVE.EXE="" ### File is deleted or hidden by a rootkit or could not be located. [System.ini] shell=Explorer.exe [User Shell] :HKCU shell="" [Main File Extensions] :HKLM .exe="%1" %* [Main File Extensions] :HKLM .com="%1" %* [Main File Extensions] :HKLM .pif="%1" %* [Main File Extensions] :HKLM .bat="%1" %* [Main File Extensions] :HKLM .cmd="%1" %* [Main File Extensions] :HKLM .scr="%1" /S [Main File Extensions] :HKLM .txt=%SystemRoot%\system32\NOTEPAD.EXE %1 [Main File Extensions] :HKLM .reg=regedit.exe "%1" [Main File Extensions] :HKLM .inf=%SystemRoot%\System32\NOTEPAD.EXE %1 [Main File Extensions] :HKLM .ini=%SystemRoot%\System32\NOTEPAD.EXE %1 [Main File Extensions] :HKLM .js=%SystemRoot%\System32\WScript.exe "%1" %* [Main File Extensions] :HKLM .vbs=%SystemRoot%\System32\WScript.exe "%1" %* [Main File Extensions] :HKLM .vbe=%SystemRoot%\System32\WScript.exe "%1" %* [Main File Extensions] :HKLM .msc=%SystemRoot%\system32\mmc.exe "%1" %* [Main File Extensions] :HKLM .jpg=rundll32.exe C:\WINDOWS\system32\shimgvw.dll ,ImageView_Fullscreen %1 [Main File Extensions] :HKLM .jpeg=rundll32.exe C:\WINDOWS\system32\shimgvw.dl l,ImageView_Fullscreen %1 [Shell Execute Hooks] :HKLM {B5A7F190-DDA6-4420-B3BA-52453494E6CD}=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIONS.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [UserInit Value] :HKLM UserInit=C:\WINDOWS\system32\userinit.exe, [Winlogon Notification] :HKLM AtiExtEvent=C:\WINDOWS\system32\ATI2EVXX.DLL ### AtiExtEvent ATI External Event Utility DLL Module ATI Technologies Inc. AT I External Event Utility for Windows 6.14.10.4162 [Winlogon Notification] :HKLM crypt32chain=C:\WINDOWS\system32\CRYPT32.DLL ### crypt32chain Crypto API32 Microsoft Corporation Microsoft Windows Operating System 5.131.2600.5779 [Winlogon Notification] :HKLM cryptnet=C:\WINDOWS\system32\CRYPTNET.DLL ### cryptnet Crypto Network Related API Microsoft Corporation Microsoft Windows Operating System 5.131.2600.5512 [Winlogon Notification] :HKLM cscdll=C:\WINDOWS\system32\CSCDLL.DLL ### cscdll Offline Network Agent Microsoft Corporation Microsoft Windows Operati

ng System 5.1.2600.5731 [Winlogon Notification] :HKLM dimsntfy=C:\WINDOWS\SYSTEM32\DIMSNTFY.DLL ### dimsntfy DIMS Notification Handler Microsoft Corporation Microsoft Windows O perating System 5.1.2600.5512 [Winlogon Notification] :HKLM RailNotification ### RailNotification File is deleted or hidden by a rootkit or could not be lo cated. [Winlogon Notification] :HKLM ScCertProp=C:\WINDOWS\system32\WLNOTIFY.DLL ### ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.5512 [Winlogon Notification] :HKLM Schedule=C:\WINDOWS\system32\WLNOTIFY.DLL ### Schedule Common DLL to receive Winlogon notifications Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.5512 [Winlogon Notification] :HKLM sclgntfy=C:\WINDOWS\system32\SCLGNTFY.DLL ### sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.5512 [Winlogon Notification] :HKLM SensLogn=C:\WINDOWS\system32\WLNOTIFY.DLL ### SensLogn Common DLL to receive Winlogon notifications Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.5512 [Winlogon Notification] :HKLM termsrv=C:\WINDOWS\system32\WLNOTIFY.DLL ### termsrv Common DLL to receive Winlogon notifications Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Winlogon Notification] :HKLM WgaLogon=C:\WINDOWS\system32\WGALOGON.DLL ### WgaLogon Windows Genuine Advantage Notifications Microsoft Corporation Mic rosoft Genuine Advantage 1.9.0040.0 [Winlogon Notification] :HKLM wlballoon=C:\WINDOWS\system32\WLNOTIFY.DLL ### wlballoon Common DLL to receive Winlogon notifications Microsoft Corporati on Microsoft Windows Operating System 5.1.2600.5512 [Shell Services DelayLoad] :HKLM WebCheck=C:\WINDOWS\SYSTEM32\WEBCHECK.DLL ### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001. 18702 [Shell Services DelayLoad] :HKLM PostBootReminder=C:\WINDOWS\SYSTEM32\SHELL32. DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.6072 [Shell Services DelayLoad] :HKLM CDBurn=C:\WINDOWS\SYSTEM32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.6072 [Shell Services DelayLoad] :HKLM SysTray=C:\WINDOWS\SYSTEM32\STOBJECT.DLL ### Systray shell service object Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Shell Services DelayLoad] :HKLM WPDShServiceObj=C:\WINDOWS\SYSTEM32\WPDSHSERV ICEOBJ.DLL ### Windows Portable Device Shell Service Object Microsoft Corporation Microso ft Windows Operating System 5.2.5721.5262 [App Paths] :HKLM AcroRd32.exe=C:\Program Files\Adobe\Reader 10.0\Reader\AcroR d32.exe ### AcroRd32.exe Adobe Reader Adobe Systems Incorporated Adobe Reader 10.0.1. 434 [App Paths] :HKLM chrome.exe=C:\Documents and Settings\rato OTM\Local Settings \Application Data\Google\Chrome\Application\chrome.exe ### chrome.exe Google Chrome Google Inc. Google Chrome 17.0.938.0 [App Paths] :HKLM cmmgr32.exe=C:\WINDOWS\system32\cmmgr32.exe ### cmmgr32.exe [App Paths] :HKLM CONF.EXE=C:\Program Files\NetMeeting\conf.exe ### CONF.EXE Windows NetMeeting Microsoft Corporation Windows NetMeeting 3.01 [App Paths] :HKLM dialer.exe=C:\Program Files\Windows NT\dialer.exe ### dialer.exe TAPI 3.0 Dialer and IP Multicast Conference Viewer Microsoft Co rporation Microsoft Windows Operating System 5.1.2600.5512 [App Paths] :HKLM excel.exe=C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE

### excel.exe Microsoft Office Excel Microsoft Corporation 2007 Microsoft Offi ce system 12.0.6611.1000 [App Paths] :HKLM firefox.exe=C:\Program Files\Mozilla Firefox\firefox.exe ### firefox.exe Firefox Mozilla Corporation Firefox 7.0.1 [App Paths] :HKLM GROOVE.EXE=C:\PROGRA~1\MICROS~2\Office12\GROOVE.EXE ### GROOVE.EXE Microsoft Office Groove Microsoft Corporation Microsoft Office Groove 4.2.2.2826 [App Paths] :HKLM hypertrm.exe="C:\Program Files\Windows NT\hypertrm.exe" ### hypertrm.exe HyperTerminal Applet Hilgraeve, Inc. Microsoft Windows Operatin g System 5.1.2600.0 [App Paths] :HKLM ICWCONN1.EXE="C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE" ### ICWCONN1.EXE Internet Connection Wizard Microsoft Corporation Microsoft Win dows Operating System 6.00.2900.5512 [App Paths] :HKLM ICWCONN2.EXE="C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE" ### ICWCONN2.EXE Internet Connection Wizard Microsoft Corporation Microsoft Win dows Operating System 6.00.2900.5512 [App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE ### IEXPLORE.EXE Internet Explorer Microsoft Corporation Windows Internet Explo rer 8.00.6001.18702 [App Paths] :HKLM INETWIZ.EXE="C:\Program Files\Internet Explorer\Connection W izard\INETWIZ.EXE" ### INETWIZ.EXE Internet Connection Wizard Microsoft Corporation Microsoft Wind ows Operating System 6.00.2900.5512 [App Paths] :HKLM infopath.exe=C:\PROGRA~1\MICROS~2\Office12\INFOPATH.EXE ### infopath.exe Microsoft Office InfoPath 2007 Microsoft Corporation Microsof t Office InfoPath 12.0.6606.1000 [App Paths] :HKLM install.exe ### install.exe [App Paths] :HKLM ISIGNUP.EXE="C:\Program Files\Internet Explorer\Connection W izard\ISIGNUP.EXE" ### ISIGNUP.EXE Internet Signup Microsoft Corporation Microsoft Windows Operatin g System 6.00.2600.0000 [App Paths] :HKLM javaws.exe=C:\Program Files\Java\jre6\bin\javaws.exe ### javaws.exe Java(TM) Web Start Launcher Sun Microsystems, Inc. Java(TM) Pla tform SE 6 U25 6.0.250.6 [App Paths] :HKLM migwiz.exe=%SystemRoot%\system32\usmt\migwiz.exe ### migwiz.exe [App Paths] :HKLM Mobile Partner.exe=C:\Program Files\Mobile Partner\Mobile Pa rtner.exe ### Mobile Partner.exe [App Paths] :HKLM moviemk.exe=C:\Program Files\Movie Maker\moviemk.exe ### moviemk.exe Windows Movie Maker Microsoft Corporation Windows Movie Maker 2.1.4028.0 [App Paths] :HKLM mpc-hc.exe="C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe" ### mpc-hc.exe Media Player Classic - Home Cinema MPC-HC Team Media Player Cla ssic - Home Cinema 1, 5, 2, 3236 [App Paths] :HKLM mplayer2.exe="C:\Program Files\Windows Media Player\mplayer2 .exe" ### mplayer2.exe Windows Media Player Microsoft Corporation Microsoft Windows Media Player 6.4.09.1125 [App Paths] :HKLM MSACCESS.EXE=C:\PROGRA~1\MICROS~2\Office12\MSACCESS.EXE ### MSACCESS.EXE Microsoft Office Access Microsoft Corporation 2007 Microsoft Office system 12.0.6606.1000 [App Paths] :HKLM msimn.exe=%ProgramFiles%\Outlook Express\msimn.exe ### msimn.exe [App Paths] :HKLM MsoHtmEd.exe ### MsoHtmEd.exe

[App Paths] :HKLM msoxmled.exe=C:\Program Files\Common Files\Microsoft Shared\ OFFICE12\MSOXMLED.EXE ### msoxmled.exe XML Editor Microsoft Corporation Microsoft Office InfoPath 12 .0.4518.1014 [App Paths] :HKLM MSPUB.EXE=C:\PROGRA~1\MICROS~2\Office12\MSPUB.EXE ### MSPUB.EXE Microsoft Office Publisher Microsoft Corporation 2007 Microsoft Office system 12.0.6606.1000 [App Paths] :HKLM ois.exe=C:\PROGRA~1\MICROS~2\Office12\OIS.EXE ### ois.exe Microsoft Office Picture Manager Microsoft Corporation Microsoft O ffice Picture Manager 12.0.6606.1000 [App Paths] :HKLM OneNote.exe=C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE ### OneNote.exe Microsoft Office OneNote Microsoft Corporation Microsoft Offic e OneNote 12.0.6606.1000 [App Paths] :HKLM OUTLOOK.EXE=C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE ### OUTLOOK.EXE Microsoft Office Outlook Microsoft Corporation Microsoft Offic e Outlook 12.0.6607.1000 [App Paths] :HKLM pbrush.exe=%SystemRoot%\system32\mspaint.exe ### pbrush.exe [App Paths] :HKLM PictureViewer.exe=C:\Program Files\QuickTime\PictureViewer.e xe ### PictureViewer.exe PictureViewer Apple Inc. QuickTime QuickTime 7.6.9 (1680 .9) [App Paths] :HKLM powerpnt.exe=C:\PROGRA~1\MICROS~2\Office12\POWERPNT.EXE ### powerpnt.exe Microsoft Office PowerPoint Microsoft Corporation 2007 Micros oft Office system 12.0.6600.1000 [App Paths] :HKLM QuickTimePlayer.exe=C:\Program Files\QuickTime\QuickTimePlay er.exe ### QuickTimePlayer.exe QuickTime Player Apple Inc. QuickTime QuickTime 7.6.9 (1680.9) [App Paths] :HKLM setup.exe ### setup.exe [App Paths] :HKLM table30.exe ### table30.exe [App Paths] :HKLM wab.exe=%ProgramFiles%\Outlook Express\wab.exe ### wab.exe [App Paths] :HKLM wabmig.exe=%ProgramFiles%\Outlook Express\wabmig.exe ### wabmig.exe [App Paths] :HKLM winnt32.exe ### winnt32.exe [App Paths] :HKLM WinRAR.exe=C:\Program Files\WinRar\WinRAR.exe ### WinRAR.exe WinRAR archiver Alexander Roshal [App Paths] :HKLM Winword.exe=C:\PROGRA~1\MICROS~2\Office12\WINWORD.EXE ### Winword.exe Microsoft Office Word Microsoft Corporation 2007 Microsoft Off ice system 12.0.6612.1000 [App Paths] :HKLM wmplayer.exe=C:\Program Files\Windows Media Player\wmplayer. exe ### wmplayer.exe Windows Media Player Microsoft Corporation Microsoft Windows Op erating System 11.0.5721.5262 [App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD. EXE ### WORDPAD.EXE WordPad MFC Application Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6010 [App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE " ### WRITE.EXE [App Paths] :HKLM XPSViewer.exe="C:\WINDOWS\system32\XPSViewer\XPSViewer.exe" ### XPSViewer.exe XPS Viewer Microsoft Corporation Microsoft Windows Operating S ystem 3.0.6920.0 [Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0 [Disable Registry Tools] :HKCU DisableRegistryTools =0

[SharedTaskScheduler] :HKLM {438755C2-A8BA-11D1-B96B-00A0C90312E1}=C:\WINDOWS\ SYSTEM32\BROWSEUI.DLL ### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.5512 [SharedTaskScheduler] :HKLM {8C7461EF-2B13-11d2-BE35-3078302C2030}=C:\WINDOWS\ SYSTEM32\BROWSEUI.DLL ### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.5512 [Print Monitors] :HKLM Local Port=C:\WINDOWS\system32\LOCALSPL.DLL ### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5830 [Print Monitors] :HKLM Send To Microsoft OneNote Monitor=C:\WINDOWS\system32\M SONPMON.DLL ### Microsoft Office OneNote 2007 Printer Driver Microsoft Corporation Microso ft Office OneNote 2007 Printer Driver 12.3.6500.5000 [Print Monitors] :HKLM Standard TCP/IP Port=C:\WINDOWS\system32\TCPMON.DLL ### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5795 [Print Monitors] :HKLM USB Monitor=C:\WINDOWS\system32\USBMON.DLL ### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 1 (GFS Unread Stub)=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIONS.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 2 (GFS Stub)= C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIONS.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 2.5 (GFS Unre ad Folder)=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIONS.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 3 (GFS Folder )=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIONS.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Shell Icon Overlay Handlers] :HKLM Groove Explorer Icon Overlay 4 (GFS Unread Mark)=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIONS.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Shell Icon Overlay Handlers] :HKLM Offline Files=C:\WINDOWS\SYSTEM32\CSCUI.DL L ### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Context Menu Handlers] :HKLM AIMP=C:\PROGRA~1\AIMP3\MODULES\AIMP_MENU32.DLL ### Context Menu Extension AIMP DevTeam AIMP3 3.0x [Context Menu Handlers] :HKLM Offline Files=C:\WINDOWS\SYSTEM32\CSCUI.DLL ### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.6072 [Context Menu Handlers] :HKLM Open With EncryptionMenu=C:\WINDOWS\SYSTEM32\SHE LL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.6072 [Context Menu Handlers] :HKLM TeraCopy=C:\PROGRAM FILES\TERACOPY\TERACOPYEXT.D LL [Context Menu Handlers] :HKLM WinRAR=C:\PROGRAM FILES\WINRAR\RAREXT.DLL

[Context Menu Handlers] :HKLM XXX Groove GFS Context Menu Handler XXX=C:\PROGR AM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIONS.DLL ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}=C:\WINDOW S\SYSTEM32\SHELL32.DLL ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.6072 [Kernel Auto Boot] [ActiveSetup] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}=C:\WINDOWS\INF\UNREGMP2. EXE ### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microso ft Windows Operating System 11.0.5721.5262 [Svchost DLLs] :HKLM HTTPFilter=C:\WINDOWS\SYSTEM32\W3SSL.DLL ### SSL service for HTTP Microsoft Corporation Internet Information Services 6 .0.2600.5512 [Svchost DLLs] :HKLM Alerter=C:\WINDOWS\SYSTEM32\ALRSVC.DLL ### Alerter Service DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Svchost DLLs] :HKLM WebClient=C:\WINDOWS\SYSTEM32\WEBCLNT.DLL ### Web DAV Service DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL ### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft Window s Operating System 5.1.2600.5512 [Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\REGSVC.DLL ### Remote Registry Service Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL ### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5512 [Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL ### SSDP Service DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5512 [Svchost DLLs] :HKLM DnsCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL ### DNS Caching Resolver Service Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5817 [Svchost DLLs] :HKLM 6to4 [Svchost DLLs] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL ### Software installation Service Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL ### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Svchost DLLs] :HKLM Browser=C:\WINDOWS\SYSTEM32\BROWSER.DLL ### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5574 [Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL ### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Svchost DLLs] :HKLM DMServer=C:\WINDOWS\SYSTEM32\DMSERVER.DLL ### Logical Disk Manager service dll Microsoft Corp. Logical Disk Manager for Windows NT 1.0 [Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCSVC.DLL ### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5614 [Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL ### Microsoft Corporation COM Services 03.00.00.4414 [Svchost DLLs] :HKLM FastUserSwitchingCompatibility=C:\WINDOWS\SYSTEM32\SHSVCS .DLL

### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5853 [Svchost DLLs] :HKLM HidServ=%SystemRoot%\System32\hidserv.dll [Svchost DLLs] :HKLM Ias [Svchost DLLs] :HKLM Iprip [Svchost DLLs] :HKLM Irmon [Svchost DLLs] :HKLM LanmanServer=C:\WINDOWS\SYSTEM32\SRVSVC.DLL ### Server Service DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6031 [Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\SYSTEM32\WKSSVC.DLL ### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5826 [Svchost DLLs] :HKLM Messenger=C:\WINDOWS\SYSTEM32\MSGSVC.DLL ### NT Messenger Service Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5512 [Svchost DLLs] :HKLM Netman=C:\WINDOWS\SYSTEM32\NETMAN.DLL ### Network Connections Manager Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Svchost DLLs] :HKLM Nla=C:\WINDOWS\SYSTEM32\MSWSOCK.DLL ### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro soft Windows Operating System 5.1.2600.5649 [Svchost DLLs] :HKLM Ntmssvc=C:\WINDOWS\SYSTEM32\NTMSSVC.DLL ### Removable Storage Manager Microsoft Corporation Microsoft Windows Whistler O perating System 5.1.2400.5512 [Svchost DLLs] :HKLM NWCWorkstation [Svchost DLLs] :HKLM Nwsapagent [Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\SYSTEM32\RASAUTO.DLL ### Remote Access AutoDial Manager Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5512 [Svchost DLLs] :HKLM Rasman=C:\WINDOWS\SYSTEM32\RASMANS.DLL ### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\SYSTEM32\MPRDIM.DLL ### Dynamic Interface Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Svchost DLLs] :HKLM Schedule=C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL ### Task Scheduler Engine Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Svchost DLLs] :HKLM Seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL ### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Svchost DLLs] :HKLM SENS=C:\WINDOWS\SYSTEM32\SENS.DLL ### System Event Notification Service (SENS) Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5512 [Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\SYSTEM32\IPNATHLP.DLL ### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5589 [Svchost DLLs] :HKLM SRService=C:\WINDOWS\SYSTEM32\SRSVC.DLL ### System Restore Service Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\SYSTEM32\TAPISRV.DLL ### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5654 [Svchost DLLs] :HKLM Themes=C:\WINDOWS\SYSTEM32\SHSVCS.DLL ### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5853 [Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\TRKWKS.DLL ### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Svchost DLLs] :HKLM W32Time=C:\WINDOWS\SYSTEM32\W32TIME.DLL

### Windows Time Service Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5635 [Svchost DLLs] :HKLM WZCSVC=C:\WINDOWS\SYSTEM32\WZCSVC.DLL ### Wireless Zero Configuration Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5585 [Svchost DLLs] :HKLM Wmi=C:\WINDOWS\SYSTEM32\ADVAPI32.DLL ### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5793 [Svchost DLLs] :HKLM WmdmPmSp [Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Svchost DLLs] :HKLM xmlprov=C:\WINDOWS\SYSTEM32\XMLPROV.DLL ### Network Provisioning Service Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Svchost DLLs] :HKLM napagent=C:\WINDOWS\SYSTEM32\QAGENTRT.DLL ### Quarantine Agent Service Run-Time Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Svchost DLLs] :HKLM hkmsvc=C:\WINDOWS\SYSTEM32\KMSVC.DLL ### Key Management Service Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Svchost DLLs] :HKLM BITS=C:\WINDOWS\SYSTEM32\QMGR.DLL ### Background Intelligent Transfer Service Microsoft Corporation Microsoft Win dows Operating System 6.7.2600.5796 [Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\WUAUSERV.DLL ### Windows Update AutoUpdate Service Microsoft Corporation Microsoft Windows Op erating System 7.4.7600.229 [Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SHSVCS.DLL ### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5853 [Svchost DLLs] :HKLM WmdmPmSN=C:\WINDOWS\SYSTEM32\MSPMSNSV.DLL ### Microsoft Media Device Service Provider Microsoft Corporation Windows Medi a Device Manager 11.0.5721.5262 [Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL ### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5755 [Svchost DLLs] :HKLM TermService=C:\WINDOWS\SYSTEM32\TERMSRV.DLL ### Terminal Server Service Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5815 [Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL ### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5755 [Svchost DLLs] :HKLM eaphost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL ### Microsoft EAPHost service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\SYSTEM32\DOT3SVC.DLL ### Wired AutoConfig Service Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5745 [Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL ### Still Image Devices Service Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Svchost DLLs] :HKLM WUDFSvc=C:\WINDOWS\SYSTEM32\WUDFSVC.DLL ### Windows Driver Foundation - User-mode Driver Framework Service Microsoft C orporation Microsoft Windows Operating System 6.0.5716.32 [Bootexecute] :HKLM BootExecute=autocheck autochk * Partizan [Winlogon System] :HKLM system="" ### File is deleted or hidden by a rootkit or could not be located. [Winlogon System] :HKLM taskman="" ### File is deleted or hidden by a rootkit or could not be located. [Winlogon System] :HKLM UIHost=C:\WINDOWS\system32\LOGONUI.EXE

### Windows Logon UI Microsoft Corporation Microsoft Windows Operating System 6. 00.2900.5512 [Winlogon Autostart] :HKLM VmApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl " [Winlogon Autostart] :HKLM AppSetup="" [KnownDLLs] :HKLM advapi32=advapi32.dll [KnownDLLs] :HKLM comdlg32=comdlg32.dll [KnownDLLs] :HKLM DllDirectory=%SystemRoot%\system32 [KnownDLLs] :HKLM gdi32=gdi32.dll [KnownDLLs] :HKLM imagehlp=imagehlp.dll [KnownDLLs] :HKLM kernel32=kernel32.dll [KnownDLLs] :HKLM lz32=lz32.dll [KnownDLLs] :HKLM ole32=ole32.dll [KnownDLLs] :HKLM oleaut32=oleaut32.dll [KnownDLLs] :HKLM olecli32=olecli32.dll [KnownDLLs] :HKLM olecnv32=olecnv32.dll [KnownDLLs] :HKLM olesvr32=olesvr32.dll [KnownDLLs] :HKLM olethk32=olethk32.dll [KnownDLLs] :HKLM rpcrt4=rpcrt4.dll [KnownDLLs] :HKLM shell32=shell32.dll [KnownDLLs] :HKLM url=url.dll [KnownDLLs] :HKLM urlmon=urlmon.dll [KnownDLLs] :HKLM user32=user32.dll [KnownDLLs] :HKLM version=version.dll [KnownDLLs] :HKLM wininet=wininet.dll [KnownDLLs] :HKLM wldap32=wldap32.dll [Environment - Path] :HKLM Path=%SystemRoot%\system32;%SystemRoot%;%SystemRoot %\System32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\ATI Technologies\AT I.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem\ [List of Injected DLLs] :HKLM AppInit_DLLs="" [LSA Notification Packages] :HKLM scecli=C:\WINDOWS\system32\SCECLI.DLL ### scecli Windows Security Configuration Editor Client Engine Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.5512 [LSA Security Packages] :HKLM kerberos=C:\WINDOWS\system32\KERBEROS.DLL ### kerberos Kerberos Security Package Microsoft Corporation Microsoft Windows O perating System 5.1.2600.6059 [LSA Security Packages] :HKLM msv1_0=C:\WINDOWS\system32\MSV1_0.DLL ### msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation Microso ft Windows Operating System 5.1.2600.5876 [LSA Security Packages] :HKLM schannel=C:\WINDOWS\system32\SCHANNEL.DLL ### schannel TLS / SSL Security Provider Microsoft Corporation Microsoft Window s Operating System 5.1.2600.6006 [LSA Security Packages] :HKLM wdigest=C:\WINDOWS\system32\WDIGEST.DLL ### wdigest Microsoft Digest Access Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5846 [Auto Services] Ati HotKey Poller ### Internal Name: Ati HotKey Poller. Status: service is running. Actual File: C:\WINDOWS\system32\Ati2evxx.exe * ATI External Event Utility EXE Module ATI T echnologies Inc. ATI External Event Utility for Windows 6.14.10.4163 [Auto Services] ATI Smart ### Internal Name: ATI Smart. Status: service stopped. Actual File: C:\WINDOWS \system32\ati2sgag.exe * ATI Smart ATI Smart 5.13.0025 [Auto Services] AudioSrv ### Internal Name: AudioSrv. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Manages audio devices for Windows-based pro grams. If this service is stopped, audio devices and effects will not function p roperly. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] Browser

### Internal Name: Browser. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k netsvcs * Maintains an updated list of computers on th e network and supplies this list to computers designated as browsers. If this se rvice is stopped, this list will not be updated or maintained. If this service i s disabled, any services that explicitly depend on it will fail to start. Generi c Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5689 [Auto Services] clr_optimization_v4.0.30319_32 ### Internal Name: clr_optimization_v4.0.30319_32. Status: service stopped. Ac tual File: C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe * Microsof t .NET Framework NGEN .NET Runtime Optimization Service Microsoft Corporation Mi crosoft .NET Framework 4.0.30319.1 [Auto Services] CryptSvc ### Internal Name: CryptSvc. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k netsvcs * Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Roo t Service, which adds and removes Trusted Root Certification Authority certifica tes from this computer; and Key Service, which helps enroll this computer for ce rtificates. If this service is stopped, these management services will not funct ion properly. If this service is disabled, any services that explicitly depend o n it will fail to start. Generic Host Process for Win32 Services Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] DcomLaunch ### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\WIN DOWS\system32\svchost -k DcomLaunch * Provides launch functionality for DCOM ser vices. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5689 [Auto Services] Dhcp ### Internal Name: Dhcp. Status: service is running. Actual File: C:\WINDOWS\s ystem32\svchost.exe -k netsvcs * Manages network configuration by registering an d updating IP addresses and DNS names. Generic Host Process for Win32 Services M icrosoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] dmserver ### Internal Name: dmserver. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Detects and monitors new hard disk drives a nd sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configura tion information may become out of date. If this service is disabled, any servic es that explicitly depend on it will fail to start. Generic Host Process for Win 32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] Dnscache ### Internal Name: Dnscache. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k NetworkService * Resolves and caches Domain Name Syst em (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers . If this service is disabled, any services that explicitly depend on it will fa il to start. Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.5689 [Auto Services] DUMeterSvc ### Internal Name: DUMeterSvc. Status: service is running. Actual File: C:\Pro gram Files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterServic e * DU Meter Service collects network traffic statistics DU Meter Service Hagel Technologies Ltd. DU Meter 4.16 Build R3102 [Auto Services] Eventlog ### Internal Name: Eventlog. Status: service is running. Actual File: C:\WINDO WS\system32\services.exe * Enables event log messages issued by Windows-based pr ograms and components to be viewed in Event Viewer. This service cannot be stopp ed. Services and Controller app Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5922

[Auto Services] JavaQuickStarterService ### Internal Name: JavaQuickStarterService. Status: service is running. Actual File: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Fil es\Java\jre6\lib\deploy\jqs\jqs.conf" * Prefetches JRE files for faster startup of Java applets and applications Java(TM) Quick Starter Service Sun Microsystems , Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Auto Services] LanmanServer ### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W INDOWS\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh aring over the network for this computer. If this service is stopped, these func tions will be unavailable. If this service is disabled, any services that explic itly depend on it will fail to start. Generic Host Process for Win32 Services Mi crosoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] lanmanworkstation ### Internal Name: lanmanworkstation. Status: service is running. Actual File: C:\WINDOWS\system32\svchost.exe -k netsvcs * Creates and maintains client netwo rk connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly d epend on it will fail to start. Generic Host Process for Win32 Services Microsof t Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] LmHosts ### Internal Name: LmHosts. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k LocalService * Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Generic Host Process for Win32 Ser vices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] PlugPlay ### Internal Name: PlugPlay. Status: service is running. Actual File: C:\WINDO WS\system32\services.exe * Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will r esult in system instability. Services and Controller app Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.5922 [Auto Services] PolicyAgent ### Internal Name: PolicyAgent. Status: service is running. Actual File: C:\WI NDOWS\system32\lsass.exe * Manages IP security policy and starts the ISAKMP/Oakl ey (IKE) and the IP security driver. LSA Shell (Export Version) Microsoft Corpor ation Microsoft Windows Operating System 5.1.2600.5512 [Auto Services] ProtectedStorage ### Internal Name: ProtectedStorage. Status: service is running. Actual File: C:\WINDOWS\system32\lsass.exe * Provides protected storage for sensitive data, s uch as private keys, to prevent access by unauthorized services, processes, or u sers. LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Auto Services] RemoteRegistry ### Internal Name: RemoteRegistry. Status: service is running. Actual File: C: \WINDOWS\system32\svchost.exe -k LocalService * Enables remote users to modify r egistry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any ser vices that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5 689 [Auto Services] RpcSs ### Internal Name: RpcSs. Status: service is running. Actual File: C:\WINDOWS\ system32\svchost -k rpcss * Provides the endpoint mapper and other miscellaneous RPC services. Generic Host Process for Win32 Services Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.5689 [Auto Services] SamSs ### Internal Name: SamSs. Status: service is running. Actual File: C:\WINDOWS\ system32\lsass.exe * Stores security information for local user accounts. LSA Sh ell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.5512

[Auto Services] Schedule ### Internal Name: Schedule. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Enables a user to configure and schedule au tomated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Serv ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] seclogon ### Internal Name: seclogon. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unava ilable. If this service is disabled, any services that explicitly depend on it w ill fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] SENS ### Internal Name: SENS. Status: service is running. Actual File: C:\WINDOWS\s ystem32\svchost.exe -k netsvcs * Tracks system events such as Windows logon, net work, and power events. Notifies COM+ Event System subscribers of these events. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O perating System 5.1.2600.5689 [Auto Services] SharedAccess ### Internal Name: SharedAccess. Status: service is running. Actual File: C:\W INDOWS\system32\svchost.exe -k netsvcs * Provides network address translation, a ddressing, name resolution and/or intrusion prevention services for a home or sm all office network. Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] ShellHWDetection ### Internal Name: ShellHWDetection. Status: service is running. Actual File: C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay hardware events. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] Spooler ### Internal Name: Spooler. Status: service is running. Actual File: C:\WINDOW S\system32\spoolsv.exe * Loads files to memory for later printing. Spooler SubSy stem App Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6024 [Auto Services] srservice ### Internal Name: srservice. Status: service is running. Actual File: C:\WIND OWS\system32\svchost.exe -k netsvcs * Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Pr operties Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] STacSV ### Internal Name: STacSV. Status: service is running. Actual File: c:\program files\idt\intelxpv_v103\wdm\STacSV.exe * Manages audio jack configurations. IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001.0 [Auto Services] Themes ### Internal Name: Themes. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Provides user experience theme management. Ge neric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5689 [Auto Services] TrkWks ### Internal Name: TrkWks. Status: service is running. Actual File: C:\WINDOWS \system32\svchost.exe -k netsvcs * Maintains links between NTFS files within a c omputer or across computers in a network domain. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] W32Time ### Internal Name: W32Time. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Maintains date and time synchronization on a ll clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services

that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O perating System 5.1.2600.5689 [Auto Services] WebClient ### Internal Name: WebClient. Status: service is running. Actual File: C:\WIND OWS\system32\svchost.exe -k LocalService * Enables Windows-based programs to cre ate, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Servi ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] winmgmt ### Internal Name: winmgmt. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k netsvcs * Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not f unction properly. If this service is disabled, any services that explicitly depe nd on it will fail to start. Generic Host Process for Win32 Services Microsoft C orporation Microsoft Windows Operating System 5.1.2600.5689 [Auto Services] wuauserv ### Internal Name: wuauserv. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k netsvcs * Enables the download and installation of Wi ndows updates. If this service is disabled, this computer will not be able to us e the Automatic Updates feature or the Windows Update Web site. Generic Host Pro cess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5689 [Auto Services] WZCSVC ### Internal Name: WZCSVC. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Provides automatic configuration for the 802. 11 adapters Generic Host Process for Win32 Services Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5689 [Drivers] ntkrnlpa.exe=C:\WINDOWS\SYSTEM32\NTKRNLPA.EXE ### NT Kernel & System Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6055 [Drivers] hal.dll=C:\WINDOWS\SYSTEM32\HAL.DLL ### Hardware Abstraction Layer DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5687 [Drivers] KDCOM.DLL=C:\WINDOWS\SYSTEM32\KDCOM.DLL ### Kernel Debugger HW Extension DLL Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.0 [Drivers] BOOTVID.dll=C:\WINDOWS\SYSTEM32\BOOTVID.DLL ### VGA Boot Driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.0 [Drivers] ACPI.sys=C:\WINDOWS\system32\DRIVERS\ACPI.sys ### ACPI Driver for NT Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] WMILIB.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\WMILIB.SYS ### WMILIB WMI support library Dll Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.0 [Drivers] Partizan.sys=C:\WINDOWS\system32\DRIVERS\Partizan.sys ### Partizan - Rootkit detector Greatis Software RegRun Security Suite 6, 8, 0 , 0 [Drivers] pci.sys=C:\WINDOWS\system32\DRIVERS\pci.sys ### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Drivers] isapnp.sys=C:\WINDOWS\system32\DRIVERS\isapnp.sys ### PNP ISA Bus Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] ohci1394.sys=C:\WINDOWS\system32\DRIVERS\ohci1394.sys ### 1394 OpenHCI Port Driver Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5706

[Drivers] 1394BUS.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\1394BUS.SYS ### 1394 Bus Device Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5749 [Drivers] pciide.sys=C:\WINDOWS\system32\DRIVERS\pciide.sys ### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] PCIIDEX.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDEX.SYS ### PCI IDE Bus Driver Extension Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Drivers] MountMgr.sys=C:\WINDOWS\system32\DRIVERS\MountMgr.sys ### Mount Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.5815 [Drivers] ftdisk.sys=C:\WINDOWS\system32\DRIVERS\ftdisk.sys ### FT Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.0 [Drivers] dmload.sys=C:\WINDOWS\system32\DRIVERS\dmload.sys ### NT Disk Manager Startup Driver Microsoft Corp., Veritas Software. Logical Disk Manager for Windows NT 1.0 [Drivers] dmio.sys=C:\WINDOWS\system32\DRIVERS\dmio.sys ### NT Disk Manager I/O Driver Microsoft Corp., Veritas Software VERITAS NT Dis k Manager 1.0 [Drivers] PartMgr.sys=C:\WINDOWS\system32\DRIVERS\PartMgr.sys ### Partition Manager Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5512 [Drivers] mvxxmm.sys=C:\WINDOWS\system32\DRIVERS\mvxxmm.sys ### Marvell Aux NV Bridge DLL Marvell Semiconductor Inc. Marvell Flash Technol ogies 1.0.0.1202 [Drivers] VolSnap.sys=C:\WINDOWS\system32\DRIVERS\VolSnap.sys ### Volume Shadow Copy Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] atapi.sys=C:\WINDOWS\system32\DRIVERS\atapi.sys ### IDE/ATAPI Port Driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Drivers] mv61xx.sys=C:\WINDOWS\system32\DRIVERS\mv61xx.sys ### Marvell Thor Windows Driver Marvell Semiconductor, Inc. Marvell Thor 1.2. 0.7300 [Drivers] SCSIPORT.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\SCSIPORT.SYS ### SCSI Port Driver Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5512 [Drivers] mv61xxmm.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MV61XXMM.SYS ### Marvell Aux NV Bridge DLL Marvell Semiconductor Inc. Marvell Flash Technol ogies 1.0.0.1200 [Drivers] mv64xxmm.sys=C:\WINDOWS\system32\DRIVERS\mv64xxmm.sys ### Marvell Aux NV Bridge DLL Marvell Semiconductor Inc. Marvell Flash Technol ogies 1.0.0.1200 [Drivers] disk.sys=C:\WINDOWS\system32\DRIVERS\disk.sys ### PnP Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5597 [Drivers] CLASSPNP.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\CLASSPNP.SYS ### SCSI Class System Dll Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Drivers] fltMgr.sys=C:\WINDOWS\system32\DRIVERS\fltMgr.sys ### Microsoft Filesystem Filter Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] sr.sys=C:\WINDOWS\system32\DRIVERS\sr.sys ### System Restore Filesystem Filter Driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5512 [Drivers] KSecDD.sys=C:\WINDOWS\system32\DRIVERS\KSecDD.sys ### Kernel Security Support Provider Interface Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5834

[Drivers] Ntfs.sys=C:\WINDOWS\system32\DRIVERS\Ntfs.sys ### NT File System Driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5782 [Drivers] NDIS.sys=C:\WINDOWS\system32\DRIVERS\NDIS.sys ### NDIS 5.1 wrapper driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5588 [Drivers] Mup.sys=C:\WINDOWS\system32\DRIVERS\Mup.sys ### Multiple UNC Provider driver Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.6103 [Drivers] intelppm.sys=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS ### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Drivers] ati2mtag.sys=C:\WINDOWS\SYSTEM32\DRIVERS\ATI2MTAG.SYS ### ATI Radeon WindowsNT Miniport Driver ATI Technologies Inc. ATI Radeon Wind owsNT Miniport Driver 6.14.10.6683 [Drivers] VIDEOPRT.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\VIDEOPRT.SYS ### Video Port Driver Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5745 [Drivers] HECI.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HECI.SYS ### Intel(R) Management Engine Interface Intel Corporation Intel(R) Management Engine Interface 2.1.22.1033 [Drivers] e1e5132.sys=C:\WINDOWS\SYSTEM32\DRIVERS\E1E5132.SYS ### Intel(R) PRO/1000 Adapter NDIS 5.2 deserialized driver Intel Corporation I ntel(R) PRO/1000 Adapter 9.4.17.0 [Drivers] usbuhci.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS ### UHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5512 [Drivers] USBPORT.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\USBPORT.SYS ### USB 1.1 & 2.0 Port Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5778 [Drivers] usbehci.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS ### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5825 [Drivers] HDAudBus.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS ### High Definition Audio Bus Driver v1.0a Windows (R) Server 2003 DDK provide r Microsoft Windows Operating System 5.10.01.5013 [Drivers] cdrom.sys=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS ### SCSI CD-ROM Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5593 [Drivers] redbook.sys=C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS ### Redbook Audio Filter Driver Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Drivers] ks.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KS.SYS ### Kernel CSA Library Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.5512 [Drivers] SAA713x.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SAA713X.SYS ### SAA713x TV Card - Video Capture Driver Philips Semiconductors SAA713x TV C ard 2, 3, 4, 8 [Drivers] STREAM.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\STREAM.SYS ### WDM CODEC Class Device Driver 2.0 Microsoft Corporation Microsoft(R) Windo ws(R) Operating System 5.3.2600.5512 [Drivers] nic1394.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NIC1394.SYS ### IEEE1394 Ndis Miniport and Call Manager Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5512 [Drivers] parport.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS ### Parallel Port Driver Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5512 [Drivers] i8042prt.sys=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS ### i8042 Port Driver Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5512

[Drivers] kbdclass.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS ### Keyboard Class Driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Drivers] serial.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS ### Serial Device Driver Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5512 [Drivers] serenum.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS ### Serial Port Enumerator Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Drivers] audstub.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS ### AudStub Driver Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.0 [Drivers] rasl2tp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS ### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.5512 [Drivers] ndistapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS ### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft Windows O perating System 5.1.2600.6132 [Drivers] ndiswan.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS ### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft W indows Operating System 5.1.2600.5588 [Drivers] raspppoe.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS ### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5815 [Drivers] raspptp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS ### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Drivers] TDI.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\TDI.SYS ### TDI Wrapper Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.5512 [Drivers] psched.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS ### MS QoS Packet Scheduler Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5848 [Drivers] msgpc.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS ### MS General Packet Classifier Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Drivers] ptilink.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS ### Parallel Technologies DirectParallel IO Library Parallel Technologies, Inc . Microsoft Windows Operating System 5.1.2600.0 [Drivers] raspti.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS ### PTI DirectParallel(R) mini-port/call-manager driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] rdpdr.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS ### Microsoft RDP Device redirector Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5875 [Drivers] termdd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS ### Terminal Server Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Drivers] mouclass.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS ### Mouse Class Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] swenum.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS ### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft(R ) Windows(R) Operating System 5.3.2600.5512 [Drivers] update.sys=C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS ### Update Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.5512 [Drivers] mssmbios.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS ### System Management BIOS Driver Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512

[Drivers] NDProxy.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS ### NDIS Proxy Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .6048 [Drivers] usbhub.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS ### Default Hub Driver for USB Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] USBD.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\USBD.SYS ### Universal Serial Bus Driver Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.0 [Drivers] sthda.sys=C:\WINDOWS\SYSTEM32\DRIVERS\STHDA.SYS ### IDT PC Audio IDT, Inc. IDT PC Audio 5.10.20001.0 [Drivers] portcls.sys=C:\WINDOWS\SYSTEM32\DRIVERS\PORTCLS.SYS ### Port Class (Class Driver for Port/Miniport Devices) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5566 [Drivers] drmk.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DRMK.SYS ### Microsoft Kernel DRM Descrambler Filter Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5512 [Drivers] WDMTuner.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WDMTUNER.SYS ### WDM TV Tuner Driver Philips Semiconductors TV Card 2, 3, 4, 7 [Drivers] Fs_Rec.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\FS_REC.SYS ### File System Recognizer Driver Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5686 [Drivers] Null.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NULL.SYS ### NULL Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.0 [Drivers] Beep.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS ### BEEP Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.0 [Drivers] vga.sys=C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS ### VGA/Super VGA Video Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] mnmdd.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MNMDD.SYS ### Frame buffer simulator Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.0 [Drivers] RDPCDD.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS ### RDP Miniport Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.0 [Drivers] Msfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MSFS.SYS ### Mailslot driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512 [Drivers] Npfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\NPFS.SYS ### NPFS Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.5512 [Drivers] rasacd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS ### RAS Automatic Connection Driver Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.0 [Drivers] ipsec.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS ### IPSec Driver Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.5512 [Drivers] tcpip.sys=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS ### TCP/IP Protocol Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.6009 [Drivers] ipnat.sys=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS ### IP Network Address Translator Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Drivers] netbt.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS ### MBT Transport driver Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5512 [Drivers] wanarp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS ### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win

dows Operating System 5.1.2600.5512 [Drivers] afd.sys=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS ### Ancillary Function Driver for WinSock Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.6142 [Drivers] arp1394.sys=C:\WINDOWS\SYSTEM32\DRIVERS\ARP1394.SYS ### IP/1394 Arp Client Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] netbios.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS ### NetBIOS interface driver Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5512 [Drivers] rdbss.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS ### Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsof t Windows Operating System 5.1.2600.5643 [Drivers] mrxsmb.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS ### Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.6133 [Drivers] HWiNFO32.SYS=C:\PROGRAM FILES\HWINFO32\HWINFO32.SYS ### HWiNFO32 Kernel Driver REALiX(tm) HWiNFO32 Kernel Driver 8.00 [Drivers] Fips.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\FIPS.SYS ### FIPS Crypto Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] usbccgp.sys=C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS ### USB Common Class Generic Parent Driver Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.5585 [Drivers] hidusb.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS ### USB Miniport Driver for Input Devices Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5512 [Drivers] HIDCLASS.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\HIDCLASS.SYS ### Hid Class Library Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5512 [Drivers] HIDPARSE.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\HIDPARSE.SYS ### Hid Parsing Library Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] ewusbmdm.sys=C:\WINDOWS\SYSTEM32\DRIVERS\EWUSBMDM.SYS ### USB Modem/Serial Device Driver Huawei Technologies Co., Ltd. Huawei Techno logies Co., Ltd. USB Modem/Serial Device Driver 2. 0. 3. 826 [Drivers] Modem.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS ### Modem Device Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] ewusbnet.sys=C:\WINDOWS\SYSTEM32\DRIVERS\EWUSBNET.SYS ### USB NDIS Miniport Driver Huawei Technologies Co., Ltd. Huawei Technologies Co., Ltd. USB NDIS Miniport Driver 1. 0. 2. 905 [Drivers] USBSTOR.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS ### USB Mass Storage Class Driver Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Drivers] mouhid.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS ### HID Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.0 [Drivers] Cdfs.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS ### CD-ROM File System Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] atapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DUMP_ATAPI.SYS [Drivers] WMILIB.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\DUMP_WMILIB.SYS [Drivers] win32k.sys=C:\WINDOWS\SYSTEM32\WIN32K.SYS ### Multi-User Win32 Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.6149 [Drivers] Dxapi.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXAPI.SYS ### DirectX API Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] watchdog.sys=C:\WINDOWS\SYSTEM32\WATCHDOG.SYS

### Watchdog Driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512 [Drivers] dxg.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXG.SYS ### DirectX Graphics Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Drivers] dxgthk.sys=C:\WINDOWS\SYSTEM32\DRIVERS\DXGTHK.SYS ### DirectX Graphics Driver Thunk Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.0 [Drivers] ati2dvag.dll=C:\WINDOWS\SYSTEM32\ATI2DVAG.DLL ### ATI Radeon WindowsNT Display Driver ATI Technologies Inc. ATI Radeon Windo wsNT Display Driver 6.14.10.6683 [Drivers] ati2cqag.dll=C:\WINDOWS\SYSTEM32\ATI2CQAG.DLL ### Central Memory Manager / Queue Server Module ATI Technologies Inc. ATI Rad eon Family 5.2.3790.1830 [Drivers] atikvmag.dll=C:\WINDOWS\SYSTEM32\ATIKVMAG.DLL ### Virtual Command And Memory Manager ATI Technologies Inc. Virtual Command A nd Memory Manager 5.2.3790.1830 [Drivers] ati3duag.dll=C:\WINDOWS\SYSTEM32\ATI3DUAG.DLL ### ati3duag.dll ATI Technologies Inc. ATI Technologies Inc. Radeon DirectX U niversal Driver 6.14.10.0489 [Drivers] ativvaxx.dll=C:\WINDOWS\SYSTEM32\ATIVVAXX.DLL ### Radeon Video Acceleration Universal Driver ATI Technologies Inc. ATI Tech nologies Inc. Radeon Video Acceleration Universal Driver 6.14.10.0148 [Drivers] ATMFD.DLL=C:\WINDOWS\SYSTEM32\ATMFD.DLL ### Windows NT OpenType/Type 1 Font Driver Adobe Systems Incorporated Adobe Ty pe Manager 5.1 Build 232 [Drivers] ndisuio.sys=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS ### NDIS User mode I/O Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Drivers] rspndr.sys=C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS ### Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation Micr osoft Windows Operating System 5.1.2600.5611 [Drivers] wdmaud.sys=C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS ### MMSYSTEM Wave/Midi API mapper Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Drivers] sysaudio.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS ### System Audio WDM Filter Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Drivers] mrxdav.sys=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS ### Windows NT WebDav Minirdr Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6007 [Drivers] ParVdm.SYS=C:\WINDOWS\SYSTEM32\DRIVERS\PARVDM.SYS ### VDM Parallel Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Drivers] srv.sys=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS ### Server driver Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.6082 [Drivers] UnHackMeDrv.sys=C:\WINDOWS\SYSTEM32\DRIVERS\UNHACKMEDRV.SYS ### UnHackMe Kernel Driver Greatis Software, LLC. UnHackme 5.00.2195.1620 [Drivers] HTTP.sys=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS ### HTTP Protocol Stack Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5891 [Drivers] kmixer.sys=C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS ### Kernel Mode Audio Mixer Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Drivers] ntdll.dll=C:\WINDOWS\SYSTEM32\NTDLL.DLL ### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.6055 [Services detected by Partizan] :HKLM .NET CLR Data [Services detected by Partizan] :HKLM .NET CLR Networking

[Services detected by Partizan] :HKLM .NET CLR Networking 4.0.0.0 [Services detected by Partizan] :HKLM .NET Data Provider for Oracle [Services detected by Partizan] :HKLM .NET Data Provider for SqlServer [Services detected by Partizan] :HKLM .NET Memory Cache 4.0 [Services detected by Partizan] :HKLM .NETFramework [Services detected by Partizan] :HKLM 713xTVCard=C:\WINDOWS\SYSTEM32\DRIVERS\S AA713X.SYS ### Driver SAA7130 TV Card Start Type: loaded automatically by Server Manager SAA713x TV Card - Video Capture Driver Philips Semiconductors SAA713x TV Card 2, 3, 4, 8 [Services detected by Partizan] :HKLM Abiosdsk ### Driver Start Type: disabled [Services detected by Partizan] :HKLM abp480n5 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SY S ### Driver Microsoft ACPI Driver Start Type: loaded automatically by the Boot Loader ACPI Driver for NT Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM ACPIEC=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIE C.SYS ### Driver Start Type: disabled ACPI Embedded Controller Driver Microsoft Corp oration Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM adpu160m ### Driver Start Type: disabled [Services detected by Partizan] :HKLM aec=C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS ### Driver Microsoft Kernel Acoustic Echo Canceller Start Type: loaded manuall y on demand Microsoft Acoustic Echo Canceller Microsoft Corporation Microsoft Win dows Operating System 5.1.2601.3142 [Services detected by Partizan] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS ### Driver AFD AFD Networking Support Environment Start Type: loaded automatic ally at Kernel initialization Ancillary Function Driver for WinSock Microsoft Co rporation Microsoft Windows Operating System 5.1.2600.6142 [Services detected by Partizan] :HKLM Aha154x ### Driver Start Type: disabled [Services detected by Partizan] :HKLM aic78u2 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM aic78xx ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Alerter=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Alerter Notifies selected users and computers of administrative al erts. If the service is stopped, programs that use administrative alerts will no t receive them. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: disabled Generic Host Process for Win32 S ervices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM ALG=C:\WINDOWS\SYSTEM32\ALG.EXE ### Service Application Layer Gateway Service Provides support for 3rd party p rotocol plug-ins for Internet Connection Sharing and the Windows Firewall. Start Type: loaded manually on demand Application Layer Gateway Service Microsoft Cor poration Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM AliIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM amsint ### Driver Start Type: disabled [Services detected by Partizan] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Application Management Provides software installation services suc h as Assign, Publish, and Remove. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Arp1394=C:\WINDOWS\SYSTEM32\DRIVERS\ARP1

394.SYS ### Driver 1394 ARP Client Protocol 1394 ARP Client Protocol Start Type: loade d manually on demand IP/1394 Arp Client Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Services detected by Partizan] :HKLM asc ### Driver Start Type: disabled [Services detected by Partizan] :HKLM asc3350p ### Driver Start Type: disabled [Services detected by Partizan] :HKLM asc3550 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ASP.NET [Services detected by Partizan] :HKLM ASP.NET_1.1.4322 [Services detected by Partizan] :HKLM ASP.NET_2.0.50727 [Services detected by Partizan] :HKLM ASP.NET_4.0.30319 [Services detected by Partizan] :HKLM aspnet_state=C:\WINDOWS\MICROSOFT.NET\FR AMEWORK\V4.0.30319\ASPNET_STATE.EXE ### Service ASP.NET State Service Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded manually on demand Microsoft ASP.NE T State Server Microsoft Corporation Microsoft .NET Framework 4.0.30319.1 [Services detected by Partizan] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASY NCMAC.SYS ### Driver RAS Asynchronous Media Driver RAS Asynchronous Media Driver Start T ype: loaded manually on demand MS Remote Access serial network driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI. SYS ### Driver Standard IDE/ESDI Hard Disk Controller Start Type: loaded automatic ally by the Boot Loader IDE/ATAPI Port Driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Atdisk ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Ati HotKey Poller=C:\WINDOWS\SYSTEM32\AT I2EVXX.EXE ### Service Start Type: loaded automatically by Server Manager ATI External Ev ent Utility EXE Module ATI Technologies Inc. ATI External Event Utility for Wind ows 6.14.10.4163 [Services detected by Partizan] :HKLM ATI Smart=C:\WINDOWS\SYSTEM32\ATI2SGAG.E XE ### Service ATI Smart Start Type: loaded automatically by Server Manager ATI S mart ATI Smart 5.13.0025 [Services detected by Partizan] :HKLM ati2mtag=C:\WINDOWS\SYSTEM32\DRIVERS\ATI 2MTAG.SYS ### Driver Start Type: loaded manually on demand ATI Radeon WindowsNT Miniport Driver ATI Technologies Inc. ATI Radeon WindowsNT Miniport Driver 6.14.10.6683 [Services detected by Partizan] :HKLM Atierecord [Services detected by Partizan] :HKLM Atmarpc=C:\WINDOWS\SYSTEM32\DRIVERS\ATMA RPC.SYS ### Driver ATM ARP Client Protocol ATM ARP Client Protocol Start Type: loaded manually on demand IP/ATM Arp Client Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5512 [Services detected by Partizan] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Audio Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Proce ss for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5689 [Services detected by Partizan] :HKLM audstub=C:\WINDOWS\SYSTEM32\DRIVERS\AUDS

TUB.SYS ### Driver Audio Stub Driver Start Type: loaded manually on demand AudStub Dri ver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM BattC [Services detected by Partizan] :HKLM Beep=C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SY S ### Driver Start Type: loaded automatically at Kernel initialization BEEP Driv er Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM BITS=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Background Intelligent Transfer Service Transfers data between cli ents and servers in the background. If BITS is disabled, features such as Window s Update will not work correctly. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Browser=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Computer Browser Maintains an updated list of computers on the net work and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is dis abled, any services that explicitly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM cbidf2k=C:\WINDOWS\SYSTEM32\DRIVERS\CBID F2K.SYS ### Driver Start Type: disabled CardBus/PCMCIA IDE Miniport Driver Microsoft C orporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM CCDECODE=C:\WINDOWS\SYSTEM32\DRIVERS\CCD ECODE.SYS ### Driver Closed Caption Decoder Start Type: loaded manually on demand WDM Cl osed Caption VBI Codec Microsoft Corporation Microsoft(R) Windows(R) Operating S ystem 5.3.2600.5512 [Services detected by Partizan] :HKLM cd20xrnt ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Cdaudio=C:\WINDOWS\SYSTEM32\DRIVERS\CDAU DIO.SYS ### Driver Start Type: loaded automatically at Kernel initialization CD-ROM Au dio Filter Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.0 [Services detected by Partizan] :HKLM Cdfs=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SY S ### Driver Start Type: disabled CD-ROM File System Driver Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM. SYS ### Driver CD-ROM Driver Start Type: loaded automatically at Kernel initializa tion SCSI CD-ROM Driver Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5593 [Services detected by Partizan] :HKLM Changer ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM ClipSrv=C:\WINDOWS\SYSTEM32\CLIPSRV.EXE ### Service ClipBook Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be a ble to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: disabled Windows NT DDE Server Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512 [Services detected by Partizan] :HKLM clr_optimization_v2.0.50727_32=C:\WINDOW S\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE ### Service .NET Runtime Optimization Service v2.0.50727_X86 Microsoft .NET Fr amework NGEN Start Type: disabled .NET Runtime Optimization Service Microsoft Co rporation Microsoft .NET Framework 2.0.50727.3053

[Services detected by Partizan] :HKLM clr_optimization_v4.0.30319_32=C:\WINDOW S\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE ### Service Microsoft .NET Framework NGEN v4.0.30319_X86 Microsoft .NET Framew ork NGEN Start Type: loaded automatically by Server Manager .NET Runtime Optimiz ation Service Microsoft Corporation Microsoft .NET Framework 4.0.30319.1 [Services detected by Partizan] :HKLM CmdIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM COMSysApp=C:\WINDOWS\SYSTEM32\DLLHOST.EX E ### Service COM+ System Application Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, a ny services that explicitly depend on it will fail to start. Start Type: loaded manually on demand COM Surrogate Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Cpqarray ### Driver Start Type: disabled [Services detected by Partizan] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Cryptographic Services Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Roo t Service, which adds and removes Trusted Root Certification Authority certifica tes from this computer; and Key Service, which helps enroll this computer for ce rtificates. If this service is stopped, these management services will not funct ion properly. If this service is disabled, any services that explicitly depend o n it will fail to start. Start Type: loaded automatically by Server Manager Gene ric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5689 [Services detected by Partizan] :HKLM dac2w2k ### Driver Start Type: disabled [Services detected by Partizan] :HKLM dac960nt ### Driver Start Type: disabled [Services detected by Partizan] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\SVCHOST.e xe ### Service DCOM Server Process Launcher Provides launch functionality for DCO M services. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5689 [Services detected by Partizan] :HKLM Dhcp=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service DHCP Client Manages network configuration by registering and updat ing IP addresses and DNS names. Start Type: loaded automatically by Server Manag er Generic Host Process for Win32 Services Microsoft Corporation Microsoft Window s Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SY S ### Driver Disk Driver Start Type: loaded automatically by the Boot Loader PnP Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.559 7 [Services detected by Partizan] :HKLM dmadmin=C:\WINDOWS\SYSTEM32\DMADMIN.EXE ### Service Logical Disk Manager Administrative Service Configures hard disk d rives and volumes. The service only runs for configuration processes and then st ops. Start Type: loaded manually on demand Logical Disk Manager service process Microsoft Corp., Veritas Software Logical Disk Manager for Windows NT 1.0 [Services detected by Partizan] :HKLM dmboot=C:\WINDOWS\SYSTEM32\DRIVERS\DMBOO T.SYS ### Driver Start Type: disabled NT Disk Manager Startup Driver Microsoft Corp. , Veritas Software VERITAS NT Disk Manager 1.0 [Services detected by Partizan] :HKLM dmio=C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SY S ### Driver Logical Disk Manager Driver Start Type: loaded automatically by the Boot Loader NT Disk Manager I/O Driver Microsoft Corp., Veritas Software VERITA

S NT Disk Manager 1.0 [Services detected by Partizan] :HKLM dmload=C:\WINDOWS\SYSTEM32\DRIVERS\DMLOA D.SYS ### Driver Start Type: loaded automatically by the Boot Loader NT Disk Manager Startup Driver Microsoft Corp., Veritas Software. Logical Disk Manager for Wind ows NT 1.0 [Services detected by Partizan] :HKLM dmserver=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Logical Disk Manager Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service fo r configuration. If this service is stopped, dynamic disk status and configurati on information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded automatical ly by Server Manager Generic Host Process for Win32 Services Microsoft Corporati on Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM DMusic=C:\WINDOWS\SYSTEM32\DRIVERS\DMUSI C.SYS ### Driver Microsoft Kernel DLS Syntheiszer Start Type: loaded manually on dem and Microsoft Kernel DLS Synthesizer Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5512 [Services detected by Partizan] :HKLM Dnscache=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service DNS Client Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to res olve DNS names and locate Active Directory domain controllers. If this service i s disabled, any services that explicitly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Serv ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Dot3svc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Wired AutoConfig This service performs IEEE 802.1X authentication on Ethernet interfaces Start Type: loaded manually on demand Generic Host Proces s for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.5689 [Services detected by Partizan] :HKLM dpti2o ### Driver Start Type: disabled [Services detected by Partizan] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMK AUD.SYS ### Driver Microsoft Kernel DRM Audio Descrambler Start Type: loaded manually on demand Microsoft Kernel DRM Audio Descrambler Filter Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM DUMeterSvc=C:\PROGRAM FILES\DU METER\DUM ETERSVC.EXE ### Service DU Meter Service DU Meter Service collects network traffic statist ics Start Type: loaded automatically by Server Manager DU Meter Service Hagel T echnologies Ltd. DU Meter 4.16 Build R3102 [Services detected by Partizan] :HKLM DumpDrv=C:\WINDOWS\SYSTEM32\DRIVERS\DUMP DRV.SYS ### Driver Crash Dump Driver Start Type: loaded automatically at Kernel initia lization Crash Dump Driver Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5864 [Services detected by Partizan] :HKLM e1express=C:\WINDOWS\SYSTEM32\DRIVERS\E1 E5132.SYS ### Driver Intel(R) PRO/1000 PCI Express Network Connection Driver Start Type: loaded manually on demand Intel(R) PRO/1000 Adapter NDIS 5.2 deserialized drive r Intel Corporation Intel(R) PRO/1000 Adapter 9.4.17.0 [Services detected by Partizan] :HKLM EapHost=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Extensible Authentication Protocol Service Provides windows client s Extensible Authentication Protocol Service Start Type: loaded manually on dema nd Generic Host Process for Win32 Services Microsoft Corporation Microsoft Window s Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Eventlog=C:\WINDOWS\SYSTEM32\SERVICES.EX E

### Service Event Log Enables event log messages issued by Windows-based progr ams and components to be viewed in Event Viewer. This service cannot be stopped. Start Type: loaded automatically by Server Manager Services and Controller app Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5922 [Services detected by Partizan] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\SVCHOST. EXE ### Service COM+ Event System Supports System Event Notification Service (SENS ), which provides automatic distribution of events to subscribing Component Obje ct Model (COM) components. If the service is stopped, SENS will close and will n ot be able to provide logon and logoff notifications. If this service is disable d, any services that explicitly depend on it will fail to start. Start Type: loa ded manually on demand Generic Host Process for Win32 Services Microsoft Corpora tion Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM ewusbnet=C:\WINDOWS\SYSTEM32\DRIVERS\EWU SBNET.SYS ### Driver HUAWEI USB-NDIS miniport Start Type: loaded manually on demand USB NDIS Miniport Driver Huawei Technologies Co., Ltd. Huawei Technologies Co., Ltd. USB NDIS Miniport Driver 1. 0. 2. 905 [Services detected by Partizan] :HKLM exFat=C:\WINDOWS\SYSTEM32\DRIVERS\EXFAT. SYS ### Driver Start Type: disabled Microsoft Extended FAT File System Microsoft C orporation Microsoft Windows Operating System 5.1.2600.5686 [Services detected by Partizan] :HKLM Fastfat=C:\WINDOWS\SYSTEM32\DRIVERS\FAST FAT.SYS ### Driver Start Type: disabled Fast FAT File System Driver Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM FastUserSwitchingCompatibility=C:\WINDOW S\SYSTEM32\SVCHOST.EXE ### Service Fast User Switching Compatibility Provides management for applicat ions that require assistance in a multiple user environment. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Fdc=C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS ### Driver Start Type: loaded automatically at Kernel initialization Floppy Di sk Controller Driver Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.5512 [Services detected by Partizan] :HKLM Fips=C:\WINDOWS\SYSTEM32\DRIVERS\FIPS.SY S ### Driver Start Type: loaded automatically at Kernel initialization FIPS Cryp to Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Flpydisk=C:\WINDOWS\SYSTEM32\DRIVERS\FLP YDISK.SYS ### Driver Start Type: loaded automatically at Kernel initialization Floppy Dr iver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMG R.SYS ### Driver FltMgr File System Filter Manager Driver Start Type: loaded automat ically by the Boot Loader Microsoft Filesystem Filter Manager Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM FontCache3.0.0.0=C:\WINDOWS\MICROSOFT.NE T\FRAMEWORK\V3.0\WPF\PRESENTATIONFONTCACHE.EXE ### Service Windows Presentation Foundation Font Cache 3.0.0.0 Optimizes perfo rmance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already r unning. It can be disabled, though doing so will degrade the performance of WPF applications. Start Type: loaded manually on demand Windows Presentation Foundat ion Font Cache Service Microsoft Corporation Microsoft Windows Operating System 3. 0.6920.0 [Services detected by Partizan] :HKLM Fs_Rec=C:\WINDOWS\SYSTEM32\DRIVERS\FS_RE C.SYS

### Driver Start Type: loaded automatically at Kernel initialization File Syst em Recognizer Driver Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.5686 [Services detected by Partizan] :HKLM Ftdisk=C:\WINDOWS\SYSTEM32\DRIVERS\FTDIS K.SYS ### Driver Volume Manager Driver Start Type: loaded automatically by the Boot Loader FT Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.0 [Services detected by Partizan] :HKLM Gpc=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SY S ### Driver Generic Packet Classifier Generic Packet Classifier Start Type: loa ded manually on demand MS General Packet Classifier Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM HDAudBus=C:\WINDOWS\SYSTEM32\DRIVERS\HDA UDBUS.SYS ### Driver Microsoft UAA Bus Driver for High Definition Audio Start Type: load ed manually on demand High Definition Audio Bus Driver v1.0a Windows (R) Server 2003 DDK provider Microsoft Windows Operating System 5.10.01.5013 [Services detected by Partizan] :HKLM HECI=C:\WINDOWS\SYSTEM32\DRIVERS\HECI.SY S ### Driver Intel(R) Management Engine Interface Start Type: loaded manually on demand Intel(R) Management Engine Interface Intel Corporation Intel(R) Manageme nt Engine Interface 2.1.22.1033 [Services detected by Partizan] :HKLM HidServ=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Human Interface Device Access Enables generic input access to Huma n Interface Devices (HID), which activates and maintains the use of predefined h ot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer functi on. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: disabled Generic Host Process for Win32 Services Micr osoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM hidusb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUS B.SYS ### Driver Microsoft HID Class Driver Start Type: loaded manually on demand US B Miniport Driver for Input Devices Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Services detected by Partizan] :HKLM hkmsvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Health Key and Certificate Management Service Manages health certi ficates and keys (used by NAP) Start Type: loaded manually on demand Generic Hos t Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5689 [Services detected by Partizan] :HKLM hpn ### Driver Start Type: disabled [Services detected by Partizan] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SY S ### Driver HTTP This service implements the hypertext transfer protocol (HTTP) . If this service is disabled, any services that explicitly depend on it will fa il to start. Start Type: loaded manually on demand HTTP Protocol Stack Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5891 [Services detected by Partizan] :HKLM HTTPFilter=C:\WINDOWS\SYSTEM32\SVCHOST.E XE ### Service HTTP SSL This service implements the secure hypertext transfer pro tocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If th is service is disabled, any services that explicitly depend on it will fail to s tart. Start Type: loaded manually on demand Generic Host Process for Win32 Servi ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM hwcdcmdm0 [Services detected by Partizan] :HKLM hwdatacard=C:\WINDOWS\SYSTEM32\DRIVERS\E WUSBMDM.SYS ### Driver Huawei DataCard USB Modem and USB Serial Start Type: loaded manuall

y on demand USB Modem/Serial Device Driver Huawei Technologies Co., Ltd. Huawei Technologies Co., Ltd. USB Modem/Serial Device Driver 2. 0. 3. 826 [Services detected by Partizan] :HKLM HWiNFO32=C:\PROGRAM FILES\HWINFO32\HWINF O32.SYS ### Driver HWiNFO32/64 Kernel Driver Start Type: loaded automatically at Kerne l initialization HWiNFO32 Kernel Driver REALiX(tm) HWiNFO32 Kernel Driver 8.00 [Services detected by Partizan] :HKLM hwusbapp [Services detected by Partizan] :HKLM hwusbdev [Services detected by Partizan] :HKLM hwusbser [Services detected by Partizan] :HKLM i2omgmt ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM i2omp ### Driver Start Type: disabled [Services detected by Partizan] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I80 42PRT.SYS ### Driver i8042 Keyboard and PS/2 Mouse Port Driver Start Type: loaded automa tically at Kernel initialization i8042 Port Driver Microsoft Corporation Microso ft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM idsvc=C:\WINDOWS\MICROSOFT.NET\FRAMEWORK \V3.0\WINDOWS COMMUNICATION FOUNDATION\INFOCARD.EXE ### Service Windows CardSpace Securely enables the creation, management, and d isclosure of digital identities. Start Type: loaded manually on demand Windows C ardSpace Microsoft Corporation Microsoft .NET Framework 3.0.4506.648 [Services detected by Partizan] :HKLM Imapi=C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI. SYS ### Driver CD-Burning Filter Driver Start Type: loaded automatically at Kernel initialization IMAPI Kernel Driver Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Services detected by Partizan] :HKLM ImapiService=C:\WINDOWS\SYSTEM32\IMAPI.E XE ### Service IMAPI CD-Burning COM Service Manages CD recording using Image Mast ering Applications Programming Interface (IMAPI). If this service is stopped, th is computer will be unable to record CDs. If this service is disabled, any servi ces that explicitly depend on it will fail to start. Start Type: loaded manually on demand Image Mastering API Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5512 [Services detected by Partizan] :HKLM inetaccs [Services detected by Partizan] :HKLM ini910u ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Inport [Services detected by Partizan] :HKLM IntelIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM intelppm=C:\WINDOWS\SYSTEM32\DRIVERS\INT ELPPM.SYS ### Driver Intel Processor Driver Start Type: loaded automatically at Kernel i nitialization Processor Device Driver Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Ip6Fw=C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW. SYS ### Driver IPv6 Windows Firewall Driver Provides intrusion prevention service for a home or small office network. Start Type: loaded manually on demand IPv6 W indows Firewall Driver Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5512 [Services detected by Partizan] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVE RS\IPFLTDRV.SYS ### Driver IP Traffic Filter Driver IP Traffic Filter Driver Start Type: loade d manually on demand IP FILTER DRIVER Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.0 [Services detected by Partizan] :HKLM IpInIp=C:\WINDOWS\SYSTEM32\DRIVERS\IPINI P.SYS

### Driver IP in IP Tunnel Driver IP in IP Tunnel Driver Start Type: loaded ma nually on demand IP in IP Encapsulation Driver Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM IpNat=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT. SYS ### Driver IP Network Address Translator IP Network Address Translator Start T ype: loaded manually on demand IP Network Address Translator Microsoft Corporati on Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM IPSec=C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC. SYS ### Driver IPSEC driver IPSEC driver Start Type: loaded automatically at Kerne l initialization IPSec Driver Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Services detected by Partizan] :HKLM IRENUM=C:\WINDOWS\SYSTEM32\DRIVERS\IRENU M.SYS ### Driver IR Enumerator Service Start Type: loaded manually on demand Infra-R ed Bus Enumerator Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.5512 [Services detected by Partizan] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPN P.SYS ### Driver PnP ISA/EISA Bus Driver Start Type: loaded automatically by the Boo t Loader PNP ISA Bus Driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Services detected by Partizan] :HKLM JavaQuickStarterService=C:\PROGRAM FILES \JAVA\JRE6\BIN\JQS.EXE ### Service Java Quick Starter Prefetches JRE files for faster startup of Java applets and applications Start Type: loaded automatically by Server Manager Jav a(TM) Quick Starter Service Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6. 0.250.6 [Services detected by Partizan] :HKLM Kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBD CLASS.SYS ### Driver Keyboard Class Driver Start Type: loaded automatically at Kernel in itialization Keyboard Class Driver Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Services detected by Partizan] :HKLM kmixer=C:\WINDOWS\SYSTEM32\DRIVERS\KMIXE R.SYS ### Driver Microsoft Kernel Wave Audio Mixer Start Type: loaded manually on de mand Kernel Mode Audio Mixer Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Services detected by Partizan] :HKLM KSecDD=C:\WINDOWS\SYSTEM32\DRIVERS\KSECD D.SYS ### Driver Start Type: loaded automatically by the Boot Loader Kernel Security Support Provider Interface Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5834 [Services detected by Partizan] :HKLM LanmanServer=C:\WINDOWS\SYSTEM32\SVCHOST .EXE ### Service Server Supports file, print, and named-pipe sharing over the netwo rk for this computer. If this service is stopped, these functions will be unavai lable. If this service is disabled, any services that explicitly depend on it wi ll fail to start. Start Type: loaded automatically by Server Manager Generic Hos t Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5689 [Services detected by Partizan] :HKLM lanmanworkstation=C:\WINDOWS\SYSTEM32\SV CHOST.EXE ### Service Workstation Creates and maintains client network connections to re mote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fai l to start. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5689

[Services detected by Partizan] :HKLM lbrtfdc ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM ldap [Services detected by Partizan] :HKLM LicenseService [Services detected by Partizan] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service TCP/IP NetBIOS Helper Enables support for NetBIOS over TCP/IP (Net BT) service and NetBIOS name resolution. Start Type: loaded automatically by Ser ver Manager Generic Host Process for Win32 Services Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Messenger=C:\WINDOWS\SYSTEM32\SVCHOST.EX E ### Service Messenger Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this s ervice is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start. Start Ty pe: disabled Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Microsoft Office Groove Audit Service=C: \PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVEAUDITSERVICE.EXE ### Service Microsoft Office Groove Audit Service Start Type: loaded manually on demand Groove Audit Service Microsoft Corporation Groove Audit Service 4.2.2. 2807 [Services detected by Partizan] :HKLM mnmdd=C:\WINDOWS\SYSTEM32\DRIVERS\MNMDD. SYS ### Driver Start Type: loaded automatically at Kernel initialization Frame buf fer simulator Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM mnmsrvc=C:\WINDOWS\SYSTEM32\MNMSRVC.EXE ### Service NetMeeting Remote Desktop Sharing Enables an authorized user to ac cess this computer remotely by using NetMeeting over a corporate intranet. If th is service is stopped, remote desktop sharing will be unavailable. If this servi ce is disabled, any services that explicitly depend on it will fail to start. St art Type: loaded manually on demand NetMeeting Remote Desktop Sharing Microsoft Corporation Windows NetMeeting 3.01 [Services detected by Partizan] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM. SYS ### Driver Start Type: loaded manually on demand Modem Device Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOU CLASS.SYS ### Driver Mouse Class Driver Start Type: loaded automatically at Kernel initi alization Mouse Class Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Services detected by Partizan] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHI D.SYS ### Driver Mouse HID Driver Start Type: loaded manually on demand HID Mouse Fi lter Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM MountMgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOU NTMGR.SYS ### Driver Start Type: loaded automatically by the Boot Loader Mount Manager M icrosoft Corporation Microsoft Windows Operating System 5.1.2600.5815 [Services detected by Partizan] :HKLM mraid35x ### Driver Start Type: disabled [Services detected by Partizan] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDA V.SYS ### Driver WebDav Client Redirector WebDav Client Redirector Start Type: loade d manually on demand Windows NT WebDav Minirdr Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.6007 [Services detected by Partizan] :HKLM MRxSmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSM B.SYS ### Driver MRXSMB MRXSMB Start Type: loaded automatically at Kernel initializa

tion Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.6133 [Services detected by Partizan] :HKLM MSDTC=C:\WINDOWS\SYSTEM32\MSDTC.EXE ### Service Distributed Transaction Coordinator Coordinates transactions that span multiple resource managers, such as databases, message queues, and file sys tems. If this service is stopped, these transactions will not occur. If this ser vice is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded manually on demand MS DTC console program Microsoft Corporat ion Microsoft Distributed Transaction Coordinator 03.01.00.4414 [Services detected by Partizan] :HKLM MSDTC Bridge 3.0.0.0 [Services detected by Partizan] :HKLM MSDTC Bridge 4.0.0.0 [Services detected by Partizan] :HKLM Msfs=C:\WINDOWS\SYSTEM32\DRIVERS\MSFS.SY S ### Driver Start Type: loaded automatically at Kernel initialization Mailslot driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM MSIServer=C:\WINDOWS\SYSTEM32\MSIEXEC.EX E ### Service Windows Installer Adds, modifies, and removes applications provide d as a Windows Installer (*.msi) package. If this service is disabled, any servi ces that explicitly depend on it will fail to start. Start Type: loaded manually on demand Windows installer Microsoft Corporation Windows Installer - Unicode 4. 5.6001.22159 [Services detected by Partizan] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKS SRV.SYS ### Driver Microsoft Streaming Service Proxy Start Type: loaded manually on de mand MS KS Server Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.5512 [Services detected by Partizan] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSP CLOCK.SYS ### Driver Microsoft Streaming Clock Proxy Start Type: loaded manually on dema nd MS Proxy Clock Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.5512 [Services detected by Partizan] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM. SYS ### Driver Microsoft Streaming Quality Manager Proxy Start Type: loaded manual ly on demand MS Proxy Quality Manager Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Services detected by Partizan] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSS MBIOS.SYS ### Driver Microsoft System Management BIOS Driver Start Type: loaded manually on demand System Management BIOS Driver Microsoft Corporation Microsoft Windows O perating System 5.1.2600.5512 [Services detected by Partizan] :HKLM MSTEE=C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE. SYS ### Driver Microsoft Streaming Tee/Sink-to-Sink Converter Start Type: loaded m anually on demand WDM Tee/Communication Transform Filter Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.5512 [Services detected by Partizan] :HKLM Mup=C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS ### Driver Mup Start Type: loaded automatically by the Boot Loader Multiple UN C Provider driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.6103 [Services detected by Partizan] :HKLM mv61xx=C:\WINDOWS\SYSTEM32\DRIVERS\MV61X X.SYS ### Driver Start Type: loaded automatically by the Boot Loader Marvell Thor Wi ndows Driver Marvell Semiconductor, Inc. Marvell Thor 1.2.0.7300 [Services detected by Partizan] :HKLM mv61xxmm=C:\WINDOWS\SYSTEM32\DRIVERS\MV6 1XXMM.SYS ### Driver Start Type: loaded automatically by the Boot Loader Marvell Aux NV Bridge DLL Marvell Semiconductor Inc. Marvell Flash Technologies 1.0.0.1200 [Services detected by Partizan] :HKLM mv64xxmm=C:\WINDOWS\SYSTEM32\DRIVERS\MV6

4XXMM.SYS ### Driver Start Type: loaded automatically by the Boot Loader Marvell Aux NV Bridge DLL Marvell Semiconductor Inc. Marvell Flash Technologies 1.0.0.1200 [Services detected by Partizan] :HKLM mvxxmm=C:\WINDOWS\SYSTEM32\DRIVERS\MVXXM M.SYS ### Driver Start Type: loaded automatically by the Boot Loader Marvell Aux NV Bridge DLL Marvell Semiconductor Inc. Marvell Flash Technologies 1.0.0.1202 [Services detected by Partizan] :HKLM NABTSFEC=C:\WINDOWS\SYSTEM32\DRIVERS\NAB TSFEC.SYS ### Driver NABTS/FEC VBI Codec Start Type: loaded manually on demand WDM NABTS /FEC VBI Codec Microsoft Corporation Microsoft(R) Windows(R) Operating System 5. 3.2600.5512 [Services detected by Partizan] :HKLM NAL=C:\WINDOWS\SYSTEM32\DRIVERS\IQVW32.S YS ### Driver Nal Service Start Type: loaded manually on demand Intel(R) Network Adapter Diagnostic Driver Intel Corporation Intel(R) iQVW32.SYS 1.03.0.4 [Services detected by Partizan] :HKLM napagent=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Network Access Protection Agent Allows windows clients to particip ate in Network Access Protection Start Type: loaded manually on demand Generic H ost Process for Win32 Services Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5689 [Services detected by Partizan] :HKLM NDIS=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SY S ### Driver NDIS System Driver Start Type: loaded automatically by the Boot Loa der NDIS 5.1 wrapper driver Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5588 [Services detected by Partizan] :HKLM NdisIP=C:\WINDOWS\SYSTEM32\DRIVERS\NDISI P.SYS ### Driver Microsoft TV/Video Connection Start Type: loaded manually on demand Microsoft IP Driver Microsoft Corporation Microsoft(R) Windows(R) Operating Sys tem 5.3.2600.5512 [Services detected by Partizan] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDI STAPI.SYS ### Driver Remote Access NDIS TAPI Driver Remote Access NDIS TAPI Driver Start Type: loaded manually on demand NDIS 3.0 connection wrapper driver Microsoft Co rporation Microsoft Windows Operating System 5.1.2600.6132 [Services detected by Partizan] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS UIO.SYS ### Driver NDIS Usermode I/O Protocol NDIS Usermode I/O Protocol Start Type: l oaded manually on demand NDIS User mode I/O Driver Microsoft Corporation Microso ft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS WAN.SYS ### Driver Remote Access NDIS WAN Driver Remote Access NDIS WAN Driver Start T ype: loaded manually on demand MS PPP Framing Driver (Strong Encryption) Microso ft Corporation Microsoft Windows Operating System 5.1.2600.5588 [Services detected by Partizan] :HKLM NDProxy=C:\WINDOWS\SYSTEM32\DRIVERS\NDPR OXY.SYS ### NDIS Proxy Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .6048 [Services detected by Partizan] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETB IOS.SYS ### Driver NetBIOS Interface NetBIOS Interface Start Type: loaded automaticall y at Kernel initialization NetBIOS interface driver Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT. SYS ### Driver NetBios over Tcpip NetBios over Tcpip Start Type: loaded automatica lly at Kernel initialization MBT Transport driver Microsoft Corporation Microsof t Windows Operating System 5.1.2600.5512

[Services detected by Partizan] :HKLM NetDDE=C:\WINDOWS\SYSTEM32\NETDDE.EXE ### Service Network DDE Provides network transport and security for Dynamic Da ta Exchange (DDE) for programs running on the same computer or on different comp uters. If this service is stopped, DDE transport and security will be unavailabl e. If this service is disabled, any services that explicitly depend on it will f ail to start. Start Type: disabled Network DDE - DDE Communication Microsoft Cor poration Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM NetDDEdsdm=C:\WINDOWS\SYSTEM32\NETDDE.EX E ### Service Network DDE DSDM Manages Dynamic Data Exchange (DDE) network share s. If this service is stopped, DDE network shares will be unavailable. If this s ervice is disabled, any services that explicitly depend on it will fail to start . Start Type: disabled Network DDE - DDE Communication Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Netlogon=C:\WINDOWS\SYSTEM32\LSASS.EXE ### Service Net Logon Supports pass-through authentication of account logon ev ents for computers in a domain. Start Type: loaded manually on demand LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .5512 [Services detected by Partizan] :HKLM Netman=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Network Connections Manages objects in the Network and Dial-Up Con nections folder, in which you can view both local area network and remote connec tions. Start Type: loaded manually on demand Generic Host Process for Win32 Serv ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM NetTcpPortSharing=C:\WINDOWS\MICROSOFT.N ET\FRAMEWORK\V4.0.30319\SMSVCHOST.EXE ### Service Net.Tcp Port Sharing Service Provides ability to share TCP ports o ver the net.tcp protocol. Start Type: disabled SMSvcHost.exe Microsoft Corporati on Microsoft .NET Framework 4.0.30319.1 [Services detected by Partizan] :HKLM NIC1394=C:\WINDOWS\SYSTEM32\DRIVERS\NIC1 394.SYS ### Driver 1394 Net Driver Start Type: loaded manually on demand IEEE1394 Ndis Miniport and Call Manager Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5512 [Services detected by Partizan] :HKLM Nla=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Network Location Awareness (NLA) Collects and stores network confi guration and location information, and notifies applications when this informati on changes. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Npfs=C:\WINDOWS\SYSTEM32\DRIVERS\NPFS.SY S ### Driver Start Type: loaded automatically at Kernel initialization NPFS Driv er Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Ntfs=C:\WINDOWS\SYSTEM32\DRIVERS\NTFS.SY S ### Driver Start Type: disabled NT File System Driver Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.5782 [Services detected by Partizan] :HKLM NtLmSsp=C:\WINDOWS\SYSTEM32\LSASS.EXE ### Service NT LM Security Support Provider Provides security to remote proced ure call (RPC) programs that use transports other than named pipes. Start Type: loaded manually on demand LSA Shell (Export Version) Microsoft Corporation Micro soft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM NtmsSvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Removable Storage Start Type: loaded manually on demand Generic Ho st Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5689 [Services detected by Partizan] :HKLM Null=C:\WINDOWS\SYSTEM32\DRIVERS\NULL.SY S ### Driver Start Type: loaded automatically at Kernel initialization NULL Driv er Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0

[Services detected by Partizan] :HKLM NwlnkFlt=C:\WINDOWS\SYSTEM32\DRIVERS\NWL NKFLT.SYS ### Driver IPX Traffic Filter Driver IPX Traffic Filter Driver Start Type: loa ded manually on demand NWLINK2 Traffic Filter Driver Microsoft Corporation Micro soft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM NwlnkFwd=C:\WINDOWS\SYSTEM32\DRIVERS\NWL NKFWD.SYS ### Driver IPX Traffic Forwarder Driver IPX Traffic Forwarder Driver Start Typ e: loaded manually on demand NWLINK2 Forwarder Driver Microsoft Corporation Micr osoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM odserv=C:\PROGRAM FILES\COMMON FILES\MIC ROSOFT SHARED\OFFICE12\ODSERV.EXE ### Service Microsoft Office Diagnostics Service Run portions of Microsoft Off ice Diagnostics. Start Type: loaded manually on demand Microsoft Office Diagnost ics Microsoft Corporation Office Diagnostics Service 12.0.6606.1000 [Services detected by Partizan] :HKLM ohci1394=C:\WINDOWS\SYSTEM32\DRIVERS\OHC I1394.SYS ### Driver Texas Instruments OHCI Compliant IEEE 1394 Host Controller Start Ty pe: loaded automatically by the Boot Loader 1394 OpenHCI Port Driver Microsoft C orporation Microsoft Windows Operating System 5.1.2600.5706 [Services detected by Partizan] :HKLM ose=C:\PROGRAM FILES\COMMON FILES\MICROS OFT SHARED\SOURCE ENGINE\OSE.EXE ### Service Office Source Engine Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error r eports. Start Type: loaded manually on demand Office Source Engine Microsoft Cor poration Office Source Engine 12.0.4518.1014 [Services detected by Partizan] :HKLM Outlook [Services detected by Partizan] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARP ORT.SYS ### Driver Parallel port driver Start Type: loaded manually on demand Parallel Port Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.551 2 [Services detected by Partizan] :HKLM Partizan=C:\WINDOWS\SYSTEM32\DRIVERS\PAR TIZAN.SYS ### Driver Partizan Start Type: loaded automatically by the Boot Loader Partiz an - Rootkit detector Greatis Software RegRun Security Suite 6, 8, 0, 0 [Services detected by Partizan] :HKLM PartMgr=C:\WINDOWS\SYSTEM32\DRIVERS\PART MGR.SYS ### Driver Start Type: loaded automatically by the Boot Loader Partition Manag er Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM ParVdm=C:\WINDOWS\SYSTEM32\DRIVERS\PARVD M.SYS ### Driver Start Type: loaded automatically by Server Manager VDM Parallel Dri ver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM PCI=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS ### Driver PCI Bus Driver Start Type: loaded automatically by the Boot Loader NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM PCIDump ### Driver Start Type: loaded automatically at Kernel initialization [Services detected by Partizan] :HKLM PCIIde=C:\WINDOWS\SYSTEM32\DRIVERS\PCIID E.SYS ### Driver Start Type: loaded automatically by the Boot Loader Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM Pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCI A.SYS ### Driver Start Type: disabled PCMCIA Bus Driver Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM PDCOMP ### Driver Start Type: loaded manually on demand

[Services detected by Partizan] :HKLM PDFRAME ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM PDRELI ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM PDRFRAME ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM perc2 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM perc2hib ### Driver Start Type: disabled [Services detected by Partizan] :HKLM PerfDisk [Services detected by Partizan] :HKLM PerfNet [Services detected by Partizan] :HKLM PerfOS [Services detected by Partizan] :HKLM PerfProc [Services detected by Partizan] :HKLM PlugPlay=C:\WINDOWS\SYSTEM32\SERVICES.EX E ### Service Plug and Play Enables a computer to recognize and adapt to hardwar e changes with little or no user input. Stopping or disabling this service will result in system instability. Start Type: loaded automatically by Server Manager Services and Controller app Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5922 [Services detected by Partizan] :HKLM PolicyAgent=C:\WINDOWS\SYSTEM32\LSASS.EX E ### Service IPSEC Services Manages IP security policy and starts the ISAKMP/Oa kley (IKE) and the IP security driver. Start Type: loaded automatically by Serve r Manager LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5512 [Services detected by Partizan] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS \RASPPTP.SYS ### Driver WAN Miniport (PPTP) WAN Miniport (PPTP) Start Type: loaded manually on demand Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Window s Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM ProtectedStorage=C:\WINDOWS\SYSTEM32\LSA SS.EXE ### Service Protected Storage Provides protected storage for sensitive data, s uch as private keys, to prevent access by unauthorized services, processes, or u sers. Start Type: loaded automatically by Server Manager LSA Shell (Export Versi on) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM PSched=C:\WINDOWS\SYSTEM32\DRIVERS\PSCHE D.SYS ### Driver QoS Packet Scheduler QoS Packet Scheduler Start Type: loaded manual ly on demand MS QoS Packet Scheduler Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5848 [Services detected by Partizan] :HKLM Ptilink=C:\WINDOWS\SYSTEM32\DRIVERS\PTIL INK.SYS ### Driver Direct Parallel Link Driver Direct Parallel Link Driver Start Type: loaded manually on demand Parallel Technologies DirectParallel IO Library Paral lel Technologies, Inc. Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM ql1080 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Ql10wnt ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ql12160 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ql1240 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM ql1280 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASAC D.SYS

### Driver Remote Access Auto Connection Driver Remote Access Auto Connection Driver Start Type: loaded automatically at Kernel initialization RAS Automatic C onnection Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .0 [Services detected by Partizan] :HKLM RasAuto=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Remote Access Auto Connection Manager Creates a connection to a re mote network whenever a program references a remote DNS or NetBIOS name or addre ss. Start Type: loaded manually on demand Generic Host Process for Win32 Service s Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL 2TP.SYS ### Driver WAN Miniport (L2TP) WAN Miniport (L2TP) Start Type: loaded manually on demand RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsof t Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM RasMan=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Remote Access Connection Manager Creates a network connection. Sta rt Type: loaded manually on demand Generic Host Process for Win32 Services Micro soft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RAS PPPOE.SYS ### Driver Remote Access PPPOE Driver Remote Access PPPOE Driver Start Type: l oaded manually on demand RAS PPPoE mini-port/call-manager driver Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.5815 [Services detected by Partizan] :HKLM Raspti=C:\WINDOWS\SYSTEM32\DRIVERS\RASPT I.SYS ### Driver Direct Parallel Direct Parallel Start Type: loaded manually on dema nd PTI DirectParallel(R) mini-port/call-manager driver Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM Rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS. SYS ### Driver Rdbss Rdbss Start Type: loaded automatically at Kernel initializati on Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5643 [Services detected by Partizan] :HKLM RDPCDD=C:\WINDOWS\SYSTEM32\DRIVERS\RDPCD D.SYS ### Driver Start Type: loaded automatically at Kernel initialization RDP Minip ort Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM RDPDD [Services detected by Partizan] :HKLM rdpdr=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR. SYS ### Driver Terminal Server Device Redirector Driver Start Type: loaded manuall y on demand Microsoft RDP Device redirector Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5875 [Services detected by Partizan] :HKLM RDPNP [Services detected by Partizan] :HKLM RDPWD=C:\WINDOWS\SYSTEM32\DRIVERS\RDPWD. SYS ### Driver Start Type: loaded manually on demand RDP Terminal Stack Driver (US /Canada Only, Not for Export) Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.6128 [Services detected by Partizan] :HKLM RDSessMgr=C:\WINDOWS\SYSTEM32\SESSMGR.EX E ### Service Remote Desktop Help Session Manager Manages and controls Remote As sistance. If this service is stopped, Remote Assistance will be unavailable. Bef ore stopping this service, see the Dependencies tab of the Properties dialog box . Start Type: loaded manually on demand Microsoft Remote Desktop Help Session Man ager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM redbook=C:\WINDOWS\SYSTEM32\DRIVERS\REDB OOK.SYS ### Driver Digital CD Audio Playback Filter Driver Start Type: loaded automati cally at Kernel initialization Redbook Audio Filter Driver Microsoft Corporation

Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM RemoteAccess=C:\WINDOWS\SYSTEM32\SVCHOST .EXE ### Service Routing and Remote Access Offers routing services to businesses in local area and wide area network environments. Start Type: disabled Generic Hos t Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5689 [Services detected by Partizan] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\SVCHO ST.EXE ### Service Remote Registry Enables remote users to modify registry settings o n this computer. If this service is stopped, the registry can be modified only b y users on this computer. If this service is disabled, any services that explici tly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft W indows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM RpcLocator=C:\WINDOWS\SYSTEM32\LOCATOR.E XE ### Service Remote Procedure Call (RPC) Locator Manages the RPC name service d atabase. Start Type: loaded manually on demand Rpc Locator Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\SVCHOST.exe ### Service Remote Procedure Call (RPC) Provides the endpoint mapper and other miscellaneous RPC services. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5689 [Services detected by Partizan] :HKLM rspndr=C:\WINDOWS\SYSTEM32\DRIVERS\RSPND R.SYS ### Driver Link-Layer Topology Discovery Responder Allows this PC to be discov ered and located on the network. Start Type: loaded automatically by Server Mana ger Link-Layer Topology Responder Driver for NDIS 6 Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5611 [Services detected by Partizan] :HKLM RSVP=C:\WINDOWS\SYSTEM32\RSVP.EXE ### Service QoS RSVP Provides network signaling and local traffic control setu p functionality for QoS-aware programs and control applets. Start Type: loaded m anually on demand Microsoft RSVP Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM SamSs=C:\WINDOWS\SYSTEM32\LSASS.EXE ### Service Security Accounts Manager Stores security information for local us er accounts. Start Type: loaded automatically by Server Manager LSA Shell (Expor t Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM SCardSvr=C:\WINDOWS\SYSTEM32\SCARDSVR.EX E ### Service Smart Card Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If t his service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded manually on demand Smart Card Resource Management Serv er Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM Schedule=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Task Scheduler Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explici tly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft W indows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Sdbus=C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS. SYS [Services detected by Partizan] :HKLM Secdrv=C:\WINDOWS\SYSTEM32\DRIVERS\SECDR V.SYS ### Driver Secdrv SafeDisc driver Start Type: loaded manually on demand Macrov ision SECURITY Driver Macrovision Corporation, Macrovision Europe Limited, and M

acrovision Japan and Asia K.K. Macrovision SECURITY Driver SECURITY Driver 4.03. 086 2006/09/13 [Services detected by Partizan] :HKLM seclogon=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Secondary Logon Enables starting processes under alternate credent ials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fai l to start. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5689 [Services detected by Partizan] :HKLM SENS=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service System Event Notification Tracks system events such as Windows log on, network, and power events. Notifies COM+ Event System subscribers of these events. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.5689 [Services detected by Partizan] :HKLM serenum=C:\WINDOWS\SYSTEM32\DRIVERS\SERE NUM.SYS ### Driver Serenum Filter Driver Start Type: loaded manually on demand Serial Port Enumerator Microsoft Corporation Microsoft Windows Operating System 5.1.2600. 5512 [Services detected by Partizan] :HKLM Serial=C:\WINDOWS\SYSTEM32\DRIVERS\SERIA L.SYS ### Driver Serial port driver Start Type: loaded automatically at Kernel initi alization Serial Device Driver Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5512 [Services detected by Partizan] :HKLM ServiceModelEndpoint 3.0.0.0 [Services detected by Partizan] :HKLM ServiceModelEndpoint 4.0.0.0 [Services detected by Partizan] :HKLM ServiceModelOperation 3.0.0.0 [Services detected by Partizan] :HKLM ServiceModelOperation 4.0.0.0 [Services detected by Partizan] :HKLM ServiceModelService 3.0.0.0 [Services detected by Partizan] :HKLM ServiceModelService 4.0.0.0 [Services detected by Partizan] :HKLM Sfloppy=C:\WINDOWS\SYSTEM32\DRIVERS\SFLO PPY.SYS ### Driver Start Type: loaded automatically at Kernel initialization SCSI Flop py Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM SharedAccess=C:\WINDOWS\SYSTEM32\SVCHOST .EXE ### Service Windows Firewall/Internet Connection Sharing (ICS) Provides networ k address translation, addressing, name resolution and/or intrusion prevention s ervices for a home or small office network. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SVC HOST.EXE ### Service Shell Hardware Detection Provides notifications for AutoPlay hardw are events. Start Type: loaded automatically by Server Manager Generic Host Proc ess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5689 [Services detected by Partizan] :HKLM Simbad ### Driver Start Type: disabled [Services detected by Partizan] :HKLM SLIP=C:\WINDOWS\SYSTEM32\DRIVERS\SLIP.SY S ### Driver BDA Slip De-Framer Start Type: loaded manually on demand Microsoft Slip Deframing Filter Minidriver Microsoft Corporation Microsoft(R) Windows(R) O perating System 5.3.2600.5512 [Services detected by Partizan] :HKLM SMSvcHost 3.0.0.0 [Services detected by Partizan] :HKLM SMSvcHost 4.0.0.0 [Services detected by Partizan] :HKLM Sparrow ### Driver Start Type: disabled [Services detected by Partizan] :HKLM splitter=C:\WINDOWS\SYSTEM32\DRIVERS\SPL

ITTER.SYS ### Driver Microsoft Kernel Audio Splitter Start Type: loaded manually on dema nd Microsoft Kernel Audio Splitter Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Services detected by Partizan] :HKLM Spooler=C:\WINDOWS\SYSTEM32\SPOOLSV.EXE ### Service Print Spooler Loads files to memory for later printing. Start Type : loaded automatically by Server Manager Spooler SubSystem App Microsoft Corpora tion Microsoft Windows Operating System 5.1.2600.6024 [Services detected by Partizan] :HKLM SR=C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS ### Driver System Restore Filter Driver Start Type: loaded automatically by th e Boot Loader System Restore Filesystem Filter Driver Microsoft Corporation Micr osoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM srservice=C:\WINDOWS\SYSTEM32\SVCHOST.EX E ### Service System Restore Service Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Pro perties Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.5689 [Services detected by Partizan] :HKLM Srv=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS ### Driver Srv Srv Start Type: loaded manually on demand Server driver Microso ft Corporation Microsoft Windows Operating System 5.1.2600.6082 [Services detected by Partizan] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service SSDP Discovery Service Enables discovery of UPnP devices on your h ome network. Start Type: loaded manually on demand Generic Host Process for Win3 2 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM STacSV=C:\PROGRAM FILES\IDT\INTELXPV_V10 3\WDM\STACSV.EXE ### Service Audio Service Manages audio jack configurations. Start Type: loade d automatically by Server Manager IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001. 0 [Services detected by Partizan] :HKLM STHDA=C:\WINDOWS\SYSTEM32\DRIVERS\STHDA. SYS ### Driver IDT High Definition Audio CODEC Start Type: loaded manually on dema nd IDT PC Audio IDT, Inc. IDT PC Audio 5.10.20001.0 [Services detected by Partizan] :HKLM stisvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Image Acquisition (WIA) Provides image acquisition service s for scanners and cameras. Start Type: loaded manually on demand Generic Host P rocess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM streamip=C:\WINDOWS\SYSTEM32\DRIVERS\STR EAMIP.SYS ### Driver BDA IPSink Start Type: loaded manually on demand Microsoft IP Test Driver Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.5 512 [Services detected by Partizan] :HKLM swenum=C:\WINDOWS\SYSTEM32\DRIVERS\SWENU M.SYS ### Driver Software Bus Driver Start Type: loaded manually on demand Plug and Play Software Device Enumerator Microsoft Corporation Microsoft(R) Windows(R) Op erating System 5.3.2600.5512 [Services detected by Partizan] :HKLM swmidi=C:\WINDOWS\SYSTEM32\DRIVERS\SWMID I.SYS ### Driver Microsoft Kernel GS Wavetable Synthesizer Start Type: loaded manual ly on demand Microsoft GS Wavetable Synthesizer Microsoft Corporation Microsoft W indows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM SwPrv=C:\WINDOWS\SYSTEM32\DLLHOST.EXE ### Service MS Software Shadow Copy Provider Manages software-based volume sha dow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabl ed, any services that explicitly depend on it will fail to start. Start Type: lo

aded manually on demand COM Surrogate Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Services detected by Partizan] :HKLM symc810 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM symc8xx ### Driver Start Type: disabled [Services detected by Partizan] :HKLM sym_hi ### Driver Start Type: disabled [Services detected by Partizan] :HKLM sym_u3 ### Driver Start Type: disabled [Services detected by Partizan] :HKLM sysaudio=C:\WINDOWS\SYSTEM32\DRIVERS\SYS AUDIO.SYS ### Driver Microsoft Kernel System Audio Device Start Type: loaded manually on demand System Audio WDM Filter Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM SysmonLog=C:\WINDOWS\SYSTEM32\SMLOGSVC.E XE ### Service Performance Logs and Alerts Collects performance data from local o r remote computers based on preconfigured schedule parameters, then writes the d ata to a log or triggers an alert. If this service is stopped, performance infor mation will not be collected. If this service is disabled, any services that exp licitly depend on it will fail to start. Start Type: loaded manually on demand P erformance Logs and Alerts Service Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Services detected by Partizan] :HKLM TapiSrv=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Telephony Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer a nd, through the LAN, on servers that are also running the service. Start Type: l oaded manually on demand Generic Host Process for Win32 Services Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP. SYS ### Driver TCP/IP Protocol Driver TCP/IP Protocol Driver Start Type: loaded au tomatically at Kernel initialization TCP/IP Protocol Driver Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.6009 [Services detected by Partizan] :HKLM TDPIPE=C:\WINDOWS\SYSTEM32\DRIVERS\TDPIP E.SYS ### Driver Start Type: loaded manually on demand Named Pipe Transport Driver M icrosoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM TDTCP=C:\WINDOWS\SYSTEM32\DRIVERS\TDTCP. SYS ### Driver Start Type: loaded manually on demand TCP Transport Driver Microsof t Corporation Microsoft Windows Operating System 5.1.2600.5770 [Services detected by Partizan] :HKLM TermDD=C:\WINDOWS\SYSTEM32\DRIVERS\TERMD D.SYS ### Driver Terminal Device Driver Start Type: loaded automatically at Kernel i nitialization Terminal Server Driver Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5512 [Services detected by Partizan] :HKLM TermService=C:\WINDOWS\SYSTEM32\SVCHOST. exe ### Service Terminal Services Allows multiple users to be connected interactiv ely to a machine as well as the display of desktops and applications to remote c omputers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Themes=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Themes Provides user experience theme management. Start Type: load ed automatically by Server Manager Generic Host Process for Win32 Services Micro soft Corporation Microsoft Windows Operating System 5.1.2600.5689

[Services detected by Partizan] :HKLM TlntSvr=C:\WINDOWS\SYSTEM32\TLNTSVR.EXE ### Service Telnet Enables a remote user to log on to this computer and run pr ograms, and supports various TCP/IP Telnet clients, including UNIX-based and Win dows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: disabled Telnet Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM TosIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Distributed Link Tracking Client Maintains links between NTFS file s within a computer or across computers in a network domain. Start Type: loaded automatically by Server Manager Generic Host Process for Win32 Services Microsof t Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM TSDDD [Services detected by Partizan] :HKLM Udfs=C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SY S ### Driver Start Type: disabled UDF File System Driver Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM ultra ### Driver Start Type: disabled [Services detected by Partizan] :HKLM Update=C:\WINDOWS\SYSTEM32\DRIVERS\UPDAT E.SYS ### Driver Microcode Update Driver Start Type: loaded manually on demand Updat e Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM upnphost=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Universal Plug and Play Device Host Provides support to host Unive rsal Plug and Play devices. Start Type: loaded manually on demand Generic Host P rocess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM UPS=C:\WINDOWS\SYSTEM32\UPS.EXE ### Service Uninterruptible Power Supply Manages an uninterruptible power supp ly (UPS) connected to the computer. Start Type: loaded manually on demand UPS Se rvice Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM usbccgp=C:\WINDOWS\SYSTEM32\DRIVERS\USBC CGP.SYS ### Driver Microsoft USB Generic Parent Driver Start Type: loaded manually on demand USB Common Class Generic Parent Driver Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5585 [Services detected by Partizan] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBE HCI.SYS ### Driver Microsoft USB 2.0 Enhanced Host Controller Miniport Driver Start Ty pe: loaded manually on demand EHCI eUSB Miniport Driver Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.5825 [Services detected by Partizan] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHU B.SYS ### Driver USB2 Enabled Hub Start Type: loaded manually on demand Default Hub Driver for USB Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5 512 [Services detected by Partizan] :HKLM USBSTOR=C:\WINDOWS\SYSTEM32\DRIVERS\USBS TOR.SYS ### Driver USB Mass Storage Driver Start Type: loaded manually on demand USB M ass Storage Class Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM usbuhci=C:\WINDOWS\SYSTEM32\DRIVERS\USBU HCI.SYS ### Driver Microsoft USB Universal Host Controller Miniport Driver Start Type: loaded manually on demand UHCI USB Miniport Driver Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM VgaSave=C:\WINDOWS\SYSTEM32\DRIVERS\VGA.

SYS ### Driver Start Type: loaded automatically at Kernel initialization VGA/Super VGA Video Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.5512 [Services detected by Partizan] :HKLM ViaIde ### Driver Start Type: disabled [Services detected by Partizan] :HKLM VolSnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLS NAP.SYS ### Driver Start Type: loaded automatically by the Boot Loader Volume Shadow C opy Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM VSS=C:\WINDOWS\SYSTEM32\VSSVC.EXE ### Service Volume Shadow Copy Manages and implements Volume Shadow Copies use d for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start. Start Type: loaded manually on demand Microsoft Volume Shadow Copy Service Microsoft Corporation Mi crosoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM W32Time=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Time Maintains date and time synchronization on all client s and servers in the network. If this service is stopped, date and time synchron ization will be unavailable. If this service is disabled, any services that expl icitly depend on it will fail to start. Start Type: loaded automatically by Server Manager Generic Host Process for Win 32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM W3SVC [Services detected by Partizan] :HKLM Wanarp=C:\WINDOWS\SYSTEM32\DRIVERS\WANAR P.SYS ### Driver Remote Access IP ARP Driver Remote Access IP ARP Driver Start Type: loaded manually on demand MS Remote Access and Routing ARP Driver Microsoft Cor poration Microsoft Windows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM WDICA ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM wdmaud=C:\WINDOWS\SYSTEM32\DRIVERS\WDMAU D.SYS ### Driver Microsoft WINMM WDM Audio Compatibility Driver Start Type: loaded m anually on demand MMSYSTEM Wave/Midi API mapper Microsoft Corporation Microsoft W indows Operating System 5.1.2600.5512 [Services detected by Partizan] :HKLM WDMTVTuner=C:\WINDOWS\SYSTEM32\DRIVERS\W DMTUNER.SYS ### Driver Universal WDM TV Tuner Start Type: loaded automatically by Server M anager WDM TV Tuner Driver Philips Semiconductors TV Card 2, 3, 4, 7 [Services detected by Partizan] :HKLM WebClient=C:\WINDOWS\SYSTEM32\SVCHOST.EX E ### Service WebClient Enables Windows-based programs to create, access, and mo dify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend o n it will fail to start. Start Type: loaded automatically by Server Manager Gene ric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5689 [Services detected by Partizan] :HKLM Windows Workflow Foundation 3.0.0.0 [Services detected by Partizan] :HKLM Windows Workflow Foundation 4.0.0.0 [Services detected by Partizan] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Management Instrumentation Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based softwa re will not function properly. If this service is disabled, any services that ex plicitly depend on it will fail to start. Start Type: loaded automatically by Se rver Manager Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.5689

[Services detected by Partizan] :HKLM Winsock ### Driver Start Type: loaded manually on demand [Services detected by Partizan] :HKLM WinSock2 [Services detected by Partizan] :HKLM WinTrust [Services detected by Partizan] :HKLM WmdmPmSN=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Portable Media Serial Number Service Retrieves the serial number o f any portable media player connected to this computer. If this service is stopp ed, protected content might not be down loaded to the device. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM Wmi=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Management Instrumentation Driver Extensions Provides syst ems management information to and from drivers. Start Type: loaded manually on d emand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM WmiApRpl [Services detected by Partizan] :HKLM WmiApSrv=C:\WINDOWS\SYSTEM32\WBEM\WMIAPS RV.EXE ### Service WMI Performance Adapter Provides performance library information f rom WMI HiPerf providers. Start Type: loaded manually on demand WMI Performance Adapter Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600. 5512 [Services detected by Partizan] :HKLM WMPNetworkSvc=C:\PROGRAM FILES\WINDOWS M EDIA PLAYER\WMPNETWK.EXE ### Service Windows Media Player Network Sharing Service Shares Windows Media Player libraries to other networked players and media devices using Universal Pl ug and Play Start Type: loaded manually on demand Windows Media Player Network S haring Service Microsoft Corporation Microsoft Windows Operating System 11.0.5721. 5262 [Services detected by Partizan] :HKLM WPFFontCache_v0400=C:\WINDOWS\MICROSOFT. NET\FRAMEWORK\V4.0.30319\WPF\WPFFONTCACHE_V0400.EXE ### Service Windows Presentation Foundation Font Cache 4.0.0.0 Optimizes perfo rmance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already r unning. It can be disabled, though doing so will degrade the performance of WPF applications. Start Type: loaded manually on demand wpffontcache_v0400.exe Micro soft Corporation Microsoft .NET Framework 4.0.30319.1 [Services detected by Partizan] :HKLM WS2IFSL=C:\WINDOWS\SYSTEM32\DRIVERS\WS2I FSL.SYS ### Start Type: loaded automatically at Kernel initialization Winsock2 IFS Lay er Microsoft Corporation Microsoft Windows Operating System 5.1.2600.0 [Services detected by Partizan] :HKLM WSTCODEC=C:\WINDOWS\SYSTEM32\DRIVERS\WST CODEC.SYS ### Driver World Standard Teletext Codec Start Type: loaded manually on demand WDM WST Codec Driver Microsoft Corporation Microsoft(R) Windows(R) Operating Sy stem 5.3.2600.5512 [Services detected by Partizan] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Automatic Updates Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Start Type: loaded au tomatically by Server Manager Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM WudfPf=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFP F.SYS ### Driver Windows Driver Foundation - User-mode Driver Framework Platform Dri ver Provide communciation services for UMDF components. Start Type: loaded manua lly on demand Windows Driver Foundation - User-mode Driver Framework Platform Dr iver Microsoft Corporation Microsoft Windows Operating System 6.0.5716.32 [Services detected by Partizan] :HKLM WudfRd=C:\WINDOWS\SYSTEM32\DRIVERS\WUDFR D.SYS

### Driver Windows Driver Foundation - User-mode Driver Framework Reflector Re flect device requests to user-mode driver drivers Start Type: loaded manually on demand Windows Driver Foundation - User-mode Driver Framework Reflector Microso ft Corporation Microsoft Windows Operating System 6.0.5716.32 [Services detected by Partizan] :HKLM WudfSvc=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Windows Driver Foundation - User-mode Driver Framework Manages use r-mode driver host processes Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5689 [Services detected by Partizan] :HKLM WZCSVC=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Wireless Zero Configuration Provides automatic configuration for t he 802.11 adapters Start Type: loaded automatically by Server Manager Generic Ho st Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5689 [Services detected by Partizan] :HKLM xmlprov=C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Service Network Provisioning Service Manages XML configuration files on a domain basis for automatic network provisioning. Start Type: loaded manually on demand Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5689 [Services detected by Partizan] :HKLM {921C2F6D-A67A-4080-88BA-A6DFFB809695} [Services detected by Partizan] :HKLM {A3FF822F-7817-4E08-BF30-BDF9ABE39E53} [Services detected by Partizan] :HKLM {C139FED1-07B2-43D2-AEBE-806A898B5653} [Services detected by Partizan] :HKLM {DAA3F3AB-E39D-41F1-A87B-EFAF86203FE4} [Codecs] :HKLM midimapper=C:\WINDOWS\system32\MIDIMAP.DLL ### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Codecs] :HKLM msacm.imaadpcm=C:\WINDOWS\system32\IMAADP32.ACM ### IMA ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Codecs] :HKLM msacm.msadpcm=C:\WINDOWS\system32\MSADP32.ACM ### Microsoft ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Codecs] :HKLM msacm.msg711=C:\WINDOWS\system32\MSG711.ACM ### Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporat ion Microsoft Windows Operating System 5.1.2600.0 [Codecs] :HKLM msacm.msgsm610=C:\WINDOWS\system32\MSGSM32.ACM ### Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.0 [Codecs] :HKLM msacm.trspch=C:\WINDOWS\system32\TSSOFT32.ACM ### DSP Group TrueSpeech(TM) Audio Codec for MSACM V3.50 DSP GROUP, INC. DSP G ROUP Windows NT(TM) TrueSpeech CODEC 1.01 [Codecs] :HKLM vidc.cvid=C:\WINDOWS\system32\ICCVID.DLL ### Cinepak Codec Radius Inc. Cinepak for Windows 32 1.10.0.0 [Codecs] :HKLM VIDC.I420=C:\WINDOWS\system32\MSH263.DRV ### Microsoft H.263 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 [Codecs] :HKLM VIDC.IYUV=C:\WINDOWS\system32\IYUV_32.DLL ### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5908 [Codecs] :HKLM vidc.mrle=C:\WINDOWS\system32\MSRLE32.DLL ### Microsoft RLE Compressor Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5908 [Codecs] :HKLM vidc.msvc=C:\WINDOWS\system32\MSVIDC32.DLL ### Microsoft Video 1 Compressor Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5908 [Codecs] :HKLM VIDC.UYVY=C:\WINDOWS\system32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo ws(R) Operating System 5.3.2600.5908 [Codecs] :HKLM VIDC.YUY2=C:\WINDOWS\system32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo ws(R) Operating System 5.3.2600.5908

[Codecs] :HKLM VIDC.YVU9=C:\WINDOWS\system32\TSBYUV.DLL ### Toshiba Video Codec Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5908 [Codecs] :HKLM VIDC.YVYU=C:\WINDOWS\system32\MSYUV.DLL ### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo ws(R) Operating System 5.3.2600.5908 [Codecs] :HKLM wavemapper=C:\WINDOWS\system32\MSACM32.DRV ### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.0 [Codecs] :HKLM msacm.msg723=C:\WINDOWS\system32\MSG723.ACM ### Microsoft G.723.1 CODEC for MSACM Microsoft Corporation Windows NetMeeting 3 .01 [Codecs] :HKLM vidc.M263=C:\WINDOWS\system32\MSH263.DRV ### Microsoft H.263 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 [Codecs] :HKLM vidc.M261=C:\WINDOWS\system32\MSH261.DRV ### Microsoft H.261 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 [Codecs] :HKLM msacm.msaudio1=C:\WINDOWS\system32\MSAUD32.ACM ### Windows Media Audio Microsoft Corporation Windows Media Audio 8.00.00.4502 [Codecs] :HKLM msacm.sl_anet=C:\WINDOWS\system32\SL_ANET.ACM ### Audio codec for MS ACM Sipro Lab Telecom Inc. ACELP.net Audio Codec 3.02 [Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSTEM32\L3CODECA.ACM ### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltu ngen IIS MPEG Layer-3 Audio Codec for MSACM 1, 0, 0, 0 [Codecs] :HKLM wave=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Codecs] :HKLM midi=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Codecs] :HKLM mixer=C:\WINDOWS\system32\WDMAUD.DRV ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Codecs] :HKLM MSVideo8=C:\WINDOWS\system32\VFWWDM32.DLL ### VfW MM Driver for WDM Video Capture Devices Microsoft Corporation Microsof t Windows Operating System 5.1.2600.5512 [Codecs] :HKLM VIDC.MPG4=C:\WINDOWS\system32\MPG4C32.DLL ### Microsoft MPEG-4 Video Codec Microsoft Corporation Microsoft MPEG-4 Video Codec 4.1.00.3920 [Codecs] :HKLM VIDC.MP42=C:\WINDOWS\system32\MPG4C32.DLL ### Microsoft MPEG-4 Video Codec Microsoft Corporation Microsoft MPEG-4 Video Codec 4.1.00.3920 [Auto Start Apps] [Registry Run] :HKCU ctfmon.exe=C:\WINDOWS\SYSTEM32\CTFMON.EXE ### CTF Loader Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .5512 [Registry Run] :HKCU DU Meter=C:\PROGRAM FILES\DU METER\DUMETER.EXE ### DU Meter Monitor Hagel Technologies Ltd. DU Meter 4.16 Build R3102 [Registry Run] :HKCU "Default Value"="" ### File is deleted or hidden by a rootkit or could not be located. [Registry Run] :HKCU StartCCC=C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-S TATIC\CLISTART.EXE [Registry Run] :HKCU UnHackMe Monitor=C:\PROGRAM FILES\UNHACKME\HACKMON.EXE ### Detects Rootkits in background Greatis Software UnHackMe 5.9 [Registry Run] :HKLM DWPersistentQueuedReporting=C:\PROGRAM FILES\COMMON FILES \MICROSOFT SHARED\DW\DWTRIG20.EXE ### Watson Subscriber for SENS Network Notifications Microsoft Corporation Wat son Subscriber for SENS Network Notifications 12.0.6606.1000 [Registry Run] :HKLM SysTrayApp=C:\PROGRAM FILES\IDT\WDM\STTRAY.EXE ### IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001.0

[Registry Run] :HKLM TV Card Remote Control Device Monitor=C:\WINDOWS\713XRMTM ON.EXE ### Remote Control Device Monitor 1, 0, 0, 0 [Registry Run] :HKLM QuickTime Task=C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE ### QuickTime Task Apple Inc. QuickTime QuickTime 7.6.9 (1680.9) [Registry Run] :HKLM SunJavaUpdateSched=C:\PROGRAM FILES\COMMON FILES\JAVA\JAV A UPDATE\JUSCHED.EXE ### Java(TM) Update Scheduler Sun Microsystems, Inc. Java(TM) Platform SE Auto Updater 2 0 2.0.4.1 [Registry Run] :HKLM Adobe Reader Speed Launcher=C:\PROGRAM FILES\ADOBE\READER 10.0\READER\READER_SL.EXE ### Adobe Acrobat SpeedLauncher Adobe Systems Incorporated Adobe Acrobat 10.0. 1.434 [Registry Run] :HKLM Adobe ARM=C:\PROGRAM FILES\COMMON FILES\ADOBE\ARM\1.0\ADO BEARM.EXE ### Adobe Reader and Acrobat Manager Adobe Systems Incorporated Adobe Reader a nd Acrobat Manager 1.4.7.0 [Registry Run] :HKLM GrooveMonitor=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\ GROOVEMONITOR.EXE ### GrooveMonitor Utility Microsoft Corporation GrooveMonitor Utility 4.2.2.28 07 [Registry RunOnceEx] :HKLM @UnHackMe=C:\PROGRA~1\UnHackMe\UnHackMe.exe /p Part izan ### 1=C:\PROGRA~1\UnHackMe\UnHackMe.exe /p Partizan [Win.ini] load="" [Win.ini] run="" [Common Startup Folder] Scheduler for OEM.lnk=C:\PROGRAM FILES\HONESTECH\HONES TECH TVR\SCHEDULETV.EXE [In memory] [Running Processes] C:\WINDOWS\SYSTEM32\SMSS.EXE ### Windows NT Session Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Running Processes] C:\WINDOWS\SYSTEM32\WINLOGON.EXE ### Windows NT Logon Application Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5788 [Running Processes] C:\WINDOWS\SYSTEM32\SERVICES.EXE ### Services and Controller app Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5922 [Running Processes] C:\WINDOWS\SYSTEM32\LSASS.EXE ### LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Running Processes] C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE ### ATI External Event Utility EXE Module ATI Technologies Inc. ATI External E vent Utility for Windows 6.14.10.4163 [Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5689 [Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE ### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5689 [Running Processes] C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE ### ATI External Event Utility EXE Module ATI Technologies Inc. ATI External E vent Utility for Windows 6.14.10.4163 [Running Processes] C:\WINDOWS\SYSTEM32\SPOOLSV.EXE ### Spooler SubSystem App Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.6024 [Running Processes] C:\PROGRAM FILES\IDT\INTELXPV_V103\WDM\STACSV.EXE ### IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001.0 [Running Processes] C:\WINDOWS\EXPLORER.EXE ### Windows Explorer Microsoft Corporation Microsoft Windows Operating System 6.

00.2900.5634 [Running Processes] C:\PROGRAM FILES\DU METER\DUMETERSVC.EXE ### DU Meter Service Hagel Technologies Ltd. DU Meter 4.16 Build R3102 [Running Processes] C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE ### Java(TM) Quick Starter Service Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Running Processes] C:\PROGRAM FILES\IDT\WDM\STTRAY.EXE ### IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001.0 [Running Processes] C:\WINDOWS\713XRMTMON.EXE ### Remote Control Device Monitor 1, 0, 0, 0 [Running Processes] C:\PROGRAM FILES\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE ### Java(TM) Update Scheduler Sun Microsystems, Inc. Java(TM) Platform SE Auto Updater 2 0 2.0.4.1 [Running Processes] C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVEMONITOR.E XE ### GrooveMonitor Utility Microsoft Corporation GrooveMonitor Utility 4.2.2.28 07 [Running Processes] C:\WINDOWS\SYSTEM32\CTFMON.EXE ### CTF Loader Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .5512 [Running Processes] C:\PROGRAM FILES\DU METER\DUMETER.EXE ### DU Meter Monitor Hagel Technologies Ltd. DU Meter 4.16 Build R3102 [Running Processes] C:\PROGRAM FILES\UNHACKME\HACKMON.EXE ### Detects Rootkits in background Greatis Software UnHackMe 5.9 [Running Processes] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\MOM. EXE ### Catalyst Control Center: Monitoring program ATI Technologies Inc. Catalyst Control Centre 2.0.0.0 [Running Processes] C:\PROGRAM FILES\HONESTECH\HONESTECH TVR\SCHEDULETV.EXE [Running Processes] C:\WINDOWS\713XRMT.EXE ### TV Card Remote Control Applet TV Card 1, 1, 0, 0 [Running Processes] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CCC. EXE ### Catalyst Control Centre: Host application ATI Technologies Inc. Catalyst C ontrol Centre 2.0.0.0 [Running Processes] C:\PROGRAM FILES\MOBILE PARTNER\MOBILE PARTNER.EXE [Running Processes] C:\PROGRAM FILES\UNHACKME\REANIMATOR.EXE ### RegRun Start Control Greatis Software RegRun Security Suite 6.99 release [Running Processes] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .18702 [Running Processes] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .18702 [Loaded DLLs] C:\WINDOWS\system32\D3DIM700.DLL ### Microsoft Direct3D Microsoft Corporation Microsoft Windows Operating System 5.03.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\DCIMAN32.dll ### DCI Manager Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.5512 [Loaded DLLs] C:\WINDOWS\system32\DDRAW.dll ### Microsoft DirectDraw Microsoft Corporation Microsoft Windows Operating Syste m 5.03.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\ddrawex.dll ### Direct Draw Ex Microsoft Corporation Microsoft Windows Operating System 5.03 .2600.5512 [Loaded DLLs] C:\WINDOWS\system32\mscms.dll ### Microsoft Color Matching System DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5627 [Loaded DLLs] C:\WINDOWS\system32\d3d8thk.dll

### Microsoft Direct3D OS Thunk Layer Microsoft Corporation Microsoft Windows Op erating System 5.03.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\d3d9.dll ### Microsoft Direct3D Microsoft Corporation Microsoft Windows Operating System 5.03.2600.5601 [Loaded DLLs] C:\WINDOWS\system32\Macromed\Flash\Flash11e.ocx ### Adobe Flash Player 11.1 r102 Adobe Systems, Inc. Shockwave Flash 11,1,102, 55 [Loaded DLLs] C:\WINDOWS\system32\jscript.dll ### Microsoft (R) JScript Microsoft Corporation Microsoft (R) JScript 5.8.6001 .23141 [Loaded DLLs] C:\WINDOWS\system32\iepeers.dll ### Internet Explorer Peer Objects Microsoft Corporation Windows Internet Explo rer 8.00.6001.23227 [Loaded DLLs] C:\WINDOWS\system32\msls31.dll ### Microsoft Line Services library file Microsoft Corporation Microsoft Line S ervices 3.10 [Loaded DLLs] C:\WINDOWS\system32\mshtml.dll ### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8 .00.6001.23250 [Loaded DLLs] C:\WINDOWS\system32\hnetcfg.dll ### Home Networking Configuration Manager Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5589 [Loaded DLLs] C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll ### Java(TM) Quick Starter binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\Program Files\Java\jre6\bin\jp2ssv.dll ### Java(TM) Platform SE binary Sun Microsystems, Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Loaded DLLs] C:\WINDOWS\system32\MSFTEDIT.DLL ### Rich Text Edit Control, v4.1 Microsoft Corporation Microsoft RichEdit Cont rol, version 4.1 4.1 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResour ce.dll ### GrooveIntlResource Module Microsoft Corporation GrooveIntlResource Module 4.2.2.2807 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50 727.6195_x-ww_44262b86\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.6195 [Loaded DLLs] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper .dll ### Adobe PDF Helper for Internet Explorer Adobe Systems Incorporated AcroIEHe lper Library 10.0.1.434 [Loaded DLLs] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper Shim.dll ### Adobe PDF Helper for Internet Explorer Adobe Systems Incorporated AcroIEHe lperShim Library 10.0.1.434 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\Program Files\Internet Explorer\xpshims.dll ### Internet Explorer Compatibility Shims for XP Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Loaded DLLs] C:\WINDOWS\system32\ACTXPRXY.DLL ### ActiveX Interface Marshaling Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.5512

[Loaded DLLs] C:\WINDOWS\system32\msfeeds.dll ### Microsoft Feeds Manager Microsoft Corporation Windows Internet Explorer 8.0 0.6001.23227 [Loaded DLLs] C:\WINDOWS\system32\xmllite.dll ### Microsoft XmlLite Library Microsoft Corporation Microsoft XML Core Service s 1.00.1018.0 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50 727.6195_x-ww_44262b86\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.6195 [Loaded DLLs] C:\WINDOWS\system32\msimtf.dll ### Active IMM Server DLL Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Loaded DLLs] C:\Program Files\Internet Explorer\ieproxy.dll ### IE ActiveX Interface Marshaling Library Microsoft Corporation Windows Inter net Explorer 8.00.6001.23227 [Loaded DLLs] C:\WINDOWS\system32\IEUI.dll ### Internet Explorer UI Engine Microsoft Corporation Windows Internet Explorer 8.00.6001.18702 [Loaded DLLs] C:\WINDOWS\system32\sensapi.dll ### SENS Connectivity API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\mstask.dll ### Task Scheduler interface DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Loaded DLLs] C:\Program Files\Mobile Partner\rvh245AutoCaps.dll [Loaded DLLs] C:\Program Files\Mobile Partner\rvgef.dll [Loaded DLLs] C:\Program Files\Mobile Partner\rv3g324m.dll ### 3G-324M Stack RADVISION RADVISION 3G-324M Stack 3.5.0.4 [Loaded DLLs] C:\Program Files\Mobile Partner\rvcommon.dll ### RADVISION Common Core DLL RADVISION RADVISION Common Core DLL 1.1.11 [Loaded DLLs] C:\Program Files\Mobile Partner\rvasn1.dll [Loaded DLLs] C:\WINDOWS\system32\AVICAP32.dll ### AVI Capture window class Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.0 [Loaded DLLs] C:\WINDOWS\system32\MSVFW32.dll ### Microsoft Video for Windows DLL Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Loaded DLLs] C:\Program Files\Mobile Partner\VideoCallUIPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\SMSPlugin.dll [Loaded DLLs] C:\Program Files\Mobile Partner\SMSUIPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\AddrBookPlugin.dll ### Address Book Plugin Huawei Technologies 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\MMParser.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\MmsDataMgrDll.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\Program Files\Mobile Partner\mm1agent.dll [Loaded DLLs] C:\Program Files\Mobile Partner\MMSUIPlugin.dll

### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\CallUIPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll [Loaded DLLs] C:\WINDOWS\system32\RICHED20.dll ### Rich Text Edit Control, v3.0 Microsoft Corporation Microsoft RichEdit Cont rol, version 3.0 3.0 [Loaded DLLs] C:\WINDOWS\system32\RICHED32.DLL ### Wrapper Dll for Richedit 1.0 Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.0 [Loaded DLLs] C:\Program Files\Mobile Partner\USSDUIPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\SkinMagicExU.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.3 [Loaded DLLs] C:\Program Files\Mobile Partner\LayoutPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\ToolBarMgrPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\FileManager.dll [Loaded DLLs] C:\Program Files\Mobile Partner\CallPlugin.dll [Loaded DLLs] C:\Program Files\Mobile Partner\StatusBarMgrPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\NotifyServicePlugin.dll [Loaded DLLs] C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll [Loaded DLLs] C:\Program Files\Mobile Partner\MenuMgrPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\WINDOWS\system32\asycfilt.dll ### Microsoft Corporation 5.1.2600.5949 [Loaded DLLs] C:\Program Files\Mobile Partner\XFramePlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\QuickLinkUIPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\NetInfoUIExPlugin.dll ### TODO: <File description> TODO: <Company name> TODO: <Product name> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\DeviceOperate.dll ### DeviceOperate.dll DeviceOperate.dll 1, 2, 2, 13 [Loaded DLLs] C:\Program Files\Mobile Partner\XCodec.dll ### XCodec.dll XCodec.dll 1, 2, 2, 13 [Loaded DLLs] C:\Program Files\Mobile Partner\atcomm.dll ### atcomm.dll atcomm.dll 1, 2, 2, 13 [Loaded DLLs] C:\Program Files\Mobile Partner\DetectDev.dll ### DetectDev.dll DetectDev.dll 1, 2, 2, 13 [Loaded DLLs] C:\Program Files\Mobile Partner\NDISAPI.dll ### NDISAPI DLL NDISAPI DLL 1, 1, 0, 8 [Loaded DLLs] C:\Program Files\Mobile Partner\NDISPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\ConfigFilePlugin.dll [Loaded DLLs] C:\Program Files\Mobile Partner\TracePlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\DialUpPlugin.dll [Loaded DLLs] C:\Program Files\Mobile Partner\NetConnectPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\NetInfoPlugin.dll [Loaded DLLs] C:\Program Files\Mobile Partner\DialupUIPlugin.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll [Loaded DLLs] C:\WINDOWS\system32\MFC71ENU.DLL ### MFC Language Specific Resources Microsoft Corporation Microsoft Visual Stud io .NET 7.10.6101.0

[Loaded DLLs] C:\Program Files\Mobile Partner\SkinMagicU.dll ### SkinMagic Toolkit Appspeed Inc. Appspeed SkinMagic Toolkit 2, 3, 1, 1 [Loaded DLLs] C:\Program Files\Mobile Partner\isaputrace.dll [Loaded DLLs] C:\Program Files\Mobile Partner\MSVCP71.dll ### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio .NET 7.10.3077.0 [Loaded DLLs] C:\Program Files\Mobile Partner\MSVCR71.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio .N ET 7.10.3052.4 [Loaded DLLs] C:\Program Files\Mobile Partner\MFC71U.DLL ### MFCDLL Shared Library - Retail Version Microsoft Corporation Microsoft Visu al Studio .NET 7.10.3077.0 [Loaded DLLs] C:\Program Files\Mobile Partner\Container.dll ### TODO: <????> TODO: <???> TODO: <???> 1.0.0.1 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dash board\2.0.2637.38560__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard. dll ### Dashboard Graphics Caste VPU Recover Aspect ATI Technologies Inc. Catalyst Control Centre 2.0.2637.38560 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboa rd\2.0.2637.38705__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ### Dashboard Graphics Caste MM Video Aspect ATI Technologies Inc. Catalyst Con trol Centre 2.0.2637.38705 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics .Dashboard\2.0.2637.38584__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics. Dashboard.dll ### Dashboard Graphics Display Colour 2 Aspect ATI Technologies Inc. Catalyst C ontrol Centre 2.0.2637.38584 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashbo ard\2.0.2637.38790__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ### Dashboard Graphics Caste R300/R400 Radeon3D Aspect ATI Technologies Inc. C atalyst Control Centre 2.0.2637.38790 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashb oard\2.0.2637.38682__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dl l ### Dashboard Graphics Caste DFP Aspect Advanced Micro Devices, Inc. Catalyst C ontrol Centre 2.0.2637.38682 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashbo ard\2.0.2637.38837__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll ### Dashboard Graphics Caste TV Aspect ATI Technologies Inc. Catalyst Control C entre 2.0.2637.38837 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashbo ard\2.0.2637.38781__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll ### Dashboard Graphics Caste CV Aspect ATI Technologies Inc. Catalyst Control C entre 2.0.2637.38781 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashb oard\2.0.2637.38693__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dl l ### Dashboard Graphics Caste CRT Aspect ATI Technologies Inc. Catalyst Control Centre 2.0.2637.38693 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics .Dashboard\2.0.2637.38735__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics. Dashboard.dll ### Dashboard Graphics Caste Display Options Aspect ATI Technologies Inc. Cata lyst Control Centre 2.0.2637.38735 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dash board\2.0.2637.38576__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard. dll ### Dashboard Graphics Caste InfoCentre Aspect ATI Technologies Inc. Catalyst C ontrol Centre 2.0.2637.38576

[Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics .Dashboard\2.0.2637.38526__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics. Dashboard.dll ### Dashboard Graphics Caste Display Manager Aspect ATI Technologies Inc. Cata lyst Control Centre 2.0.2637.38526 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboa rd\2.0.2637.38891__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ### Dashboard Graphics Caste Welcome Aspect Advanced Mirco Devices, Inc. Catal yst Control Centre 2.0.2637.38891 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared \2.0.2614.20446__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ### Dashboard Graphics Shared Caste ATI Technologies Inc. Catalyst Control Cent re 2.0.2614.20446 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.26 37.38515__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ### Dashboard Graphics Caste ATI Technologies Inc. Catalyst Control Centre 2.0. 2637.38515 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Priv ate\2.0.2614.20444__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ### Dashboard Component Shared Private Types ATI Technologies Inc. Catalyst Con trol Centre 2.0.2614.20444 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0. 2614.20438__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ### Dashboard Component Shared Types ATI Technologies Inc. Catalyst Control Cen tre 2.0.2614.20438 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.2637.38 509__90ba9c70f846762e\CLI.Component.Dashboard.dll ### Dashboard Component ATI Technologies Inc. Catalyst Control Centre 2.0.2637. 38509 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard \2.0.2637.38807__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll ### Wizard DeviceCV Aspect ATI Technologies Inc. Catalyst Control Centre 2.0.26 37.38807 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard \2.0.2637.38844__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll ### Wizard DeviceTV Aspect ATI Technologies Inc. Catalyst Control Centre 2.0.26 37.38844 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wiza rd\2.0.2637.38569__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ### Wizard Graphics Caste InfoCentre Aspect ATI Technologies Inc. Catalyst Cont rol Centre 2.0.2637.38569 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\ 2.0.2637.38815__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ### Wizard Graphics Caste MM Video Aspect ATI Technologies Inc. Catalyst Contro l Centre 2.0.2637.38815 [Loaded DLLs] C:\Program Files\Common Files\ATI Technologies\Multimedia\atidvc r.dll ### ATI Digital VCR ATI Technologies, Inc. ATI Multimedia Center 9.14.0.60504 [Loaded DLLs] C:\WINDOWS\system32\urlmon.dll ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\Program Files\Common Files\ATI Technologies\Multimedia\atixco de.dll ### ATI Video Transcoder ATI Technologies, Inc. ATI Multimedia Center 9.14.0.6 0504 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\ atixclib.dll

### Assembly imported from type library 'ATIXCodeLib'. 1.0.0.0 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Share d\2.0.2614.20469__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ### Dashboard Local Caste TransCode Shared ATI Technologies Inc. Catalyst Contr ol Centre 2.0.2614.20469 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics .Wizard\2.0.2637.38552__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wiz ard.dll ### Wizard DisplaysManager Aspect ATI Technologies Inc. Catalyst Control Centre 2.0.2637.38552 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard \2.0.2637.38797__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ### Wizard Graphics Caste R300/R400 Radeon3D Aspect ATI Technologies Inc. Cata lyst Control Centre 2.0.2637.38797 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizar d\2.0.2637.38884__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ### Dashboard Local Caste TransCode Wizard ATI Technologies Inc. Catalyst Contr ol Centre 2.0.2637.38884 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2. 0.2614.20448__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ### Wizard Graphics Shared Caste ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20448 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2637. 38541__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ### Wizard Graphics Caste ATI Technologies Inc. Catalyst Control Centre 2.0.263 7.38541 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private \2.0.2614.20466__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ### Wizard Component Shared Private Types ATI Technologies Inc. Catalyst Contro l Centre 2.0.2614.20466 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.261 4.20444__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ### Wizard Component Shared Types ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20444 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.261 4.20437__90ba9c70f846762e\CLI.Component.Client.Shared.dll ### Client Shared ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20437 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.2637.38535 __90ba9c70f846762e\CLI.Component.Wizard.dll ### Wizard Component ATI Technologies Inc. Catalyst Control Centre 2.0.2637.385 35 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private \2.0.2614.20439__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ### Client Shared Private ATI Technologies Inc. Catalyst Control Centre 2.0.261 4.20439 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.2637.3 8851__90ba9c70f846762e\CLI.Component.Systemtray.dll ### SystemTray Component ATI Technologies Inc. Catalyst Control Centre 2.0.2637 .38851 [Loaded DLLs] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df95 8ca96c9b8945f836759b6abd34\System.Web.ni.dll ### System.Web.dll Microsoft Corporation Microsoft .NET Framework 2.0.50727.361 8 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.2614.20454__90ba 9c70f846762e\APM.Foundation.dll ### APM Foundation ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20454 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\ 2.0.2614.20452__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ### Shared Graphics Caste MM Video Aspect ATI Technologies Inc. Catalyst Contro

l Centre 2.0.2614.20452 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime \2.0.2637.38700__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ### Runtime Graphics Caste MM Video Aspect ATI Technologies Inc. Catalyst Contr ol Centre 2.0.2637.38700 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared \2.0.2614.20453__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ### Shared Graphics Caste R300/R400 Radeon3D Aspect ATI Technologies Inc. Cata lyst Control Centre 2.0.2614.20453 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtim e\2.0.2637.38787__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ### Runtime Graphics Caste R300/R400 Radeon3D Aspect ATI Technologies Inc. Cat alyst Control Centre 2.0.2637.38787 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shar ed\2.0.2614.20449__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll ### Shared Graphics Caste VPU Recover Aspect ATI Technologies Inc. Catalyst Con trol Centre 2.0.2614.20449 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runt ime\2.0.2637.38559__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll ### Runtime Graphics Caste VPU Recover Aspect ATI Technologies Inc. Catalyst Co ntrol Centre 2.0.2637.38559 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Share d\2.0.2614.20452__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ### Shared Graphics Caste DFP Aspect ATI Technologies Inc. Catalyst Control Cen tre 2.0.2614.20452 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runti me\2.0.2637.38690__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ### Runtime Graphics Caste DFP Aspect Advanced Micro Devices, Inc. Catalyst Con trol Centre 2.0.2637.38690 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Share d\2.0.2614.20447__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ### Shared Graphics Caste LCD Aspect ATI Technologies Inc. Catalyst Control Cen tre 2.0.2614.20447 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runti me\2.0.2637.38758__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ### Runtime Graphics Caste LCD Aspect Advanced Micro Devices, Inc. Catalyst Con trol Centre 2.0.2637.38758 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Share d\2.0.2614.20452__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ### Shared Graphics Caste CRT Aspect ATI Technologies Inc. Catalyst Control Cen tre 2.0.2614.20452 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runti me\2.0.2637.38699__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ### Runtime Graphics Caste CRT Aspect ATI Technologies Inc. Catalyst Control Ce ntre 2.0.2637.38699 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics .Shared\2.0.2614.20452__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Sha red.dll ### Shared Graphics Caste Display Option Aspect ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20452 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics .Runtime\2.0.2637.38733__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Ru ntime.dll ### Runtime Graphics Caste Display Option Aspect ATI Technologies Inc. Catalys t Control Centre 2.0.2637.38733 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics .Shared\2.0.2614.20450__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Sha red.dll ### Shared Graphics Caste Display Colour 2 Aspect ATI Technologies Inc. Cataly st Control Centre 2.0.2614.20450

[Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics .Runtime\2.0.2637.38591__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Ru ntime.dll ### Runtime Graphics Caste Display Colour 2 ATI Technologies Inc. Catalyst Cont rol Centre 2.0.2637.38591 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Shar ed\2.0.2614.20449__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Shared.dll ### Shared Graphics Caste InforCentre Aspect ATI Technologies Inc. Catalyst Con trol Centre 2.0.2614.20449 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runt ime\2.0.2637.38567__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.dll ### Runtime Graphics Caste InfoCentre Aspect ATI Technologies Inc. Catalyst Con trol Centre 2.0.2637.38567 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2614.20455 __90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ### GD source plugin shared ATI Technologies Inc. Catalyst Control Centre 2.0.2 614.20455 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared \2.0.2614.20454__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ### Shared Graphics Caste TV Aspect ATI Technologies Inc. Catalyst Control Cent re 2.0.2614.20454 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtim e\2.0.2637.38833__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ### Runtime Graphics Caste CRT Aspect ATI Technologies Inc. Catalyst Control Ce ntre 2.0.2637.38833 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics. Shared\2.0.2614.20445__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Share d.dll ### Shared Graphics Caste Common Display Device Aspect ATI Technologies Inc. C atalyst Control Centre 2.0.2614.20445 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics. Runtime\2.0.2637.38689__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runt ime.dll ### Runtime Graphics Caste DeviceProperty Aspect Shared Advanced Micro Devices , Inc. Catalyst Control Centre 2.0.2637.38689 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.S hared\2.0.2614.20445__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared. dll ### Shared Custom Formats ATI Technologies Inc. Catalyst Control Centre 2.0.261 4.20445 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared \2.0.2614.20453__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ### Shared Graphics Caste CV Aspect ATI Technologies Inc. Catalyst Control Cent re 2.0.2614.20453 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.P rivate\2.0.2614.20460__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Privat e.dll ### Runtime Shared Private Graphics Caste ATI Technologies Inc. Catalyst Contro l Centre 2.0.2614.20460 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtim e\2.0.2637.38776__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ### Runtime Graphics Caste CV Aspect ATI Technologies Inc. Catalyst Control Cen tre 2.0.2637.38776 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics .Shared\2.0.2614.20448__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Sha red.dll ### Shared Graphics Caste HotkeysHandling Aspect ATI Technologies Inc. Catalys t Control Centre 2.0.2614.20448 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics .Runtime\2.0.2637.38522__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Ru

ntime.dll ### Runtime Graphics Caste HotkeysHandling Aspect ATI Technologies Inc. Cataly st Control Centre 2.0.2637.38522 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.2637.38497__90ba9c70f8 46762e\ATIDEMOS.dll ### OS DEM ATI Technologies Inc. Catalyst Control Centre 2.0.2637.38497 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.2614.20454__90ba9c70f846 762e\DEM.OS.dll ### DEM OS ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20454 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2614.20 437__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ### AEM Actions Shared ATI Technologies Inc. Catalyst Control Centre 2.0.2614.2 0437 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2614.20448__90ba9c 70f846762e\DEM.OS.I0602.dll ### DEM.OS.I0602 ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20448 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared \2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ### ACE Graphics DisplaysManager Shared ATI Technologies Inc. Catalyst Control Centre 2.0.2573.17685 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2614. 20439__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ### Shared Graphics Caste Advanced Mirco Devices, Inc. Catalyst Control Centre 2.0.2614.20439 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2637 .38498__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ### Runtime Graphics Caste Advanced Mirco Devices, Inc. Catalyst Control Centre 2.0.2637.38498 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df _1.0.6002.22509_x-ww_c7dad023\gdiplus.dll ### Microsoft GDI+ Microsoft Corporation Microsoft Windows Operating System 5.2. 6002.22509 [Loaded DLLs] C:\WINDOWS\system32\wbem\wbemprox.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll ### WMINet_Utils.dll Microsoft Corporation Microsoft .NET Framework 2.0.50727.3 053 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f 11d50a3a\System.Management.dll ### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.305 3 [Loaded DLLs] C:\WINDOWS\system32\ATIDEMGX.dll ### Graphics DEM Advanced Micro Devices, Inc. Catalyst Control Centre 2.0.2629. 37759 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.2614.20446__90ba9c 70f846762e\DEM.Graphics.dll ### DEM Graphics ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20446 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba 9c70f846762e\DEM.Foundation.dll ### DEM Foundation ATI Technologies Inc. Catalyst Control Centre 2.0.2573.17684 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__ 90ba9c70f846762e\DEM.Graphics.I0601.dll ### DEM Graphics I0601 ATI Technologies Inc. Catalyst Control Centre 2.0.2573.1 7685 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2614. 20455__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ### HK Shared ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20455 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2614.204 68__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll

### DPPE Shared ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20468 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.26 37.38921__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ### AEM Event Sources Kit ATI Technologies Inc. Catalyst Control Centre 2.0.263 7.38921 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2614.20443__9 0ba9c70f846762e\AEM.Server.Shared.dll ### AEM Server Shared ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20 443 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2614.2044 3__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ### EEU source plugin shared ATI Technologies Inc. Catalyst Control Centre 2.0. 2614.20443 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Foundation\2.0.2614.20434__90ba 9c70f846762e\AEM.Foundation.dll ### AEM Foundation ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20434 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU \2.0.2637.38493__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ### EEU Runtime Extension ATI Technologies Inc. Catalyst Control Centre 2.0.263 7.38493 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ ATICCCom.dll ### CCCCom ATI Technologies Inc. Catalyst Control Centre 2.0.0.0 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.26 14.20437__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ### Runtime Shared ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20437 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2614.204 36__90ba9c70f846762e\CLI.Foundation.Private.dll ### CLI Foundation Private ATI Technologies Inc. Catalyst Control Centre 2.0.26 14.20436 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Privat e\2.0.2614.20444__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ### Runtime Shared Private ATI Technologies Inc. Catalyst Control Centre 2.0.26 14.20444 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.2637.3849 6__90ba9c70f846762e\CLI.Component.Runtime.dll ### Runtime Component Advanced Micro Devices, Inc. Catalyst Control Centre 2.0. 2637.38496 [Loaded DLLs] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc 44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.308 2 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2614.2 0493__90ba9c70f846762e\CLI.Foundation.XManifest.dll ### CLI Foundation XManifest ATI Technologies Inc. Catalyst Control Centre 2.0 .2614.20493 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.2614.20435__90ba 9c70f846762e\CLI.Foundation.dll ### CLI Foundation ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20435 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.2637.38861__ 90ba9c70f846762e\CCC.Implementation.dll ### CCC Application Implementation ATI Technologies Inc. Catalyst Control Centr e 2.0.2637.38861 [Loaded DLLs] C:\WINDOWS\system32\msdmo.dll [Loaded DLLs] C:\WINDOWS\system32\devenum.dll [Loaded DLLs] C:\WINDOWS\system32\34api.dll ### 34api.dll Philips Semiconductors UM proxy 2, 3, 1, 1

[Loaded DLLs] C:\WINDOWS\system32\oledlg.dll ### Microsoft Windows(TM) OLE 2.0 User Interface Support Microsoft Corporation Microsoft Windows(TM) OLE 2.0 User Interface Support 2.01 [Loaded DLLs] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll ### Dia based SymReader Microsoft Corporation Microsoft Visual Studio 2005 8.0.5 0727.3053 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2614.20436__9 0ba9c70f846762e\NEWAEM.Foundation.dll ### AEM Foundation ATI Technologies Inc. Catalyst Control Centre 2.0.2614.20436 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.2637.38494__90ba9c70 f846762e\AEM.Server.dll ### AEM Server ATI Technologies Inc. Catalyst Control Centre 2.0.2637.38494 [Loaded DLLs] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df95 8ca96c9b8945f836759b6abd34\System.Web.ni.dll ### System.Web.dll Microsoft Corporation Microsoft .NET Framework 2.0.50727.361 8 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\urlmon.dll ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Loaded DLLs] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Re mo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll ### Microsoft .NET Runtime Object Remoting Microsoft Corporation Microsoft .NET Framework 2.0.50727.3053 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Priva te\2.0.2614.20444__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ### LOG Foundation Implementation Private SDK ATI Technologies Inc. Catalyst Co ntrol Centre 2.0.2614.20444 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.2614.20445__90ba 9c70f846762e\MOM.Foundation.dll ### MOM Foundation Advanced Micro Devices Inc. Catalyst Control Centre 2.0.2614 .20445 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2 637.38859__90ba9c70f846762e\LOG.Foundation.Implementation.dll ### LOG Foundation Implementation ATI Technologies Inc. Catalyst Control Centre 2.0.2637.38859 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2614.204 36__90ba9c70f846762e\LOG.Foundation.Private.dll ### LOG Foundation Dynamic ATI Technologies Inc. Catalyst Control Centre 2.0.26 14.20436 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.2614.20433__90ba 9c70f846762e\LOG.Foundation.dll ### LOG Foundation Static ATI Technologies Inc. Catalyst Control Centre 2.0.261 4.20433 [Loaded DLLs] C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.2637.38862__ 90ba9c70f846762e\MOM.Implementation.dll ### MOM Implementation Advanced Micro Devices Inc. Catalyst Control Centre 2.0 .2637.38862 [Loaded DLLs] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Fo rms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.362 3 [Loaded DLLs] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c1 0bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.305 3 [Loaded DLLs] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644

af02873b9bae319f2bfb13\System.ni.dll ### .NET Framework Microsoft Corporation Microsoft .NET Framework 2.0.50727.362 4 [Loaded DLLs] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll ### Microsoft .NET Runtime Just-In-Time Compiler Microsoft Corporation Microso ft .NET Framework 2.0.50727.3623 [Loaded DLLs] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84 221991839abbe7d4bc9c6721\mscorlib.ni.dll ### Microsoft Common Language Runtime Class Library Microsoft Corporation Micr osoft .NET Framework 2.0.50727.3625 [Loaded DLLs] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll ### Microsoft .NET Runtime Common Language Runtime - WorkStation Microsoft Cor poration Microsoft .NET Framework 2.0.50727.3625 [Loaded DLLs] C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll ### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE T Framework 4.0.30319.1 [Loaded DLLs] C:\WINDOWS\system32\mscoree.dll ### Microsoft .NET Runtime Execution Engine Microsoft Corporation Microsoft .NE T Framework 4.0.31106.0 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50 727.6195_x-ww_44262b86\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.6195 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\Wship6.dll ### IPv6 Helper DLL Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512 [Loaded DLLs] C:\WINDOWS\system32\oleacc.dll ### Active Accessibility Core Component Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6153 [Loaded DLLs] C:\WINDOWS\system32\MSUTB.dll ### MSUTB Server DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5512 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\USP10.dll ### Uniscribe Unicode script processor Microsoft Corporation Microsoft(R) Unis cribe Unicode script processor 1.0626.6002.22402 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50 727.6195_x-ww_44262b86\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.6195 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\stacapi.dll ### IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001.0 [Loaded DLLs] C:\WINDOWS\system32\MFC42u.DLL ### MFCDLL Shared Library - Retail Version Microsoft Corporation Microsoft (R) Visual C++ 6.02.400 [Loaded DLLs] C:\Program Files\IDT\WDM\STLang.dll

### IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001.0 [Loaded DLLs] C:\WINDOWS\system32\perfdisk.dll ### Windows Disk Performance Objects DLL Microsoft Corporation Microsoft Window s Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\perfos.dll ### Windows System Performance Objects DLL Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\odbcint.dll ### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat a Access Components 3.525.1132.0 [Loaded DLLs] C:\WINDOWS\system32\odbcbcp.dll ### Microsoft BCP for ODBC Microsoft Corporation Microsoft SQL Server 3.85.300 9 [Loaded DLLs] C:\WINDOWS\system32\pdh.dll ### Windows Performance Data Helper DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5773 [Loaded DLLs] C:\Program Files\Java\jre6\bin\MSVCR71.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio .N ET 7.10.3052.4 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\olepro32.dll ### Microsoft Corporation 5.1.2600.5512 [Loaded DLLs] C:\Program Files\DU Meter\sqlite3.dll ### SQLite Database Library Hagel Technologies Ltd [Loaded DLLs] C:\WINDOWS\system32\SHFolder.dll ### Shell Folder Service Microsoft Corporation Microsoft Windows Operating Syste m 6.00.2900.5512 [Loaded DLLs] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.d ll ### ACE Context Menu ACE Context Menu 2, 0, 0, 0 [Loaded DLLs] C:\Program Files\TeraCopy\TeraCopyExt.dll [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResour ce.dll ### GrooveIntlResource Module Microsoft Corporation GrooveIntlResource Module 4.2.2.2807 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30 729.5054_x-ww_029f6dc7\MSVCR90.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 8 9.00.30729.5054 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30 729.5054_x-ww_029f6dc7\MSVCP90.dll ### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio 2 008 9.00.30729.5054 [Loaded DLLs] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll ### PDF Shell Extension Adobe Systems, Inc. Adobe PDF Shell Extension 10.0.1.4 34 [Loaded DLLs] C:\Program Files\K-Lite Codec Pack\Filters\Haali\mkunicode.dll [Loaded DLLs] C:\Program Files\K-Lite Codec Pack\Filters\Haali\mmfinfo.dll [Loaded DLLs] C:\WINDOWS\system32\wzcdlg.dll ### Wireless Zero Configuration Service UI Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.5815 [Loaded DLLs] C:\WINDOWS\system32\PortableDeviceApi.dll ### Windows Portable Device API Components Microsoft Corporation Microsoft Wind ows Operating System 5.2.5721.5262 [Loaded DLLs] C:\WINDOWS\system32\PortableDeviceTypes.dll ### Windows Portable Device (Parameter) Types Component Microsoft Corporation Microsoft Windows Operating System 5.2.5721.5262 [Loaded DLLs] C:\WINDOWS\system32\mydocs.dll

### My Documents Folder UI Microsoft Corporation Microsoft Windows Operating Sys tem 6.00.2900.5512 [Loaded DLLs] C:\WINDOWS\system32\WPDShServiceObj.dll ### Windows Portable Device Shell Service Object Microsoft Corporation Microso ft Windows Operating System 5.2.5721.5262 [Loaded DLLs] C:\WINDOWS\system32\BatMeter.dll ### Battery Meter Helper DLL Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.5512 [Loaded DLLs] C:\WINDOWS\system32\stobject.dll ### Systray shell service object Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\MLANG.dll ### Multi Language Support DLL Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5512 [Loaded DLLs] C:\WINDOWS\system32\webcheck.dll ### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001. 18702 [Loaded DLLs] C:\WINDOWS\system32\MSCTF.dll ### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5655 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll ### GrooveMisc Module Microsoft Corporation GrooveMisc Module 4.2.2.2807 [Loaded DLLs] C:\WINDOWS\system32\ieframe.dll ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .23227 [Loaded DLLs] C:\WINDOWS\system32\ntshrui.dll ### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\LINKINFO.dll ### Windows Volume Tracking Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\msxml3.dll ### MSXML 3.0 SP10 Microsoft Corporation Microsoft(R) MSXML 3.0 SP10 8.100.105 2.0 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\GrooveSystemServices. dll ### GrooveSystemServices Module Microsoft Corporation GrooveSystemServices Mod ule 4.2.2.2807 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\themeui.dll ### Windows Theme API Microsoft Corporation Microsoft Windows Operating System 6 .00.2900.5512 [Loaded DLLs] C:\WINDOWS\system32\MSImg32.dll ### GDIEXT Client DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5512 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50 727.6195_x-ww_a4c618fa\ATL80.DLL ### ATL Module for Windows (Unicode) Microsoft Corporation Microsoft Visual Stu dio 2005 8.00.50727.6195 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL ### GrooveNew Module Microsoft Corporation GrooveNew Module 4.2.2.2807 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50 727.6195_x-ww_44262b86\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.6195 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL ### GrooveUtil Module Microsoft Corporation GrooveUtil Module 4.2.2.2826 [Loaded DLLs] C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions

.dll ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\SHDOCVW.dll ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.5512 [Loaded DLLs] C:\WINDOWS\system32\BROWSEUI.dll ### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.5512 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\stacapi.dll ### IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001.0 [Loaded DLLs] C:\WINDOWS\system32\DSOUND.dll ### DirectSound Microsoft Corporation Microsoft(R) Windows(R) Operating System 5.3.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\inetpp.dll ### Internet Print Provider DLL Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5716 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\NETRAP.dll ### Net Remote Admin Protocol DLL Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\win32spl.dll ### 32-bit Spooler API DLL Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5664 [Loaded DLLs] C:\WINDOWS\System32\winrnr.dll ### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\spool\PRTPROCS\W32X86\msonpppr.dll ### Microsoft Office OneNote 2007 Printer Driver Microsoft Corporation Microso ft Office OneNote 2007 Printer Driver 12.3.4518.1014 [Loaded DLLs] C:\WINDOWS\System32\spool\PRTPROCS\W32X86\filterpipelineprintpro c.dll ### Print Filter Pipeline Proxy Microsoft Corporation Microsoft Windows Operatin g System 6.1.2600.5863 [Loaded DLLs] C:\WINDOWS\system32\usbmon.dll ### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\tcpmon.dll ### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5795 [Loaded DLLs] C:\WINDOWS\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 4.5.60 02.22362 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50 727.6195_x-ww_44262b86\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.6195 [Loaded DLLs] C:\WINDOWS\system32\msonpmon.dll ### Microsoft Office OneNote 2007 Printer Driver Microsoft Corporation Microso ft Office OneNote 2007 Printer Driver 12.3.6500.5000 [Loaded DLLs] C:\WINDOWS\system32\localspl.dll ### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System 5

.1.2600.5830 [Loaded DLLs] C:\WINDOWS\system32\SPOOLSS.DLL ### Spooler SubSystem DLL Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\ati2evxx.dll ### ATI External Event Utility DLL Module ATI Technologies Inc. ATI External E vent Utility for Windows 6.14.10.4162 [Loaded DLLs] C:\WINDOWS\system32\Ati2edxx.dll ### ati2edxx ATI Technologies, Inc. ATI External Device Utility 6, 14, 10, 251 1 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\wbem\ncprov.dll ### Non-COM WMI Event Provision APIs Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\RASDLG.dll ### Remote Access Common Dialog API Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\RASQEC.DLL ### RAS Quarantine Enforcement Client Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\ntlsapi.dll ### Microsoft License Server Interface DLL Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\rasppp.dll ### Remote Access PPP Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\HID.DLL ### Hid User Library Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\hidphone.tsp ### Microsoft HID Phone TSP Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\h323.tsp ### Microsoft H.323 Telephony Service Provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\ipconf.tsp ### Microsoft Multicast Conference TAPI Service Provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\ndptsp.tsp ### NDIS Proxy TAPI Service Provider Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\kmddsp.tsp ### TAPI Kernel-Mode Service Provider Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\modemui.dll ### Windows Modem Properties Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\unimdmat.dll ### Unimodem Service Provider AT Mini Driver Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\uniplat.dll ### Unimodem AT Mini Driver Platform Driver for Windows NT Microsoft Corporati on Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\unimdm.tsp ### Unimodem 5 Service Provider Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5815 [Loaded DLLs] C:\WINDOWS\System32\rastapi.dll ### Remote Access TAPI Compliance Layer Microsoft Corporation Microsoft Windows

Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\tapisrv.dll ### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5654 [Loaded DLLs] C:\WINDOWS\System32\rasadhlp.dll ### Remote Access AutoDial Helper Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\rasmans.dll ### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\netcfgx.dll ### Network Configuration Objects Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\wbem\wbemess.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\wbem\wmiprvsd.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5755 [Loaded DLLs] C:\WINDOWS\system32\wbem\repdrvfs.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\wbem\wmiutils.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\wbem\wbemsvc.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\Wbem\FastProx.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5755 [Loaded DLLs] C:\WINDOWS\System32\Wbem\esscli.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\Wbem\wbemcore.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\wbem\wbemcomn.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\SSDPAPI.dll ### SSDP Client API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\upnp.dll ### Universal Plug and Play API Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\wups2.dll ### Windows Update client proxy stub 2 Microsoft Corporation Microsoft Windows O perating System 7.4.7600.229 [Loaded DLLs] C:\WINDOWS\System32\RESUTILS.DLL ### Microsoft Cluster Resource Utility DLL Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\CLUSAPI.DLL ### Cluster API Library Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\WSOCK32.dll ### Windows Socket 32-Bit DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\MTXCLU.DLL ### MS DTC amd MTS clustering support DLL Microsoft Corporation COM Services 0 3.01.00.4414 [Loaded DLLs] C:\WINDOWS\system32\colbact.DLL ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\system32\comsvcs.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\System32\SXS.DLL ### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .5699 [Loaded DLLs] c:\windows\system32\ipnathlp.dll

### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5589 [Loaded DLLs] c:\windows\system32\browser.dll ### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5574 [Loaded DLLs] C:\WINDOWS\System32\mspatcha.dll ### Microsoft(R) Patch Engine Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\Cabinet.dll ### Microsoft Cabinet File API Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\WINHTTP.dll ### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5868 [Loaded DLLs] C:\WINDOWS\system32\wuaueng.dll ### Windows Update Agent Microsoft Corporation Microsoft Windows Operating Syste m 7.4.7600.229 [Loaded DLLs] c:\windows\system32\wuauserv.dll ### Windows Update AutoUpdate Service Microsoft Corporation Microsoft Windows Op erating System 7.4.7600.229 [Loaded DLLs] C:\WINDOWS\system32\VSSAPI.DLL ### Microsoft Volume Shadow Copy Requestor/Writer Services API DLL Microsoft Co rporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\wbem\wmisvc.dll ### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\trkwks.dll ### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\srsvc.dll ### System Restore Service Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\sens.dll ### System Event Notification Service (SENS) Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\seclogon.dll ### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\WZCSAPI.DLL ### Wireless Zero Configuration service API Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\eappprxy.dll ### Microsoft EAPHost Peer Client DLL Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\eappcfg.dll ### Eap Peer Config Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512 [Loaded DLLs] c:\windows\system32\OneX.DLL ### IEEE 802.1X supplicant library Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\dot3dlg.dll ### 802.3 UI Helper Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512 [Loaded DLLs] c:\windows\system32\credui.dll ### Credential Manager User Interface Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\netshell.dll ### Network Connections Shell Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\netman.dll ### Network Connections Manager Microsoft Corporation Microsoft Windows Operatin

g System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\srvsvc.dll ### Server Service DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6031 [Loaded DLLs] c:\windows\system32\es.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] c:\windows\system32\dmserver.dll ### Logical Disk Manager service dll Microsoft Corp. Logical Disk Manager for Windows NT 1.0 [Loaded DLLs] c:\windows\system32\certcli.dll ### Microsoft Certificate Services Client Microsoft Corporation Microsoft Window s Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\cryptsvc.dll ### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\wkssvc.dll ### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5826 [Loaded DLLs] c:\windows\system32\audiosrv.dll ### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\MSIDLE.DLL ### User Idle Monitor Microsoft Corporation Microsoft Windows Operating System 6 .00.2900.5512 [Loaded DLLs] C:\WINDOWS\System32\raschap.dll ### Remote Access PPP CHAP Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5886 [Loaded DLLs] c:\windows\system32\schedsvc.dll ### Task Scheduler Engine Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\TAPI32.dll ### Microsoft Windows(TM) Telephony API Client DLL Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\rasman.dll ### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\RASAPI32.dll ### Remote Access API Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5586 [Loaded DLLs] C:\WINDOWS\System32\MPRAPI.dll ### Windows NT MP Router Administration DLL Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\iertutil.dll ### Run time utility for Internet Explorer Microsoft Corporation Windows Intern et Explorer 8.00.6001.23227 [Loaded DLLs] C:\WINDOWS\system32\urlmon.dll ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Loaded DLLs] C:\WINDOWS\system32\WININET.dll ### Internet Extensions for Win32 Microsoft Corporation Windows Internet Explor er 8.00.6001.23227 [Loaded DLLs] C:\WINDOWS\System32\CRYPTUI.dll ### Microsoft Trust UI Provider Microsoft Corporation Microsoft Windows Operatin g System 5.131.2600.5512 [Loaded DLLs] C:\WINDOWS\System32\rastls.dll ### Remote Access PPP EAP-TLS Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5886

[Loaded DLLs] c:\windows\system32\ESENT.dll ### Server Database Storage Engine Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\dot3api.dll ### 802.3 Autoconfiguration API Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\QUtil.dll ### Quarantine Utilities Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\EapolQec.dll ### Microsoft EAPOL NAP Enforcement Client Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\WMI.dll ### WMI DC and DP functionality Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\rtutils.dll ### Routing Utilities Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5512 [Loaded DLLs] c:\windows\system32\wzcsvc.dll ### Wireless Zero Configuration Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5585 [Loaded DLLs] c:\windows\system32\dhcpcsvc.dll ### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5614 [Loaded DLLs] c:\windows\system32\ATL.DLL ### ATL Module for Windows XP (Unicode) Microsoft Corporation Microsoft (R) Vi sual C++ 6.05.2284 [Loaded DLLs] c:\windows\system32\adsldpc.dll ### ADs LDAP Provider C DLL Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\ACTIVEDS.dll ### ADs Router Layer DLL Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\mstlsapi.dll ### Microsoft Terminal Server Licensing Microsoft Corporation Microsoft Windows O perating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\ICAAPI.dll ### DLL Interface to TermDD Device Driver Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\termsrv.dll ### Terminal Server Service Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5815 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] c:\windows\system32\rpcss.dll ### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5755 [Loaded DLLs] C:\WINDOWS\system32\atipdlxx.dll ### ATI Desktop CWDDEDI DLL ATI Technologies, Inc. ATI Desktop Component 6, 14 , 10, 2516 [Loaded DLLs] C:\WINDOWS\system32\Ati2edxx.dll ### ati2edxx ATI Technologies, Inc. ATI External Device Utility 6, 14, 10, 251 1 [Loaded DLLs] C:\WINDOWS\system32\cfgMgr32.dll ### Configuration Manager Forwarder DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\powrprof.dll ### Power Profile Helper DLL Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.5512

[Loaded DLLs] C:\WINDOWS\system32\dssenh.dll ### Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5507 [Loaded DLLs] C:\WINDOWS\System32\wshtcpip.dll ### Windows Sockets Helper DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\psbase.dll ### Protected Storage default provider Microsoft Corporation Microsoft Windows O perating System 5.1.2600.5642 [Loaded DLLs] C:\WINDOWS\system32\hnetcfg.dll ### Home Networking Configuration Manager Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5589 [Loaded DLLs] C:\WINDOWS\system32\pstorsvc.dll ### Protected storage server Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\mswsock.dll ### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro soft Windows Operating System 5.1.2600.5649 [Loaded DLLs] C:\WINDOWS\system32\WINIPSEC.DLL ### Windows IPSec SPD Client DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\oakley.DLL ### Oakley Key Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5886 [Loaded DLLs] C:\WINDOWS\system32\ipsecsvc.dll ### Windows IPSec SPD Server DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\scecli.dll ### Windows Security Configuration Editor Client Engine Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\wdigest.dll ### Microsoft Digest Access Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5846 [Loaded DLLs] C:\WINDOWS\system32\schannel.dll ### TLS / SSL Security Provider Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.6006 [Loaded DLLs] C:\WINDOWS\system32\w32time.dll ### Windows Time Service Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5635 [Loaded DLLs] C:\WINDOWS\system32\netlogon.dll ### Net Logon Services DLL Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5755 [Loaded DLLs] C:\WINDOWS\system32\kerberos.dll ### Kerberos Security Package Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6059 [Loaded DLLs] C:\WINDOWS\system32\msprivs.dll ### Microsoft Privilege Translations Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\AppPatch\AcGenral.DLL ### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\SAMSRV.dll ### SAM Server DLL Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.5512 [Loaded DLLs] C:\WINDOWS\system32\DNSAPI.dll ### DNS Client API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6089 [Loaded DLLs] C:\WINDOWS\system32\NTDSAPI.dll ### NT5DS Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5582

[Loaded DLLs] C:\WINDOWS\system32\LSASRV.dll ### LSA Server DLL Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.6058 [Loaded DLLs] C:\WINDOWS\system32\eventlog.dll ### Event Logging Service Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\AppPatch\AcAdProc.dll ### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\ShimEng.dll ### Shim Engine DLL Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5555 [Loaded DLLs] C:\WINDOWS\system32\umpnpmgr.dll ### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5708 [Loaded DLLs] C:\WINDOWS\system32\SCESRV.dll ### Windows Security Configuration Editor Engine Microsoft Corporation Microso ft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\MSVCP60.dll ### Microsoft (R) C++ Runtime Library Microsoft Corporation Microsoft (R) Visu al C++ 6.02.3104.0 [Loaded DLLs] C:\WINDOWS\system32\NCObjAPI.DLL ### Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\midimap.dll ### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\MSACM32.dll ### Microsoft ACM Audio Filter Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\msacm32.drv ### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.0 [Loaded DLLs] C:\WINDOWS\system32\wdmaud.drv ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\cscui.dll ### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\iphlpapi.dll ### IP Helper API Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.5512 [Loaded DLLs] C:\WINDOWS\system32\cryptdll.dll ### Cryptography Manager Microsoft Corporation Microsoft Windows Operating Syste m 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\msv1_0.dll ### Microsoft Authentication Package v1.0 Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5876 [Loaded DLLs] C:\WINDOWS\system32\COMRes.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\system32\CLBCATQ.DLL ### Microsoft Corporation COM Services 03.00.00.4414 [Loaded DLLs] C:\WINDOWS\system32\WLDAP32.dll ### Win32 LDAP API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5740 [Loaded DLLs] C:\WINDOWS\system32\SAMLIB.dll ### SAM Library DLL Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512

[Loaded DLLs] C:\WINDOWS\system32\NTMARTA.DLL ### Windows NT MARTA provider Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\WgaLogon.dll ### Windows Genuine Advantage Notifications Microsoft Corporation Microsoft Ge nuine Advantage 1.9.0040.0 [Loaded DLLs] C:\WINDOWS\system32\WINSPOOL.DRV ### Windows Spooler Driver Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\MPR.dll ### Multiple Provider Router DLL Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\WlNotify.dll ### Common DLL to receive Winlogon notifications Microsoft Corporation Microso ft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\rsaenh.dll ### Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft W indows Operating System 5.1.2600.5507 [Loaded DLLs] C:\WINDOWS\System32\dimsntfy.dll ### DIMS Notification Handler Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\cscdll.dll ### Offline Network Agent Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5731 [Loaded DLLs] C:\WINDOWS\system32\OLEAUT32.dll ### Microsoft Corporation 5.1.2600.6058 [Loaded DLLs] C:\WINDOWS\system32\Ati2evxx.dll ### ATI External Event Utility DLL Module ATI Technologies Inc. ATI External E vent Utility for Windows 6.14.10.4162 [Loaded DLLs] C:\WINDOWS\system32\WINMM.dll ### MCI API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.5512 [Loaded DLLs] C:\WINDOWS\system32\uxtheme.dll ### Microsoft UxTheme Library Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5512 [Loaded DLLs] C:\WINDOWS\system32\WTSAPI32.dll ### Windows Terminal Server SDK APIs Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\WINSCARD.DLL ### Microsoft Smart Card API Microsoft Corporation Microsoft Windows Operating S ystem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\msctfime.ime ### Microsoft Text Frame Work Service IME Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5768 [Loaded DLLs] C:\WINDOWS\system32\Apphelp.dll ### Application Compatibility Client Library Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\ole32.dll ### Microsoft OLE for Windows Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6010 [Loaded DLLs] C:\WINDOWS\system32\sfc_os.dll ### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\sfc.dll ### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\SHSVCS.dll ### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5853 [Loaded DLLs] C:\WINDOWS\system32\odbcint.dll

### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat a Access Components 3.525.1132.0 [Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b641 44ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll ### User Experience Controls Library Microsoft Corporation Microsoft Windows Ope rating System 6.00.2900.6028 [Loaded DLLs] C:\WINDOWS\system32\SHLWAPI.dll ### Shell Light-weight Utility Library Microsoft Corporation Microsoft Windows O perating System 6.00.2900.5912 [Loaded DLLs] C:\WINDOWS\system32\SHELL32.dll ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.6072 [Loaded DLLs] C:\WINDOWS\system32\comdlg32.dll ### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5512 [Loaded DLLs] C:\WINDOWS\system32\ODBC32.dll ### Microsoft Data Access - ODBC Driver Manager Microsoft Corporation Microsof t Data Access Components 3.525.3012.0 [Loaded DLLs] C:\WINDOWS\system32\COMCTL32.dll ### Common Controls Library Microsoft Corporation Microsoft Windows Operating Sy stem 6.00.2900.6028 [Loaded DLLs] C:\WINDOWS\system32\MSGINA.dll ### Windows NT Logon GINA DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5587 [Loaded DLLs] C:\WINDOWS\system32\USP10.dll ### Uniscribe Unicode script processor Microsoft Corporation Microsoft(R) Unis cribe Unicode script processor 1.0626.6002.22384 [Loaded DLLs] C:\WINDOWS\system32\LPK.DLL ### Language Pack Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.5512 [Loaded DLLs] C:\WINDOWS\system32\IMM32.DLL ### Windows XP IMM32 API Client DLL Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\WS2HELP.dll ### Windows Socket 2.0 Helper for Windows NT Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\WS2_32.dll ### Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\IMAGEHLP.dll ### Windows NT Image Helper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\WINTRUST.dll ### Microsoft Trust Verification APIs Microsoft Corporation Microsoft Windows Op erating System 5.131.2600.5922 [Loaded DLLs] C:\WINDOWS\system32\WINSTA.dll ### Winstation Library Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\VERSION.dll ### Version Checking and File Installation Libraries Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\SETUPAPI.dll ### Windows Setup API Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5603 [Loaded DLLs] C:\WINDOWS\system32\REGAPI.dll ### Registry Configuration APIs Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\PSAPI.DLL ### Process Status Helper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512

[Loaded DLLs] C:\WINDOWS\system32\USERENV.dll ### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.55 12 [Loaded DLLs] C:\WINDOWS\system32\NETAPI32.dll ### Net Win32 API DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5694 [Loaded DLLs] C:\WINDOWS\system32\PROFMAP.dll ### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.55 12 [Loaded DLLs] C:\WINDOWS\system32\NDdeApi.dll ### Network DDE Share Management APIs Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\GDI32.dll ### GDI Client DLL Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.5732 [Loaded DLLs] C:\WINDOWS\system32\USER32.dll ### Windows XP USER API Client DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5577 [Loaded DLLs] C:\WINDOWS\system32\MSASN1.dll ### ASN.1 Runtime APIs Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5875 [Loaded DLLs] C:\WINDOWS\system32\CRYPT32.dll ### Crypto API32 Microsoft Corporation Microsoft Windows Operating System 5.131. 2600.5779 [Loaded DLLs] C:\WINDOWS\system32\msvcrt.dll ### Windows NT CRT DLL Microsoft Corporation Microsoft Windows Operating System 7.0.2600.5701 [Loaded DLLs] C:\WINDOWS\system32\AUTHZ.dll ### Authorization Framework Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Loaded DLLs] C:\WINDOWS\system32\Secur32.dll ### Security Support Provider Interface Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5834 [Loaded DLLs] C:\WINDOWS\system32\RPCRT4.dll ### Remote Procedure Call Runtime Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.6022 [Loaded DLLs] C:\WINDOWS\system32\ADVAPI32.dll ### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5793 [Loaded DLLs] C:\WINDOWS\system32\kernel32.dll ### Windows NT BASE API Client DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5781 [Loaded DLLs] C:\WINDOWS\system32\ntdll.dll ### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.6055 [Explorer's DLLs] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacm xx.dll ### ACE Context Menu ACE Context Menu 2, 0, 0, 0 [Explorer's DLLs] C:\Program Files\TeraCopy\TeraCopyExt.dll [Explorer's DLLs] C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlRe source.dll ### GrooveIntlResource Module Microsoft Corporation GrooveIntlResource Module 4.2.2.2807 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9. 0.30729.5054_x-ww_029f6dc7\MSVCR90.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 8 9.00.30729.5054 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9. 0.30729.5054_x-ww_029f6dc7\MSVCP90.dll ### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio 2

008 9.00.30729.5054 [Explorer's DLLs] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell .dll ### PDF Shell Extension Adobe Systems, Inc. Adobe PDF Shell Extension 10.0.1.4 34 [Explorer's DLLs] C:\Program Files\K-Lite Codec Pack\Filters\Haali\mkunicode.d ll [Explorer's DLLs] C:\Program Files\K-Lite Codec Pack\Filters\Haali\mmfinfo.dll [Explorer's DLLs] C:\WINDOWS\system32\wzcdlg.dll ### Wireless Zero Configuration Service UI Microsoft Corporation Microsoft Wind ows Operating System 5.1.2600.5815 [Explorer's DLLs] C:\WINDOWS\system32\PortableDeviceApi.dll ### Windows Portable Device API Components Microsoft Corporation Microsoft Wind ows Operating System 5.2.5721.5262 [Explorer's DLLs] C:\WINDOWS\system32\PortableDeviceTypes.dll ### Windows Portable Device (Parameter) Types Component Microsoft Corporation Microsoft Windows Operating System 5.2.5721.5262 [Explorer's DLLs] C:\WINDOWS\system32\mydocs.dll ### My Documents Folder UI Microsoft Corporation Microsoft Windows Operating Sys tem 6.00.2900.5512 [Explorer's DLLs] C:\WINDOWS\system32\WPDShServiceObj.dll ### Windows Portable Device Shell Service Object Microsoft Corporation Microso ft Windows Operating System 5.2.5721.5262 [Explorer's DLLs] C:\WINDOWS\system32\BatMeter.dll ### Battery Meter Helper DLL Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.5512 [Explorer's DLLs] C:\WINDOWS\system32\stobject.dll ### Systray shell service object Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\MLANG.dll ### Multi Language Support DLL Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5512 [Explorer's DLLs] C:\WINDOWS\system32\webcheck.dll ### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001. 18702 [Explorer's DLLs] C:\WINDOWS\system32\MSCTF.dll ### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 5. 1.2600.5655 [Explorer's DLLs] C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll ### GrooveMisc Module Microsoft Corporation GrooveMisc Module 4.2.2.2807 [Explorer's DLLs] C:\WINDOWS\system32\ieframe.dll ### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001 .23227 [Explorer's DLLs] C:\WINDOWS\system32\ntshrui.dll ### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\LINKINFO.dll ### Windows Volume Tracking Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\msxml3.dll ### MSXML 3.0 SP10 Microsoft Corporation Microsoft(R) MSXML 3.0 SP10 8.100.105 2.0 [Explorer's DLLs] C:\Program Files\Microsoft Office\Office12\GrooveSystemServi ces.dll ### GrooveSystemServices Module Microsoft Corporation GrooveSystemServices Mod ule 4.2.2.2807 [Explorer's DLLs] C:\WINDOWS\system32\xpsp2res.dll ### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\themeui.dll

### Windows Theme API Microsoft Corporation Microsoft Windows Operating System 6 .00.2900.5512 [Explorer's DLLs] C:\WINDOWS\system32\MSImg32.dll ### GDIEXT Client DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5512 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8. 0.50727.6195_x-ww_a4c618fa\ATL80.DLL ### ATL Module for Windows (Unicode) Microsoft Corporation Microsoft Visual Stu dio 2005 8.00.50727.6195 [Explorer's DLLs] C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL ### GrooveNew Module Microsoft Corporation GrooveNew Module 4.2.2.2807 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8. 0.50727.6195_x-ww_44262b86\MSVCR80.dll ### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200 5 8.00.50727.6195 [Explorer's DLLs] C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL ### GrooveUtil Module Microsoft Corporation GrooveUtil Module 4.2.2.2826 [Explorer's DLLs] C:\Program Files\Microsoft Office\Office12\GrooveShellExtens ions.dll ### GrooveShellExtensions Module Microsoft Corporation GrooveShellExtensions M odule 4.2.2.2807 [Explorer's DLLs] C:\WINDOWS\system32\Normaliz.dll ### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating System 6.0.5441.0 [Explorer's DLLs] C:\WINDOWS\system32\SHDOCVW.dll ### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window s Operating System 6.00.2900.5512 [Explorer's DLLs] C:\WINDOWS\system32\BROWSEUI.dll ### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.5512 [Explorer's DLLs] C:\WINDOWS\system32\msi.dll ### Windows Installer Microsoft Corporation Windows Installer - Unicode 4.5.60 02.22362 [Explorer's DLLs] C:\WINDOWS\System32\SXS.DLL ### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System 5.1.2600 .5699 [Explorer's DLLs] C:\WINDOWS\System32\WINHTTP.dll ### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5868 [Explorer's DLLs] c:\windows\system32\WZCSAPI.DLL ### Wireless Zero Configuration service API Microsoft Corporation Microsoft Win dows Operating System 5.1.2600.5512 [Explorer's DLLs] c:\windows\system32\eappprxy.dll ### Microsoft EAPHost Peer Client DLL Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Explorer's DLLs] c:\windows\system32\eappcfg.dll ### Eap Peer Config Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512 [Explorer's DLLs] c:\windows\system32\OneX.DLL ### IEEE 802.1X supplicant library Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5512 [Explorer's DLLs] c:\windows\system32\dot3dlg.dll ### 802.3 UI Helper Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5512 [Explorer's DLLs] c:\windows\system32\credui.dll ### Credential Manager User Interface Microsoft Corporation Microsoft Windows Op erating System 5.1.2600.5512 [Explorer's DLLs] c:\windows\system32\netshell.dll ### Network Connections Shell Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512

[Explorer's DLLs] C:\WINDOWS\system32\iertutil.dll ### Run time utility for Internet Explorer Microsoft Corporation Windows Intern et Explorer 8.00.6001.23227 [Explorer's DLLs] C:\WINDOWS\system32\urlmon.dll ### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer 8.00.6001.23227 [Explorer's DLLs] C:\WINDOWS\system32\WININET.dll ### Internet Extensions for Win32 Microsoft Corporation Windows Internet Explor er 8.00.6001.23227 [Explorer's DLLs] C:\WINDOWS\System32\CRYPTUI.dll ### Microsoft Trust UI Provider Microsoft Corporation Microsoft Windows Operatin g System 5.131.2600.5512 [Explorer's DLLs] c:\windows\system32\dot3api.dll ### 802.3 Autoconfiguration API Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5512 [Explorer's DLLs] c:\windows\system32\rtutils.dll ### Routing Utilities Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5512 [Explorer's DLLs] c:\windows\system32\ATL.DLL ### ATL Module for Windows XP (Unicode) Microsoft Corporation Microsoft (R) Vi sual C++ 6.05.2284 [Explorer's DLLs] C:\WINDOWS\system32\powrprof.dll ### Power Profile Helper DLL Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.5512 [Explorer's DLLs] C:\WINDOWS\AppPatch\AcGenral.DLL ### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\ShimEng.dll ### Shim Engine DLL Microsoft Corporation Microsoft Windows Operating System 5.1 .2600.5555 [Explorer's DLLs] C:\WINDOWS\system32\MSVCP60.dll ### Microsoft (R) C++ Runtime Library Microsoft Corporation Microsoft (R) Visu al C++ 6.02.3104.0 [Explorer's DLLs] C:\WINDOWS\system32\midimap.dll ### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\MSACM32.dll ### Microsoft ACM Audio Filter Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\msacm32.drv ### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.0 [Explorer's DLLs] C:\WINDOWS\system32\wdmaud.drv ### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\cscui.dll ### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys tem 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\iphlpapi.dll ### IP Helper API Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.5512 [Explorer's DLLs] C:\WINDOWS\system32\COMRes.dll ### Microsoft Corporation COM Services 03.00.00.4414 [Explorer's DLLs] C:\WINDOWS\system32\CLBCATQ.DLL ### Microsoft Corporation COM Services 03.00.00.4414 [Explorer's DLLs] C:\WINDOWS\system32\WLDAP32.dll ### Win32 LDAP API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5740 [Explorer's DLLs] C:\WINDOWS\system32\SAMLIB.dll ### SAM Library DLL Microsoft Corporation Microsoft Windows Operating System 5.1

.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\rsaenh.dll ### Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft W indows Operating System 5.1.2600.5507 [Explorer's DLLs] C:\WINDOWS\system32\cscdll.dll ### Offline Network Agent Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5731 [Explorer's DLLs] C:\WINDOWS\system32\OLEAUT32.dll ### Microsoft Corporation 5.1.2600.6058 [Explorer's DLLs] C:\WINDOWS\system32\WINMM.dll ### MCI API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.260 0.5512 [Explorer's DLLs] C:\WINDOWS\system32\uxtheme.dll ### Microsoft UxTheme Library Microsoft Corporation Microsoft Windows Operating System 6.00.2900.5512 [Explorer's DLLs] C:\WINDOWS\system32\WTSAPI32.dll ### Windows Terminal Server SDK APIs Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\msctfime.ime ### Microsoft Text Frame Work Service IME Microsoft Corporation Microsoft Windo ws Operating System 5.1.2600.5768 [Explorer's DLLs] C:\WINDOWS\system32\Apphelp.dll ### Application Compatibility Client Library Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\ole32.dll ### Microsoft OLE for Windows Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6010 [Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595 b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll ### User Experience Controls Library Microsoft Corporation Microsoft Windows Ope rating System 6.00.2900.6028 [Explorer's DLLs] C:\WINDOWS\system32\SHLWAPI.dll ### Shell Light-weight Utility Library Microsoft Corporation Microsoft Windows O perating System 6.00.2900.5912 [Explorer's DLLs] C:\WINDOWS\system32\SHELL32.dll ### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S ystem 6.00.2900.6072 [Explorer's DLLs] C:\WINDOWS\system32\COMCTL32.dll ### Common Controls Library Microsoft Corporation Microsoft Windows Operating Sy stem 6.00.2900.6028 [Explorer's DLLs] C:\WINDOWS\system32\USP10.dll ### Uniscribe Unicode script processor Microsoft Corporation Microsoft(R) Unis cribe Unicode script processor 1.0626.6002.22384 [Explorer's DLLs] C:\WINDOWS\system32\LPK.DLL ### Language Pack Microsoft Corporation Microsoft Windows Operating System 5.1.2 600.5512 [Explorer's DLLs] C:\WINDOWS\system32\IMM32.DLL ### Windows XP IMM32 API Client DLL Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\WS2HELP.dll ### Windows Socket 2.0 Helper for Windows NT Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\WS2_32.dll ### Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\IMAGEHLP.dll ### Windows NT Image Helper Microsoft Corporation Microsoft Windows Operating Sy stem 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\WINTRUST.dll ### Microsoft Trust Verification APIs Microsoft Corporation Microsoft Windows Op

erating System 5.131.2600.5922 [Explorer's DLLs] C:\WINDOWS\system32\WINSTA.dll ### Winstation Library Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\VERSION.dll ### Version Checking and File Installation Libraries Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.5512 [Explorer's DLLs] C:\WINDOWS\system32\SETUPAPI.dll ### Windows Setup API Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5603 [Explorer's DLLs] C:\WINDOWS\system32\USERENV.dll ### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.55 12 [Explorer's DLLs] C:\WINDOWS\system32\NETAPI32.dll ### Net Win32 API DLL Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5694 [Explorer's DLLs] C:\WINDOWS\system32\GDI32.dll ### GDI Client DLL Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.5732 [Explorer's DLLs] C:\WINDOWS\system32\USER32.dll ### Windows XP USER API Client DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5577 [Explorer's DLLs] C:\WINDOWS\system32\MSASN1.dll ### ASN.1 Runtime APIs Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5875 [Explorer's DLLs] C:\WINDOWS\system32\CRYPT32.dll ### Crypto API32 Microsoft Corporation Microsoft Windows Operating System 5.131. 2600.5779 [Explorer's DLLs] C:\WINDOWS\system32\msvcrt.dll ### Windows NT CRT DLL Microsoft Corporation Microsoft Windows Operating System 7.0.2600.5701 [Explorer's DLLs] C:\WINDOWS\system32\Secur32.dll ### Security Support Provider Interface Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5834 [Explorer's DLLs] C:\WINDOWS\system32\RPCRT4.dll ### Remote Procedure Call Runtime Microsoft Corporation Microsoft Windows Operat ing System 5.1.2600.6022 [Explorer's DLLs] C:\WINDOWS\system32\ADVAPI32.dll ### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati ng System 5.1.2600.5793 [Explorer's DLLs] C:\WINDOWS\system32\kernel32.dll ### Windows NT BASE API Client DLL Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5781 [Explorer's DLLs] C:\WINDOWS\system32\ntdll.dll ### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 5.1.26 00.6055 [Running Services] ALG ### Internal Name: ALG. Status: service is running. Actual File: C:\WINDOWS\Sy stem32\alg.exe * Provides support for 3rd party protocol plug-ins for Internet C onnection Sharing and the Windows Firewall. Application Layer Gateway Service Mi crosoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Running Services] Ati HotKey Poller ### Internal Name: Ati HotKey Poller. Status: service is running. Actual File: C:\WINDOWS\system32\Ati2evxx.exe * ATI External Event Utility EXE Module ATI T echnologies Inc. ATI External Event Utility for Windows 6.14.10.4163 [Running Services] AudioSrv ### Internal Name: AudioSrv. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Manages audio devices for Windows-based pro grams. If this service is stopped, audio devices and effects will not function p roperly. If this service is disabled, any services that explicitly depend on it

will fail to start. Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.5689 [Running Services] Browser ### Internal Name: Browser. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k netsvcs * Maintains an updated list of computers on th e network and supplies this list to computers designated as browsers. If this se rvice is stopped, this list will not be updated or maintained. If this service i s disabled, any services that explicitly depend on it will fail to start. Generi c Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operatin g System 5.1.2600.5689 [Running Services] CryptSvc ### Internal Name: CryptSvc. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k netsvcs * Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Roo t Service, which adds and removes Trusted Root Certification Authority certifica tes from this computer; and Key Service, which helps enroll this computer for ce rtificates. If this service is stopped, these management services will not funct ion properly. If this service is disabled, any services that explicitly depend o n it will fail to start. Generic Host Process for Win32 Services Microsoft Corpo ration Microsoft Windows Operating System 5.1.2600.5689 [Running Services] DcomLaunch ### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\WIN DOWS\system32\svchost -k DcomLaunch * Provides launch functionality for DCOM ser vices. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi ndows Operating System 5.1.2600.5689 [Running Services] Dhcp ### Internal Name: Dhcp. Status: service is running. Actual File: C:\WINDOWS\s ystem32\svchost.exe -k netsvcs * Manages network configuration by registering an d updating IP addresses and DNS names. Generic Host Process for Win32 Services M icrosoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] dmserver ### Internal Name: dmserver. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Detects and monitors new hard disk drives a nd sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configura tion information may become out of date. If this service is disabled, any servic es that explicitly depend on it will fail to start. Generic Host Process for Win 32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] Dnscache ### Internal Name: Dnscache. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k NetworkService * Resolves and caches Domain Name Syst em (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers . If this service is disabled, any services that explicitly depend on it will fa il to start. Generic Host Process for Win32 Services Microsoft Corporation Micro soft Windows Operating System 5.1.2600.5689 [Running Services] DUMeterSvc ### Internal Name: DUMeterSvc. Status: service is running. Actual File: C:\Pro gram Files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterServic e * DU Meter Service collects network traffic statistics DU Meter Service Hagel Technologies Ltd. DU Meter 4.16 Build R3102 [Running Services] Eventlog ### Internal Name: Eventlog. Status: service is running. Actual File: C:\WINDO WS\system32\services.exe * Enables event log messages issued by Windows-based pr ograms and components to be viewed in Event Viewer. This service cannot be stopp ed. Services and Controller app Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5922 [Running Services] EventSystem ### Internal Name: EventSystem. Status: service is running. Actual File: C:\WI

NDOWS\system32\svchost.exe -k netsvcs * Supports System Event Notification Servi ce (SENS), which provides automatic distribution of events to subscribing Compon ent Object Model (COM) components. If the service is stopped, SENS will close an d will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] FastUserSwitchingCompatibility ### Internal Name: FastUserSwitchingCompatibility. Status: service is running. Actual File: C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides management f or applications that require assistance in a multiple user environment. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] JavaQuickStarterService ### Internal Name: JavaQuickStarterService. Status: service is running. Actual File: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Fil es\Java\jre6\lib\deploy\jqs\jqs.conf" * Prefetches JRE files for faster startup of Java applets and applications Java(TM) Quick Starter Service Sun Microsystems , Inc. Java(TM) Platform SE 6 U25 6.0.250.6 [Running Services] LanmanServer ### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W INDOWS\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh aring over the network for this computer. If this service is stopped, these func tions will be unavailable. If this service is disabled, any services that explic itly depend on it will fail to start. Generic Host Process for Win32 Services Mi crosoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] lanmanworkstation ### Internal Name: lanmanworkstation. Status: service is running. Actual File: C:\WINDOWS\system32\svchost.exe -k netsvcs * Creates and maintains client netwo rk connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly d epend on it will fail to start. Generic Host Process for Win32 Services Microsof t Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] LmHosts ### Internal Name: LmHosts. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k LocalService * Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Generic Host Process for Win32 Ser vices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] Netman ### Internal Name: Netman. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Manages objects in the Network and Dial-Up Co nnections folder, in which you can view both local area network and remote conne ctions. Generic Host Process for Win32 Services Microsoft Corporation Microsoft W indows Operating System 5.1.2600.5689 [Running Services] Nla ### Internal Name: Nla. Status: service is running. Actual File: C:\WINDOWS\sy stem32\svchost.exe -k netsvcs * Collects and stores network configuration and lo cation information, and notifies applications when this information changes. Gen eric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Opera ting System 5.1.2600.5689 [Running Services] PlugPlay ### Internal Name: PlugPlay. Status: service is running. Actual File: C:\WINDO WS\system32\services.exe * Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will r esult in system instability. Services and Controller app Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.5922 [Running Services] PolicyAgent ### Internal Name: PolicyAgent. Status: service is running. Actual File: C:\WI NDOWS\system32\lsass.exe * Manages IP security policy and starts the ISAKMP/Oakl ey (IKE) and the IP security driver. LSA Shell (Export Version) Microsoft Corpor

ation Microsoft Windows Operating System 5.1.2600.5512 [Running Services] ProtectedStorage ### Internal Name: ProtectedStorage. Status: service is running. Actual File: C:\WINDOWS\system32\lsass.exe * Provides protected storage for sensitive data, s uch as private keys, to prevent access by unauthorized services, processes, or u sers. LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512 [Running Services] RasMan ### Internal Name: RasMan. Status: service is running. Actual File: C:\WINDOWS \system32\svchost.exe -k netsvcs * Creates a network connection. Generic Host Pr ocess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] RemoteRegistry ### Internal Name: RemoteRegistry. Status: service is running. Actual File: C: \WINDOWS\system32\svchost.exe -k LocalService * Enables remote users to modify r egistry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any ser vices that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5 689 [Running Services] RpcSs ### Internal Name: RpcSs. Status: service is running. Actual File: C:\WINDOWS\ system32\svchost -k rpcss * Provides the endpoint mapper and other miscellaneous RPC services. Generic Host Process for Win32 Services Microsoft Corporation Mic rosoft Windows Operating System 5.1.2600.5689 [Running Services] SamSs ### Internal Name: SamSs. Status: service is running. Actual File: C:\WINDOWS\ system32\lsass.exe * Stores security information for local user accounts. LSA Sh ell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1. 2600.5512 [Running Services] Schedule ### Internal Name: Schedule. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Enables a user to configure and schedule au tomated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Serv ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] seclogon ### Internal Name: seclogon. Status: service is running. Actual File: C:\WINDO WS\System32\svchost.exe -k netsvcs * Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unava ilable. If this service is disabled, any services that explicitly depend on it w ill fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] SENS ### Internal Name: SENS. Status: service is running. Actual File: C:\WINDOWS\s ystem32\svchost.exe -k netsvcs * Tracks system events such as Windows logon, net work, and power events. Notifies COM+ Event System subscribers of these events. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O perating System 5.1.2600.5689 [Running Services] SharedAccess ### Internal Name: SharedAccess. Status: service is running. Actual File: C:\W INDOWS\system32\svchost.exe -k netsvcs * Provides network address translation, a ddressing, name resolution and/or intrusion prevention services for a home or sm all office network. Generic Host Process for Win32 Services Microsoft Corporatio n Microsoft Windows Operating System 5.1.2600.5689 [Running Services] ShellHWDetection ### Internal Name: ShellHWDetection. Status: service is running. Actual File: C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay hardware events. Generic Host Process for Win32 Services Microsoft Corporation

Microsoft Windows Operating System 5.1.2600.5689 [Running Services] Spooler ### Internal Name: Spooler. Status: service is running. Actual File: C:\WINDOW S\system32\spoolsv.exe * Loads files to memory for later printing. Spooler SubSy stem App Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6024 [Running Services] srservice ### Internal Name: srservice. Status: service is running. Actual File: C:\WIND OWS\system32\svchost.exe -k netsvcs * Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Pr operties Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] SSDPSRV ### Internal Name: SSDPSRV. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k LocalService * Enables discovery of UPnP devices on yo ur home network. Generic Host Process for Win32 Services Microsoft Corporation M icrosoft Windows Operating System 5.1.2600.5689 [Running Services] STacSV ### Internal Name: STacSV. Status: service is running. Actual File: c:\program files\idt\intelxpv_v103\wdm\STacSV.exe * Manages audio jack configurations. IDT PC Audio IDT, Inc. IDT PC Audio 1.0.20001.0 [Running Services] TapiSrv ### Internal Name: TapiSrv. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Provides Telephony API (TAPI) support for pr ograms that control telephony devices and IP based voice connections on the loca l computer and, through the LAN, on servers that are also running the service. G eneric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Ope rating System 5.1.2600.5689 [Running Services] TermService ### Internal Name: TermService. Status: service is running. Actual File: C:\WI NDOWS\System32\svchost -k DComLaunch * Allows multiple users to be connected int eractively to a machine as well as the display of desktops and applications to r emote computers. The underpinning of Remote Desktop (including RD for Administra tors), Fast User Switching, Remote Assistance, and Terminal Server. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Syst em 5.1.2600.5689 [Running Services] Themes ### Internal Name: Themes. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Provides user experience theme management. Ge neric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Oper ating System 5.1.2600.5689 [Running Services] TrkWks ### Internal Name: TrkWks. Status: service is running. Actual File: C:\WINDOWS \system32\svchost.exe -k netsvcs * Maintains links between NTFS files within a c omputer or across computers in a network domain. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] W32Time ### Internal Name: W32Time. Status: service is running. Actual File: C:\WINDOW S\System32\svchost.exe -k netsvcs * Maintains date and time synchronization on a ll clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O perating System 5.1.2600.5689 [Running Services] WebClient ### Internal Name: WebClient. Status: service is running. Actual File: C:\WIND OWS\system32\svchost.exe -k LocalService * Enables Windows-based programs to cre ate, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Generic Host Process for Win32 Servi ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5689

[Running Services] winmgmt ### Internal Name: winmgmt. Status: service is running. Actual File: C:\WINDOW S\system32\svchost.exe -k netsvcs * Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not f unction properly. If this service is disabled, any services that explicitly depe nd on it will fail to start. Generic Host Process for Win32 Services Microsoft C orporation Microsoft Windows Operating System 5.1.2600.5689 [Running Services] wuauserv ### Internal Name: wuauserv. Status: service is running. Actual File: C:\WINDO WS\system32\svchost.exe -k netsvcs * Enables the download and installation of Wi ndows updates. If this service is disabled, this computer will not be able to us e the Automatic Updates feature or the Windows Update Web site. Generic Host Pro cess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5 .1.2600.5689 [Running Services] WZCSVC ### Internal Name: WZCSVC. Status: service is running. Actual File: C:\WINDOWS \System32\svchost.exe -k netsvcs * Provides automatic configuration for the 802. 11 adapters Generic Host Process for Win32 Services Microsoft Corporation Micros oft Windows Operating System 5.1.2600.5689 [MD5] [478C5A707844DAED39B10A39F36B94C7][1 1046072 6FBF9A699E3691BCFA4DEC5544D EB77CAB9C0BE7 ]C:\DOCUMENTS AND SETTINGS\RATO OTM\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\APPLICATION\CHROME.EXE [3456913D093B50955802A1DB13CECE71][2 318464 7FA5E228E085D0D96BCFB1405CC 9DF6D313EA4DE ]C:\PROGRA~1\AIMP3\MODULES\AIMP_MENU32.DLL [2424231BBD703A677D115C29983B4293][1 43392 6C65C280141E868EED012624A22 20CB90F5EE99A ]C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL [FAA2C245179D345FD0CDB9127B926BE2][1 39464 F9A369D47BDC79BEB20ED5BA002 7C3F307CF786E ]C:\PROGRA~1\MICROS~2\OFFICE12\REFIEBAR.DLL [8A6683AC1DAFA824615BB3857EF8C709][1 35736 ]C:\PROGRAM FILES\ADOBE\READER 10.0\READER\READER_SL.EXE [0FC4CA031C46CE1BBDD8A7E91ED2251B][2 49152 ]C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CCC.EXE [033FF248550305ED52ED2D2844A8A11B][2 90112 ]C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CLISTART .EXE [36B9FC05B2091A5782D4A0189FE1735C][2 49152 ]C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\MOM.EXE [C7FD3845BB18BC594E274DF87A9F19C9][1 1384256 02E927505395FE33C0A7D4BAA7B F5B58923685E8 ]C:\PROGRAM FILES\AVANT BROWSER\AVANT.EXE [F31208835709A62ECC5D45211D89C772][1 62376 ]C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELP ERSHIM.DLL [BAD6BEA0DE1F69C82BDB74378CE0C20A][1 932288 ]C:\PROGRAM FILES\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE [13B19DD5EBEB6FDDBD11DD77490A3585][1 253672 ]C:\PROGRAM FILES\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE [FF8E3E68F2FCC5F515EC1F3D0A546903][1 434080 47B4AFD117B0025A997986CCF24 72553AE16A6AE ]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\DW\DWTRIG20.EXE [9E7370CC3D6A43942433F85D0E2BBDD8][1 873216 ]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\HELP\HXDS.DLL [785F487A64950F3CB8E9F16253BA3B7B][1 440696 7DC30282F022278E28F524FEC67 50C05DB4CFABB ]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE12\ODSERV .EXE [5A432A042DAE460ABE7199B758E8606C][1 145184 ]C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SOURCE ENGINE\O SE.EXE [EA55087E90871D29911399EB02DE8807][1 2749984 ]C:\PROGRAM FILES\DU METER\DUMETER.EXE

[8D0FD6A587B1C9B6C3BB41D00213DB6E][1 1391136 ]C:\PROGRAM FILES\DU METER\DUMETERSVC.EXE [F8CC2031A59308D2A6A7E805B97835C7][2 307200 ]C:\PROGRAM FILES\HONESTECH\HONESTECH TVR\SCHEDULETV.EXE [A8631A5C888203D9EBEF43A474D7613F][1 20216 2C301ECEF06705A7A6B4373EE0C BB80CA10F4654 ]C:\PROGRAM FILES\HWINFO32\HWINFO32.SYS [C5003D42CC88C1F5D54ED9AF28D6ED7B][1 254036 ]C:\PROGRAM FILES\IDT\INTELXPV_V103\WDM\STACSV.EXE [F956060FB03F581A7A66AB4EF87CD412][1 483422 ]C:\PROGRAM FILES\IDT\WDM\STTRAY.EXE [B60DDDD2D63CE41CB8C487FCFBB6419E][1 638816 ]C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE [EC48890B04D283371DC2CADAC40AD5B5][1 41760 ]C:\PROGRAM FILES\JAVA\JRE6\BIN\JP2SSV.DLL [11C3EFB4BAC41175D03B1595DB1A4A4F][1 153376 ]C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE [0DB5B013E0ABCB6502F4CC9516872D29][1 79648 ]C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\IE\JQS_PLUGIN.DLL [123271BD5237AB991DC5C21FDF8835EB][1 64856 ]C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVEAUDITSERVICE. EXE [0E34B7BB1FCF22BCC1E394D16F9E992B][1 30040 877DB8C126B94EEC57062BDB541 9A1A99D4D916B ]C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVEMONITOR.EXE [30DB64D316F502558DB2380F7343C9FD][1 2217832 5D3FE20C290B30B4BAC3F738101 D3493EFA7D5F6 ]C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESHELLEXTENSIO NS.DLL [D8C2B95BC2353E1F18850D6B8F5DBA13][1 178040 84DC7BFD5D62D3AB13B9A2A6D48 07AC4D1619247 ]C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVESYSTEMSERVICE S.DLL [7BA449C5554E143ABF62C8CA5767C6CE][2 528384 6BCB631B506AC4F45317634265E AF54801C86969 ]C:\PROGRAM FILES\MOBILE PARTNER\MOBILE PARTNER.EXE [8A3314F8E2D828C689A1AFABAADF1453][1 134104 74D04B2043BEF4383AA4AEB5DA6 C916E0626B145 ]C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS\BROWSERCOMPS.DLL [4E5585800B561FBEF64B27425365A36F][1 924632 ]C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE [99C904854E154E903C8EAC4329DD48C2][1 947056 83F9893A7259BBFF0EEF0CC0AA5 01E5BBEA7CD4A ]C:\PROGRAM FILES\OPERA\OPERA.EXE [5168F2598B005AAA07563C23E0E58F06][2 1367040 CD12DA4B0F285170178A5A26C81 822109B98E745 ]C:\PROGRAM FILES\ORCA BROWSER\ORCA.EXE [0AEE5668EB59912F32FF245BFA72465F][2 421888 ]C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE [771C906AA119777D3FE7377F9A6A19DC][2 305664 ]C:\PROGRAM FILES\TERACOPY\TERACOPYEXT.DLL [BCC83F64C6178FE42C25F3B79ADAA543][1 594192 65EADC16473B057A0C66821D61F F55CCCCB1473E ]C:\PROGRAM FILES\UNHACKME\HACKMON.EXE [36D3D85C0341532772A8701F6E63C575][1 8533816 A920F1B3FF76B039A97695D13B2 9192D00CB3D6E ]C:\PROGRAM FILES\UNHACKME\REANIMATOR.EXE [6BAB4DC65515A098505F8B3D01FB6FE5][1 913408 ]C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNETWK.EXE [B88407A3562B200AD2D3AA4F8D8ED41A][1 218112 ]C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.EXE [323E124D88B48D60B92DFD0962A91398][2 128512 ]C:\PROGRAM FILES\WINRAR\RAREXT.DLL [5D2C6C4E7451097923B70B1AE05DAF8C][2 401408 09537083277059354613FF3B0C7 A1B7F6A8C6AA9 ]C:\WINDOWS\713XRMT.EXE [957F1267283AFE3B8E3FC0A738AE1F8A][2 352256 ]C:\WINDOWS\713XRMTMON.EXE [2BB75B7F548D82A099125D0C5971DE7D][1 1033728 ]C:\WINDOWS\EXPLORER.EXE [F07D034C791327B956906CCE087A0E27][1 317440

]C:\WINDOWS\INF\UNREGMP2.EXE [D87ACAED61E417BBA546CED5E7E36D9C][1 69632 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE [E7CC3AEAED9893A88876744CD439F76C][2 864256 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.0\WINDOWS COMMUNICATION FOUNDATION\INFOCARD.EXE [993883524AA9CF1C90E1545411A9AC9C][1 36864 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.0\WPF\PRESENTATIONFONTCA CHE.EXE [776ACEFA0CA9DF0FAA51A5FB2F435705][1 35160 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\ASPNET_STATE.EXE [C5A75EB48E2344ABDC162BDA79E16841][1 130384 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE [D22CD77D4F0D63D1169BB35911BFF12D][1 124240 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\SMSVCHOST.EXE [DCF3E3EDF5109EE8BC02FE6E1F045795][1 753504 ]C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\WPF\WPFFONTCACHE _V0400.EXE [AAC1D4EE39DF138C5D30AC5883E3B59F][6 558080 ]C:\WINDOWS\NETWORK DIAGNOSTIC\XPNETDIAG.EXE [DA1BF58EE904C814E748C9FC90B37DA2][1 617472 ]C:\WINDOWS\SYSTEM32\ADVAPI32.DLL [8C515081584A38AA007909CD02020B3D][6 44544 ]C:\WINDOWS\SYSTEM32\ALG.EXE [A9A3DAA780CA6C9671A19D52456705B4][6 17408 ]C:\WINDOWS\SYSTEM32\ALRSVC.DLL [D8849F77C0B66226335A59D26CB4EDC6][6 167936 ]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL [39B41D50B26A520CA3D88C07628F71A4][1 356352 ]C:\WINDOWS\SYSTEM32\ATI2CQAG.DLL [FD5367B7F9B60FF166A0A2E19E06EE08][1 267776 ]C:\WINDOWS\SYSTEM32\ATI2DVAG.DLL [26C062626374F148CA26C8FB5D83AC4E][1 114688 ]C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL [F33F4B8A00B42AB5CB16ED503063FA35][1 450560 ]C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE [A56E7A416DEDC95F9FD626BB75E7535B][2 520192 ]C:\WINDOWS\SYSTEM32\ATI2SGAG.EXE [AB21E102466C742C993E62F3ECE92E7A][1 2820544 ]C:\WINDOWS\SYSTEM32\ATI3DUAG.DLL [4CFEED9ED9B40ACCF44D988B3165ED7E][1 258048 ]C:\WINDOWS\SYSTEM32\ATIKVMAG.DLL [49F64A964CEA3675CAE30EA4E74EB6E0][1 1315712 ]C:\WINDOWS\SYSTEM32\ATIVVAXX.DLL [801A664AE0C1ADC3ADEC0C4829E3D0B3][1 290432 ]C:\WINDOWS\SYSTEM32\ATMFD.DLL [DEF7A7882BEC100FE0B2CE2549188F9D][6 42496 ]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL [CC306BF581446D5E443EAE5B3BB900F0][6 12288 ]C:\WINDOWS\SYSTEM32\BOOTVID.DLL [7E39A3EDC13B076E70FDB9A6F6D7A4B4][1 78336 ]C:\WINDOWS\SYSTEM32\BROWSER.DLL [E392E172687BE172F8600C5F41AB03D9][1 1025024 ]C:\WINDOWS\SYSTEM32\BROWSEUI.DLL [34CBE729F38138217F9C80212A2A0C82][1 33280 ]C:\WINDOWS\SYSTEM32\CLIPSRV.EXE [1280A158C722FA95A80FB7AEBE78FA7D][1 792064 ]C:\WINDOWS\SYSTEM32\COMRES.DLL [08DDB6061D93E5293CF349230B5021A6][1 599552 ]C:\WINDOWS\SYSTEM32\CRYPT32.DLL

[C14350FC0D47D806699C4F907FC6785B][6 64512 ]C:\WINDOWS\SYSTEM32\CRYPTNET.DLL [3D4E199942E29207970E04315D02AD3B][6 62464 ]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL [E69BDCDA821E8BE9DE1BA1EF72F8C94D][1 102400 ]C:\WINDOWS\SYSTEM32\CSCDLL.DLL [085ED2E391A871C7BAE87E0228B546BA][1 326656 ]C:\WINDOWS\SYSTEM32\CSCUI.DLL [5F1D5F88303D4A4DBC8E5F97BA967CC3][1 15360 ]C:\WINDOWS\SYSTEM32\CTFMON.EXE [F099B129022170F2DF9E1C0185C9BCFB][6 1179648 ]C:\WINDOWS\SYSTEM32\D3D8.DLL [31B067C412FA1A9BAD3CA2A63D7DA440][6 8192 ]C:\WINDOWS\SYSTEM32\D3D8THK.DLL [A340CD71EB535A3DD751B5F28723E50C][6 279552 ]C:\WINDOWS\SYSTEM32\DDRAW.DLL [C51DE19619D50CBD03708647ACA10E70][1 126976 ]C:\WINDOWS\SYSTEM32\DHCPCSVC.DLL [E2092F0A1D7ABC243F9C2362483D150D][6 19456 ]C:\WINDOWS\SYSTEM32\DIMSNTFY.DLL [0A9BA6AF531AFE7FA5E4FB973852D863][6 5120 ]C:\WINDOWS\SYSTEM32\DLLHOST.EXE [E46050330BD42F33609117F861E32D3C][6 224768 ]C:\WINDOWS\SYSTEM32\DMADMIN.EXE [57EDEC2E5F59F0335E92F35184BC8631][6 23552 ]C:\WINDOWS\SYSTEM32\DMSERVER.DLL [FE120AC2244572B2FA4023B7270E956E][1 45568 ]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL [B4109C8C3D54C83246997A777724F318][1 132096 ]C:\WINDOWS\SYSTEM32\DOT3SVC.DLL [E6C6F61E9BEC02B3AAE09C988BC5D8D1][1 53504 ]C:\WINDOWS\SYSTEM32\DRIVERS\1394BUS.SYS [8FD99680A539792A30E97944FDAECF17][6 187776 ]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS [9859C0F6936E723E4892D7141B1327D5][6 11648 ]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEC.SYS [8BED39E3C35D6A489438B8141717A557][6 142592 ]C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS [F6B7B1ECD7B41736BDB6FF4B092BCB79][1 138496 81957DE0E7C06511FA0E3AB4747 3EE60211D318D ]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS [D7701D7E72243286CC88C9973D891057][6 37376 ]C:\WINDOWS\SYSTEM32\DRIVERS\amdk6.sys [8FCE268CDBDD83B23419D1F35F42C7B1][6 37760 ]C:\WINDOWS\SYSTEM32\DRIVERS\amdk7.sys [B5B8A80875C1DEDEDA8B02765642C32F][6 60800 ]C:\WINDOWS\SYSTEM32\DRIVERS\ARP1394.SYS [B153AFFAC761E7F5FCFA822B9C4E97BC][6 14336 ]C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS [9F3A2F5AA6875C72BF062C712CFA2674][6 96512 ]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS [24A95249512198927304A2BC0F8DA115][1 49152 ]C:\WINDOWS\SYSTEM32\DRIVERS\ati2erec.dll [B2580F3DE6A4E84060F8073DF2CA0951][1 1986560 ]C:\WINDOWS\SYSTEM32\DRIVERS\ATI2MTAG.SYS [9916C1225104BA14794209CFA8012159][6 59904 ]C:\WINDOWS\SYSTEM32\DRIVERS\ATMARPC.SYS [39A0A59180F19946374275745B21AEBA][6 31360 ]C:\WINDOWS\SYSTEM32\DRIVERS\atmepvc.sys [AE76348A2605FB197FA8FF1D6F547836][6 55808 ]C:\WINDOWS\SYSTEM32\DRIVERS\atmlane.sys

[E7EF69B38D17BA01F914AE8F66216A38][6 352256 ]C:\WINDOWS\SYSTEM32\DRIVERS\atmuni.sys [D9F724AA26C010A217C97606B160ED68][6 3072 ]C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS [DA1F27D85E0D1525F6621372E7B685E9][6 4224 ]C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS [F934D1B230F84E1D19DD00AC5A7A83ED][6 71552 ]C:\WINDOWS\SYSTEM32\DRIVERS\bridge.sys [51D05D5A8A7D93AB0B1A8D6A38DB3CA4][1 272128 ]C:\WINDOWS\SYSTEM32\DRIVERS\bthport.sys [90A673FC8E12A79AFBED2576F6A7AAF9][6 13952 ]C:\WINDOWS\SYSTEM32\DRIVERS\CBIDF2K.SYS [0BE5AEF125BE881C4F854C554F2B025C][1 17024 ]C:\WINDOWS\SYSTEM32\DRIVERS\CCDECODE.SYS [C1B486A7658353D33A10CC15211A873B][6 18688 ]C:\WINDOWS\SYSTEM32\DRIVERS\CDAUDIO.SYS [C885B02847F5D2FD45A24E219ED93B32][6 63744 ]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS [4B0A100EAF5C49EF3CCA8C641431EACC][1 62976 ]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS [B562592B7F5759C99E179CA467ECFB4C][6 262528 ]C:\WINDOWS\SYSTEM32\DRIVERS\cinemst2.sys [FE47DD8FE6D7768FF94EBEC6C74B2719][6 49536 ]C:\WINDOWS\SYSTEM32\DRIVERS\CLASSPNP.SYS [9624293E55AD405415862B504CA95B73][6 11776 ]C:\WINDOWS\SYSTEM32\DRIVERS\cpqdap01.sys [F50D9BDBB25CCE075E514DC07472A22F][6 36736 ]C:\WINDOWS\SYSTEM32\DRIVERS\crusoe.sys [47B6AAEC570F2C11D8BAD80A064D8ED1][1 36352 ]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS [E65E2353A5D74EA89971CB918EEEB2F6][6 14208 ]C:\WINDOWS\SYSTEM32\DRIVERS\diskdump.sys [D992FE1274BDE0F84AD826ACAE022A41][6 799744 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS [7C824CF7BBDE77D95C08005717A95F6F][6 153344 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS [E9317282A63CA4D188C0DF5E09C6AC5F][6 5888 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS [8A208DFCF89792A484E76C40E5F50B45][6 52864 ]C:\WINDOWS\SYSTEM32\DRIVERS\DMUSIC.SYS [6CB08593487F5701D2D2254E693EAFCE][6 60160 ]C:\WINDOWS\SYSTEM32\DRIVERS\DRMK.SYS [8F5FCFF8E8848AFAC920905FBD9D33C8][6 2944 ]C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS [B327281012B48BD73F587799F9F29BE2][1 9472 ]C:\WINDOWS\SYSTEM32\DRIVERS\DUMPDRV.SYS [FE97D0343ACFDEBDD578FC67CC91FA87][6 10496 ]C:\WINDOWS\SYSTEM32\DRIVERS\DXAPI.SYS [AC7280566A7BB85CB3291F04DDC1198E][6 71168 ]C:\WINDOWS\SYSTEM32\DRIVERS\DXG.SYS [A73F5D6705B1D820C19B18782E176EFD][6 3328 ]C:\WINDOWS\SYSTEM32\DRIVERS\DXGTHK.SYS [6F7CCD3C02B26D530900F06D98171A69][1 230400 ]C:\WINDOWS\SYSTEM32\DRIVERS\E1E5132.SYS [80D1B490B60E74E002DC116EC5D41748][1 6400 ]C:\WINDOWS\SYSTEM32\DRIVERS\enum1394.sys [4183BE439981BBC77EF2C1D66629F124][1 24448 ]C:\WINDOWS\SYSTEM32\DRIVERS\ewdcsc.sys [922065957563D851B5A68B95AADAC6AD][1 100736 ]C:\WINDOWS\SYSTEM32\DRIVERS\ewusbdev.sys

[20330198554B7DDB44403AF21D6AE179][1 102528 ]C:\WINDOWS\SYSTEM32\DRIVERS\EWUSBMDM.SYS [6295A7A4CB6A85A2D9CECB69C67511BB][1 113280 ]C:\WINDOWS\SYSTEM32\DRIVERS\EWUSBNET.SYS [4D893323DAE445E34A4C9038B0551BC9][1 133632 ]C:\WINDOWS\SYSTEM32\DRIVERS\EXFAT.SYS [38D332A6D56AF32635675F132548343E][6 143744 ]C:\WINDOWS\SYSTEM32\DRIVERS\FASTFAT.SYS [92CDD60B6730B9F50F6A1A0C1F8CDC81][6 27392 ]C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS [D45926117EB9FA946A6AF572FBE1CAA3][6 44544 ]C:\WINDOWS\SYSTEM32\DRIVERS\FIPS.SYS [9D27E7B80BFCDF1CDD9B555862D5E7F0][6 20480 ]C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS [B2CF4B0786F8212CB92ED2B50C6DB6B0][6 129792 ]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS [30D42943A54704EF13E2562911DBFCEA][1 9216 ]C:\WINDOWS\SYSTEM32\DRIVERS\FS_REC.SYS [455F778EE14368468560BD7CB8C854D0][6 12160 ]C:\WINDOWS\SYSTEM32\DRIVERS\fsvga.sys [6AC26732762483366C3969C9E4D2259D][6 125056 ]C:\WINDOWS\SYSTEM32\DRIVERS\FTDISK.SYS [573C7D0A32852B48F3058CFD8026F511][6 144384 ]C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS [9C1A84CB7D209CBECB1909DE4875E9D6][1 44416 ]C:\WINDOWS\SYSTEM32\DRIVERS\HECI.SYS [1AF592532532A402ED7C060F6954004F][1 36864 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDCLASS.SYS [96ECCF28FDBF1B2CC12725818A63628D][1 24960 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDPARSE.SYS [CCF82C5EC8A7326C3066DE870C06DAF1][1 10368 ]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS [937031C085718C1C04A9C0864625EC6B][1 265728 ]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS [4A0B06AA8943C1E332520F7440C0AA30][6 52480 ]C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS [C0BAF70FCF73409AC25620FF26C06B48][1 119296 ]C:\WINDOWS\SYSTEM32\DRIVERS\ianswxp.sys [083A052659F5310DD8B6A6CB05EDCF8E][6 42112 ]C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS [8C953733D8F36EB2133F5BB58808B66B][6 36352 ]C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS [3BB22519A194418D5FEC05D800A19AD0][6 36608 ]C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW.SYS [731F22BA402EE4B62748ADAF6363C182][6 32896 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS [B87AB476DCF76E72010632B5550955F5][6 20864 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS [CC748EA12C6EFFDE940EE98098BF96BB][6 152832 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS [23C74D75E36E7158768DD63D92789A91][6 75264 ]C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS [1E59AAED42A5E3A5ED86EC403F9C0776][2 24064 ]C:\WINDOWS\SYSTEM32\DRIVERS\IQVW32.SYS [C93C9FF7B04D772627A3646D89F7BF89][6 11264 ]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS [05A299EC56E52649B1CF2FC52D20F2D7][6 37248 ]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS [463C1EC80CD17420A542B7F36A36F128][6 24576 ]C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS

[692BCF44383D056AED41B045A323D378][6 172416 ]C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS [0753515F78DF7F271A5E61C20BCD36A1][6 141056 ]C:\WINDOWS\SYSTEM32\DRIVERS\KS.SYS [C6EBF1D6AD71DF30DB49B8D3287E1368][1 92928 ]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS [D1F8BE91ED4DDB671D42E473E3FE71AB][6 7680 ]C:\WINDOWS\SYSTEM32\DRIVERS\mcd.sys [A7DA20AB18A1BDAE28B0F349E57DA0D1][6 63744 ]C:\WINDOWS\SYSTEM32\DRIVERS\mf.sys [4AE068242760A1FB6E1A44BF4E16AFA6][6 4224 ]C:\WINDOWS\SYSTEM32\DRIVERS\MNMDD.SYS [DFCBAD3CEC1C5F964962AE10E0BCC8E1][6 30080 ]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS [35C9E97194C8CFB8430125F8DBC34D04][6 23040 ]C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS [B1C303E17FB9D46E87A98E4BA6769685][1 12160 ]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS [1A1FAA5102466F418494E94FF9B0B091][1 42752 ]C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS [08C0E61E6B34444F17AC6B5A9658C212][1 92544 ]C:\WINDOWS\SYSTEM32\DRIVERS\mqac.sys [4FEFD389D71126EE581B9F9CB2918BE4][6 180096 ]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS [FB2FCCC70F7174C7BF64F48E96D3ADF4][1 457856 ]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS [C941EA2454BA8350021D774DAF0F1027][6 19072 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSFS.SYS [0A02C63C8B144BD8C86B103DEE7C86A2][6 35072 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS [D1575E71568F4D9E14CA56B7B0453BF1][6 7552 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS [325BB26842FC7CCC1FCCE2C457317F3E][6 5376 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS [BAD59648BA099DA4A17680B39730CB3D][6 4992 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS [AF5F4F3F14A8EA2C26DE30F7A1E17136][6 15488 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS [E53736A9E30C45FA9E7B5EAC55056D1D][1 5504 ]C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS [F7B1AD991491F02AF6DA70B00B8BF114][1 105472 ]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS [B361C529A8E39F447E81CDB5C35DB4F4][1 156200 ]C:\WINDOWS\SYSTEM32\DRIVERS\MV61XX.SYS [354A04BF1603CB4B07346C470EA52E73][2 5632 ]C:\WINDOWS\SYSTEM32\DRIVERS\MV61XXMM.SYS [6090786DAA545A3EC7D34A46A8CD1661][2 5632 ]C:\WINDOWS\SYSTEM32\DRIVERS\MV64XXMM.SYS [B937B5F8CC5644F9BF9373E16A9AA0B4][2 5632 ]C:\WINDOWS\SYSTEM32\DRIVERS\MVXXMM.SYS [5B50F1B2A2ED47D560577B221DA734DB][1 85248 ]C:\WINDOWS\SYSTEM32\DRIVERS\NABTSFEC.SYS [B5B1080D35974C0E718D64280761BCD5][1 182912 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS [7FF1F1FD8609C149AA432F95A8163D97][1 10880 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDISIP.SYS [0109C4F3850DFBAB279542515386AE22][1 10496 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS [F927A4434C5028758A842943EF1A3849][6 14592 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS

[B053A8411045FD0664B389A090CB2BBC][1 91776 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS [816460BD4B4ACD27937D1D0813E2E9E9][1 40960 ]C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS [5D81CF9A2F1A3A756B66CF684911CDF0][6 34688 ]C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS [74B2B2F5BEA5E9A3DC021D685551BD3D][6 162816 ]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS [E9E47CFB2D461FA0FC75B7A74C6383EA][6 61824 ]C:\WINDOWS\SYSTEM32\DRIVERS\NIC1394.SYS [BE984D604D91C217355CDD3737AAD25D][6 12032 ]C:\WINDOWS\SYSTEM32\DRIVERS\nikedrv.sys [1E421A6BCF2203CC61B821ADA9DE878B][6 40320 ]C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys [3182D64AE053D6FB034F44B6DEF8034A][6 30848 ]C:\WINDOWS\SYSTEM32\DRIVERS\NPFS.SYS [AE8CAD8F28DB13B515A68510A539B0B8][1 576512 ]C:\WINDOWS\SYSTEM32\DRIVERS\NTFS.SYS [73C1E1F395918BC2C6DD67AF7591A3AD][6 2944 ]C:\WINDOWS\SYSTEM32\DRIVERS\NULL.SYS [B305F3FAD35083837EF46A0BBCE2FC57][6 12416 ]C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFLT.SYS [C99B3415198D1AAB7227F2C88FD664B9][6 32512 ]C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFWD.SYS [8B8B1BE2DBA4025DA6786C645F77F123][6 88320 ]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys [56D34A67C05E94E16377C60609741FF8][6 63232 ]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnknb.sys [C0BB7D1615E1ACBDC99757F6CEAF8CF0][6 55936 ]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkspx.sys [36B9B950E3D2E100970A48D8BAD86740][6 163584 ]C:\WINDOWS\SYSTEM32\DRIVERS\nwrdr.sys [2553F7C60B8D291B5A812245E6D4DA6E][1 61824 ]C:\WINDOWS\SYSTEM32\DRIVERS\OHCI1394.SYS [4BB30DDC53EBC76895E38694580CDFE9][6 3456 ]C:\WINDOWS\SYSTEM32\DRIVERS\oprghdlr.sys [C90018BAFDC7098619A4A95B046B30F3][6 42752 ]C:\WINDOWS\SYSTEM32\DRIVERS\p3.sys [5575FAF8F97CE5E713D108C2A58D7C7C][6 80128 ]C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS [6DDCF3F801EC15FE698F6A215CF30A1F][1 35816 ]C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS [BEB3BA25197665D82EC7065B724171C6][6 19712 ]C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS [70E98B3FD8E963A6A46A2E6247E0BEA1][6 6784 ]C:\WINDOWS\SYSTEM32\DRIVERS\PARVDM.SYS [A219903CCF74233761D92BEF471A07B1][6 68224 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS [CCF5F451BB1A5A2A522A76E670000FF0][1 3328 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS [52E60F29221D0D1AC16737E8DBF7C3E9][6 24960 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDEX.SYS [9E89EF60E9EE05E3F2EEF2DA7397F1C1][6 120192 ]C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS [AEF54BF915BF5C2ED1B856EF94E89721][1 146048 ]C:\WINDOWS\SYSTEM32\DRIVERS\PORTCLS.SYS [A32BEBAF723557681BFC6BD93E98BD26][6 35840 ]C:\WINDOWS\SYSTEM32\DRIVERS\processr.sys [D8E11D311785F89F1D70A28B0E879127][1 70272 ]C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS

[80D317BD1C3DBC5D4FE7B1678C60CADD][6 17792 ]C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS [FE0D99D6F31E4FAD8159F690D68DED9C][6 8832 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS [11B4A627BC9614B885C4969BFA5FF8A6][6 51328 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS [2C9D4620A0FD35DE1828370B392F6E2D][1 41472 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS [EFEEC01B1D3CF84F16DDD24D9D9D8F99][6 48384 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS [FDBB1D60066FCFBB7452FD8F9829B242][6 16512 ]C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS [01524CD237223B18ADBB48F70083F101][6 34432 ]C:\WINDOWS\SYSTEM32\DRIVERS\rawwan.sys [77050C6615F6EB5402F832B27FD695E0][1 174848 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS [4912D5B403614CE99C28420F75353332][6 4224 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS [47EA20320E3D6FDC7B7BB22B2B881CA6][1 195712 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS [3348E61A78BA4F79C795AAD6565D3B6F][1 139656 ]C:\WINDOWS\SYSTEM32\DRIVERS\RDPWD.SYS [F828DD7E1419B6653894A8F97A0094C5][6 57600 ]C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS [A56FE08EC7473E8580A390BB1081CDD7][6 12032 ]C:\WINDOWS\SYSTEM32\DRIVERS\rio8drv.sys [0A854DF84C77A0BE205BFEAB2AE4F0EC][6 12032 ]C:\WINDOWS\SYSTEM32\DRIVERS\riodrv.sys [21F412DBFFFE34D39287E13674DB04F1][1 203776 ]C:\WINDOWS\SYSTEM32\DRIVERS\RMCast.sys [00E0D363C7A087021D773B83D299382F][1 30592 ]C:\WINDOWS\SYSTEM32\DRIVERS\rndismp.sys [D8B0B4ADE32574B2D9C5CC34DC0DBBE7][6 5888 ]C:\WINDOWS\SYSTEM32\DRIVERS\rootmdm.sys [743D7D59767073A617B1DCC6C546F234][1 62848 ]C:\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS [9F08D38B3E255F5BBB97AD3936425FAF][2 289280 46217ED6E1DED493C2B777B3368 3072505A6E0E6 ]C:\WINDOWS\SYSTEM32\DRIVERS\SAA713X.SYS [76C465F570E90C28942D52CCB2580A10][6 96384 ]C:\WINDOWS\SYSTEM32\DRIVERS\SCSIPORT.SYS [D1FACB3C7D12F439C18EF01AA88C2A9D][1 80384 ]C:\WINDOWS\SYSTEM32\DRIVERS\SDBUS.SYS [90A3935D05B494A5A39D37E71F09A677][6 20480 ]C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS [0F29512CCD6BEAD730039FB4BD2C85CE][6 15744 ]C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS [CCA207A8896D4C6A0C9CE29A4AE411A7][6 64512 ]C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS [B8CB06ED5DA508DCB59BBB3FD04F856B][1 13824 ]C:\WINDOWS\SYSTEM32\DRIVERS\sffdisk.sys [D66D22D76878BF3483A6BE30183FB648][6 10240 ]C:\WINDOWS\SYSTEM32\DRIVERS\sffp_mmc.sys [DE56A5909C65C25475C476690C327BA8][1 11520 ]C:\WINDOWS\SYSTEM32\DRIVERS\sffp_sd.sys [8E6B8C671615D126FDC553D1E2DE5562][6 11392 ]C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS [866D538EBE33709A5C9F5C62B73B7D14][1 11136 ]C:\WINDOWS\SYSTEM32\DRIVERS\SLIP.SYS [017DAECF0ED3AA731313433601EC40FA][6 14592 ]C:\WINDOWS\SYSTEM32\DRIVERS\smclib.sys

[489703624DAC94ED943C2ABDA022A1CD][6 25344 ]C:\WINDOWS\SYSTEM32\DRIVERS\sonydcam.sys [AB8B92451ECB048A4D1DE7C3FFCB4A9F][6 6272 ]C:\WINDOWS\SYSTEM32\DRIVERS\SPLITTER.SYS [76BB022C2FB6902FD5BDD4F78FC13A5D][6 73472 ]C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS [9B390283569EA58D43D2586032B892F5][1 357888 ]C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS [228519217A88C2F6B0CF8C022E6D669C][1 1550613 ]C:\WINDOWS\SYSTEM32\DRIVERS\STHDA.SYS [3E5D89099DED9E86E5639F411693218F][6 49408 ]C:\WINDOWS\SYSTEM32\DRIVERS\STREAM.SYS [77813007BA6265C4B6098187E6ED79D2][1 15232 ]C:\WINDOWS\SYSTEM32\DRIVERS\STREAMIP.SYS [3941D127AEF12E93ADDF6FE6EE027E0F][6 4352 ]C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS [8CE882BCC6CF8A62F2B2323D95CB3D01][6 56576 ]C:\WINDOWS\SYSTEM32\DRIVERS\SWMIDI.SYS [8B83F3ED0F1688B4958F77CD6D2BF290][6 60800 ]C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS [FD6093E3DECD925F1CFFC8A0DD539D72][6 14976 ]C:\WINDOWS\SYSTEM32\DRIVERS\tape.sys [51E41F16ACD80B8B39C0AE703A213F09][1 361600 2754CA0874252664FEF48BBB886 6603BEF2A7722 ]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS [F4A3C6ABE7818B1B53F58FA1ADB605CD][1 226880 ]C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys [0539D5E53587F82D1B4FD74C5BE205CF][6 19072 ]C:\WINDOWS\SYSTEM32\DRIVERS\TDI.SYS [6471A66807F5E104E4885F5B67349397][6 12040 ]C:\WINDOWS\SYSTEM32\DRIVERS\TDPIPE.SYS [C0578456F29E5F26285F81B7B71FE57D][1 22024 ]C:\WINDOWS\SYSTEM32\DRIVERS\TDTCP.SYS [88155247177638048422893737429D9E][6 40840 ]C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS [699450901C5CCFD82357CBC531CEDD23][6 51712 ]C:\WINDOWS\SYSTEM32\DRIVERS\tosdvd.sys [D74A8EC75305F1D3CFDE7C7FC1BD62A9][6 21376 ]C:\WINDOWS\SYSTEM32\DRIVERS\tsbvcap.sys [8F861EDA21C05857EB8197300A92501C][6 12288 ]C:\WINDOWS\SYSTEM32\DRIVERS\tunmp.sys [5787B80C2E3C5E2F56C2A233D91FA2C9][6 66048 ]C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS [3E6946D73B8575F85A5837138D0FAC53][1 11040 ]C:\WINDOWS\SYSTEM32\DRIVERS\UNHACKMEDRV.SYS [402DDC88356B1BAC0EE3DD1580C76A31][6 384768 ]C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS [BEE793D4A059CAEA55D6AC20E19B3A8F][6 12800 ]C:\WINDOWS\SYSTEM32\DRIVERS\usb8023.sys [1C1A47B40C23358245AA8D0443B6935E][6 25600 ]C:\WINDOWS\SYSTEM32\DRIVERS\usbcamd.sys [CE97845D2E3F0D274B8BAC1ED07C6149][6 25728 ]C:\WINDOWS\SYSTEM32\DRIVERS\usbcamd2.sys [C18D6C74953621346DF6B0A11F80C1CC][1 32384 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS [64CA8ED4B0980AAE46BEB3727046E860][1 29184 ]C:\WINDOWS\SYSTEM32\DRIVERS\usbccid.sys [596EB39B50D6EBD9B734DC4AE0544693][1 4736 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBD.SYS [52674B5DBEE499342A599C7771ABECAA][1 30464 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS

[1AB3CDDE553B6E064D2E754EFE20285C][1 59520 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS [290913DC4F1125E5A82DE52579A44C43][6 15872 ]C:\WINDOWS\SYSTEM32\DRIVERS\usbintel.sys [4C6263D3996BFF1B0A29703D70403EC6][1 144000 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBPORT.SYS [A32426D9B14A089EAA1D922E0C5801A9][1 26368 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS [26496F9DEE2D787FC3E61AD54821FFE6][1 20608 ]C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS [55E01061C74A8CEFFF58DC36114A8D3F][6 58112 ]C:\WINDOWS\SYSTEM32\DRIVERS\vdmindvd.sys [0D3A8FAFCEACD8B7625CD549757A7DF1][6 20992 ]C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS [1AAE066851FD2916E36678ECCF75B704][1 81792 ]C:\WINDOWS\SYSTEM32\DRIVERS\VIDEOPRT.SYS [4C8FCB5CC53AAB716D810740FE59D025][6 52352 ]C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS [E20B95BAEDB550F32DD489265C1DA1F6][6 34560 ]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS [6768ACF64B18196494413695F0C3A00F][6 83072 ]C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS [C422F2EBED42889E3E918B72645EDCEA][2 26880 7FBBFCFB45F617ABBF6DE1934A0 993DC669CBF5A ]C:\WINDOWS\SYSTEM32\DRIVERS\WDMTUNER.SYS [2F31B7F954BED437F2C75026C65CAF7B][6 4352 ]C:\WINDOWS\SYSTEM32\DRIVERS\WMILIB.SYS [C60DC16D4E406810FAD54B98DC92D5EC][1 38528 ]C:\WINDOWS\SYSTEM32\DRIVERS\wpdusb.sys [6ABE6E225ADB5A751622A9CC3BC19CE8][6 12032 ]C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS [C98B39829C2BBD34E454150633C62C78][1 19200 ]C:\WINDOWS\SYSTEM32\DRIVERS\WSTCODEC.SYS [F15FEAFFFBB3644CCC80C5DA584E6311][6 77568 ]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFPF.SYS [28B524262BCE6DE1F7EF9F510BA3985B][6 82944 ]C:\WINDOWS\SYSTEM32\DRIVERS\WUDFRD.SYS [4D83ED8BDDEC431FC8AD907B47CFB6E3][6 367616 ]C:\WINDOWS\SYSTEM32\DSOUND.DLL [2187855A7703ADEF0CEF9EE4285182CC][6 33792 ]C:\WINDOWS\SYSTEM32\EAPSVC.DLL [F17F6226BDC0CD5F0BEF0DAF84D29BEC][1 253952 ]C:\WINDOWS\SYSTEM32\ES.DLL [AA6E613D106C8523C7E14AFF11314541][1 286720 ]C:\WINDOWS\SYSTEM32\GDI32.DLL [E33DE9C65B3625BDD00C1313179DA5A5][1 134528 ]C:\WINDOWS\SYSTEM32\HAL.DLL [0A878AA66E4DD3E2608192A1ECCD9F8F][1 344064 ]C:\WINDOWS\SYSTEM32\HNETCFG.DLL [2E1D8E1D957CDDBFA7A628A27BCF8D57][1 80384 ]C:\WINDOWS\SYSTEM32\ICCVID.DLL [C7D32F283994CC77DE43AD34FCBEA60D][1 11084288 8AF976BE9C034AC4CF3B064431C A0D54DF34BC1B ]C:\WINDOWS\SYSTEM32\IEFRAME.DLL [577E496F0D41411BF149394D80959D53][1 16384 ]C:\WINDOWS\SYSTEM32\IMAADP32.ACM [30DEAF54A9755BB8546168CFE8A6B5E1][6 150528 ]C:\WINDOWS\SYSTEM32\IMAPI.EXE [0DA85218E92526972A821587E6A8BF8F][6 110080 ]C:\WINDOWS\SYSTEM32\IMM32.DLL [3B438284E0F22B154E9ECC27FE0EC3AE][1 692736 A51EA513C9F0BC7042A0F93A329 45B746D6B4247 ]C:\WINDOWS\SYSTEM32\INETCOMM.DLL

[4F10A2FA76B5BD54CD68AFA94E8ADB39][1 330752 ]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL [0EC5ECE8762728ED734258B22D348A32][6 138240 ]C:\WINDOWS\SYSTEM32\ITSS.DLL [B2F70D12FE0ABC7C91E73BFB2BA8A768][1 48128 ]C:\WINDOWS\SYSTEM32\IYUV_32.DLL [945FBB881AE927A44DFD96440F2F4F44][6 7040 ]C:\WINDOWS\SYSTEM32\KDCOM.DLL [4260BDCD96976DA6F44E9CA8B2E029E5][1 301568 ]C:\WINDOWS\SYSTEM32\KERBEROS.DLL [DA11D9D6ECBDF0F93436A4B7C13F7BEC][1 991744 ]C:\WINDOWS\SYSTEM32\KERNEL32.DLL [8878BD685E490239777BFE51320B88E9][6 61440 ]C:\WINDOWS\SYSTEM32\KMSVC.DLL [9B9F1C38D559047B8AC0DBA2D5FEBDE9][6 4096 ]C:\WINDOWS\SYSTEM32\KSUSER.DLL [499EDF986588A3A0B55DD5EFAD922C9E][1 307260 ]C:\WINDOWS\SYSTEM32\L3CODECA.ACM [A7DB739AE99A796D91580147E919CC59][6 13824 ]C:\WINDOWS\SYSTEM32\LMHSVC.DLL [54199235EA029E96AACB646DED61CB46][1 346112 ]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL [AAED593F84AFA419BBAE8572AF87CF6A][6 75264 ]C:\WINDOWS\SYSTEM32\LOCATOR.EXE [2081A5B5E4ABA206A0A8A1A97DF0FB23][1 514560 ]C:\WINDOWS\SYSTEM32\LOGONUI.EXE [012DF358CEBAA23ACB26D82077820817][6 22016 ]C:\WINDOWS\SYSTEM32\LPK.DLL [BF2466B3E18E970D8A976FB95FC1CA85][6 13312 ]C:\WINDOWS\SYSTEM32\LSASS.EXE [5C12660A97822F6E61576943B49AAAD6][1 18944 ]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL [D18F1F0C101D06A1C1ADF26EED16FCDD][1 32768 ]C:\WINDOWS\SYSTEM32\MNMSRVC.EXE [AF91E5DB83377132D9F885FD8467D1C8][1 420240 ]C:\WINDOWS\SYSTEM32\MPG4C32.DLL [7E699FF5F59B5D9DE5390E3C34C67CF5][6 53248 ]C:\WINDOWS\SYSTEM32\MPRDIM.DLL [9A3BD5F55AADFF859539142F6328A66E][1 20480 ]C:\WINDOWS\SYSTEM32\MSACM32.DRV [C5648BE5409E0AABDA8C9047BAC8F603][1 14848 ]C:\WINDOWS\SYSTEM32\MSADP32.ACM [36427ED6CEC83DA7023F5C718579D634][1 282654 ]C:\WINDOWS\SYSTEM32\MSAUD32.ACM [08A73B0E7EE6E32983B5F9E540A8E380][1 297808 ]C:\WINDOWS\SYSTEM32\MSCOREE.DLL [A137F1470499A205ABBB9AAFB3B6F2B1][1 6144 ]C:\WINDOWS\SYSTEM32\MSDTC.EXE [33271A2667334B9A8842C65A079EF375][1 9216 ]C:\WINDOWS\SYSTEM32\MSG711.ACM [B87F759738C52E8D6FBCDAAA84C6486F][1 118784 ]C:\WINDOWS\SYSTEM32\MSG723.ACM [3A9846E207DAFC13009C048A2F6F8C2A][1 19968 ]C:\WINDOWS\SYSTEM32\MSGSM32.ACM [986B1FF5814366D71E0AC5755C88F2D3][6 33792 ]C:\WINDOWS\SYSTEM32\MSGSVC.DLL [C6FD300A6100AC89BC4CB944C19FA2A9][1 188416 ]C:\WINDOWS\SYSTEM32\MSH261.DRV [7D529AA41EA993357F8C3D7E92C2372A][1 294912 ]C:\WINDOWS\SYSTEM32\MSH263.DRV

[1240A6B7B470BED0AA6C9FEC7AB0EA26][1 5972992 466C35E24D9D3400A6B4F4F0C53 E3E8CC6A8A811 ]C:\WINDOWS\SYSTEM32\MSHTML.DLL [7F7BC88C8FB6B52989E0E93084B5E678][1 95744 ]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE [C52CE534397E1D3A442FB4C88A3CBE42][1 31640 E793C202ED02B63BD63E929611D 20E84FD0E4BC1 ]C:\WINDOWS\SYSTEM32\MSONPMON.DLL [051B1BDECD6DEE18C771B5D5EC7F044D][1 27136 ]C:\WINDOWS\SYSTEM32\MSPMSNSV.DLL [61FC8479F93B42F4DA540DF1B8DA99D7][1 11264 ]C:\WINDOWS\SYSTEM32\MSRLE32.DLL [1C59CE39DF670CA45E3962BDA56D22CD][1 136704 ]C:\WINDOWS\SYSTEM32\MSV1_0.DLL [06B8485FB1DA9A552B10AB978CD1AC85][1 343040 ]C:\WINDOWS\SYSTEM32\MSVCRT.DLL [02D267236B49C0771264955C021327D4][1 28672 ]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL [3F0CF84469AD2DC8382312814A223BCE][6 1428992 ]C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL [290C1A30DEFC723BBE10910AC2D6F6D0][1 245248 ]C:\WINDOWS\SYSTEM32\MSWSOCK.DLL [AA4FF1252834649C04C512C4C4789274][1 17920 ]C:\WINDOWS\SYSTEM32\MSYUV.DLL [B857BA82860D7FF85AE29B095645563B][6 111104 ]C:\WINDOWS\SYSTEM32\NETDDE.EXE [13E67B55B3ABD7BF3FE7AAE5A0F9A9DE][6 198144 ]C:\WINDOWS\SYSTEM32\NETMAN.DLL [15CE4DBC22FAB90B3CA5352AF1FFF81C][1 718336 ]C:\WINDOWS\SYSTEM32\NTDLL.DLL [F917F7E5FC9F80D3C36978A9CCEF6BE4][1 2027008 ]C:\WINDOWS\SYSTEM32\NTKRNLPA.EXE [156F64A3345BD23C600655FB4D10BC08][6 435200 ]C:\WINDOWS\SYSTEM32\NTMSSVC.DLL [5652F6CE1D9E9D8068B9D29BC21B5409][6 84992 ]C:\WINDOWS\SYSTEM32\OLEPRO32.DLL [0102140028FAD045756796E1C685D695][6 291328 ]C:\WINDOWS\SYSTEM32\QAGENTRT.DLL [F13D1AA04F1F02399EB87F011584B7C0][1 408576 ]C:\WINDOWS\SYSTEM32\QMGR.DLL [6F9BEF24C578D5D6740E080BEDD6A448][6 7680 ]C:\WINDOWS\SYSTEM32\RASADHLP.DLL [AD188BE7BDF94E8DF4CA0A55C00A5073][6 88576 ]C:\WINDOWS\SYSTEM32\RASAUTO.DLL [76A9A3CBEADD68CC57CDA5E1D7448235][6 186368 ]C:\WINDOWS\SYSTEM32\RASMANS.DLL [5B19B557B0C188210A56A6B699D90B8F][6 59904 ]C:\WINDOWS\SYSTEM32\REGSVC.DLL [9222562D44021B988B9F9F62207FB6F2][1 401408 ]C:\WINDOWS\SYSTEM32\RPCSS.DLL [471B3F9741D762ABE75E9DEEA4787E47][6 132608 ]C:\WINDOWS\SYSTEM32\RSVP.EXE [72451FD61DDBB0A1FB071B7C3CDE5594][6 92672 ]C:\WINDOWS\SYSTEM32\RSVPSP.DLL [037B1E7798960E0420003D05BB577EE6][1 33280 ]C:\WINDOWS\SYSTEM32\RUNDLL32.EXE [86D007E7A654B9A71D1D7D856B104353][6 95744 ]C:\WINDOWS\SYSTEM32\SCARDSVR.EXE [A86BB5E61BF3E39B62AB4C7E7085A084][6 181248 ]C:\WINDOWS\SYSTEM32\SCECLI.DLL [E04B6497B6407D2F444E86B30680DC5A][1 149504 ]C:\WINDOWS\SYSTEM32\SCHANNEL.DLL

[0A9A7365A1CA4319AA7C1D6CD8E4EAFA][6 192512 ]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL [63FF9068E5BDA0BC9ECD38FBBB216E24][6 20480 ]C:\WINDOWS\SYSTEM32\SCLGNTFY.DLL [CBE612E2BB6A10E3563336191EDA1250][6 18944 ]C:\WINDOWS\SYSTEM32\SECLOGON.DLL [7FDD5D0684ECA8C1F68B4D99D124DCD0][6 39424 ]C:\WINDOWS\SYSTEM32\SENS.DLL [C519E15665CD89A91AD383FCE3CB556A][1 110592 ]C:\WINDOWS\SYSTEM32\SERVICES.EXE [3C37BF86641BDA977C3BF8A840F3B7FA][6 141312 ]C:\WINDOWS\SYSTEM32\SESSMGR.EXE [9DD07AF82244867CA36681EA2D29CE79][1 1614848 ]C:\WINDOWS\SYSTEM32\SFCFILES.DLL [26CB10FA893F940AB09713FF46DCDADE][1 1499136 ]C:\WINDOWS\SYSTEM32\SHDOCVW.DLL [1026E80450E2CF36A3D69C0EA319EB95][1 8463360 ]C:\WINDOWS\SYSTEM32\SHELL32.DLL [888CD7B39C37E13A2419BECFAAF0A28C][1 135168 ]C:\WINDOWS\SYSTEM32\SHSVCS.DLL [0DBB250A89E2E1C9281009AC269F0805][1 86016 ]C:\WINDOWS\SYSTEM32\SL_ANET.ACM [C7ABBC59B43274B1109DF6B24D617051][6 89600 ]C:\WINDOWS\SYSTEM32\SMLOGSVC.EXE [5F816C1F539266D2D4C78694239DA0B5][6 50688 ]C:\WINDOWS\SYSTEM32\SMSS.EXE [258DD5D4283FD9F9A7166BE9AE45CE73][6 58880 ]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE [3805DF0AC4296A34BA4BF93B346CC378][6 171008 ]C:\WINDOWS\SYSTEM32\SRSVC.DLL [3695B8D03745B2F8022B161238347A9D][1 99840 ]C:\WINDOWS\SYSTEM32\SRVSVC.DLL [0A5679B3714EDAB99E357057EE88FCA6][6 71680 ]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL [50512FC9B7878E3C2C147BC17326A7DB][1 121856 ]C:\WINDOWS\SYSTEM32\STOBJECT.DLL [67E38B4A549833E02D4D1617B5DBC318][1 14848 ]C:\WINDOWS\SYSTEM32\SVCHOST.EXE [74EA5C974AFADFA5FB0F054E7280777C][1 300544 ]C:\WINDOWS\SYSTEM32\SYSDM.CPL [E2B32B10ACC5D97623275AAFB67E5F03][1 249856 ]C:\WINDOWS\SYSTEM32\TAPISRV.DLL [2CD1C3506A85B38E2D17E61ADED175C4][1 135680 ]C:\WINDOWS\SYSTEM32\TASKMGR.EXE [E31A6FD8A36280D25D7732624E944C7F][1 45568 ]C:\WINDOWS\SYSTEM32\TCPMON.DLL [5128852A18AE46C387F87BF27DA4C9DD][1 296960 ]C:\WINDOWS\SYSTEM32\TERMSRV.DLL [DB7205804759FF62C34E3EFD8A4CC76A][6 73216 ]C:\WINDOWS\SYSTEM32\TLNTSVR.EXE [55BCA12F7F523D35CA3CB833C725F54E][6 90112 ]C:\WINDOWS\SYSTEM32\TRKWKS.DLL [35AF5717ABCCF3E3A2DED99CB7F03292][1 8704 ]C:\WINDOWS\SYSTEM32\TSBYUV.DLL [E8CD0D7E169ECCE2D4FD829DAAB786ED][1 8192 ]C:\WINDOWS\SYSTEM32\TSSOFT32.ACM [1EBAFEB9A3FBDC41B8D9C7F0F687AD91][6 185856 ]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL [05365FB38FCA1E98F7A566AAAF5D1815][6 18432 ]C:\WINDOWS\SYSTEM32\UPS.EXE

[C959E26CF5AB9C0E68ED3A70386BDBD6][1 1214464 3BEF5585DC7D94A16241C7E0314 DCC763D89B5B9 ]C:\WINDOWS\SYSTEM32\URLMON.DLL [F26385E8BA4549B5186B774EC0E45D86][6 16896 ]C:\WINDOWS\SYSTEM32\USBMON.DLL [3DE22354C3609B3C3E5DC2C19C5E0693][1 578560 ]C:\WINDOWS\SYSTEM32\USER32.DLL [A93AEE1928A9D7CE3E16D24EC7380F89][6 26112 ]C:\WINDOWS\SYSTEM32\USERINIT.EXE [88F5BE9AE5B87B82E83718F3E425E82D][6 218624 ]C:\WINDOWS\SYSTEM32\UXTHEME.DLL [E2A57AC21705D3A05BB89BE201FA5C0C][1 53760 ]C:\WINDOWS\SYSTEM32\VFWWDM32.DLL [7A9DB3A67C333BF0BD42E42B8596854B][6 289792 ]C:\WINDOWS\SYSTEM32\VSSVC.EXE [9F8A0D0CBB2FA265A754516128C00E22][1 175616 ]C:\WINDOWS\SYSTEM32\W32TIME.DLL [6100A808600F44D999CEBDEF8841C7A3][6 15872 ]C:\WINDOWS\SYSTEM32\W3SSL.DLL [9A10AACBFDC4922715375FB4065EC930][6 17664 ]C:\WINDOWS\SYSTEM32\WATCHDOG.SYS [E0673F1106E62A68D2257E376079F821][6 126464 ]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE [2D0E4ED081963804CCC196A0929275B5][6 144896 ]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL [BAE413E34804DDD5C763B3BEC1005FCB][1 54272 ]C:\WINDOWS\SYSTEM32\WDIGEST.DLL [680B56A8B62D1BCF4A0B2AAAD03D88E4][1 23552 ]C:\WINDOWS\SYSTEM32\WDMAUD.DRV [CC8915DB4E33E8FB29CA0D2DBF75306E][1 236544 ]C:\WINDOWS\SYSTEM32\WEBCHECK.DLL [77A354E28153AD2D5E120A5A8687BC06][6 68096 ]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL [02CF580510234E519736559A7F19EA20][1 239496 ]C:\WINDOWS\SYSTEM32\WGALOGON.DLL [477BB51076B926E1A68840C267540042][6 75776 ]C:\WINDOWS\SYSTEM32\WIASCR.DLL [8BAD69CBAC032D4BBACFCE0306174C30][6 333824 ]C:\WINDOWS\SYSTEM32\WIASERVC.DLL [C30AAF3B63F3BE3B515B50FB7292EA9F][1 1867904 85DB82818DF49FCCE39EF808C77 7E575D535179F ]C:\WINDOWS\SYSTEM32\WIN32K.SYS [53A8857723277B1D6D5EE60A9F85B117][1 509440 ]C:\WINDOWS\SYSTEM32\WINLOGON.EXE [D72B9EC3337B247A666F098F3D6B43DE][6 16896 ]C:\WINDOWS\SYSTEM32\WINRNR.DLL [3B9324D60DD321BAB7BF6F77931D3FD1][1 134144 ]C:\WINDOWS\SYSTEM32\WKSSVC.DLL [2CC34E8BB667EEF78899546E12649196][6 92672 ]C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL [D7D69F304A604387B86BE991CBF07663][1 133632 ]C:\WINDOWS\SYSTEM32\WPDSHSERVICEOBJ.DLL [9789E95E1D88EEB4B922BF3EA7779C28][6 19968 ]C:\WINDOWS\SYSTEM32\WS2HELP.DLL [FC1E3B06AE8D160B686C5D04B5E85371][1 22520 ]C:\WINDOWS\SYSTEM32\WUAUSERV.DLL [05231C04253C5BC30B26CBAAE680ED89][6 55808 ]C:\WINDOWS\SYSTEM32\WUDFSVC.DLL [349B8D2BB755E8C3B0E3E82A87663E55][1 483328 ]C:\WINDOWS\SYSTEM32\WZCSVC.DLL [295D21F14C335B53CB8154E5B1F892B9][6 129024 ]C:\WINDOWS\SYSTEM32\XMLPROV.DLL

=== [MBR] [MD5=D0D78552330424127A42FB11AC414640] M8CO0LwAfPtQB1Af/L4bfL8bBlBXueUB86TLvb4HsQQ4bgB8CXUTg8UQ4vTNGIv1g8YQSXQZ OCx09qC1B7QHi/CsPAB0/LsHALQOzRDr8ohOEOhGAHMq/kYQgH4EC3QLgH4EDHQFoLYHddKA RgIGg0YIBoNWCgDoIQBzBaC2B+u8gT7+fVWqdAuAfhAAdMigtwfrqYv8HleL9cu/BQCKVgC0 CM0TciOKwSQ/mIreivxD9+OL0YbWsQbS7kL34jlWCncjcgU5RghzHLgBArsAfItOAotWAM0T c1FPdE4y5IpWAM0T6+SKVgBgu6pVtEHNE3I2gftVqnUw9sEBdCthYGoAagD/dgr/dghqAGgA fGoBahC0Qov0zRNhYXMOT3QLMuSKVgDNE+vWYfnDSW52YWxpZCBwYXJ0aXRpb24gdGFibGUA RXJyb3IgbG9hZGluZyBvcGVyYXRpbmcgc3lzdGVtAE1pc3Npbmcgb3BlcmF0aW5nIHN5c3Rl bQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAsRGM= ===

Anda mungkin juga menyukai