Вы находитесь на странице: 1из 91

SpyHolesList Version:11.5 Build:7.90.0.

190
27.01.2016 12:08:30 PM
WinDir=C:\WINDOWS
Startup=C:\Documents and Settings\xpsp3\Start Menu\Programs\Startup\
Common Startup=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Windows XP Service Pack 3 (5.1.2600)
Internet Explorer 8.0.6001.18702
DBS Version: 1.550
[Internet Explorer]
[Default Home Page] :HKLM Default_Page_URL=http://go.microsoft.com/fwlink/?Lin
kId=69157
[Current Home Page] :HKCU Start Page=http://www.microsoft.com/isapi/redir.dll?
prd=ie&pver=6&ar=msnhome
[Current Home Page] :HKCU HOMEOldSP=""
[Current Home Page] :HKCU Default_Page_URL=""
[Current Home Page] :HKLM Start Page=http://go.microsoft.com/fwlink/?LinkId=69
157
[Current Home Page] :HKLM HOMEOldSP=""
[All Users Search] :HKLM Default_Search_URL=http://go.microsoft.com/fwlink/?Li
nkId=54896
[All Users Search] :HKLM Search Page=http://go.microsoft.com/fwlink/?LinkId=54
896
[Current Users Search] :HKCU Default_Search_URL=""
[Current Users Search] :HKCU Search Page=http://www.microsoft.com/isapi/redir.
dll?prd=ie&ar=iesearch
[Current Users Search] :HKCU Search Bar=""
[IE Local Blank Page] :HKCU Local Page=C:\WINDOWS\system32\blank.htm
[IE Local Blank Page] :HKLM Local Page=C:\WINDOWS\system32\blank.htm
[Browser Helper Objects] {0055C089-8582-441B-A0BF-17B458C2A3A8}=C:\PROGRAM FIL
ES\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL
### IDM BHO Module Tonec Inc. Internet Download Manager Module 5, 18, 7, 0
[Browser Helper Objects] {18DF081C-E8AD-4283-A596-FA578C2EBDC3}=C:\PROGRAM FIL
ES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPERSHIM.DLL
### Adobe PDF Helper for Internet Explorer Adobe Systems Incorporated AcroIEHe
lperShim Library 10.1.0.534
[Auto Search URL] :HKCU provider=""
[Auto Search URL] :HKCU "Default Value"=""
[Search Assistant] :HKCU SearchAssistant=""
[Search Assistant] :HKLM SearchAssistant=http://ie.search.msn.com/{SUB_RFC1766
}/srchasst/srchasst.htm
[Search Assistant] :HKCU CustomizeSearch=""
[Search Assistant] :HKLM CustomizeSearch=http://ie.search.msn.com/{SUB_RFC1766
}/srchasst/srchcust.htm
[Search Provider for All Users] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}=http://
search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
### Live Search
[Search Provider for All Users] DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B
2E3A}
[CustomizeSearch] :HKLM CustomizeSearch=""
[URLSearchHook] :HKCU {CFBFAE00-17A6-11D0-99CB-00C04FD64497}=C:\WINDOWS\SYSTEM
32\IEFRAME.DLL
### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001
.18702
[Search URL Template] :HKLM 1=""
[Search URL Template] :HKLM 2=""
[Search URL Template] :HKLM 3=""
[Search URL Template] :HKLM 4=""
[Default Prefix] :HKLM "Default Value"=http://
[URL Default Prefixes] :HKLM ftp=ftp://
[URL Default Prefixes] :HKLM gopher=gopher://

[URL Default Prefixes] :HKLM home=http://


[URL Default Prefixes] :HKLM mosaic=http://
[URL Default Prefixes] :HKLM www=http://
[Safe Sites] :HKLM ie.search.msn.com=http://ie.search.msn.com/*
[AboutURLs] :HKLM DesktopItemNavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NavigationFailure=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM NavigationCanceled=res://ieframe.dll/navcancl.htm
[AboutURLs] :HKLM OfflineInformation=res://ieframe.dll/offcancl.htm
[AboutURLs] :HKLM Home=270
[AboutURLs] :HKLM blank=res://mshtml.dll/blank.htm
[AboutURLs] :HKLM PostNotCached=res://ieframe.dll/repost.htm
[AboutURLs] :HKLM InPrivate=res://ieframe.dll/inprivate.htm
[AboutURLs] :HKLM NoAdd-ons=res://ieframe.dll/noaddon.htm
[AboutURLs] :HKLM NoAdd-onsInfo=res://ieframe.dll/noaddoninfo.htm
[AboutURLs] :HKLM SecurityRisk=res://ieframe.dll/securityatrisk.htm
[AboutURLs] :HKLM Tabs=res://ieframe.dll/tabswelcome.htm
[User Style Sheet] :HKCU User Stylesheet=""
[User Style Sheet] :HKCU Use My Stylesheet=0
[Execute unsigned ActiveX in My Computer Zone] :HKCU 1201=1
[Execute unsigned ActiveX in My Computer Zone] :HKLM 1201=1
[Execute unsigned ActiveX in Local Intranet Zone] :HKCU 1201=3
[Execute unsigned ActiveX in Local Intranet Zone] :HKLM 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKCU 1201=3
[Execute unsigned ActiveX in Internet Zone] :HKLM 1201=3
[Links Toolbar] :HKCU LinksFolderName=Links
[Explorer Bars] :HKLM {4D5C8C25-D075-11d0-B416-00C04FB90376}=C:\WINDOWS\SYSTEM
32\SHDOCVW.DLL
### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window
s Operating System 6.00.2900.6452 C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
[IE Extensions - All Users] :HKLM {e2e2dd38-d088-4134-82b7-f2ba38496583}=C:\WI
NDOWS\NETWORK DIAGNOSTIC\XPNETDIAG.EXE
### Network Diagnostic for Windows XP Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512 C:\WINDOWS\NETWORK DIAGNOSTIC\XPNETDIAG.EXE
[IE Extensions - All Users] :HKLM {FB5F1910-F110-11d2-BB9E-00C04F795683}=C:\PR
OGRAM FILES\MESSENGER\MSMSGS.EXE
### Windows Messenger Microsoft Corporation Messenger Version 4.7.3001
[Context menu items] :HKCU Download all links with IDM=C:\PROGRAM FILES\INTERN
ET DOWNLOAD MANAGER\IEGETALL.HTM
[Context menu items] :HKCU Download FLV video content with IDM=C:\PROGRAM FILE
S\INTERNET DOWNLOAD MANAGER\IEGETVL.HTM
[Context menu items] :HKCU Download with IDM=C:\PROGRAM FILES\INTERNET DOWNLOA
D MANAGER\IEEXT.HTM
[Active Desktop Components] :HKCU 0=About:Home
### Source=About:Home SubscribedURL=About:Home
[AutoConfigURL] :HKCU AutoConfigURL=""
[Protocols Filter] :HKLM Class Install Handler=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Filter] :HKLM deflate=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Filter] :HKLM gzip=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Filter] :HKLM lzdhtml=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Filter] :HKLM text/webviewhtml=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242 C:\WINDOWS\SYSTEM32\SHELL32.DLL

[Protocols Handler] :HKLM about=C:\WINDOWS\SYSTEM32\MSHTML.DLL


### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8
.00.6001.18702
[Protocols Handler] :HKLM cdl=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Handler] :HKLM dvd=C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow 6.05.
2600.5512
[Protocols Handler] :HKLM file=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Handler] :HKLM ftp=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Handler] :HKLM gopher=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Handler] :HKLM http=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Handler] :HKLM https=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Handler] :HKLM ipp
[Protocols Handler] :HKLM its=C:\WINDOWS\SYSTEM32\ITSS.DLL
### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi
ndows Operating System 5.2.3790.4186
[Protocols Handler] :HKLM javascript=C:\WINDOWS\SYSTEM32\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8
.00.6001.18702
[Protocols Handler] :HKLM local=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Handler] :HKLM mailto=C:\WINDOWS\SYSTEM32\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8
.00.6001.18702
[Protocols Handler] :HKLM mhtml=C:\WINDOWS\SYSTEM32\INETCOMM.DLL
### Microsoft Internet Messaging API Microsoft Corporation Microsoft Windows Ope
rating System 6.00.2900.6157 C:\WINDOWS\SYSTEM32\INETCOMM.DLL
[Protocols Handler] :HKLM mk=C:\WINDOWS\SYSTEM32\URLMON.DLL
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Protocols Handler] :HKLM ms-its=C:\WINDOWS\SYSTEM32\ITSS.DLL
### Microsoft InfoTech Storage System Library Microsoft Corporation Microsoft Wi
ndows Operating System 5.2.3790.4186
[Protocols Handler] :HKLM msdaipp
[Protocols Handler] :HKLM res=C:\WINDOWS\SYSTEM32\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8
.00.6001.18702
[Protocols Handler] :HKLM sysimage=C:\WINDOWS\SYSTEM32\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8
.00.6001.18702 C:\WINDOWS\SYSTEM32\MSHTML.DLL
[Protocols Handler] :HKLM tv=C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL
### ActiveX control for streaming video Microsoft Corporation DirectShow 6.05.
2600.5512
[Protocols Handler] :HKLM vbscript=C:\WINDOWS\SYSTEM32\MSHTML.DLL
### Microsoft (R) HTML Viewer Microsoft Corporation Windows Internet Explorer 8
.00.6001.18702
[Protocols Handler] :HKLM wia=C:\WINDOWS\SYSTEM32\WIASCR.DLL

### WIA Scripting Layer Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Proxy] :HKCU ProxyServer=""
[Proxy] :HKCU ProxyEnable=0
[Network Settings]
[Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc
[Hosts File Contents] :HKLM 127.0.0.1
localhost
[Browsers]
[Installed Browsers] IEXPLORE.EXE=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.
EXE
### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001
.18702
[Installed Browsers] launcher.exe=C:\PROGRAM FILES\OPERA\LAUNCHER.EXE
### Default Browser
Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Installed Browsers] OperaStable=C:\PROGRAM FILES\OPERA\LAUNCHER.EXE
### Default Browser
Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Google Chrome Settings] :HKLM backup.homepage=""
[Google Chrome Settings] :HKLM backup.session.urls_to_restore_on_startup=""
[Google Chrome Settings] :HKLM session.startup_urls=""
[Google Chrome Settings] :HKLM default_search_provider.icon_url=""
[Google Chrome Settings] :HKLM default_search_provider.keyword=""
[Google Chrome Settings] :HKLM default_search_provider.name=""
[Google Chrome Settings] :HKLM default_search_provider.search_url=""
[Google Chrome Settings] :HKLM default_search_provider.suggest_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
alternate_urls=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
favicon_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
keyword=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
short_name=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
suggest_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
new_tab_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
instant_url=""
[Google Chrome Settings] :HKLM default_search_provider_data.template_url_data.
image_url=""
[Google Chrome Settings] :HKLM homepage=""
[Google Chrome Settings] :HKLM session.urls_to_restore_on_startup=""
[Network Settings]
[Domain Name] :HKLM Domain=""
[Name Server] {442C6BF5-2B45-4FC8-A7CE-A59F5F6C35B2}=8.8.8.8
### Network Card:Realtek RTL8139 Family PCI Fast Ethernet NIC DHCPNameServer:8
.8.8.8 DhcpDefaultGateway:192.168.1.1
DhcpServer:192.168.1.1
[WinSock2 Components] mswsock.dll=C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 5.1.2600.5625 C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
[WinSock2 Components] winrnr.dll=C:\WINDOWS\SYSTEM32\WINRNR.DLL
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512 C:\WINDOWS\SYSTEM32\WINRNR.DLL
[WinSock2 Components] idmmbc.dll=C:\WINDOWS\SYSTEM32\IDMMBC.DLL
### Internet Download Manager LSP dll Tonec Inc. Internet Download Manager LSP

dll 5, 18, 2, 0
[WinSock2 Components] rsvpsp.dll=C:\WINDOWS\SYSTEM32\RSVPSP.DLL
### Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation Microsof
t Windows Operating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\RSVPSP.DLL
[Windows Shell]
[Display Scrap's Extensions] :HKLM NeverShowExt=""
[ScreenSaver] :HKCU SCRNSAVE.EXE=C:\WINDOWS\SYSTEM32\LOGON.SCR
### Logon Screen Saver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[System.ini] shell=Explorer.exe
[User Shell] :HKCU shell=""
[Internet Shortcuts] :HKLM C:\Documents and Settings\All Users\Start Menu\Prog
rams\UnHackMe\Check for UnHackMe updates.lnk=HTTP://GREATIS.COM/UNHACKME.INI
### C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\UnHackMe\CHECKF~1.LNK
[Internet Shortcuts] :HKLM C:\Documents and Settings\All Users\Start Menu\Wind
ows Catalog.lnk=HTTP://GO.MICROSOFT.COM/FWLINK/?LINKID=374
### C:\DOCUME~1\ALLUSE~1\STARTM~1\WINDOW~2.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\Any Video Conve
rter Ultimate.lnk=C:\Program Files\AnvSoft\Any Video Converter Ultimate\AVCUltim
ate.exe
### C:\DOCUME~1\xpsp3\Desktop\ANYVID~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\Counter Strike
1.6 No Steam.lnk=C:\Program Files\Counter-Strike 1.6\hl.exe
### C:\DOCUME~1\xpsp3\Desktop\COUNTE~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\Dedicated Serve
r.lnk=C:\Program Files\Counter-Strike 1.6\hlds.exe
### C:\DOCUME~1\xpsp3\Desktop\DEDICA~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\Stop Installati
on Tool.lnk=C:\Program Files\Stop Software Installation Tool\stopinst.exe
### C:\DOCUME~1\xpsp3\Desktop\STOPIN~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\Total Commander
.lnk=C:\totalcmd\TOTALCMD.EXE
### C:\DOCUME~1\xpsp3\Desktop\TOTALC~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\UnHackMe.lnk=C:
\Program Files\UnHackMe\Unhackme.exe
### C:\DOCUME~1\xpsp3\Desktop\UnHackMe.lnk
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\WPS Presentatio
n.lnk=C:\Documents and Settings\xpsp3\Local Settings\Application Data\Kingsoft\W
PS Office\ksolaunch.exe
### C:\DOCUME~1\xpsp3\Desktop\WPSPRE~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\WPS Spreadsheet
s.lnk=C:\Documents and Settings\xpsp3\Local Settings\Application Data\Kingsoft\W
PS Office\ksolaunch.exe
### C:\DOCUME~1\xpsp3\Desktop\WPSSPR~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Desktop\WPS Writer.lnk=
C:\Documents and Settings\xpsp3\Local Settings\Application Data\Kingsoft\WPS Off
ice\ksolaunch.exe
### C:\DOCUME~1\xpsp3\Desktop\WPSWRI~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\All Users\Desktop\Adobe Reade
r X.lnk=C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
### C:\DOCUME~1\ALLUSE~1\Desktop\ADOBER~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\All Users\Desktop\Avira AntiV
ir Control Center.lnk=C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
### C:\DOCUME~1\ALLUSE~1\Desktop\AVIRAA~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\All Users\Desktop\Opera.lnk=C
:\Program Files\Opera\launcher.exe
### C:\DOCUME~1\ALLUSE~1\Desktop\Opera.lnk
[User Shortcuts] :HKLM C:\Documents and Settings\All Users\Desktop\TuneUp 1-Cl
ick Maintenance.lnk=C:\Program Files\TuneUp Utilities 2013\OneClick.exe
### C:\DOCUME~1\ALLUSE~1\Desktop\TUNEUP~2.LNK

[User Shortcuts] :HKLM C:\Documents and Settings\All Users\Desktop\TuneUp Util


ities 2013.lnk=C:\Program Files\TuneUp Utilities 2013\Integrator.exe
### C:\DOCUME~1\ALLUSE~1\Desktop\TUNEUP~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Application Data\Micros
oft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk=C:\Progr
am Files\Internet Explorer\iexplore.exe
### C:\DOCUME~1\xpsp3\APPLIC~1\MICROS~1\INTERN~1\QUICKL~1\LAUNCH~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Application Data\Micros
oft\Internet Explorer\Quick Launch\Opera.lnk=C:\Program Files\Opera\launcher.exe
### C:\DOCUME~1\xpsp3\APPLIC~1\MICROS~1\INTERN~1\QUICKL~1\Opera.lnk
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Application Data\Micros
oft\Internet Explorer\Quick Launch\TuneUp Utilities 2013.lnk=C:\Program Files\Tu
neUp Utilities 2013\Integrator.exe
### C:\DOCUME~1\xpsp3\APPLIC~1\MICROS~1\INTERN~1\QUICKL~1\TUNEUP~1.LNK
[User Shortcuts] :HKLM C:\Documents and Settings\xpsp3\Application Data\Micros
oft\Internet Explorer\Quick Launch\Windows Media Player.lnk=C:\Program Files\Win
dows Media Player\wmplayer.exe
### C:\DOCUME~1\xpsp3\APPLIC~1\MICROS~1\INTERN~1\QUICKL~1\WINDOW~1.LNK
[Main File Extensions] :HKLM .exe="%1" %*
[Main File Extensions] :HKLM .com="%1" %*
[Main File Extensions] :HKLM .pif="%1" %*
[Main File Extensions] :HKLM .bat="%1" %*
[Main File Extensions] :HKLM .cmd="%1" %*
[Main File Extensions] :HKLM .scr="%1" /S
[Main File Extensions] :HKLM .txt=%SystemRoot%\system32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .reg=regedit.exe "%1"
[Main File Extensions] :HKLM .inf=%SystemRoot%\System32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .ini=%SystemRoot%\System32\NOTEPAD.EXE %1
[Main File Extensions] :HKLM .js=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .vbs=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .vbe=%SystemRoot%\System32\WScript.exe "%1" %*
[Main File Extensions] :HKLM .msc=%SystemRoot%\system32\mmc.exe "%1" %*
[Main File Extensions] :HKLM .jpg=rundll32.exe C:\WINDOWS\system32\shimgvw.dll
,ImageView_Fullscreen %1
[Main File Extensions] :HKLM .jpeg=rundll32.exe C:\WINDOWS\system32\shimgvw.dl
l,ImageView_Fullscreen %1
[Shell Execute Hooks] :HKLM {AEB6717E-7E19-11d0-97EE-00C04FD91972}=C:\WINDOWS\
system32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242 C:\WINDOWS\system32\SHELL32.DLL
[UserInit Value] :HKLM UserInit=C:\WINDOWS\system32\userinit.exe,
[Winlogon Notification] :HKLM crypt32chain=C:\WINDOWS\system32\CRYPT32.DLL
### crypt32chain Crypto API32 Microsoft Corporation Microsoft Windows Operating
System 5.131.2600.6459 C:\WINDOWS\system32\CRYPT32.DLL
[Winlogon Notification] :HKLM cryptnet=C:\WINDOWS\system32\CRYPTNET.DLL
### cryptnet Crypto Network Related API Microsoft Corporation Microsoft Windows
Operating System 5.131.2600.5512 C:\WINDOWS\system32\CRYPTNET.DLL
[Winlogon Notification] :HKLM cscdll=C:\WINDOWS\system32\CSCDLL.DLL
### cscdll Offline Network Agent Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512 C:\WINDOWS\system32\CSCDLL.DLL
[Winlogon Notification] :HKLM dimsntfy=C:\WINDOWS\SYSTEM32\DIMSNTFY.DLL
### dimsntfy DIMS Notification Handler Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\DIMSNTFY.DLL
[Winlogon Notification] :HKLM igfxcui=C:\WINDOWS\system32\IGFXDEV.DLL
### igfxcui igfxdev Module Intel Corporation Intel(R) Common User Interface 6.
14.10.4926 C:\WINDOWS\system32\IGFXDEV.DLL
[Winlogon Notification] :HKLM ScCertProp=C:\WINDOWS\system32\WLNOTIFY.DLL
### ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporat
ion Microsoft Windows Operating System 5.1.2600.5512 C:\WINDOWS\system32\WLNOTIFY
.DLL

[Winlogon Notification] :HKLM Schedule=C:\WINDOWS\system32\WLNOTIFY.DLL


### Schedule Common DLL to receive Winlogon notifications Microsoft Corporatio
n Microsoft Windows Operating System 5.1.2600.5512 C:\WINDOWS\system32\WLNOTIFY.D
LL
[Winlogon Notification] :HKLM sclgntfy=C:\WINDOWS\system32\SCLGNTFY.DLL
### sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation Mi
crosoft Windows Operating System 5.1.2600.5512 C:\WINDOWS\system32\SCLGNTFY.DLL
[Winlogon Notification] :HKLM SensLogn=C:\WINDOWS\system32\WLNOTIFY.DLL
### SensLogn Common DLL to receive Winlogon notifications Microsoft Corporatio
n Microsoft Windows Operating System 5.1.2600.5512 C:\WINDOWS\system32\WLNOTIFY.D
LL
[Winlogon Notification] :HKLM termsrv=C:\WINDOWS\system32\WLNOTIFY.DLL
### termsrv Common DLL to receive Winlogon notifications Microsoft Corporation
Microsoft Windows Operating System 5.1.2600.5512 C:\WINDOWS\system32\WLNOTIFY.DL
L
[Winlogon Notification] :HKLM wlballoon=C:\WINDOWS\system32\WLNOTIFY.DLL
### wlballoon Common DLL to receive Winlogon notifications Microsoft Corporati
on Microsoft Windows Operating System 5.1.2600.5512 C:\WINDOWS\system32\WLNOTIFY.
DLL
[Shell Services DelayLoad] :HKLM PostBootReminder=C:\WINDOWS\SYSTEM32\SHELL32.
DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[Shell Services DelayLoad] :HKLM CDBurn=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[Shell Services DelayLoad] :HKLM WebCheck=C:\WINDOWS\SYSTEM32\WEBCHECK.DLL
### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001.
18702
[Shell Services DelayLoad] :HKLM SysTray=C:\WINDOWS\SYSTEM32\STOBJECT.DLL
### Systray shell service object Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[System Shell Policies ] :HKCU shell=""
[System Shell Policies ] :HKLM shell=""
[System Shell Policies ] :HKCU run=""
[System Shell Policies ] :HKLM run=""
[Prevents Display in Control Panel from running.] :HKCU NoDispCpl=0
[Disable Registry Tools] :HKCU DisableRegistryTools =0
[SharedTaskScheduler] :HKLM {438755C2-A8BA-11D1-B96B-00A0C90312E1}=C:\WINDOWS\
SYSTEM32\BROWSEUI.DLL
### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6452 C:\WINDOWS\SYSTEM32\BROWSEUI.DLL
[SharedTaskScheduler] :HKLM {8C7461EF-2B13-11d2-BE35-3078302C2030}=C:\WINDOWS\
SYSTEM32\BROWSEUI.DLL
### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6452 C:\WINDOWS\SYSTEM32\BROWSEUI.DLL
[Print Monitors] :HKLM BJ Language Monitor=C:\WINDOWS\system32\CNBJMON.DLL
### Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation Microso
ft Windows Operating System 5.1.2600.2082 C:\WINDOWS\system32\CNBJMON.DLL
[Print Monitors] :HKLM Local Port=C:\WINDOWS\system32\LOCALSPL.DLL
### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.6226 C:\WINDOWS\system32\LOCALSPL.DLL
[Print Monitors] :HKLM PJL Language Monitor=C:\WINDOWS\system32\PJLMON.DLL
### PJL Language monitor Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512 C:\WINDOWS\system32\PJLMON.DLL
[Print Monitors] :HKLM Standard TCP/IP Port=C:\WINDOWS\system32\TCPMON.DLL
### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512 C:\WINDOWS\system32\TCPMON.DLL
[Print Monitors] :HKLM USB Monitor=C:\WINDOWS\system32\USBMON.DLL
### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft

Windows Operating System 5.1.2600.5512 C:\WINDOWS\system32\USBMON.DLL


[Shell Icon Overlay Handlers] :HKLM Offline Files=C:\WINDOWS\SYSTEM32\CSCUI.DL
L
### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512 C:\WINDOWS\SYSTEM32\CSCUI.DLL
[Context Menu Handlers] :HKLM Offline Files=C:\WINDOWS\SYSTEM32\CSCUI.DLL
### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512 C:\WINDOWS\SYSTEM32\CSCUI.DLL
[Context Menu Handlers] :HKLM Open With=C:\WINDOWS\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[Context Menu Handlers] :HKLM Open With EncryptionMenu=C:\WINDOWS\SYSTEM32\SHE
LL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[Context Menu Handlers] :HKLM Shell Extension for Malware scanning=C:\PROGRAM
FILES\AVIRA\ANTIVIR DESKTOP\SHLEXT.DLL
### AntiVirus context menu Avira GmbH AntiVir Desktop 10.00.00.03
[Context Menu Handlers] :HKLM TuneUp Shredder Shell Extension=C:\PROGRAM FILES
\TUNEUP UTILITIES 2013\SDSHELEX-WIN32.DLL
### TuneUp Shredder Shell Extension TuneUp Software TuneUp Utilities 2013 13.0
.2013.194
[Context Menu Handlers] :HKLM WinRAR=C:\PROGRAM FILES\WINRAR\RAREXT.DLL
[Context Menu Handlers] :HKLM {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}=C:\WINDOW
S\SYSTEM32\SHELL32.DLL
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242 C:\WINDOWS\SYSTEM32\SHELL32.DLL
[App Paths] :HKLM AcroRd32.exe=C:\Program Files\Adobe\Reader 10.0\Reader\AcroR
d32.exe
### AcroRd32.exe Adobe Reader Adobe Systems Incorporated Adobe Reader 10.1.0.
534
[App Paths] :HKLM bckgzm.exe=C:\Program Files\MSN Gaming Zone\Windows\bckgzm.e
xe
### bckgzm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1
[App Paths] :HKLM chkrzm.exe=C:\Program Files\MSN Gaming Zone\Windows\chkrzm.e
xe
### chkrzm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1
[App Paths] :HKLM cmmgr32.exe=C:\WINDOWS\system32\cmmgr32.exe
### cmmgr32.exe
[App Paths] :HKLM CONF.EXE=C:\Program Files\NetMeeting\conf.exe
### CONF.EXE Windows NetMeeting Microsoft Corporation Windows NetMeeting 3.01
[App Paths] :HKLM dialer.exe=C:\Program Files\Windows NT\dialer.exe
### dialer.exe TAPI 3.0 Dialer and IP Multicast Conference Viewer Microsoft Co
rporation Microsoft Windows Operating System 5.1.2600.5512
[App Paths] :HKLM HELPCTR.EXE=C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HELPCTR.EXE
### HELPCTR.EXE Microsoft Help and Support Center Microsoft Corporation Micros
oft Windows Operating System 5.1.2600.5512
[App Paths] :HKLM hrtzzm.exe=C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.e
xe
### hrtzzm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1
[App Paths] :HKLM hypertrm.exe="C:\Program Files\Windows NT\hypertrm.exe"
### hypertrm.exe HyperTerminal Applet Hilgraeve, Inc. Microsoft Windows Operatin
g System 5.1.2600.0
[App Paths] :HKLM ICWCONN1.EXE="C:\Program Files\Internet Explorer\Connection
Wizard\ICWCONN1.EXE"
### ICWCONN1.EXE Internet Connection Wizard Microsoft Corporation Microsoft Win
dows Operating System 6.00.2900.5512
[App Paths] :HKLM ICWCONN2.EXE="C:\Program Files\Internet Explorer\Connection
Wizard\ICWCONN2.EXE"
### ICWCONN2.EXE Internet Connection Wizard Microsoft Corporation Microsoft Win

dows Operating System 6.00.2900.5512


[App Paths] :HKLM IEXPLORE.EXE=C:\Program Files\Internet Explorer\IEXPLORE.EXE
### IEXPLORE.EXE Internet Explorer Microsoft Corporation Windows Internet Explo
rer 8.00.6001.18702
[App Paths] :HKLM INETWIZ.EXE="C:\Program Files\Internet Explorer\Connection W
izard\INETWIZ.EXE"
### INETWIZ.EXE Internet Connection Wizard Microsoft Corporation Microsoft Wind
ows Operating System 6.00.2900.5512
[App Paths] :HKLM install.exe
### install.exe
[App Paths] :HKLM ISIGNUP.EXE="C:\Program Files\Internet Explorer\Connection W
izard\ISIGNUP.EXE"
### ISIGNUP.EXE Internet Signup Microsoft Corporation Microsoft Windows Operatin
g System 6.00.2600.0000
[App Paths] :HKLM migwiz.exe=%SystemRoot%\system32\usmt\migwiz.exe
### migwiz.exe
[App Paths] :HKLM moviemk.exe=C:\Program Files\Movie Maker\moviemk.exe
### moviemk.exe Windows Movie Maker Microsoft Corporation Windows Movie Maker
2.1.4028.0
[App Paths] :HKLM mpc-hc.exe="C:\Program Files\K-Lite Codec Pack\Media Player
Classic\mpc-hc.exe"
### mpc-hc.exe Media Player Classic - Home Cinema MPC-HC Team Media Player Cla
ssic - Home Cinema 1, 5, 2, 3236
[App Paths] :HKLM mplayer2.exe="C:\Program Files\Windows Media Player\mplayer2
.exe"
### mplayer2.exe Windows Media Player Microsoft Corporation Microsoft Windows
Media Player 6.4.09.1125
[App Paths] :HKLM MSCONFIG.EXE=C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.E
XE
### MSCONFIG.EXE System Configuration Utility Microsoft Corporation Microsoft W
indows Operating System 5.1.2600.5512
[App Paths] :HKLM msimn.exe=%ProgramFiles%\Outlook Express\msimn.exe
### msimn.exe
[App Paths] :HKLM msinfo32.exe=C:\Program Files\Common Files\Microsoft Shared\
MSInfo\MSInfo32.exe
### msinfo32.exe System Information Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.0
[App Paths] :HKLM MSMSGS.EXE=C:\Program Files\Messenger\msmsgs.exe
### MSMSGS.EXE Windows Messenger Microsoft Corporation Messenger Version 4.7.3
001
[App Paths] :HKLM opera.exe="C:\Program Files\Opera\Launcher.exe"
### opera.exe Opera Internet Browser Opera Software Opera Internet Browser 34.
0.2036.36
[App Paths] :HKLM pbrush.exe=%SystemRoot%\system32\mspaint.exe
### pbrush.exe
[App Paths] :HKLM pinball.exe=C:\Program Files\Windows NT\Pinball\pinball.exe
### pinball.exe 3D Pinball Cinematronics 3D Pinball 5.1.2600.5512
[App Paths] :HKLM rvsezm.exe=C:\Program Files\MSN Gaming Zone\Windows\rvsezm.e
xe
### rvsezm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1
[App Paths] :HKLM setup.exe
### setup.exe
[App Paths] :HKLM shvlzm.exe=C:\Program Files\MSN Gaming Zone\Windows\shvlzm.e
xe
### shvlzm.exe Zone Datafile Microsoft Corporation Zone.com 1.2.626.1
[App Paths] :HKLM table30.exe
### table30.exe
[App Paths] :HKLM wab.exe=%ProgramFiles%\Outlook Express\wab.exe
### wab.exe
[App Paths] :HKLM wabmig.exe=%ProgramFiles%\Outlook Express\wabmig.exe

### wabmig.exe
[App Paths] :HKLM winnt32.exe
### winnt32.exe
[App Paths] :HKLM WinRAR.exe=C:\Program Files\WinRAR\WinRAR.exe
### WinRAR.exe
[App Paths] :HKLM wmplayer.exe=C:\Program Files\Windows Media Player\wmplayer.
exe
### wmplayer.exe Windows Media Player Microsoft Corporation Microsoft(R) Windo
ws Media Player 9.00.00.4503
[App Paths] :HKLM WORDPAD.EXE=C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.
EXE
### WORDPAD.EXE WordPad MFC Application Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.6010 C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.
EXE
[App Paths] :HKLM WRITE.EXE="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE
"
### WRITE.EXE
[Kernel Auto Boot]
[ActiveSetup] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}=C:\WINDOWS\INF\UNREGMP2.
EXE
### Microsoft Windows Media Player Setup Utility Microsoft Corporation Microso
ft(R) Windows Media Player 9.00.00.4503 C:\WINDOWS\INF\UNREGMP2.EXE
[Auto Services] AntiVirSchedulerService
### Internal Name: AntiVirSchedulerService. Status: service is running. Actual
File: "C:\Program Files\Avira\AntiVir Desktop\sched.exe" * Service to schedule
Avira AntiVir Personal - Free Antivirus jobs and updates. Antivirus Scheduler Av
ira GmbH AntiVir Desktop 10.00.00.21
[Auto Services] AntiVirService
### Internal Name: AntiVirService. Status: service is running. Actual File: "C
:\Program Files\Avira\AntiVir Desktop\avguard.exe" * Offers permanent protection
against viruses and malware with the AntiVir search engine. Antivirus On-Access
Service Avira GmbH AntiVir Desktop 10.00.01.58
[Auto Services] AudioSrv
### Internal Name: AudioSrv. Status: service is running. Actual File: C:\WINDO
WS\System32\svchost.exe -k netsvcs * Manages audio devices for Windows-based pro
grams. If this service is stopped, audio devices and effects will not function p
roperly. If this service is disabled, any services that explicitly depend on it
will fail to start. Generic Host Process for Win32 Services Microsoft Corporatio
n Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] Browser
### Internal Name: Browser. Status: service is running. Actual File: C:\WINDOW
S\system32\svchost.exe -k netsvcs * Maintains an updated list of computers on th
e network and supplies this list to computers designated as browsers. If this se
rvice is stopped, this list will not be updated or maintained. If this service i
s disabled, any services that explicitly depend on it will fail to start. Generi
c Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Auto Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File: C:\WINDO
WS\system32\svchost.exe -k netsvcs * Provides three management services: Catalog
Database Service, which confirms the signatures of Windows files; Protected Roo
t Service, which adds and removes Trusted Root Certification Authority certifica
tes from this computer; and Key Service, which helps enroll this computer for ce
rtificates. If this service is stopped, these management services will not funct
ion properly. If this service is disabled, any services that explicitly depend o
n it will fail to start. Generic Host Process for Win32 Services Microsoft Corpo
ration Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\WIN
DOWS\system32\svchost -k DcomLaunch * Provides launch functionality for DCOM ser

vices. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Auto Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File: C:\WINDOWS\s
ystem32\svchost.exe -k netsvcs * Manages network configuration by registering an
d updating IP addresses and DNS names. Generic Host Process for Win32 Services M
icrosoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] dmserver
### Internal Name: dmserver. Status: service is running. Actual File: C:\WINDO
WS\System32\svchost.exe -k netsvcs * Detects and monitors new hard disk drives a
nd sends disk volume information to Logical Disk Manager Administrative Service
for configuration. If this service is stopped, dynamic disk status and configura
tion information may become out of date. If this service is disabled, any servic
es that explicitly depend on it will fail to start. Generic Host Process for Win
32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File: C:\WINDO
WS\system32\svchost.exe -k NetworkService * Resolves and caches Domain Name Syst
em (DNS) names for this computer. If this service is stopped, this computer will
not be able to resolve DNS names and locate Active Directory domain controllers
. If this service is disabled, any services that explicitly depend on it will fa
il to start. Generic Host Process for Win32 Services Microsoft Corporation Micro
soft Windows Operating System 5.1.2600.5512
[Auto Services] ERSvc
### Internal Name: ERSvc. Status: service is running. Actual File: C:\WINDOWS\
System32\svchost.exe -k netsvcs * Allows error reporting for services and applic
tions running in non-standard environments. Generic Host Process for Win32 Servi
ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] Eventlog
### Internal Name: Eventlog. Status: service is running. Actual File: C:\WINDO
WS\system32\services.exe * Enables event log messages issued by Windows-based pr
ograms and components to be viewed in Event Viewer. This service cannot be stopp
ed. Services and Controller app Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5755
[Auto Services] helpsvc
### Internal Name: helpsvc. Status: service is running. Actual File: C:\WINDOW
S\System32\svchost.exe -k netsvcs * Enables Help and Support Center to run on th
is computer. If this service is stopped, Help and Support Center will be unavail
able. If this service is disabled, any services that explicitly depend on it wil
l fail to start. Generic Host Process for Win32 Services Microsoft Corporation M
icrosoft Windows Operating System 5.1.2600.5512
[Auto Services] HidServ
### Internal Name: HidServ. Status: service is running. Actual File: C:\WINDOW
S\System32\svchost.exe -k netsvcs * Enables generic input access to Human Interf
ace Devices (HID), which activates and maintains the use of predefined hot butto
ns on keyboards, remote controls, and other multimedia devices. If this service
is stopped, hot buttons controlled by this service will no longer function. If t
his service is disabled, any services that explicitly depend on it will fail to
start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Auto Services] Kingsoft_WPS_UpdateService
### Internal Name: Kingsoft_WPS_UpdateService. Status: service is running. Act
ual File: C:\Documents and Settings\xpsp3\Local Settings\Application Data\Kingso
ft\WPS Office\9.1.0.5234\wtoolex\wpsupdatesvr.exe * WPS Office Update Service. W
PS Office Expansion tool Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 9,1,
0,5234
[Auto Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W
INDOWS\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh

aring over the network for this computer. If this service is stopped, these func
tions will be unavailable. If this service is disabled, any services that explic
itly depend on it will fail to start. Generic Host Process for Win32 Services Mi
crosoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] lanmanworkstation
### Internal Name: lanmanworkstation. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * Creates and maintains client netwo
rk connections to remote servers. If this service is stopped, these connections
will be unavailable. If this service is disabled, any services that explicitly d
epend on it will fail to start. Generic Host Process for Win32 Services Microsof
t Corporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] LmHosts
### Internal Name: LmHosts. Status: service is running. Actual File: C:\WINDOW
S\system32\svchost.exe -k LocalService * Enables support for NetBIOS over TCP/IP
(NetBT) service and NetBIOS name resolution. Generic Host Process for Win32 Ser
vices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File: C:\WINDO
WS\system32\services.exe * Enables a computer to recognize and adapt to hardware
changes with little or no user input. Stopping or disabling this service will r
esult in system instability. Services and Controller app Microsoft Corporation M
icrosoft Windows Operating System 5.1.2600.5755
[Auto Services] PolicyAgent
### Internal Name: PolicyAgent. Status: service is running. Actual File: C:\WI
NDOWS\system32\lsass.exe * Manages IP security policy and starts the ISAKMP/Oakl
ey (IKE) and the IP security driver. LSA Shell (Export Version) Microsoft Corpor
ation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] ProtectedStorage
### Internal Name: ProtectedStorage. Status: service is running. Actual File:
C:\WINDOWS\system32\lsass.exe * Provides protected storage for sensitive data, s
uch as private keys, to prevent access by unauthorized services, processes, or u
sers. LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Auto Services] RemoteRegistry
### Internal Name: RemoteRegistry. Status: service is running. Actual File: C:
\WINDOWS\system32\svchost.exe -k LocalService * Enables remote users to modify r
egistry settings on this computer. If this service is stopped, the registry can
be modified only by users on this computer. If this service is disabled, any ser
vices that explicitly depend on it will fail to start. Generic Host Process for
Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5
512
[Auto Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File: C:\WINDOWS\
system32\svchost -k rpcss * Provides the endpoint mapper and other miscellaneous
RPC services. Generic Host Process for Win32 Services Microsoft Corporation Mic
rosoft Windows Operating System 5.1.2600.5512
[Auto Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File: C:\WINDOWS\
system32\lsass.exe * Stores security information for local user accounts. LSA Sh
ell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.5512
[Auto Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File: C:\WINDO
WS\System32\svchost.exe -k netsvcs * Enables a user to configure and schedule au
tomated tasks on this computer. If this service is stopped, these tasks will not
be run at their scheduled times. If this service is disabled, any services that
explicitly depend on it will fail to start. Generic Host Process for Win32 Serv
ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] seclogon
### Internal Name: seclogon. Status: service is running. Actual File: C:\WINDO

WS\System32\svchost.exe -k netsvcs * Enables starting processes under alternate


credentials. If this service is stopped, this type of logon access will be unava
ilable. If this service is disabled, any services that explicitly depend on it w
ill fail to start. Generic Host Process for Win32 Services Microsoft Corporation
Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] SENS
### Internal Name: SENS. Status: service is running. Actual File: C:\WINDOWS\s
ystem32\svchost.exe -k netsvcs * Tracks system events such as Windows logon, net
work, and power events. Notifies COM+ Event System subscribers of these events.
Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512
[Auto Services] SharedAccess
### Internal Name: SharedAccess. Status: service is running. Actual File: C:\W
INDOWS\system32\svchost.exe -k netsvcs * Provides network address translation, a
ddressing, name resolution and/or intrusion prevention services for a home or sm
all office network. Generic Host Process for Win32 Services Microsoft Corporatio
n Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Generic Host Process for Win32 Services Microsoft Corporation
Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] ShutdownService
### Internal Name: ShutdownService. Status: service is running. Actual File: C
:\Auto Shutdown Genius\ShutdownSvr.exe *
[Auto Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File: C:\WINDOW
S\system32\spoolsv.exe * Loads files to memory for later printing. Spooler SubSy
stem App Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6024
[Auto Services] srservice
### Internal Name: srservice. Status: service is running. Actual File: C:\WIND
OWS\system32\svchost.exe -k netsvcs * Performs system restore functions. To stop
service, turn off System Restore from the System Restore tab in My Computer->Pr
operties Generic Host Process for Win32 Services Microsoft Corporation Microsoft
Windows Operating System 5.1.2600.5512
[Auto Services] Themes
### Internal Name: Themes. Status: service is running. Actual File: C:\WINDOWS
\System32\svchost.exe -k netsvcs * Provides user experience theme management. Ge
neric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512
[Auto Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File: C:\WINDOWS
\system32\svchost.exe -k netsvcs * Maintains links between NTFS files within a c
omputer or across computers in a network domain. Generic Host Process for Win32
Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] W32Time
### Internal Name: W32Time. Status: service is running. Actual File: C:\WINDOW
S\System32\svchost.exe -k netsvcs * Maintains date and time synchronization on a
ll clients and servers in the network. If this service is stopped, date and time
synchronization will be unavailable. If this service is disabled, any services
that explicitly depend on it will fail to start.
Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512
[Auto Services] WebClient
### Internal Name: WebClient. Status: service is running. Actual File: C:\WIND
OWS\system32\svchost.exe -k LocalService * Enables Windows-based programs to cre
ate, access, and modify Internet-based files. If this service is stopped, these
functions will not be available. If this service is disabled, any services that
explicitly depend on it will fail to start. Generic Host Process for Win32 Servi
ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512

[Auto Services] winmgmt


### Internal Name: winmgmt. Status: service is running. Actual File: C:\WINDOW
S\system32\svchost.exe -k netsvcs * Provides a common interface and object model
to access management information about operating system, devices, applications
and services. If this service is stopped, most Windows-based software will not f
unction properly. If this service is disabled, any services that explicitly depe
nd on it will fail to start. Generic Host Process for Win32 Services Microsoft C
orporation Microsoft Windows Operating System 5.1.2600.5512
[Auto Services] wscsvc
### Internal Name: wscsvc. Status: service is running. Actual File: C:\WINDOWS
\System32\svchost.exe -k netsvcs * Monitors system security settings and configu
rations. Generic Host Process for Win32 Services Microsoft Corporation Microsoft
Windows Operating System 5.1.2600.5512
[Auto Services] wuauserv
### Internal Name: wuauserv. Status: service is running. Actual File: C:\WINDO
WS\system32\svchost.exe -k netsvcs * Enables the download and installation of Wi
ndows updates. If this service is disabled, this computer will not be able to us
e the Automatic Updates feature or the Windows Update Web site. Generic Host Pro
cess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Auto Services] WZCSVC
### Internal Name: WZCSVC. Status: service is running. Actual File: C:\WINDOWS
\System32\svchost.exe -k netsvcs * Provides automatic configuration for the 802.
11 adapters Generic Host Process for Win32 Services Microsoft Corporation Micros
oft Windows Operating System 5.1.2600.5512
[Auto Services] TuneUp.UtilitiesSvc
### Internal Name: TuneUp.UtilitiesSvc. Status: service is running. Actual Fil
e: "C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe" * This
service analyzes the usage of your computer in the background, enabling automati
c usage-dependent optimizations. All of its functions can be set in TuneUp Utili
ties. If you stop or disable this service, parts of TuneUp Utilities will not wo
rk anymore. TuneUp Utilities Service TuneUp Software TuneUp Utilities 2013 13.0.
2013.194
[Svchost DLLs] :HKLM HTTPFilter=C:\WINDOWS\SYSTEM32\W3SSL.DLL
### SSL service for HTTP Microsoft Corporation Internet Information Services 6
.0.2600.5512 C:\WINDOWS\SYSTEM32\W3SSL.DLL
[Svchost DLLs] :HKLM Alerter=C:\WINDOWS\SYSTEM32\ALRSVC.DLL
### Alerter Service DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 C:\WINDOWS\SYSTEM32\ALRSVC.DLL
[Svchost DLLs] :HKLM WebClient=C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
### Web DAV Service DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[Svchost DLLs] :HKLM LmHosts=C:\WINDOWS\SYSTEM32\LMHSVC.DLL
### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft Window
s Operating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\LMHSVC.DLL
[Svchost DLLs] :HKLM RemoteRegistry=C:\WINDOWS\SYSTEM32\REGSVC.DLL
### Remote Registry Service Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 C:\WINDOWS\SYSTEM32\REGSVC.DLL
[Svchost DLLs] :HKLM upnphost=C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
### UPnP Device Host Microsoft Corporation Microsoft Windows Operating System 5.
1.2600.5512 C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[Svchost DLLs] :HKLM SSDPSRV=C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
### SSDP Service DLL Microsoft Corporation Microsoft Windows Operating System 5.
1.2600.5512 C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[Svchost DLLs] :HKLM DnsCache=C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
### DNS Caching Resolver Service Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5797 C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
[Svchost DLLs] :HKLM 6to4
[Svchost DLLs] :HKLM AppMgmt=C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
### Software installation Service Microsoft Corporation Microsoft Windows Operat

ing System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\APPMGMTS.DLL


[Svchost DLLs] :HKLM AudioSrv=C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512 C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[Svchost DLLs] :HKLM Browser=C:\WINDOWS\SYSTEM32\BROWSER.DLL
### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.6260 C:\WINDOWS\SYSTEM32\BROWSER.DLL
[Svchost DLLs] :HKLM CryptSvc=C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512 C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[Svchost DLLs] :HKLM DMServer=C:\WINDOWS\SYSTEM32\DMSERVER.DLL
### Logical Disk Manager service dll Microsoft Corp. Logical Disk Manager for
Windows NT 1.0 C:\WINDOWS\SYSTEM32\DMSERVER.DLL
[Svchost DLLs] :HKLM DHCP=C:\WINDOWS\SYSTEM32\DHCPCSVC.DLL
### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 C:\WINDOWS\SYSTEM32\DHCPCSVC.DLL
[Svchost DLLs] :HKLM ERSvc=C:\WINDOWS\SYSTEM32\ERSVC.DLL
### Windows Error Reporting Service Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\ERSVC.DLL
[Svchost DLLs] :HKLM EventSystem=C:\WINDOWS\SYSTEM32\ES.DLL
### Microsoft Corporation COM Services 03.00.00.4414
[Svchost DLLs] :HKLM FastUserSwitchingCompatibility=C:\WINDOWS\SYSTEM32\SHSVCS
.DLL
### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating
System 6.00.2900.5853 C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[Svchost DLLs] :HKLM HidServ=%SystemRoot%\System32\hidserv.dll
[Svchost DLLs] :HKLM Ias
[Svchost DLLs] :HKLM Iprip
[Svchost DLLs] :HKLM Irmon
[Svchost DLLs] :HKLM LanmanServer=C:\WINDOWS\SYSTEM32\SRVSVC.DLL
### Server Service DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[Svchost DLLs] :HKLM LanmanWorkstation=C:\WINDOWS\SYSTEM32\WKSSVC.DLL
### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5826 C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[Svchost DLLs] :HKLM Messenger=C:\WINDOWS\SYSTEM32\MSGSVC.DLL
### NT Messenger Service Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512 C:\WINDOWS\SYSTEM32\MSGSVC.DLL
[Svchost DLLs] :HKLM Netman=C:\WINDOWS\SYSTEM32\NETMAN.DLL
### Network Connections Manager Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\NETMAN.DLL
[Svchost DLLs] :HKLM Nla=C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 5.1.2600.5625 C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
[Svchost DLLs] :HKLM Ntmssvc=C:\WINDOWS\SYSTEM32\NTMSSVC.DLL
### Removable Storage Manager Microsoft Corporation Microsoft Windows Whistler O
perating System 5.1.2400.5512 C:\WINDOWS\SYSTEM32\NTMSSVC.DLL
[Svchost DLLs] :HKLM NWCWorkstation
[Svchost DLLs] :HKLM Nwsapagent
[Svchost DLLs] :HKLM Rasauto=C:\WINDOWS\SYSTEM32\RASAUTO.DLL
### Remote Access AutoDial Manager Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[Svchost DLLs] :HKLM Rasman=C:\WINDOWS\SYSTEM32\RASMANS.DLL
### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\RASMANS.DLL
[Svchost DLLs] :HKLM Remoteaccess=C:\WINDOWS\SYSTEM32\MPRDIM.DLL
### Dynamic Interface Manager Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[Svchost DLLs] :HKLM Schedule=C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
### Task Scheduler Engine Microsoft Corporation Microsoft Windows Operating Syst

em 5.1.2600.5512 C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[Svchost DLLs] :HKLM Seclogon=C:\WINDOWS\SYSTEM32\SECLOGON.DLL
### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[Svchost DLLs] :HKLM SENS=C:\WINDOWS\SYSTEM32\SENS.DLL
### System Event Notification Service (SENS) Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\SENS.DLL
[Svchost DLLs] :HKLM Sharedaccess=C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[Svchost DLLs] :HKLM SRService=C:\WINDOWS\SYSTEM32\SRSVC.DLL
### System Restore Service Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512
[Svchost DLLs] :HKLM Tapisrv=C:\WINDOWS\SYSTEM32\TAPISRV.DLL
### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[Svchost DLLs] :HKLM Themes=C:\WINDOWS\SYSTEM32\SHSVCS.DLL
### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating
System 6.00.2900.5853 C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[Svchost DLLs] :HKLM TrkWks=C:\WINDOWS\SYSTEM32\TRKWKS.DLL
### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[Svchost DLLs] :HKLM W32Time=C:\WINDOWS\SYSTEM32\W32TIME.DLL
### Windows Time Service Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512
[Svchost DLLs] :HKLM WZCSVC=C:\WINDOWS\SYSTEM32\WZCSVC.DLL
### Wireless Zero Configuration Service Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\WZCSVC.DLL
[Svchost DLLs] :HKLM Wmi=C:\WINDOWS\SYSTEM32\ADVAPI32.DLL
### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5755 C:\WINDOWS\SYSTEM32\ADVAPI32.DLL
[Svchost DLLs] :HKLM WmdmPmSp
[Svchost DLLs] :HKLM winmgmt=C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[Svchost DLLs] :HKLM wscsvc=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
### Windows Security Center Service Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[Svchost DLLs] :HKLM xmlprov=C:\WINDOWS\SYSTEM32\XMLPROV.DLL
### Network Provisioning Service Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\XMLPROV.DLL
[Svchost DLLs] :HKLM napagent=C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
### Quarantine Agent Service Run-Time Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
[Svchost DLLs] :HKLM hkmsvc=C:\WINDOWS\SYSTEM32\KMSVC.DLL
### Key Management Service Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512 C:\WINDOWS\SYSTEM32\KMSVC.DLL
[Svchost DLLs] :HKLM BITS=C:\WINDOWS\SYSTEM32\QMGR.DLL
### Background Intelligent Transfer Service Microsoft Corporation Microsoft Win
dows Operating System 6.7.2600.5512
[Svchost DLLs] :HKLM wuauserv=C:\WINDOWS\SYSTEM32\WUAUSERV.DLL
### Windows Update AutoUpdate Service Microsoft Corporation Microsoft Windows Op
erating System 5.4.3790.5512
[Svchost DLLs] :HKLM ShellHWDetection=C:\WINDOWS\SYSTEM32\SHSVCS.DLL
### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating
System 6.00.2900.5853 C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[Svchost DLLs] :HKLM helpsvc=C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\PCHSVC.DLL
### Microsoft PCHealth Service Holder Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512 C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\PCHSVC.DLL
[Svchost DLLs] :HKLM WmdmPmSN=C:\WINDOWS\SYSTEM32\MSPMSNSV.DLL

### Microsoft Media Device Service Provider Microsoft Corporation Windows Medi
a Device Manager 9.0.1.56
[Svchost DLLs] :HKLM DcomLaunch=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5755 C:\WINDOWS\SYSTEM32\RPCSS.DLL
[Svchost DLLs] :HKLM TermService=C:\WINDOWS\SYSTEM32\TERMSRV.DLL
### Terminal Server Service Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 C:\WINDOWS\SYSTEM32\TERMSRV.DLL
[Svchost DLLs] :HKLM RpcSs=C:\WINDOWS\SYSTEM32\RPCSS.DLL
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5755 C:\WINDOWS\SYSTEM32\RPCSS.DLL
[Svchost DLLs] :HKLM eaphost=C:\WINDOWS\SYSTEM32\EAPSVC.DLL
### Microsoft EAPHost service Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[Svchost DLLs] :HKLM dot3svc=C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
### Wired AutoConfig Service Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5512 C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
[Svchost DLLs] :HKLM StiSvc=C:\WINDOWS\SYSTEM32\WIASERVC.DLL
### Still Image Devices Service Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[Bootexecute] :HKLM BootExecute=autocheck autochk *
Partizan
[Winlogon System] :HKLM system=""
### File is deleted or hidden by a rootkit or could not be located.
[Winlogon System] :HKLM taskman=""
### File is deleted or hidden by a rootkit or could not be located.
[Winlogon System] :HKLM UIHost=C:\WINDOWS\system32\LOGONUI.EXE
### Windows Logon UI Microsoft Corporation Microsoft Windows Operating System 6.
00.2900.5512 C:\WINDOWS\system32\LOGONUI.EXE
[Winlogon Autostart] :HKLM VmApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl
"
[Winlogon Autostart] :HKLM AppSetup=""
[KnownDLLs] :HKLM advapi32=advapi32.dll
[KnownDLLs] :HKLM comdlg32=comdlg32.dll
[KnownDLLs] :HKLM DllDirectory=%SystemRoot%\system32
[KnownDLLs] :HKLM gdi32=gdi32.dll
[KnownDLLs] :HKLM imagehlp=imagehlp.dll
[KnownDLLs] :HKLM kernel32=kernel32.dll
[KnownDLLs] :HKLM lz32=lz32.dll
[KnownDLLs] :HKLM ole32=ole32.dll
[KnownDLLs] :HKLM oleaut32=oleaut32.dll
[KnownDLLs] :HKLM olecli32=olecli32.dll
[KnownDLLs] :HKLM olecnv32=olecnv32.dll
[KnownDLLs] :HKLM olesvr32=olesvr32.dll
[KnownDLLs] :HKLM olethk32=olethk32.dll
[KnownDLLs] :HKLM rpcrt4=rpcrt4.dll
[KnownDLLs] :HKLM shell32=shell32.dll
[KnownDLLs] :HKLM url=url.dll
[KnownDLLs] :HKLM urlmon=urlmon.dll
[KnownDLLs] :HKLM user32=user32.dll
[KnownDLLs] :HKLM version=version.dll
[KnownDLLs] :HKLM wininet=wininet.dll
[KnownDLLs] :HKLM wldap32=wldap32.dll
[Environment - Path] :HKLM Path=%SystemRoot%\system32;%SystemRoot%;%SystemRoot
%\System32\Wbem
[List of Injected DLLs] :HKLM AppInit_DLLs=""
[LSA Notification Packages] :HKLM scecli=C:\WINDOWS\system32\SCECLI.DLL
### scecli Windows Security Configuration Editor Client Engine Microsoft Corpo
ration Microsoft Windows Operating System 5.1.2600.5512 C:\WINDOWS\system32\SCECL
I.DLL

[LSA Security Packages] :HKLM kerberos=C:\WINDOWS\system32\KERBEROS.DLL


### kerberos Kerberos Security Package Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.6059 C:\WINDOWS\system32\KERBEROS.DLL
[LSA Security Packages] :HKLM msv1_0=C:\WINDOWS\system32\MSV1_0.DLL
### msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation Microso
ft Windows Operating System 5.1.2600.5876 C:\WINDOWS\system32\MSV1_0.DLL
[LSA Security Packages] :HKLM schannel=C:\WINDOWS\system32\SCHANNEL.DLL
### schannel TLS / SSL Security Provider Microsoft Corporation Microsoft Window
s Operating System 5.1.2600.6239 C:\WINDOWS\system32\SCHANNEL.DLL
[LSA Security Packages] :HKLM wdigest=C:\WINDOWS\system32\WDIGEST.DLL
### wdigest Microsoft Digest Access Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5834 C:\WINDOWS\system32\WDIGEST.DLL
[Drivers] :HKLM ACPI=C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
### ACPI Driver for NT Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ACPIEC=C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEC.SYS
### ACPI Embedded Controller Driver Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM aec=C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
### Microsoft Acoustic Echo Canceller Microsoft Corporation Microsoft Windows Op
erating System 5.1.2601.3142 Service registry key doesn't exist or hidden.
[Drivers] :HKLM AFD=C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
### Ancillary Function Driver for WinSock Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.6142 C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS Service re
gistry key doesn't exist or hidden.
[Drivers] :HKLM ALCXWDM=C:\WINDOWS\SYSTEM32\DRIVERS\ALCXWDM.SYS
### Realtek AC'97 Audio Driver (WDM) Realtek Semiconductor Corp. Windows (R) W
DM driver for Realtek AC'97 Audio(HRTF data Copyright 1994 by MIT Media Lab) 5.1
0.00.6240 Service registry key doesn't exist or hidden.
[Drivers] :HKLM anvsnddrv=C:\WINDOWS\SYSTEM32\DRIVERS\ANVSNDDRV.SYS
### AnvSoft Virtual Audio Device AnvSoft Inc. AnvSoftVirtualSound 1, 2, 0, 00
Service registry key doesn't exist or hidden.
[Drivers] :HKLM AsyncMac=C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
### MS Remote Access serial network driver Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM atapi=C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
### IDE/ATAPI Port Driver Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Atmarpc=C:\WINDOWS\SYSTEM32\DRIVERS\ATMARPC.SYS
### IP/ATM Arp Client Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM audstub=C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS
### AudStub Driver Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM avgio=C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGIO.SYS
### Avira AntiVir Support for Minifilter Avira GmbH AntiVir 7.00.00.00 C:\PRO
GRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGIO.SYS Service registry key doesn't exist or
hidden.
[Drivers] :HKLM avgntflt=C:\WINDOWS\SYSTEM32\DRIVERS\AVGNTFLT.SYS
### Avira Minifilter Driver Avira GmbH AntiVir Workstation 10.00.08.07 Servic
e registry key doesn't exist or hidden.
[Drivers] :HKLM avipbb=C:\WINDOWS\SYSTEM32\DRIVERS\AVIPBB.SYS
### Avira Driver for Security Enhancement Avira GmbH AntiVir Desktop 10.00.32.
03 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Beep=C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS
### BEEP Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260
0.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM cbidf2k=C:\WINDOWS\SYSTEM32\DRIVERS\CBIDF2K.SYS
### CardBus/PCMCIA IDE Miniport Driver Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.0 Service registry key doesn't exist or hidden.

[Drivers] :HKLM Cdaudio=C:\WINDOWS\SYSTEM32\DRIVERS\CDAUDIO.SYS


### CD-ROM Audio Filter Driver Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Cdfs=C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
### CD-ROM File System Driver Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Cdrom=C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
### SCSI CD-ROM Driver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Disk=C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
### PnP Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dmboot=C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS
### NT Disk Manager Startup Driver Microsoft Corp., Veritas Software VERITAS NT
Disk Manager 1.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dmio=C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS
### NT Disk Manager I/O Driver Microsoft Corp., Veritas Software VERITAS NT Dis
k Manager 1.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM dmload=C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS
### NT Disk Manager Startup Driver Microsoft Corp., Veritas Software. Logical
Disk Manager for Windows NT 1.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM DMusic=C:\WINDOWS\SYSTEM32\DRIVERS\DMUSIC.SYS
### Microsoft Kernel DLS Synthesizer Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM drmkaud=C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
### Microsoft Kernel DRM Audio Descrambler Filter Microsoft Corporation Micros
oft Windows Operating System 5.1.2600.5512 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM Fastfat=C:\WINDOWS\SYSTEM32\DRIVERS\FASTFAT.SYS
### Fast FAT File System Driver Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Fdc=C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
### Floppy Disk Controller Driver Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Fips=C:\WINDOWS\SYSTEM32\DRIVERS\FIPS.SYS
### FIPS Crypto Driver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Flpydisk=C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
### Floppy Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM FltMgr=C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
### Microsoft Filesystem Filter Manager Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ftdisk=C:\WINDOWS\SYSTEM32\DRIVERS\FTDISK.SYS
### FT Disk Driver Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Gpc=C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS
### MS General Packet Classifier Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM hidusb=C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
### USB Miniport Driver for Input Devices Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM HTTP=C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
### HTTP Protocol Stack Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM i8042prt=C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
### i8042 Port Driver Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ialm=C:\WINDOWS\SYSTEM32\DRIVERS\IGXPMP32.SYS
### Intel Graphics Miniport Driver Intel Corporation Intel Graphics Accelerato

r Drivers for Windows NT(R) 6.14.10.4926 Service registry key doesn't exist or
hidden.
[Drivers] :HKLM Imapi=C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS
### IMAPI Kernel Driver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IntelIde=C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
### Intel PCI IDE Driver Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM intelppm=C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
### Processor Device Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ip6Fw=C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW.SYS
### IPv6 Windows Firewall Driver Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IpFilterDriver=C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
### IP FILTER DRIVER Microsoft Corporation Microsoft Windows Operating System 5.
1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IpInIp=C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS
### IP in IP Encapsulation Driver Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IpNat=C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
### IP Network Address Translator Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IPSec=C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS
### IPSec Driver Microsoft Corporation Microsoft Windows Operating System 5.1.26
00.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM IRENUM=C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
### Infra-Red Bus Enumerator Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM isapnp=C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
### PNP ISA Bus Driver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Kbdclass=C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
### Keyboard Class Driver Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM kbdhid=C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
### HID Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM kmixer=C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS
### Kernel Mode Audio Mixer Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM KSecDD=C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
### Kernel Security Support Provider Interface Microsoft Corporation Microsoft
Windows Operating System 5.1.2600.5834 Service registry key doesn't exist or hid
den.
[Drivers] :HKLM mnmdd=C:\WINDOWS\SYSTEM32\DRIVERS\MNMDD.SYS
### Frame buffer simulator Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Modem=C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
### Modem Device Driver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Mouclass=C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
### Mouse Class Driver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mouhid=C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
### HID Mouse Filter Driver Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MountMgr=C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
### Mount Manager Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512 Service registry key doesn't exist or hidden.

[Drivers] :HKLM MRxDAV=C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS


### Windows NT WebDav Minirdr Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MRxSmb=C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
### Windows NT SMB Minirdr Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.6133 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Msfs=C:\WINDOWS\SYSTEM32\DRIVERS\MSFS.SYS
### Mailslot driver Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSKSSRV=C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
### MS KS Server Microsoft Corporation Microsoft(R) Windows(R) Operating Syste
m 5.3.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSPCLOCK=C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
### MS Proxy Clock Microsoft Corporation Microsoft(R) Windows(R) Operating Sys
tem 5.3.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM MSPQM=C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
### MS Proxy Quality Manager Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM mssmbios=C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
### System Management BIOS Driver Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Mup=C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
### Multiple UNC Provider driver Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.6103 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NDIS=C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
### NDIS 5.1 wrapper driver Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisTapi=C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
### NDIS 3.0 connection wrapper driver Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.6132 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ndisuio=C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
### NDIS User mode I/O Driver Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NdisWan=C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
### MS PPP Framing Driver (Strong Encryption) Microsoft Corporation Microsoft W
indows Operating System 5.1.2600.5512 Service registry key doesn't exist or hidd
en.
[Drivers] :HKLM NDProxy=C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
### NDIS Proxy Microsoft Corporation Microsoft Windows Operating System 5.1.2600
.6484 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NetBIOS=C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
### NetBIOS interface driver Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NetBT=C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
### MBT Transport driver Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Npfs=C:\WINDOWS\SYSTEM32\DRIVERS\NPFS.SYS
### NPFS Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260
0.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ntfs=C:\WINDOWS\SYSTEM32\DRIVERS\NTFS.SYS
### NT File System Driver Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Null=C:\WINDOWS\SYSTEM32\DRIVERS\NULL.SYS
### NULL Driver Microsoft Corporation Microsoft Windows Operating System 5.1.260
0.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NwlnkFlt=C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFLT.SYS
### NWLINK2 Traffic Filter Driver Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM NwlnkFwd=C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFWD.SYS
### NWLINK2 Forwarder Driver Microsoft Corporation Microsoft Windows Operating S

ystem 5.1.2600.0 Service registry key doesn't exist or hidden.


[Drivers] :HKLM Parport=C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
### Parallel Port Driver Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Partizan=C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS
### Partizan - Rootkit detector Greatis Software RegRun Security Suite 6, 8, 0
, 0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PartMgr=C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
### Partition Manager Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ParVdm=C:\WINDOWS\SYSTEM32\DRIVERS\PARVDM.SYS
### VDM Parallel Driver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PCI=C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
### NT Plug and Play PCI Enumerator Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PCIIde=C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
### Generic PCI IDE Bus Driver Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Pcmcia=C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
### PCMCIA Bus Driver Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PptpMiniport=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
### Peer-to-Peer Tunneling Protocol Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM PSched=C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS
### MS QoS Packet Scheduler Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Ptilink=C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS
### Parallel Technologies DirectParallel IO Library Parallel Technologies, Inc
. Microsoft Windows Operating System 5.1.2600.0 Service registry key doesn't exis
t or hidden.
[Drivers] :HKLM RasAcd=C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
### RAS Automatic Connection Driver Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Rasl2tp=C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
### RAS L2TP mini-port/call-manager driver Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RasPppoe=C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
### RAS PPPoE mini-port/call-manager driver Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512 Service registry key doesn't exist or hidden
.
[Drivers] :HKLM Raspti=C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS
### PTI DirectParallel(R) mini-port/call-manager driver Microsoft Corporation
Microsoft Windows Operating System 5.1.2600.0 Service registry key doesn't exist
or hidden.
[Drivers] :HKLM RD9700=C:\WINDOWS\SYSTEM32\DRIVERS\RD9700.SYS
### Fast Ethernet USB Lan Adapter Corechip Semiconductor, Inc. Co Ltd. Fast Et
hernet USB Lan Adapter 1.2.1.2 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Rdbss=C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
### Redirected Drive Buffering SubSystem Driver Microsoft Corporation Microsof
t Windows Operating System 5.1.2600.5512 Service registry key doesn't exist or hi
dden.
[Drivers] :HKLM RDPCDD=C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS
### RDP Miniport Microsoft Corporation Microsoft Windows Operating System 5.1.26
00.0 Service registry key doesn't exist or hidden.
[Drivers] :HKLM rdpdr=C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
### Microsoft RDP Device redirector Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM RDPWD=C:\WINDOWS\SYSTEM32\DRIVERS\RDPWD.SYS

### RDP Terminal Stack Driver (US/Canada Only, Not for Export) Microsoft Corpo
ration Microsoft Windows Operating System 5.1.2600.6258 Service registry key does
n't exist or hidden.
[Drivers] :HKLM redbook=C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS
### Redbook Audio Filter Driver Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM rtl8139=C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.SYS
### Realtek RTL8139 NDIS 5.0 Driver Realtek Semiconductor Corporation Realtek
RTL8139 Family Fast Ethernet Adapter 5.398.613.2003 Service registry key doesn'
t exist or hidden.
[Drivers] :HKLM Secdrv=C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS
### Macrovision SECURITY Driver Macrovision Corporation, Macrovision Europe Li
mited, and Macrovision Japan and Asia K.K. Macrovision SECURITY Driver SECURITY
Driver 4.03.086 2006/09/13 Service registry key doesn't exist or hidden.
[Drivers] :HKLM serenum=C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
### Serial Port Enumerator Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Serial=C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
### Serial Device Driver Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Sfloppy=C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
### SCSI Floppy Driver Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM splitter=C:\WINDOWS\SYSTEM32\DRIVERS\SPLITTER.SYS
### Microsoft Kernel Audio Splitter Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM sr=C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS
### System Restore Filesystem Filter Driver Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512 Service registry key doesn't exist or hidden
.
[Drivers] :HKLM Srv=C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
### Server driver Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.6082 Service registry key doesn't exist or hidden.
[Drivers] :HKLM ssmdrv=C:\WINDOWS\SYSTEM32\DRIVERS\SSMDRV.SYS
### AVIRA SnapShot Driver Avira GmbH 7.00.02.02 Service registry key doesn't
exist or hidden.
[Drivers] :HKLM swenum=C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
### Plug and Play Software Device Enumerator Microsoft Corporation Microsoft(R
) Windows(R) Operating System 5.3.2600.5512 Service registry key doesn't exist
or hidden.
[Drivers] :HKLM swmidi=C:\WINDOWS\SYSTEM32\DRIVERS\SWMIDI.SYS
### Microsoft GS Wavetable Synthesizer Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM sysaudio=C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS
### System Audio WDM Filter Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Tcpip=C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
### TCP/IP Protocol Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5625 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TDPIPE=C:\WINDOWS\SYSTEM32\DRIVERS\TDPIPE.SYS
### Named Pipe Transport Driver Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TDTCP=C:\WINDOWS\SYSTEM32\DRIVERS\TDTCP.SYS
### TCP Transport Driver Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TermDD=C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS
### Terminal Server Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM TuneUpUtilitiesDrv=C:\PROGRAM FILES\TUNEUP UTILITIES 2013\TUNE
UPUTILITIESDRIVER32.SYS

### TuneUp Utilities Driver TuneUp Software TuneUp Utilities C:\PROGRAM FILES
\TUNEUP UTILITIES 2013\TUNEUPUTILITIESDRIVER32.SYS Service registry key doesn't
exist or hidden.
[Drivers] :HKLM Udfs=C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
### UDF File System Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Update=C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS
### Update Driver Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbccgp=C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
### USB Common Class Generic Parent Driver Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.6437 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbehci=C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
### EHCI eUSB Miniport Driver Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5778 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbhub=C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
### Default Hub Driver for USB Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbstor=C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
### USB Mass Storage Class Driver Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM usbuhci=C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
### UHCI USB Miniport Driver Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM VgaSave=C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS
### VGA/Super VGA Video Driver Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS Service registry key
doesn't exist or hidden.
[Drivers] :HKLM VolSnap=C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
### Volume Shadow Copy Driver Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM Wanarp=C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
### MS Remote Access and Routing ARP Driver Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512 Service registry key doesn't exist or hidden
.
[Drivers] :HKLM wdmaud=C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS
### MMSYSTEM Wave/Midi API mapper Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512 Service registry key doesn't exist or hidden.
[Drivers] :HKLM WS2IFSL=C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
### Winsock2 IFS Layer Microsoft Corporation Microsoft Windows Operating System
5.1.2600.0 C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS Service registry key doesn't
exist or hidden.
[Codecs] :HKLM midimapper=C:\WINDOWS\system32\MIDIMAP.DLL
### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512 C:\WINDOWS\system32\MIDIMAP.DLL
[Codecs] :HKLM msacm.imaadpcm=C:\WINDOWS\system32\IMAADP32.ACM
### IMA ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512 C:\WINDOWS\system32\IMAADP32.ACM
[Codecs] :HKLM msacm.msadpcm=C:\WINDOWS\system32\MSADP32.ACM
### Microsoft ADPCM CODEC for MSACM Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512 C:\WINDOWS\system32\MSADP32.ACM
[Codecs] :HKLM msacm.msg711=C:\WINDOWS\system32\MSG711.ACM
### Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM Microsoft Corporat
ion Microsoft Windows Operating System 5.1.2600.0 C:\WINDOWS\system32\MSG711.ACM
[Codecs] :HKLM msacm.msgsm610=C:\WINDOWS\system32\MSGSM32.ACM
### Microsoft GSM 6.10 Audio CODEC for MSACM Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.0 C:\WINDOWS\system32\MSGSM32.ACM
[Codecs] :HKLM msacm.trspch=C:\WINDOWS\system32\TSSOFT32.ACM
### DSP Group TrueSpeech(TM) Audio Codec for MSACM V3.50 DSP GROUP, INC. DSP G
ROUP Windows NT(TM) TrueSpeech CODEC 1.01 C:\WINDOWS\system32\TSSOFT32.ACM

[Codecs] :HKLM vidc.cvid=C:\WINDOWS\system32\ICCVID.DLL


### Cinepak Codec Radius Inc. Cinepak for Windows 32 1.10.0.0 C:\WINDOWS\syste
m32\ICCVID.DLL
[Codecs] :HKLM vidc.I420=C:\WINDOWS\system32\MSH263.DRV
### Microsoft H.263 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 C:
\WINDOWS\system32\MSH263.DRV
[Codecs] :HKLM vidc.iv31=C:\WINDOWS\system32\IR32_32.DLL
### C:\WINDOWS\system32\IR32_32.DLL
[Codecs] :HKLM vidc.iv32=C:\WINDOWS\system32\IR32_32.DLL
### C:\WINDOWS\system32\IR32_32.DLL
[Codecs] :HKLM vidc.iv41=C:\WINDOWS\system32\IR41_32.AX
### Intel Indeo Video 4.5 Intel Corporation Intel Indeo Video 4.5 4.51.16.03 C:
\WINDOWS\system32\IR41_32.AX
[Codecs] :HKLM vidc.iyuv=C:\WINDOWS\system32\IYUV_32.DLL
### Intel Indeo(R) Video YUV Codec Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5908 C:\WINDOWS\system32\IYUV_32.DLL
[Codecs] :HKLM vidc.mrle=C:\WINDOWS\system32\MSRLE32.DLL
### Microsoft RLE Compressor Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5908 C:\WINDOWS\system32\MSRLE32.DLL
[Codecs] :HKLM vidc.msvc=C:\WINDOWS\system32\MSVIDC32.DLL
### Microsoft Video 1 Compressor Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5908 C:\WINDOWS\system32\MSVIDC32.DLL
[Codecs] :HKLM vidc.uyvy=C:\WINDOWS\system32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo
ws(R) Operating System 5.3.2600.5908 C:\WINDOWS\system32\MSYUV.DLL
[Codecs] :HKLM vidc.yuy2=C:\WINDOWS\system32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo
ws(R) Operating System 5.3.2600.5908 C:\WINDOWS\system32\MSYUV.DLL
[Codecs] :HKLM vidc.yvu9=C:\WINDOWS\system32\TSBYUV.DLL
### Toshiba Video Codec Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5908 C:\WINDOWS\system32\TSBYUV.DLL
[Codecs] :HKLM vidc.yvyu=C:\WINDOWS\system32\MSYUV.DLL
### Microsoft UYVY Video Decompressor Microsoft Corporation Microsoft(R) Windo
ws(R) Operating System 5.3.2600.5908 C:\WINDOWS\system32\MSYUV.DLL
[Codecs] :HKLM wavemapper=C:\WINDOWS\system32\MSACM32.DRV
### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.0 C:\WINDOWS\system32\MSACM32.DRV
[Codecs] :HKLM msacm.msg723=C:\WINDOWS\system32\MSG723.ACM
### Microsoft G.723.1 CODEC for MSACM Microsoft Corporation Windows NetMeeting 3
.01 C:\WINDOWS\system32\MSG723.ACM
[Codecs] :HKLM vidc.M263=C:\WINDOWS\system32\MSH263.DRV
### Microsoft H.263 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 C:
\WINDOWS\system32\MSH263.DRV
[Codecs] :HKLM vidc.M261=C:\WINDOWS\system32\MSH261.DRV
### Microsoft H.261 ICM Driver Microsoft Corporation Windows NetMeeting 3.01 C:
\WINDOWS\system32\MSH261.DRV
[Codecs] :HKLM msacm.msaudio1=C:\WINDOWS\system32\MSAUD32.ACM
### Windows Media Audio Microsoft Corporation Windows Media Audio 8.00.00.4502
C:\WINDOWS\system32\MSAUD32.ACM
[Codecs] :HKLM msacm.sl_anet=C:\WINDOWS\system32\SL_ANET.ACM
### Audio codec for MS ACM Sipro Lab Telecom Inc. ACELP.net Audio Codec 3.02
C:\WINDOWS\system32\SL_ANET.ACM
[Codecs] :HKLM msacm.iac2=C:\WINDOWS\SYSTEM32\IAC25_32.AX
### Indeo audio software Intel Corporation Indeo audio software 2.05.53
[Codecs] :HKLM vidc.iv50=C:\WINDOWS\system32\IR50_32.DLL
### Intel Indeo video 5.10 Intel Corporation Intel Indeo video 5.10 R.5.10.15.2.
55 C:\WINDOWS\system32\IR50_32.DLL
[Codecs] :HKLM msacm.l3acm=C:\WINDOWS\SYSTEM32\L3CODECA.ACM
### MPEG Layer-3 Audio Codec for MSACM Fraunhofer Institut Integrierte Schaltu
ngen IIS MPEG Layer-3 Audio Codec for MSACM 1, 0, 0, 0

[Codecs] :HKLM wave=C:\WINDOWS\system32\WDMAUD.DRV


### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 C:\WINDOWS\system32\WDMAUD.DRV
[Codecs] :HKLM midi=C:\WINDOWS\system32\WDMAUD.DRV
### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 C:\WINDOWS\system32\WDMAUD.DRV
[Codecs] :HKLM mixer=C:\WINDOWS\system32\WDMAUD.DRV
### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 C:\WINDOWS\system32\WDMAUD.DRV
[Codecs] :HKLM VIDC.XVID=C:\WINDOWS\system32\XVIDVFW.DLL
### C:\WINDOWS\system32\XVIDVFW.DLL
[Codecs] :HKLM VIDC.YV12=C:\WINDOWS\system32\YV12VFW.DLL
### Helix YV12 YUV Codec www.helixcommunity.org Helix YV12 YUV Codec Helix YV1
2 YUV Codec C:\WINDOWS\system32\YV12VFW.DLL
[Codecs] :HKLM msacm.ac3acm=C:\WINDOWS\system32\AC3ACM.ACM
### AC-3 ACM Codec fccHandler AC-3 ACM Codec 1, 6, 0, 0 C:\WINDOWS\system32\A
C3ACM.ACM
[Codecs] :HKLM msacm.lameacm=C:\WINDOWS\system32\LAMEACM.ACM
### Lame MP3 codec engine http://www.mp3dev.org/ Lame MP3 codec 0.9.2 C:\WIND
OWS\system32\LAMEACM.ACM
[Codecs] :HKLM VIDC.FFDS=C:\WINDOWS\system32\FF_VFW.DLL
### C:\WINDOWS\system32\FF_VFW.DLL
[Codecs] :HKLM wave1=C:\WINDOWS\system32\WDMAUD.DRV
### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 C:\WINDOWS\system32\WDMAUD.DRV
[Codecs] :HKLM midi1=C:\WINDOWS\system32\WDMAUD.DRV
### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 C:\WINDOWS\system32\WDMAUD.DRV
[Codecs] :HKLM mixer1=C:\WINDOWS\system32\WDMAUD.DRV
### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512 C:\WINDOWS\system32\WDMAUD.DRV
[DCOM Components] :HKLM {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=C:\WINDOWS\SYST
EM32\WBEM\WBEMESS.DLL
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[DCOM Components] :HKLM {5839FCA9-774D-42A1-ACDA-D6A79037F57F}=C:\WINDOWS\SYST
EM32\WBEM\FASTPROX.DLL
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5755
[DCOM Components] :HKLM {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=C:\WINDOWS\SYST
EM32\SHDOCVW.DLL
### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window
s Operating System 6.00.2900.6452
[DCOM User Components] :HKCU {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}=""
[DCOM User Components] :HKCU {FBEB8A05-BEEE-4442-804E-409D6C4515E9}=""
[DCOM User Components] :HKCU {42AEDC87-2188-41FD-B9A3-0C966FEABEC1}=""
[Auto Start Apps]
[Registry Run] :HKCU IDMan=C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EX
E
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM)
5, 18, 8, 0 C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
[Registry Run] :HKCU ctfmon.exe=C:\WINDOWS\SYSTEM32\CTFMON.EXE
### CTF Loader Microsoft Corporation Microsoft Windows Operating System 5.1.2600
.5512
[Registry Run] :HKCU UnHackMe Monitor=C:\PROGRAM FILES\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 7.75
[Registry Run] :HKLM avgnt=C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGNT.EXE
### Antivirus System Tray Tool Avira GmbH AntiVir Desktop 10.00.13.18 C:\PROG
RAM FILES\AVIRA\ANTIVIR DESKTOP\AVGNT.EXE
[Registry Run] :HKLM IgfxTray=C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
### igfxTray Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926

[Registry Run] :HKLM HotKeysCmds=C:\WINDOWS\SYSTEM32\HKCMD.EXE


### hkcmd Module Intel Corporation Intel(R) Common User Interface 6.14.10.4926
[Registry Run] :HKLM Persistence=C:\WINDOWS\SYSTEM32\IGFXPERS.EXE
### persistence Module Intel Corporation Intel(R) Common User Interface 6.14.1
0.4926
[Registry RunOnceEx] :HKLM @UnHackMe=C:\PROGRA~1\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 7.90 C:\PROGRA~1\U
NHACKME\UNHACKME.EXE
[Win.ini] :HKCU load=""
### File is deleted or hidden by a rootkit or could not be located.
[Win.ini] :HKCU run=""
### File is deleted or hidden by a rootkit or could not be located.
[Common Startup Folder] Control & Monitor - Auto Shutdown Genius.lnk=C:\AUTO S
HUTDOWN GENIUS\CONTROLMONITOR.EXE
### Auto shutdown, stand by, turn off and reboot program LONKING SOFTWARE, LLC
. Auto Shutdown Genius 3.0.1.12
[Scheduled Tasks] WpsNotifyTask_xpsp3=C:\DOCUMENTS AND SETTINGS\XPSP3\LOCAL SE
TTINGS\APPLICATION DATA\KINGSOFT\WPS OFFICE\9.1.0.5234\WTOOLEX\WPSNOTIFY.EXE
### WPS Office Expansion tool Zhuhai Kingsoft Office Software Co.,Ltd WPS Offi
ce 9,1,0,5234
[Scheduled Tasks] WGASetup=C:\WINDOWS\SYSTEM32\KB905474\WGASETUP.EXE
### Windows Genuine Advantage Notifications Setup Microsoft Corporation Micros
oft Genuine Advantage 1.9.0040.0
[Scheduled Tasks] Opera scheduled Autoupdate 1453512555=C:\PROGRAM FILES\OPERA
\LAUNCHER.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Scheduled Tasks] Microsoft Windows XP End of Service Notification Monthly=C:\
WINDOWS\SYSTEM32\XP_EOS.EXE
### Windows XP End of Service notification Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.6526
[Scheduled Tasks] Microsoft Windows XP End of Service Notification Logon=C:\WI
NDOWS\SYSTEM32\XP_EOS.EXE
### Windows XP End of Service notification Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.6526
[Scheduled Tasks] WpsUpdateTask_xpsp3=C:\DOCUMENTS AND SETTINGS\XPSP3\LOCAL SE
TTINGS\APPLICATION DATA\KINGSOFT\WPS OFFICE\9.1.0.5234\WTOOLEX\WPSUPDATE.EXE
### WPS Office Expansion tool Zhuhai Kingsoft Office Software Co.,Ltd WPS Offi
ce 9,1,0,5234
[Detected using Heuristic Algorithm] :HKLM {C4ABDBC8-1C81-42C9-BFFC-4A68511E9E
4F}=C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{C4ABDBC8-1C81-42C9-BFF
C-4A68511E9E4F}\
### "{D3742F82-1C1A-4DCC-ABBD-0E831C0185CC}.MSI"
[Detected using Heuristic Algorithm] :HKLM ADOBE=C:\DOCUMENTS AND SETTINGS\ALL
USERS\APPLICATION DATA\ADOBE\
### "ACROBAT\" "ARM\" "SETUP\"
[Detected using Heuristic Algorithm] :HKLM AVIRA=C:\DOCUMENTS AND SETTINGS\ALL
USERS\APPLICATION DATA\AVIRA\
### "ANTIVIR DESKTOP\"
[Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\DOCUMENTS AND SETTI
NGS\ALL USERS\APPLICATION DATA\COMMON FILES\
### "E7A35917-BEE1-5D46-F954-4FD78E1AD587.DAT"
[Detected using Heuristic Algorithm] :HKLM IDM=C:\DOCUMENTS AND SETTINGS\ALL U
SERS\APPLICATION DATA\IDM\
[Detected using Heuristic Algorithm] :HKLM INSTALL-BLOCK=C:\DOCUMENTS AND SETT
INGS\ALL USERS\APPLICATION DATA\INSTALL-BLOCK\
### "BL.DAT" "BLD.DAT" "CF.DAT" "GS.DAT" "IBEN.DAT" "KF.DAT" "KL.DAT" "LOG.DA
T" "LOGTEMP.DAT" "NPM.DAT" "RF.DAT"
[Detected using Heuristic Algorithm] :HKLM KINGSOFT=C:\DOCUMENTS AND SETTINGS\
ALL USERS\APPLICATION DATA\KINGSOFT\

### "OFFICE6\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\DOCUMENTS AND SETTINGS
\ALL USERS\APPLICATION DATA\MICROSOFT\
### "CRYPTO\" "DR WATSON\" "HTML HELP\" "MEDIA INDEX\" "MEDIA PLAYER\" "NETWO
RK\" "USER ACCOUNT PICTURES\"
[Detected using Heuristic Algorithm] :HKLM REGRUN=C:\DOCUMENTS AND SETTINGS\AL
L USERS\APPLICATION DATA\REGRUN\
[Detected using Heuristic Algorithm] :HKLM TUNEUP SOFTWARE=C:\DOCUMENTS AND SE
TTINGS\ALL USERS\APPLICATION DATA\TUNEUP SOFTWARE\
### "TU2013\" "TUNEUP UTILITIES\" "TUNEUP UTILITIES 2013\"
[Detected using Heuristic Algorithm] :HKLM APPLICATION DATA=C:\DOCUMENTS AND S
ETTINGS\XPSP3\APPLICATION DATA\
### "ADOBE\" "ANVSOFT\" "AVIRA\" "DESKTOP.INI" "DMCACHE\" "GHISLER\" "IDENTIT
IES\" "IDM\" "KINGSOFT\" "MEDIA PLAYER CLASSIC\" "MICROSOFT\"
[Detected using Heuristic Algorithm] :HKLM ADOBE=C:\DOCUMENTS AND SETTINGS\XPS
P3\APPLICATION DATA\ADOBE\
### "ACROBAT\" "FLASH PLAYER\" "HEADLIGHTS\" "LINGUISTICS\" "LOGTRANSPORT2\"
[Detected using Heuristic Algorithm] :HKLM ANVSOFT=C:\DOCUMENTS AND SETTINGS\X
PSP3\APPLICATION DATA\ANVSOFT\
### "ANY VIDEO CONVERTER ULTIMATE\" "ANY VIDEO RECORDER\"
[Detected using Heuristic Algorithm] :HKLM AVIRA=C:\DOCUMENTS AND SETTINGS\XPS
P3\APPLICATION DATA\AVIRA\
### "ANTIVIR DESKTOP\"
[Detected using Heuristic Algorithm] :HKLM DMCACHE=C:\DOCUMENTS AND SETTINGS\X
PSP3\APPLICATION DATA\DMCACHE\
### "SETTINGS.BAK"
[Detected using Heuristic Algorithm] :HKLM GHISLER=C:\DOCUMENTS AND SETTINGS\X
PSP3\APPLICATION DATA\GHISLER\
### "WINCMD.INI"
[Detected using Heuristic Algorithm] :HKLM IDENTITIES=C:\DOCUMENTS AND SETTING
S\XPSP3\APPLICATION DATA\IDENTITIES\
### "{71074E96-60BF-4C8C-9F13-B17928F56E7B}\"
[Detected using Heuristic Algorithm] :HKLM IDM=C:\DOCUMENTS AND SETTINGS\XPSP3
\APPLICATION DATA\IDM\
### "DEFEXTMAP.DAT" "DWNLDATA\" "FOLDRESHISTORY.TXT" "GRABBER\" "IDMMZCC3\" "
SCHEDULER\" "URLEXCLIST.DAT" "URLHISTORY.TXT"
[Detected using Heuristic Algorithm] :HKLM KINGSOFT=C:\DOCUMENTS AND SETTINGS\
XPSP3\APPLICATION DATA\KINGSOFT\
### "OFFICE6\" "WPS\"
[Detected using Heuristic Algorithm] :HKLM MEDIA PLAYER CLASSIC=C:\DOCUMENTS A
ND SETTINGS\XPSP3\APPLICATION DATA\MEDIA PLAYER CLASSIC\
### "DEFAULT.MPCPL"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\DOCUMENTS AND SETTINGS
\XPSP3\APPLICATION DATA\MICROSOFT\
### "CREDENTIALS\" "CRYPTNETURLCACHE\" "CRYPTO\" "HTML HELP\" "IME12\" "IMJP1
2\" "IMJP8_1\" "IMJP9_0\" "INTERNET EXPLORER\" "MEDIA PLAYER\" "MMC\"
[Detected using Heuristic Algorithm] :HKLM OPERA SOFTWARE=C:\DOCUMENTS AND SET
TINGS\XPSP3\APPLICATION DATA\OPERA SOFTWARE\
### "OPERA STABLE\"
[Detected using Heuristic Algorithm] :HKLM TUNEUP SOFTWARE=C:\DOCUMENTS AND SE
TTINGS\XPSP3\APPLICATION DATA\TUNEUP SOFTWARE\
### "TU2013\" "TUNEUP UTILITIES\"
[Detected using Heuristic Algorithm] :HKLM WINRAR=C:\DOCUMENTS AND SETTINGS\XP
SP3\APPLICATION DATA\WINRAR\
### "VERSION.DAT"
[Detected using Heuristic Algorithm] :HKLM COOKIES=C:\DOCUMENTS AND SETTINGS\X
PSP3\COOKIES\
### "INDEX.DAT" "XPSP3@AUTO.SEARCH.MSN[1].TXT" "XPSP3@BING[1].TXT" "XPSP3@BLO
GGER[1].TXT" "XPSP3@CXENSE[1].TXT" "XPSP3@D.CPSOFT86[2].TXT" "XPSP3@GOMLAB[1].TX
T" "XPSP3@GOOGLE.CO[2].TXT" "XPSP3@GOOGLE[1].TXT" "XPSP3@INFO.GOMLAB[2].TXT" "XP

SP3@MASTERKREATIF[2].TXT"
[Detected using Heuristic Algorithm] :HKLM DESKTOP=C:\DOCUMENTS AND SETTINGS\X
PSP3\DESKTOP\
### "ANY VIDEO CONVERTER ULTIMATE.LNK" "COUNTER STRIKE 1.6 NO STEAM.LNK" "DED
ICATED SERVER.LNK" "OPERA_NI_STABLE.EXE" "STOP INSTALLATION TOOL.LNK" "TOTAL COM
MANDER.LNK" "TU.2013.V13.0.2013.194\" "UNHACKME.LNK" "WPS PRESENTATION.LNK" "WPS
SPREADSHEETS.LNK" "WPS WRITER.LNK"
[Detected using Heuristic Algorithm] :HKLM FAVORITES=C:\DOCUMENTS AND SETTINGS
\XPSP3\FAVORITES\
### "DESKTOP.INI" "LINKS\" "MICROSOFT WEBSITES\" "MSN.COM.URL" "RADIO STATION
GUIDE.URL"
[Detected using Heuristic Algorithm] :HKLM IETLDCACHE=C:\DOCUMENTS AND SETTING
S\XPSP3\IETLDCACHE\
### "INDEX.DAT"
[Detected using Heuristic Algorithm] :HKLM LOCAL SETTINGS=C:\DOCUMENTS AND SET
TINGS\XPSP3\LOCAL SETTINGS\
### "APPLICATION DATA\" "DESKTOP.INI" "HISTORY\" "TEMP\" "TEMPORARY INTERNET
FILES\"
[Detected using Heuristic Algorithm] :HKLM ADOBE=C:\DOCUMENTS AND SETTINGS\XPS
P3\LOCAL SETTINGS\APPLICATION DATA\ADOBE\
### "ACROBAT\" "COLOR\"
[Detected using Heuristic Algorithm] :HKLM GHISLER=C:\DOCUMENTS AND SETTINGS\X
PSP3\LOCAL SETTINGS\APPLICATION DATA\GHISLER\
[Detected using Heuristic Algorithm] :HKLM KINGSOFT=C:\DOCUMENTS AND SETTINGS\
XPSP3\LOCAL SETTINGS\APPLICATION DATA\KINGSOFT\
### "WPS CLOUD FILES\" "WPS OFFICE\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT=C:\DOCUMENTS AND SETTINGS
\XPSP3\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\
### "CD BURNING\" "CREDENTIALS\" "FEEDS\" "FEEDS CACHE\" "HELPCTR\" "IME12\"
"IMJP12\" "IMJP8_1\" "IMJP9_0\" "INTERNET EXPLORER\" "MEDIA PLAYER\"
[Detected using Heuristic Algorithm] :HKLM OPERA SOFTWARE=C:\DOCUMENTS AND SET
TINGS\XPSP3\LOCAL SETTINGS\APPLICATION DATA\OPERA SOFTWARE\
### "OPERA STABLE\"
[Detected using Heuristic Algorithm] :HKLM TEMP=C:\DOCUMENTS AND SETTINGS\XPSP
3\LOCAL SETTINGS\APPLICATION DATA\TEMP\
### "ADOBE\"
[Detected using Heuristic Algorithm] :HKLM MY DOCUMENTS=C:\DOCUMENTS AND SETTI
NGS\XPSP3\MY DOCUMENTS\
### "ANY VIDEO CONVERTER ULTIMATE\" "CERAMAH AGAMA - PENGAJIAN GUS MUS.3GP" "
DESKTOP.INI" "DOWNLOADS\" "HITMAN-AGENT-47_INDONESIAN-1225911.ZIP" "HITMAN-AGENT
-47_INDONESIAN-1226865.ZIP" "INSTALL BLOCK 2.06 FULL.RAR" "MY MUSIC\" "MY PICTUR
ES\" "MY VIDEOS\" "PENGAJIAN GUS MUS TERBARU PALING LUCU 2015 KENAPA INGIN SURGA
TAKUT NERAKA CERAMAH GUS MUSTOFA BISRI.3GP"
[Detected using Heuristic Algorithm] :HKLM NETHOOD=C:\DOCUMENTS AND SETTINGS\X
PSP3\NETHOOD\
### "DATA KURIKULUM ON MAT\" "HA IL TIRTA 4 ON MAT\" "KESISWAAN ON USER\" "KU
S ON USER-PC\" "PAI 8 ON USER-PC\" "SKL SKL SKL_UN ON MAT\" "USERS ON DELL_SAPTO
\" "USERS ON MAT\" "USERS ON USER\" "XXX ON DELL_SAPTO\"
[Detected using Heuristic Algorithm] :HKLM PRINTHOOD=C:\DOCUMENTS AND SETTINGS
\XPSP3\PRINTHOOD\
[Detected using Heuristic Algorithm] :HKLM RECENT=C:\DOCUMENTS AND SETTINGS\XP
SP3\RECENT\
### "2015-2016.LNK" "AVI.LNK" "DAFNILAKMUL.LNK" "DESKTOP.INI" "FAST.AND.FURIO
US.7.2015.720P.HDRIP.900MB.GANOOL.LNK" "FAST.AND.FURIOUS.7.2015.DVDRIP.600MB.GAN
OOL.COM.LNK" "FF7.LNK" "HITMAN AGENT 47 (2015) 720P BRRIP X264 YIFY.LNK" "HITMAN
.AGENT.47.2015.720P.BLURAY.X264.YIFY.LNK" "HITMAN.AGENT.47.2015.DVDRIP.XVID-ETRG
.LNK" "HITMAN.AGENT.47.2015.LNK"
[Detected using Heuristic Algorithm] :HKLM SENDTO=C:\DOCUMENTS AND SETTINGS\XP
SP3\SENDTO\
### "COMPRESSED (ZIPPED) FOLDER.ZFSENDTOTARGET" "DESKTOP (CREATE SHORTCUT).DE

SKLINK" "DESKTOP.INI" "MAIL RECIPIENT.MAPIMAIL" "MY DOCUMENTS.MYDOCS"


[Detected using Heuristic Algorithm] :HKLM START MENU=C:\DOCUMENTS AND SETTING
S\XPSP3\START MENU\
### "DESKTOP.INI" "PROGRAMS\"
[Detected using Heuristic Algorithm] :HKLM TEMPLATES=C:\DOCUMENTS AND SETTINGS
\XPSP3\TEMPLATES\
### "AMIPRO.SAM" "EXCEL.XLS" "EXCEL4.XLS" "LOTUS.WK4" "POWERPNT.PPT" "PRESENT
A.SHW" "QUATTRO.WB2" "SNDREC.WAV" "WINWORD.DOC" "WINWORD2.DOC" "WORDPFCT.WPD"
[Detected using Heuristic Algorithm] :HKLM ADOBE=C:\PROGRAM FILES\ADOBE\
### "READER 10.0\"
[Detected using Heuristic Algorithm] :HKLM ANVSOFT=C:\PROGRAM FILES\ANVSOFT\
### "ANY VIDEO CONVERTER ULTIMATE\"
[Detected using Heuristic Algorithm] :HKLM AVIRA=C:\PROGRAM FILES\AVIRA\
### "ANTIVIR DESKTOP\"
[Detected using Heuristic Algorithm] :HKLM BASH SOFTWARE=C:\PROGRAM FILES\BASH
SOFTWARE\
### "INSTALL-BLOCK\"
[Detected using Heuristic Algorithm] :HKLM CHEATING-DEATH=C:\PROGRAM FILES\CHE
ATING-DEATH\
### "4.32.0\" "CDEATH.EXE" "CDEATH.INI" "CDEULA.TXT" "README.HTM" "UADOC.CSS"
"UNINSTCD.EXE"
[Detected using Heuristic Algorithm] :HKLM COMMON FILES=C:\PROGRAM FILES\COMMO
N FILES\
### "ADOBE\" "INSTALLSHIELD\" "MICROSOFT SHARED\" "MSSOAP\" "ODBC\" "SERVICES
\" "SPEECHENGINES\" "SYSTEM\"
[Detected using Heuristic Algorithm] :HKLM ADOBE=C:\PROGRAM FILES\COMMON FILES
\ADOBE\
### "ACROBAT\" "ARM\" "HELP\" "HELPCFG\"
[Detected using Heuristic Algorithm] :HKLM INSTALLSHIELD=C:\PROGRAM FILES\COMM
ON FILES\INSTALLSHIELD\
### "PROFESSIONAL\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT SHARED=C:\PROGRAM FILES\C
OMMON FILES\MICROSOFT SHARED\
### "DAO\" "MSINFO\" "SPEECH\" "STATIONERY\" "TEXTCONV\" "TRIEDIT\" "VC\" "VG
X\" "WEB FOLDERS\" "WEB SERVER EXTENSIONS\"
[Detected using Heuristic Algorithm] :HKLM MSSOAP=C:\PROGRAM FILES\COMMON FILE
S\MSSOAP\
### "BINARIES\"
[Detected using Heuristic Algorithm] :HKLM ODBC=C:\PROGRAM FILES\COMMON FILES\
ODBC\
### "DATA SOURCES\"
[Detected using Heuristic Algorithm] :HKLM SERVICES=C:\PROGRAM FILES\COMMON FI
LES\SERVICES\
### "BIGFOOT.BMP" "VERISIGN.BMP" "WHOWHERE.BMP"
[Detected using Heuristic Algorithm] :HKLM SPEECHENGINES=C:\PROGRAM FILES\COMM
ON FILES\SPEECHENGINES\
### "MICROSOFT\"
[Detected using Heuristic Algorithm] :HKLM SYSTEM=C:\PROGRAM FILES\COMMON FILE
S\SYSTEM\
### "ADO\" "DIRECTDB.DLL" "MSADC\" "OLE DB\" "WAB32.DLL" "WAB32RES.DLL"
[Detected using Heuristic Algorithm] :HKLM COMPLUS APPLICATIONS=C:\PROGRAM FIL
ES\COMPLUS APPLICATIONS\
[Detected using Heuristic Algorithm] :HKLM COUNTER-STRIKE 1.6=C:\PROGRAM FILES
\COUNTER-STRIKE 1.6\
### "A3DAPI.DLL" "C-D\" "CORE.DLL" "CSTRIKE\" "DBG.DLL" "DEMOPLAYER.DLL" "FIL
ESYSTEM_STDIO.DLL" "FILESYSTEM_STEAM.DLL" "GLDRV\" "HL.EXE" "HL.ICO"
[Detected using Heuristic Algorithm] :HKLM GRETECH=C:\PROGRAM FILES\GRETECH\
[Detected using Heuristic Algorithm] :HKLM INSTALLSHIELD INSTALLATION INFORMAT
ION=C:\PROGRAM FILES\INSTALLSHIELD INSTALLATION INFORMATION\
### "{8F1A2017-DF3D-44D3-BE79-C616CF5946D3}\" "{F132AF7F-7BCA-4EDE-8A7C-95810

8FE7DBC}\"
[Detected using Heuristic Algorithm] :HKLM INTERNET DOWNLOAD MANAGER=C:\PROGRA
M FILES\INTERNET DOWNLOAD MANAGER\
### "DEFEXCLIST.TXT" "DOWNLWITHIDM.DLL" "GLOBALERRORS.LOG" "GRABBER.CHM" "IDM
AN.CHM" "IDMAN.EXE" "IDMAN.EXE.BAK" "IDMANTYPEINFO.TLB" "IDMBRBTN.DLL" "IDMFSA.D
LL" "IDMFTYPE.DLL"
[Detected using Heuristic Algorithm] :HKLM INTERNET EXPLORER=C:\PROGRAM FILES\
INTERNET EXPLORER\
### "CONNECTION WIZARD\" "EN-US\" "EXTEXPORT.EXE" "HMMAPI.DLL" "IE8PROPS.PROP
DESC" "IECOMPAT.DLL" "IEDVTOOL.DLL" "IEDW.EXE" "IEPROXY.DLL" "IEXPLORE.EXE" "IEX
PLORE.EXE.MUI"
[Detected using Heuristic Algorithm] :HKLM K-LITE CODEC PACK=C:\PROGRAM FILES\
K-LITE CODEC PACK\
### "FFDSHOW\" "FILTERS\" "ICONS\" "INFO\" "INSTALL.LOG" "MEDIA PLAYER CLASSI
C\" "PSVINCE.DLL" "TOOLS\" "UNINS000.DAT" "UNINS000.EXE"
[Detected using Heuristic Algorithm] :HKLM MESSENGER=C:\PROGRAM FILES\MESSENGE
R\
### "CUSTSAT.DLL" "LOGOWIN.GIF" "LVBACK.GIF" "MSGSC.DLL" "MSGSLANG.DLL" "MSMS
GS.EXE" "NEWALERT.WAV" "NEWEMAIL.WAV" "ONLINE.WAV" "TYPE.WAV" "XPMSGR.CHM"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT FRONTPAGE=C:\PROGRAM FILE
S\MICROSOFT FRONTPAGE\
### "VERSION3.0\"
[Detected using Heuristic Algorithm] :HKLM MICROSOFT OFFICE=C:\PROGRAM FILES\M
ICROSOFT OFFICE\
### "OFFICE\"
[Detected using Heuristic Algorithm] :HKLM MOVIE MAKER=C:\PROGRAM FILES\MOVIE
MAKER\
### "MOVIEMK.EXE" "MUI\" "SHARED\" "WMM2AE.DLL" "WMM2ERES.DLL" "WMM2EXT.DLL"
"WMM2FILT.DLL" "WMM2FXA.DLL" "WMM2FXB.DLL" "WMM2RES.DLL" "WMM2RES2.DLL"
[Detected using Heuristic Algorithm] :HKLM MSN=C:\PROGRAM FILES\MSN\
### "MSNCOREFILES\"
[Detected using Heuristic Algorithm] :HKLM MSN GAMING ZONE=C:\PROGRAM FILES\MS
N GAMING ZONE\
### "WINDOWS\"
[Detected using Heuristic Algorithm] :HKLM NETMEETING=C:\PROGRAM FILES\NETMEET
ING\
### "BLIP.WAV" "CALLCONT.DLL" "CB32.EXE" "CONF.EXE" "CONFMRSL.DLL" "DCAP32.DL
L" "H323CC.DLL" "MST120.DLL" "MST123.DLL" "NAC.DLL" "NETMEET.HTM"
[Detected using Heuristic Algorithm] :HKLM ONLINE SERVICES=C:\PROGRAM FILES\ON
LINE SERVICES\
### "REFER ME TO MORE INTERNET SERVICE PROVIDERS.LNK" "USE MSN EXPLORER TO SI
GN UP FOR INTERNET ACCESS (US ONLY).LNK"
[Detected using Heuristic Algorithm] :HKLM OPERA=C:\PROGRAM FILES\OPERA\
### "34.0.2036.36\" "ASSETS\" "INSTALLATION_STATUS.XML" "INSTALLER_PREFS.JSON
" "LAUNCHER.EXE" "LAUNCHER.VISUALELEMENTSMANIFEST.XML" "RESOURCES.PRI" "SERVER_T
RACKING_DATA"
[Detected using Heuristic Algorithm] :HKLM OUTLOOK EXPRESS=C:\PROGRAM FILES\OU
TLOOK EXPRESS\
### "MSIMN.EXE" "MSOE.DLL" "MSOE.TXT" "MSOERES.DLL" "OEIMPORT.DLL" "OEMIG50.E
XE" "OEMIGLIB.DLL" "SETUP50.EXE" "WAB.EXE" "WABFIND.DLL" "WABIMP.DLL"
[Detected using Heuristic Algorithm] :HKLM REALTEK=C:\PROGRAM FILES\REALTEK\
### "AUDIO\" "INSTALLSHIELD\"
[Detected using Heuristic Algorithm] :HKLM STOP SOFTWARE INSTALLATION TOOL=C:\
PROGRAM FILES\STOP SOFTWARE INSTALLATION TOOL\
### "DF_X64.SYS" "DF_X86.SYS" "DRV.DLL" "INSTDRV32.EXE" "INSTDRV64.EXE" "LICE
NSE.DAT" "LICENSE.TXT" "README.TXT" "SCHOME.URL" "STOPINST.DAT" "STOPINST.EXE"
[Detected using Heuristic Algorithm] :HKLM TUNEUP UTILITIES 2013=C:\PROGRAM FI
LES\TUNEUP UTILITIES 2013\
### "APPINITIALIZATION.BPL" "APPINITIALIZATION.BPL.BAK" "AUTHUITU-X86.DLL" "A
VGREPLIBX.DLL" "BROWSERCLEANER.EXE" "CEFCOMPONENT.BPL" "COMMONFORMS.BPL" "COMMON

FORMS.BPL.BAK" "CXLIBRARYD12.BPL" "DATA\" "DBRTL120.BPL"


[Detected using Heuristic Algorithm] :HKLM UNHACKME=C:\PROGRAM FILES\UNHACKME\
### "7ZA.EXE" "APPDATA.INI" "DATABASE.RDB" "DBS.DB" "DBS.INI" "DBS.ZIP" "DBSW
WW.INI" "GWEBUPDATE.EXE" "HACKMON.EXE" "JSONFAST.DLL" "LICENSE.TXT"
[Detected using Heuristic Algorithm] :HKLM UNINSTALL INFORMATION=C:\PROGRAM FI
LES\UNINSTALL INFORMATION\
[Detected using Heuristic Algorithm] :HKLM WINDOWS MEDIA PLAYER=C:\PROGRAM FIL
ES\WINDOWS MEDIA PLAYER\
### "CUSTSAT.DLL" "ICONS\" "MIGRATE.EXE" "MPLAYER2.EXE" "MPVIS.DLL" "NPDRMV2.
DLL" "NPDRMV2.ZIP" "NPDS.ZIP" "NPDSPLAY.DLL" "NPWMSDRM.DLL" "SAMPLE PLAYLISTS\"
[Detected using Heuristic Algorithm] :HKLM WINDOWS NT=C:\PROGRAM FILES\WINDOWS
NT\
### "ACCESSORIES\" "DIALER.EXE" "HTRN_JIS.DLL" "HYPERTRM.EXE" "PINBALL\"
[Detected using Heuristic Algorithm] :HKLM WINDOWSUPDATE=C:\PROGRAM FILES\WIND
OWSUPDATE\
[Detected using Heuristic Algorithm] :HKLM WINRAR=C:\PROGRAM FILES\WINRAR\
### "DEFAULT.SFX" "DESCRIPT.ION" "FILE_ID.DIZ" "FORMATS\" "LICENSE.TXT" "ORDE
R.HTM" "RAR.EXE" "RAR.TXT" "RAREXT.DLL" "RAREXT64.DLL" "RAREXTLOADER.EXE"
[Detected using Heuristic Algorithm] :HKLM XEROX=C:\PROGRAM FILES\XEROX\
### "NWWIA\"
[In memory]
[Running Processes] C:\WINDOWS\SYSTEM32\SMSS.EXE
### Windows NT Session Manager Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\CSRSS.EXE
### Client Server Runtime Process Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\WINLOGON.EXE
### Windows NT Logon Application Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\SERVICES.EXE
### Services and Controller app Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5755
[Running Processes] C:\WINDOWS\SYSTEM32\LSASS.EXE
### LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512
[Running Processes] C:\WINDOWS\EXPLORER.EXE
### Windows Explorer Microsoft Corporation Microsoft Windows Operating System 6.
00.2900.5512
[Running Processes] C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
### Spooler SubSystem App Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.6024
[Running Processes] C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGUARD.EXE
### Antivirus On-Access Service Avira GmbH AntiVir Desktop 10.00.01.58
[Running Processes] C:\DOCUMENTS AND SETTINGS\XPSP3\LOCAL SETTINGS\APPLICATION

DATA\KINGSOFT\WPS OFFICE\9.1.0.5234\WTOOLEX\WPSUPDATESVR.EXE
### WPS Office Expansion tool Zhuhai Kingsoft Office Software Co.,Ltd WPS Offi
ce 9,1,0,5234
[Running Processes] C:\AUTO SHUTDOWN GENIUS\SHUTDOWNSVR.EXE
[Running Processes] C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVSHADOW.EXE
### AntiVir shadow copy service Avira GmbH AntiVir Desktop 1.0.0.6
[Running Processes] C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGNT.EXE
### Antivirus System Tray Tool Avira GmbH AntiVir Desktop 10.00.13.18
[Running Processes] C:\WINDOWS\SOUNDMAN.EXE
### Realtek Sound Manager Realtek Semiconductor Corp. Realtek HD Sound Manager
1, 0, 0, 30
[Running Processes] C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
### igfxTray Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Running Processes] C:\WINDOWS\SYSTEM32\HKCMD.EXE
### hkcmd Module Intel Corporation Intel(R) Common User Interface 6.14.10.4926
[Running Processes] C:\WINDOWS\SYSTEM32\IGFXPERS.EXE
### persistence Module Intel Corporation Intel(R) Common User Interface 6.14.1
0.4926
[Running Processes] C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE
### igfxsrvc Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Running Processes] C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
### Internet Download Manager (IDM) Tonec Inc. Internet Download Manager (IDM)
5, 18, 8, 0
[Running Processes] C:\AUTO SHUTDOWN GENIUS\CONTROLMONITOR.EXE
### Auto shutdown, stand by, turn off and reboot program LONKING SOFTWARE, LLC
. Auto Shutdown Genius 3.0.1.12
[Running Processes] C:\WINDOWS\SYSTEM32\WSCNTFY.EXE
### Windows Security Center Notification App Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\ALG.EXE
### Application Layer Gateway Service Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Running Processes] C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEMONITOR.EXE
### Internet Download Manager agent for click monitoring in IE-based browsers
Tonec Inc. IEMonitor Application 5, 18, 4, 0
[Running Processes] C:\PROGRAM FILES\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
### Adobe Reader and Acrobat Manager Adobe Systems Incorporated Adobe Reader a
nd Acrobat Manager 1.824.16.6751
[Running Processes] C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\SCHED.EXE
### Antivirus Scheduler Avira GmbH AntiVir Desktop 10.00.00.21
[Running Processes] C:\WINDOWS\SYSTEM32\CMD.EXE
### Windows Command Processor Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\PING.EXE
### TCP/IP Ping Command Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\DLLHOST.EXE
### COM Surrogate Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512
[Running Processes] C:\WINDOWS\SYSTEM32\CTFMON.EXE
### CTF Loader Microsoft Corporation Microsoft Windows Operating System 5.1.2600
.5512
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA_CRASHREPORTER.EX
E
### Opera crash-reporter Opera Software Opera crash-reporter 34.0.2036.36

[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE


### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\PROGRAM FILES\BASH SOFTWARE\INSTALL-BLOCK\BSIBR.EXE
### Bash Software Install-Block 2.00.0006
[Running Processes] C:\PROGRAM FILES\TUNEUP UTILITIES 2013\TUNEUPUTILITIESSERV
ICE32.EXE
### TuneUp Utilities Service TuneUp Software TuneUp Utilities 2013 13.0.2013.1
94
[Running Processes] C:\PROGRAM FILES\TUNEUP UTILITIES 2013\TUNEUPUTILITIESAPP3
2.EXE
### TuneUp Utilities TuneUp Software TuneUp Utilities 2013 13.0.2013.194
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
### Opera Internet Browser Opera Software Opera Internet Browser 34.0.2036.36
[Running Processes] C:\WINDOWS\SYSTEM32\MSDTC.EXE
### MS DTC console program Microsoft Corporation Microsoft Distributed Transac
tion Coordinator 03.01.00.4414
[Running Processes] C:\WINDOWS\SYSTEM32\SVCHOST.EXE
### Generic Host Process for Win32 Services Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512
[Running Processes] C:\PROGRAM FILES\UNHACKME\HACKMON.EXE
### Detects Rootkits in background Greatis Software UnHackMe 7.75
[Running Processes] C:\PROGRAM FILES\UNHACKME\UNHACKME.EXE
### Detects and removes rootkits Greatis Software UnHackMe 7.90
[Running Processes] C:\TOTALCMD\TOTALCMD.EXE
### Total Commander 32 bit Ghisler Software GmbH Total Commander 7.56
[Running Processes] C:\PROGRAM FILES\UNHACKME\REANIMATOR.EXE
### RegRun Start Control Greatis Software RegRun Security Suite 7.90
[Loaded DLLs] C:\WINDOWS\system32\ieframe.dll
### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001
.18702
[Loaded DLLs] C:\Program Files\UnHackMe\jsonfast.dll
### JSON processing DLL Greatis Software LLC RegRun Suite 7.80
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\Program Files\UnHackMe\parser.dll
### Analytics Parser Greatis Software UnHackMe 7.65
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] c:\windows\system32\webclnt.dll
### Web DAV Service DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\MTxOCI.Dll
### Microsoft database support DLL for Oracle Microsoft Corporation COM Servic

es 03.01.00.4414
[Loaded DLLs] C:\WINDOWS\system32\MSDTCLOG.dll
### MS DTC log manager DLL Microsoft Corporation Microsoft Distributed Transac
tion Coordinator 03.01.00.4414
[Loaded DLLs] C:\WINDOWS\system32\MSDTCTM.dll
### MS DTC transaction manager DLL Microsoft Corporation Microsoft Distributed
Transaction Coordinator 03.01.00.4414
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\Program Files\TuneUp Utilities 2013\TUTuningIndex.dll
### TuneUp Tuning Index TuneUp Software TuneUp Utilities 2013 13.0.2013.194
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\ieframe.dll
### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001
.18702
[Loaded DLLs] C:\WINDOWS\system32\dscbtshl.dll
### dscbtshl Delphin Software Delphin Software dscbtshl 1, 0, 0, 4
[Loaded DLLs] C:\WINDOWS\system32\MSWINSCK.OCX
### Microsoft Winsock Control DLL Microsoft Corporation Microsoft Winsock Cont
rol 6.00.8988
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\OutlookBar.ocx
### OutlookBar Control UniCont Soft OutlookBar Control 1.03.0002
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\msinet.ocx
### Microsoft Internet Transfer Control DLL Microsoft Corporation Microsoft In
ternet Transfer Control 6.00.8862

[Loaded DLLs] C:\WINDOWS\system32\comdlg32.ocx


### CMDialog ActiveX Control DLL Microsoft Corporation CMDIALOG 6.01.9782
[Loaded DLLs] C:\WINDOWS\system32\AS-IFce1.ocx
### Ariad Interface Components Cyotek Ariad Interface Components 1.03.0149
[Loaded DLLs] C:\WINDOWS\system32\MSCOMCTL.OCX
### Windows Common Controls ActiveX Control DLL Microsoft Corporation MSCOMCTL
6.01.9545
[Loaded DLLs] C:\WINDOWS\system32\MSVBVM60.DLL
### Visual Basic Virtual Machine Microsoft Corporation Visual Basic 6.00.9802
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\LPK.DLL
### Language Pack Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\dscbtshl.dll
### dscbtshl Delphin Software Delphin Software dscbtshl 1, 0, 0, 4
[Loaded DLLs] C:\WINDOWS\system32\wuapi.dll
### Windows Update Client API Microsoft Corporation Microsoft Windows Operating
System 7.6.7600.256
[Loaded DLLs] C:\WINDOWS\system32\mscms.dll
### Microsoft Color Matching System DLL Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.5627
[Loaded DLLs] C:\WINDOWS\system32\mstask.dll
### Task Scheduler interface DLL Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] C:\Program Files\Internet Download Manager\idmmkb.dll
### Internet Download Manager module Tonec Inc. Internet Download Manager 5, 1
6, 1, 0
[Loaded DLLs] C:\WINDOWS\system32\idmmbc.dll
### Internet Download Manager LSP dll Tonec Inc. Internet Download Manager LSP
dll 5, 18, 2, 0
[Loaded DLLs] C:\WINDOWS\system32\CFGMGR32.dll
### Configuration Manager Forwarder DLL Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\wlanapi.dll
### Windows Wireless LAN 802.11 Client Side API DLL Microsoft Corporation Micr
osoft Windows Operating System 5.1.2600.5512

[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll


### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\system32\USP10.dll
### Uniscribe Unicode script processor Microsoft Corporation Microsoft(R) Unis
cribe Unicode script processor 1.0420.2600.6421
[Loaded DLLs] C:\WINDOWS\system32\odbcbcp.dll
### Microsoft BCP for ODBC Microsoft Corporation Microsoft SQL Server 3.85.113
2
[Loaded DLLs] C:\WINDOWS\system32\pdh.dll
### Windows Performance Data Helper DLL Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.5773
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\Program Files\Opera\34.0.2036.36\opera.dll
[Loaded DLLs] C:\WINDOWS\system32\MSUTB.dll
### MSUTB Server DLL Microsoft Corporation Microsoft Windows Operating System 5.
1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\clbcatex.dll
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] C:\WINDOWS\system32\MSDTCPRX.dll
### MS DTC OLE Transactions interface proxy DLL Microsoft Corporation Microsof
t Distributed Transaction Coordinator 03.01.00.4414
[Loaded DLLs] C:\WINDOWS\system32\XOLEHLP.DLL
### MS DTC helper APIs DLL Microsoft Corporation Microsoft Distributed Transac
tion Coordinator 03.01.00.4414
[Loaded DLLs] C:\WINDOWS\system32\txflog.dll
### Simple Kernel-mode File-based Log Microsoft Corporation COM Services 03.00
.00.4414
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
### SQLite 3 Database Library SQLite Database 3.06.19.00
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\cfglib.dll
### Antivirus configuration library Avira GmbH AntiVir Desktop and Server 10.0
0.13.00
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\avevtlog.dll
### Event Logger Avira GmbH AntiVir Desktop 10.00.00.08
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\schedr.dll
### avschdr Dynamic Link Library Avira GmbH AntiVir Desktop 10.00.04.00
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\Program Files\Internet Download Manager\idmmkb.dll
### Internet Download Manager module Tonec Inc. Internet Download Manager 5, 1
6, 1, 0
[Loaded DLLs] C:\WINDOWS\System32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] C:\WINDOWS\system32\dscbtshl.dll
### dscbtshl Delphin Software Delphin Software dscbtshl 1, 0, 0, 4

[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll


[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\RICHED20.dll
### Rich Text Edit Control, v3.0 Microsoft Corporation Microsoft RichEdit Cont
rol, version 3.0 3.0
[Loaded DLLs] C:\WINDOWS\system32\RichEd32.Dll
### Wrapper Dll for Richedit 1.0 Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.0
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\OLEPRO32.DLL
### Microsoft Corporation 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\oledlg.dll
### Microsoft Windows(TM) OLE 2.0 User Interface Support Microsoft Corporation
Microsoft Windows(TM) OLE 2.0 User Interface Support 2.01
[Loaded DLLs] C:\WINDOWS\system32\igfxdev.dll
### igfxdev Module Intel Corporation Intel(R) Common User Interface 6.14.10.49
26
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\igfxsrvc.dll
### igfxsrvc Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\igfxres.dll
### igfxres Module Intel Corporation Intel(R) Common User Interface 6.14.10.49
26
[Loaded DLLs] C:\WINDOWS\system32\igfxsrvc.dll
### igfxsrvc Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\igfxress.dll
### igfxress Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Loaded DLLs] C:\WINDOWS\system32\igfxres.dll
### igfxres Module Intel Corporation Intel(R) Common User Interface 6.14.10.49
26
[Loaded DLLs] C:\WINDOWS\system32\igfxsrvc.dll
### igfxsrvc Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\hccutils.DLL
### hccutils Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Loaded DLLs] C:\WINDOWS\system32\dscbtshl.dll
### dscbtshl Delphin Software Delphin Software dscbtshl 1, 0, 0, 4
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] c:\program files\avira\antivir desktop\ccmainrc.dll
### Control Center Resources Avira GmbH AntiVir Desktop 10.00.11.00
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\rcimage.dll

### Avira AntiVir PersonalEdition Classic Master Resource File (English) Avira
GmbH AntiVir Desktop 10.00.00.26
[Loaded DLLs] c:\program files\avira\antivir desktop\ccmsgrc.dll
### Control Center MSG Plugin Resources Avira GmbH AntiVir Desktop 10.00.09.00
[Loaded DLLs] c:\program files\avira\antivir desktop\ccmsg.dll
### Control Center Message Plugin Avira GmbH AntiVir Desktop 10.00.09.35
[Loaded DLLs] c:\program files\avira\antivir desktop\cclicrc.dll
### Control Center License Plugin Resources Avira GmbH AntiVir Desktop 10.00.0
9.00
[Loaded DLLs] c:\program files\avira\antivir desktop\cclic.dll
### Control Center License Plugin Avira GmbH AntiVir Desktop 10.00.09.23
[Loaded DLLs] c:\program files\avira\antivir desktop\ccupdrc.dll
### Control Center Updater Plugin Resources Avira GmbH AntiVir Desktop 10.00.2
9.02
[Loaded DLLs] c:\program files\avira\antivir desktop\ccupdate.dll
### Control Center Updater Plugin Avira GmbH AntiVir Desktop 10.00.29.10
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\avipc.dll
### AVIRA IPC Library Avira GmbH AntiVir Desktop 1.2.0.24
[Loaded DLLs] c:\program files\avira\antivir desktop\ccgrdw.dll
### Control Center Guard Worker Plugin Avira GmbH AntiVir Desktop 10.00.09.25
[Loaded DLLs] c:\program files\avira\antivir desktop\ccgrdrc.dll
### Control Center Guard Plugin Resources Avira GmbH AntiVir Desktop 10.00.29.
00
[Loaded DLLs] c:\program files\avira\antivir desktop\ccguard.dll
### Control Center Guard Plugin Avira GmbH AntiVir Desktop 10.00.28.13
[Loaded DLLs] c:\program files\avira\antivir desktop\ccgenrc.dll
### Control Center General Plugin Resources Avira GmbH AntiVir Desktop 10.00.3
5.00
[Loaded DLLs] c:\program files\avira\antivir desktop\ccgen.dll
### Control Center General Plugin Avira GmbH AntiVir Desktop 10.00.34.00
[Loaded DLLs] c:\program files\avira\antivir desktop\cfglib.dll
### Antivirus configuration library Avira GmbH AntiVir Desktop and Server 10.0
0.13.00
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\ccwkrlib.dll
### Antivirus Control Center Common Worker Library Avira GmbH AntiVir Desktop
10.00.00.18
[Loaded DLLs] C:\WINDOWS\system32\vss_ps.dll
### Microsoft Volume Shadow Copy Service proxy/stub Microsoft Corporation Micro
soft Windows Operating System 5.1.2600.0
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\avipc.dll
### AVIRA IPC Library Avira GmbH AntiVir Desktop 1.2.0.24
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\avipc.dll
### AVIRA IPC Library Avira GmbH AntiVir Desktop 1.2.0.24
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aebb.dll
### AntiVir Engine Module for Windows Avira GmbH AVBB 8.1.1.0
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aeemu.dll
### AntiVir Engine Module for Windows Avira GmbH AVEMU 8.1.3.0
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aegen.dll
### AntiVir Engine Module for Windows Avira GmbH AVGEN 8.1.5.6
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aehelp.dll

### AntiVir Engine Module for Windows Avira GmbH AVHELP 8.1.17.5
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aeheur.dll
### AntiVir Engine Module for Windows Avira GmbH AVHEUR 8.1.2.144
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aeoffice.dll
### AntiVir Engine Module for Windows Avira GmbH AVOFFICE 8.1.2.12
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\unacev2.dll
### UNACE Dynamic Link Library ACE Compression Software UNACE - freeware ACE e
xtraction component 2.6.0.3
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aepack.dll
### AntiVir Engine Module for Windows Avira GmbH AVPACK 8.2.9.5
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aerdl.dll
### AntiVir Engine Module for Windows Avira GmbH AVRDL 8.1.9.13
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aesbx.dll
### AntiVir Engine Module for Windows Avira GmbH AVSBX 8.2.1.34
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aescn.dll
### AntiVir Engine Module for Windows Avira GmbH AVSCN 8.1.7.2
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aescript.dll
### AntiVir Engine Module for Windows Avira GmbH AVSCRIPT 8.1.3.73
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aevdf.dll
### AntiVir Engine Module for Windows Avira GmbH AVVDF 8.1.2.1
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\aecore.dll
### AntiVir Engine Module for Windows Avira GmbH AVCORE 8.1.22.4
[Loaded DLLs] C:\WINDOWS\system32\FLTLIB.DLL
### Filter Library Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.5512
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\AVGIO.DLL
### On-access scan support Avira GmbH 10.00.08.02
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\avsmtp.dll
### Antivirus email sender library Avira GmbH AntiVir Desktop and Server 10.00
.00.17
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\AVPREF.DLL
### Prefix DLL Avira GmbH AntiVir Desktop 10.00.00.00
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
### SQLite 3 Database Library SQLite Database 3.06.19.00
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\cfglib.dll
### Antivirus configuration library Avira GmbH AntiVir Desktop and Server 10.0
0.13.00
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\guardmsg.dll
### AntiVir Guard Messages (Deutsch) Avira GmbH 10.00.07.00
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\AVEvtLog.dll
### Event Logger Avira GmbH AntiVir Desktop 10.00.00.08
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\libdb44.dll
### Berkeley DB 4.4 DLL Sleepycat Software Sleepycat Software libdb 4.4.20
[Loaded DLLs] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1100GC.dll
### Marvell Printer Software Driver Marvell Printer Software Driver 2012.0831.
1.57034
[Loaded DLLs] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hp1100su.dll
### Marvell Printer Software Driver Marvell Printer Software Driver 2012.0831.
1.57034
[Loaded DLLs] C:\WINDOWS\system32\inetpp.dll
### Internet Print Provider DLL Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\win32spl.dll
### 32-bit Spooler API DLL Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\usbmon.dll
### Standard Dynamic Printing Port Monitor DLL Microsoft Corporation Microsoft

Windows Operating System 5.1.2600.5512


[Loaded DLLs] C:\WINDOWS\system32\tcpmon.dll
### Standard TCP/IP Port Monitor DLL Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\pjlmon.dll
### PJL Language monitor Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\cnbjmon.dll
### Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation Microso
ft Windows Operating System 5.1.2600.2082
[Loaded DLLs] C:\WINDOWS\system32\localspl.dll
### Local Spooler DLL Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.6226
[Loaded DLLs] C:\WINDOWS\system32\SPOOLSS.DLL
### Spooler SubSystem DLL Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Loaded DLLs] C:\Program Files\TuneUp Utilities 2013\SDShelEx-win32.dll
### TuneUp Shredder Shell Extension TuneUp Software TuneUp Utilities 2013 13.0
.2013.194
[Loaded DLLs] C:\WINDOWS\system32\zipfldr.dll
### Compressed (zipped) Folders Microsoft Corporation Microsoft Windows Operatin
g System 6.00.2900.5512
[Loaded DLLs] C:\WINDOWS\system32\dscbtshl.dll
### dscbtshl Delphin Software Delphin Software dscbtshl 1, 0, 0, 4
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0
.30729.4148_x-ww_15fc9313\MFC90ENU.DLL
### MFC Language Specific Resources Microsoft Corporation Microsoft Visual Stud
io 2008 9.00.30729.4148
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30
729.4148_x-ww_a57c1f53\mfc90u.dll
### MFCDLL Shared Library - Retail Version Microsoft Corporation Microsoft Visu
al Studio 2008 9.00.30729.4148
[Loaded DLLs] C:\Program Files\Avira\AntiVir Desktop\shlext.dll
### AntiVirus context menu Avira GmbH AntiVir Desktop 10.00.00.03
[Loaded DLLs] C:\Program Files\WinRAR\rarext.dll
[Loaded DLLs] C:\WINDOWS\system32\MSCTF.dll
### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 5.
1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\perfos.dll
### Windows System Performance Objects DLL Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df
_1.0.6002.23084_x-ww_f3f35550\gdiplus.dll
### Microsoft GDI+ Microsoft Corporation Microsoft Windows Operating System 5.2.
6002.23084
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\System32\Wbem\framedyn.dll
### WMI SDK Provider Framework Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\srclient.dll
### SR CLIENT DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512
[Loaded DLLs] C:\WINDOWS\system32\Oleacc.dll
### Active Accessibility Core Component Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.6153
[Loaded DLLs] C:\WINDOWS\system32\DUSER.dll
### Windows DirectUser Engine Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512

[Loaded DLLs] C:\WINDOWS\system32\browselc.dll


### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.5512
[Loaded DLLs] C:\WINDOWS\system32\igfxsrvc.dll
### igfxsrvc Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Loaded DLLs] C:\WINDOWS\system32\igfxress.dll
### igfxress Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Loaded DLLs] C:\WINDOWS\system32\igfxres.dll
### igfxres Module Intel Corporation Intel(R) Common User Interface 6.14.10.49
26
[Loaded DLLs] C:\WINDOWS\system32\hccutils.DLL
### hccutils Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Loaded DLLs] C:\WINDOWS\system32\igfxpph.dll
### igfxpph Module Intel Corporation Intel(R) Common User Interface 6.14.10.49
26
[Loaded DLLs] C:\Documents and Settings\xpsp3\Local Settings\Application Data\
Kingsoft\WPS Office\9.1.0.5234\office6\qingshellext.dll
### qingbangong shellext Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 9,
1,0,5234
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30
729.4148_x-ww_d495ac4e\MSVCR90.dll
### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200
8 9.00.30729.4148
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30
729.4148_x-ww_d495ac4e\MSVCP90.dll
### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio 2
008 9.00.30729.4148
[Loaded DLLs] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
### PDF Shell Extension Adobe Systems, Inc. Adobe PDF Shell Extension 10.1.0.5
34
[Loaded DLLs] C:\Auto Shutdown Genius\MHK.dll
[Loaded DLLs] C:\WINDOWS\system32\BatMeter.dll
### Battery Meter Helper DLL Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.5512
[Loaded DLLs] C:\WINDOWS\system32\stobject.dll
### Systray shell service object Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\MLANG.dll
### Multi Language Support DLL Microsoft Corporation Microsoft Windows Operating
System 6.00.2900.5512
[Loaded DLLs] C:\WINDOWS\system32\webcheck.dll
### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001.
18702
[Loaded DLLs] C:\WINDOWS\system32\eappprxy.dll
### Microsoft EAPHost Peer Client DLL Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\OneX.DLL
### IEEE 802.1X supplicant library Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\davclnt.dll
### Web DAV Client DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\NETRAP.dll
### Net Remote Admin Protocol DLL Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\NETUI1.dll
### NT LM UI Common Code - Networking classes Microsoft Corporation Microsoft W

indows Operating System 5.1.2600.5512


[Loaded DLLs] C:\WINDOWS\System32\NETUI0.dll
### NT LM UI Common Code - GUI Classes Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\ntlanman.dll
### Microsoft Lan Manager Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\drprov.dll
### Microsoft Terminal Server Network Provider Microsoft Corporation Microsoft
Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\ntshrui.dll
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\linkinfo.dll
### Windows Volume Tracking Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\shdoclc.dll
### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window
s Operating System 6.00.2900.5512
[Loaded DLLs] C:\WINDOWS\system32\ieframe.dll
### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001
.18702
[Loaded DLLs] C:\WINDOWS\system32\msxml3.dll
### MSXML 3.0 SP10 Microsoft Corporation Microsoft(R) MSXML 3.0 SP10 8.100.105
4.0
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\MSIMG32.dll
### GDIEXT Client DLL Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\themeui.dll
### Windows Theme API Microsoft Corporation Microsoft Windows Operating System 6
.00.2900.6437
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\SHDOCVW.dll
### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window
s Operating System 6.00.2900.6452
[Loaded DLLs] C:\WINDOWS\system32\BROWSEUI.dll
### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6452
[Loaded DLLs] c:\windows\system32\ssdpsrv.dll
### SSDP Service DLL Microsoft Corporation Microsoft Windows Operating System 5.
1.2600.5512
[Loaded DLLs] c:\windows\system32\regsvc.dll
### Remote Registry Service Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\lmhsvc.dll
### TCPIP NetBios Transport Services DLL Microsoft Corporation Microsoft Window
s Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\dnsrslvr.dll
### DNS Caching Resolver Service Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5797
[Loaded DLLs] c:\windows\system32\NTMSDBA.dll
### Removable Storage Manager DB Object APIs Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\ntmssvc.dll
### Removable Storage Manager Microsoft Corporation Microsoft Windows Whistler O

perating System 5.1.2400.5512


[Loaded DLLs] C:\WINDOWS\System32\MfcSubs.dll
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] C:\WINDOWS\System32\catsrv.dll
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] C:\WINDOWS\System32\catsrvut.dll
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] C:\WINDOWS\System32\RASQEC.DLL
### RAS Quarantine Enforcement Client Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\ntlsapi.dll
### Microsoft License Server Interface DLL Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\rasppp.dll
### Remote Access PPP Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\hidphone.tsp
### Microsoft HID Phone TSP Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\h323.tsp
### Microsoft H.323 Telephony Service Provider Microsoft Corporation Microsoft
Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\ipconf.tsp
### Microsoft Multicast Conference TAPI Service Provider Microsoft Corporation
Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\ndptsp.tsp
### NDIS Proxy TAPI Service Provider Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\kmddsp.tsp
### TAPI Kernel-Mode Service Provider Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\uniplat.dll
### Unimodem AT Mini Driver Platform Driver for Windows NT Microsoft Corporati
on Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\unimdm.tsp
### Unimodem 5 Service Provider Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\rastapi.dll
### Remote Access TAPI Compliance Layer Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\rasmans.dll
### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\tapisrv.dll
### Microsoft Windows(TM) Telephony Server Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\advpack.dll
### ADVPACK Microsoft Corporation Windows Internet Explorer 8.00.6001.18702
[Loaded DLLs] c:\windows\system32\SHFOLDER.dll
### Shell Folder Service Microsoft Corporation Microsoft Windows Operating Syste
m 6.00.2900.5512
[Loaded DLLs] c:\windows\system32\qmgr.dll
### Background Intelligent Transfer Service Microsoft Corporation Microsoft Win
dows Operating System 6.7.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\RASDLG.dll
### Remote Access Common Dialog API Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\netcfgx.dll
### Network Configuration Objects Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512

[Loaded DLLs] C:\WINDOWS\system32\SSDPAPI.dll


### SSDP Client API DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\upnp.dll
### Universal Plug and Play API Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\wbem\ncprov.dll
### Non-COM WMI Event Provision APIs Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\wbem\wbemess.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\RESUTILS.DLL
### Microsoft Cluster Resource Utility DLL Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\CLUSAPI.DLL
### Cluster API Library Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\WSOCK32.dll
### Windows Socket 32-Bit DLL Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\MTXCLU.DLL
### MS DTC amd MTS clustering support DLL Microsoft Corporation COM Services 0
3.01.00.4414
[Loaded DLLs] C:\WINDOWS\system32\colbact.DLL
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] C:\WINDOWS\system32\comsvcs.dll
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] C:\WINDOWS\system32\wbem\wmiprvsd.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5755
[Loaded DLLs] C:\WINDOWS\system32\wbem\repdrvfs.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\wbem\wmiutils.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\Wbem\esscli.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\Wbem\wbemcore.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\wscsvc.dll
### Windows Security Center Service Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\ipnathlp.dll
### Microsoft NAT Helper Components Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\mspatcha.dll
### Microsoft(R) Patch Engine Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\Cabinet.dll
### Microsoft Cabinet File API Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\wuaueng.dll
### Windows Update Agent Microsoft Corporation Microsoft Windows Operating Syste
m 7.6.7600.256
[Loaded DLLs] c:\windows\system32\browser.dll
### Computer Browser Service DLL Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.6260
[Loaded DLLs] c:\windows\system32\wuauserv.dll
### Windows Update AutoUpdate Service Microsoft Corporation Microsoft Windows Op
erating System 5.4.3790.5512
[Loaded DLLs] C:\WINDOWS\system32\VSSAPI.DLL
### Microsoft Volume Shadow Copy Requestor/Writer Services API DLL Microsoft Co

rporation Microsoft Windows Operating System 5.1.2600.5512


[Loaded DLLs] c:\windows\system32\wbem\wmisvc.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\POWRPROF.dll
### Power Profile Helper DLL Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.5512
[Loaded DLLs] c:\windows\system32\srsvc.dll
### System Restore Service Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\trkwks.dll
### Distributed Link Tracking Client Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\seclogon.dll
### Secondary Logon Service DLL Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\sens.dll
### System Event Notification Service (SENS) Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\WZCSAPI.DLL
### Wireless Zero Configuration service API Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\eappprxy.dll
### Microsoft EAPHost Peer Client DLL Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\eappcfg.dll
### Eap Peer Config Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512
[Loaded DLLs] c:\windows\system32\OneX.DLL
### IEEE 802.1X supplicant library Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\dot3dlg.dll
### 802.3 UI Helper Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512
[Loaded DLLs] c:\windows\system32\credui.dll
### Credential Manager User Interface Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\netshell.dll
### Network Connections Shell Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\netman.dll
### Network Connections Manager Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\srvsvc.dll
### Server Service DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Loaded DLLs] c:\windows\pchealth\helpctr\binaries\pchsvc.dll
### Microsoft PCHealth Service Holder Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\HID.DLL
### Hid User Library Microsoft Corporation Microsoft Windows Operating System 5.
1.2600.5512
[Loaded DLLs] c:\windows\system32\hidserv.dll
### HID Audio Service Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Loaded DLLs] c:\windows\system32\es.dll
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] c:\windows\system32\ersvc.dll
### Windows Error Reporting Service Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\dmserver.dll

### Logical Disk Manager service dll Microsoft Corp. Logical Disk Manager for
Windows NT 1.0
[Loaded DLLs] c:\windows\system32\certcli.dll
### Microsoft Certificate Services Client Microsoft Corporation Microsoft Window
s Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\cryptsvc.dll
### Cryptographic Services Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\wkssvc.dll
### Workstation Service DLL Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5826
[Loaded DLLs] c:\windows\system32\audiosrv.dll
### Windows Audio Service Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\MSIDLE.DLL
### User Idle Monitor Microsoft Corporation Microsoft Windows Operating System 6
.00.2900.5512
[Loaded DLLs] C:\WINDOWS\System32\raschap.dll
### Remote Access PPP CHAP Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5886
[Loaded DLLs] c:\windows\system32\schedsvc.dll
### Task Scheduler Engine Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\MPRAPI.dll
### Windows NT MP Router Administration DLL Microsoft Corporation Microsoft Win
dows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\iertutil.dll
### Run time utility for Internet Explorer Microsoft Corporation Windows Intern
et Explorer 8.00.6001.18702
[Loaded DLLs] C:\WINDOWS\system32\urlmon.dll
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Loaded DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Loaded DLLs] C:\WINDOWS\system32\WININET.dll
### Internet Extensions for Win32 Microsoft Corporation Windows Internet Explor
er 8.00.6001.18702
[Loaded DLLs] C:\WINDOWS\System32\CRYPTUI.dll
### Microsoft Trust UI Provider Microsoft Corporation Microsoft Windows Operatin
g System 5.131.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\rastls.dll
### Remote Access PPP EAP-TLS Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5886
[Loaded DLLs] c:\windows\system32\ESENT.dll
### Server Database Storage Engine Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\dot3api.dll
### 802.3 Autoconfiguration API Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\QUtil.dll
### Quarantine Utilities Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\EapolQec.dll
### Microsoft EAPOL NAP Enforcement Client Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\WMI.dll
### WMI DC and DP functionality Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\wzcsvc.dll

### Wireless Zero Configuration Service Microsoft Corporation Microsoft Windows


Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\dhcpcsvc.dll
### DHCP Client Service Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\msi.dll
### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40
01.5512
[Loaded DLLs] C:\WINDOWS\System32\winrnr.dll
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\ATL.DLL
### ATL Module for Windows XP (Unicode) Microsoft Corporation Microsoft (R) Vi
sual C++ 6.05.2284
[Loaded DLLs] c:\windows\system32\adsldpc.dll
### ADs LDAP Provider C DLL Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\ACTIVEDS.dll
### ADs Router Layer DLL Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\mstlsapi.dll
### Microsoft Terminal Server Licensing Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\ICAAPI.dll
### DLL Interface to TermDD Device Driver Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\termsrv.dll
### Terminal Server Service Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] c:\windows\system32\rpcss.dll
### Distributed COM Services Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5755
[Loaded DLLs] C:\WINDOWS\system32\rasadhlp.dll
### Remote Access AutoDial Helper Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\rtutils.dll
### Routing Utilities Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\TAPI32.dll
### Microsoft Windows(TM) Telephony API Client DLL Microsoft Corporation Micros
oft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\rasman.dll
### Remote Access Connection Manager Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\RASAPI32.DLL
### Remote Access API Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\WINHTTP.dll
### Windows HTTP Services Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.6175
[Loaded DLLs] C:\WINDOWS\system32\SensApi.dll
### SENS Connectivity API DLL Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\cryptnet.dll

### Crypto Network Related API Microsoft Corporation Microsoft Windows Operating
System 5.131.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\dssenh.dll
### Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider Microsoft
Corporation Microsoft Windows Operating System 5.1.2600.5507
[Loaded DLLs] C:\WINDOWS\System32\wshtcpip.dll
### Windows Sockets Helper DLL Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\hnetcfg.dll
### Home Networking Configuration Manager Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\mswsock.dll
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 5.1.2600.5625
[Loaded DLLs] C:\WINDOWS\system32\idmmbc.dll
### Internet Download Manager LSP dll Tonec Inc. Internet Download Manager LSP
dll 5, 18, 2, 0
[Loaded DLLs] C:\WINDOWS\system32\psbase.dll
### Protected Storage default provider Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\pstorsvc.dll
### Protected storage server Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\WINIPSEC.DLL
### Windows IPSec SPD Client DLL Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\oakley.DLL
### Oakley Key Manager Microsoft Corporation Microsoft Windows Operating System
5.1.2600.6462
[Loaded DLLs] C:\WINDOWS\system32\ipsecsvc.dll
### Windows IPSec SPD Server DLL Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\scecli.dll
### Windows Security Configuration Editor Client Engine Microsoft Corporation
Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\wdigest.dll
### Microsoft Digest Access Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5834
[Loaded DLLs] C:\WINDOWS\system32\schannel.dll
### TLS / SSL Security Provider Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.6239
[Loaded DLLs] C:\WINDOWS\system32\w32time.dll
### Windows Time Service Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\netlogon.dll
### Net Logon Services DLL Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\kerberos.dll
### Kerberos Security Package Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.6059
[Loaded DLLs] C:\WINDOWS\system32\msprivs.dll
### Microsoft Privilege Translations Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\AppPatch\AcGenral.DLL
### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\SAMSRV.dll

### SAM Server DLL Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.5512
[Loaded DLLs] C:\WINDOWS\system32\LSASRV.dll
### LSA Server DLL Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.6058
[Loaded DLLs] C:\WINDOWS\system32\eventlog.dll
### Event Logging Service Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\AppPatch\AcAdProc.dll
### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\ShimEng.dll
### Shim Engine DLL Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\umpnpmgr.dll
### User-mode Plug-and-Play Service Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\SCESRV.dll
### Windows Security Configuration Editor Engine Microsoft Corporation Microso
ft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\NCObjAPI.DLL
### Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\DNSAPI.dll
### DNS Client API DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.6089
[Loaded DLLs] C:\WINDOWS\system32\NTDSAPI.dll
### NT5DS Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\MSVCP60.dll
### Microsoft (R) C++ Runtime Library Microsoft Corporation Microsoft (R) Visu
al C++ 6.02.3104.0
[Loaded DLLs] C:\WINDOWS\system32\wbem\fastprox.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5755
[Loaded DLLs] C:\WINDOWS\system32\wbem\wbemsvc.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\wbem\wbemcomn.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\wbem\wbemprox.dll
### WMI Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\CLBCATQ.DLL
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] C:\WINDOWS\system32\OLEAUT32.dll
### Microsoft Corporation 5.1.2600.6341
[Loaded DLLs] C:\WINDOWS\system32\COMRes.dll
### Microsoft Corporation COM Services 03.00.00.4414
[Loaded DLLs] C:\WINDOWS\system32\midimap.dll
### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\MSACM32.dll
### Microsoft ACM Audio Filter Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\msacm32.drv
### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.0
[Loaded DLLs] C:\WINDOWS\system32\wdmaud.drv
### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\iphlpapi.dll
### IP Helper API Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512

[Loaded DLLs] C:\WINDOWS\system32\cryptdll.dll


### Cryptography Manager Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\msv1_0.dll
### Microsoft Authentication Package v1.0 Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5876
[Loaded DLLs] C:\WINDOWS\system32\WLDAP32.dll
### Win32 LDAP API DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\NTMARTA.DLL
### Windows NT MARTA provider Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\cscui.dll
### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\SAMLIB.dll
### SAM Library DLL Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\rsaenh.dll
### Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft W
indows Operating System 5.1.2600.5507
[Loaded DLLs] C:\WINDOWS\system32\WINSPOOL.DRV
### Windows Spooler Driver Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\MPR.dll
### Multiple Provider Router DLL Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\WlNotify.dll
### Common DLL to receive Winlogon notifications Microsoft Corporation Microso
ft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\System32\dimsntfy.dll
### DIMS Notification Handler Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\cscdll.dll
### Offline Network Agent Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\uxtheme.dll
### Microsoft UxTheme Library Microsoft Corporation Microsoft Windows Operating
System 6.00.2900.5512
[Loaded DLLs] C:\WINDOWS\system32\WINMM.dll
### MCI API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.260
0.6160
[Loaded DLLs] C:\WINDOWS\system32\WTSAPI32.dll
### Windows Terminal Server SDK APIs Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\WINSCARD.DLL
### Microsoft Smart Card API Microsoft Corporation Microsoft Windows Operating S
ystem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\msctfime.ime
### Microsoft Text Frame Work Service IME Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\Apphelp.dll
### Application Compatibility Client Library Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\ole32.dll
### Microsoft OLE for Windows Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.6435

[Loaded DLLs] C:\WINDOWS\system32\sfc_os.dll


### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\sfc.dll
### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\SHSVCS.dll
### Windows Shell Services Dll Microsoft Corporation Microsoft Windows Operating
System 6.00.2900.5853
[Loaded DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Loaded DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b641
44ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
### User Experience Controls Library Microsoft Corporation Microsoft Windows Ope
rating System 6.00.2900.6028
[Loaded DLLs] C:\WINDOWS\system32\SHLWAPI.dll
### Shell Light-weight Utility Library Microsoft Corporation Microsoft Windows O
perating System 6.00.2900.5912
[Loaded DLLs] C:\WINDOWS\system32\SHELL32.dll
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242
[Loaded DLLs] C:\WINDOWS\system32\comdlg32.dll
### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System
6.00.2900.5512
[Loaded DLLs] C:\WINDOWS\system32\ODBC32.dll
### Microsoft Data Access - ODBC Driver Manager Microsoft Corporation Microsof
t Data Access Components 3.525.3012.0
[Loaded DLLs] C:\WINDOWS\system32\COMCTL32.dll
### Common Controls Library Microsoft Corporation Microsoft Windows Operating Sy
stem 6.00.2900.6028
[Loaded DLLs] C:\WINDOWS\system32\MSGINA.dll
### Windows NT Logon GINA DLL Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\IMM32.DLL
### Windows XP IMM32 API Client DLL Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\WS2HELP.dll
### Windows Socket 2.0 Helper for Windows NT Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\WS2_32.dll
### Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\IMAGEHLP.dll
### Windows NT Image Helper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.6479
[Loaded DLLs] C:\WINDOWS\system32\WINTRUST.dll
### Microsoft Trust Verification APIs Microsoft Corporation Microsoft Windows Op
erating System 5.131.2600.6285
[Loaded DLLs] C:\WINDOWS\system32\WINSTA.dll
### Winstation Library Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\VERSION.dll
### Version Checking and File Installation Libraries Microsoft Corporation Mic
rosoft Windows Operating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\SETUPAPI.dll
### Windows Setup API Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\REGAPI.dll
### Registry Configuration APIs Microsoft Corporation Microsoft Windows Operatin

g System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\PSAPI.DLL
### Process Status Helper Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\USERENV.dll
### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.55
12
[Loaded DLLs] C:\WINDOWS\system32\NETAPI32.dll
### Net Win32 API DLL Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.6260
[Loaded DLLs] C:\WINDOWS\system32\PROFMAP.dll
### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.55
12
[Loaded DLLs] C:\WINDOWS\system32\NDdeApi.dll
### Network DDE Share Management APIs Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\MSASN1.dll
### ASN.1 Runtime APIs Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5875
[Loaded DLLs] C:\WINDOWS\system32\CRYPT32.dll
### Crypto API32 Microsoft Corporation Microsoft Windows Operating System 5.131.
2600.6459
[Loaded DLLs] C:\WINDOWS\system32\msvcrt.dll
### Windows NT CRT DLL Microsoft Corporation Microsoft Windows Operating System
7.0.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\AUTHZ.dll
### Authorization Framework Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\Secur32.dll
### Security Support Provider Interface Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.5834
[Loaded DLLs] C:\WINDOWS\system32\RPCRT4.dll
### Remote Procedure Call Runtime Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.6477
[Loaded DLLs] C:\WINDOWS\system32\ADVAPI32.dll
### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5755
[Loaded DLLs] C:\WINDOWS\system32\sxs.dll
### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System 5.1.2600
.5512
[Loaded DLLs] C:\WINDOWS\system32\USER32.dll
### Windows XP USER API Client DLL Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\KERNEL32.dll
### Windows NT BASE API Client DLL Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.6532
[Loaded DLLs] C:\WINDOWS\system32\GDI32.dll
### GDI Client DLL Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.6460
[Loaded DLLs] C:\WINDOWS\system32\winsrv.dll
### Windows Server DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.6368
[Loaded DLLs] C:\WINDOWS\system32\basesrv.dll
### Windows NT BASE API Server DLL Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512
[Loaded DLLs] C:\WINDOWS\system32\CSRSRV.dll
### Client Server Runtime Process Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.6166
[Loaded DLLs] C:\WINDOWS\system32\ntdll.dll
### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 5.1.26

00.6055
[Explorer's DLLs] C:\Program Files\TuneUp Utilities 2013\SDShelEx-win32.dll
### TuneUp Shredder Shell Extension TuneUp Software TuneUp Utilities 2013 13.0
.2013.194
[Explorer's DLLs] C:\WINDOWS\system32\zipfldr.dll
### Compressed (zipped) Folders Microsoft Corporation Microsoft Windows Operatin
g System 6.00.2900.5512
[Explorer's DLLs] C:\WINDOWS\system32\dscbtshl.dll
### dscbtshl Delphin Software Delphin Software dscbtshl 1, 0, 0, 4
[Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b
_9.0.30729.4148_x-ww_15fc9313\MFC90ENU.DLL
### MFC Language Specific Resources Microsoft Corporation Microsoft Visual Stud
io 2008 9.00.30729.4148
[Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.
0.30729.4148_x-ww_a57c1f53\mfc90u.dll
### MFCDLL Shared Library - Retail Version Microsoft Corporation Microsoft Visu
al Studio 2008 9.00.30729.4148
[Explorer's DLLs] C:\Program Files\Avira\AntiVir Desktop\shlext.dll
### AntiVirus context menu Avira GmbH AntiVir Desktop 10.00.00.03
[Explorer's DLLs] C:\Program Files\WinRAR\rarext.dll
[Explorer's DLLs] C:\WINDOWS\system32\MSCTF.dll
### MSCTF Server DLL Microsoft Corporation Microsoft Windows Operating System 5.
1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\perfos.dll
### Windows System Performance Objects DLL Microsoft Corporation Microsoft Wind
ows Operating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144cc
f1df_1.0.6002.23084_x-ww_f3f35550\gdiplus.dll
### Microsoft GDI+ Microsoft Corporation Microsoft Windows Operating System 5.2.
6002.23084
[Explorer's DLLs] C:\WINDOWS\system32\odbcint.dll
### Microsoft Data Access - ODBC Resources Microsoft Corporation Microsoft Dat
a Access Components 3.525.1132.0
[Explorer's DLLs] C:\WINDOWS\System32\Wbem\framedyn.dll
### WMI SDK Provider Framework Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\srclient.dll
### SR CLIENT DLL Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512
[Explorer's DLLs] C:\WINDOWS\system32\Oleacc.dll
### Active Accessibility Core Component Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.6153
[Explorer's DLLs] C:\WINDOWS\system32\DUSER.dll
### Windows DirectUser Engine Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\browselc.dll
### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.5512
[Explorer's DLLs] C:\WINDOWS\system32\igfxsrvc.dll
### igfxsrvc Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Explorer's DLLs] C:\WINDOWS\system32\igfxress.dll
### igfxress Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926
[Explorer's DLLs] C:\WINDOWS\system32\igfxres.dll
### igfxres Module Intel Corporation Intel(R) Common User Interface 6.14.10.49
26
[Explorer's DLLs] C:\WINDOWS\system32\hccutils.DLL
### hccutils Module Intel Corporation Intel(R) Common User Interface 6.14.10.4
926

[Explorer's DLLs] C:\WINDOWS\system32\igfxpph.dll


### igfxpph Module Intel Corporation Intel(R) Common User Interface 6.14.10.49
26
[Explorer's DLLs] C:\Documents and Settings\xpsp3\Local Settings\Application D
ata\Kingsoft\WPS Office\9.1.0.5234\office6\qingshellext.dll
### qingbangong shellext Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 9,
1,0,5234
[Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.
0.30729.4148_x-ww_d495ac4e\MSVCR90.dll
### Microsoft C Runtime Library Microsoft Corporation Microsoft Visual Studio 200
8 9.00.30729.4148
[Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.
0.30729.4148_x-ww_d495ac4e\MSVCP90.dll
### Microsoft C++ Runtime Library Microsoft Corporation Microsoft Visual Studio 2
008 9.00.30729.4148
[Explorer's DLLs] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell
.dll
### PDF Shell Extension Adobe Systems, Inc. Adobe PDF Shell Extension 10.1.0.5
34
[Explorer's DLLs] C:\Auto Shutdown Genius\MHK.dll
[Explorer's DLLs] C:\WINDOWS\system32\BatMeter.dll
### Battery Meter Helper DLL Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.5512
[Explorer's DLLs] C:\WINDOWS\system32\stobject.dll
### Systray shell service object Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\MLANG.dll
### Multi Language Support DLL Microsoft Corporation Microsoft Windows Operating
System 6.00.2900.5512
[Explorer's DLLs] C:\WINDOWS\system32\webcheck.dll
### Web Site Monitor Microsoft Corporation Windows Internet Explorer 8.00.6001.
18702
[Explorer's DLLs] C:\WINDOWS\system32\eappprxy.dll
### Microsoft EAPHost Peer Client DLL Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\OneX.DLL
### IEEE 802.1X supplicant library Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\System32\davclnt.dll
### Web DAV Client DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\System32\NETRAP.dll
### Net Remote Admin Protocol DLL Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\System32\NETUI1.dll
### NT LM UI Common Code - Networking classes Microsoft Corporation Microsoft W
indows Operating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\System32\NETUI0.dll
### NT LM UI Common Code - GUI Classes Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\System32\ntlanman.dll
### Microsoft Lan Manager Microsoft Corporation Microsoft Windows Operating Syste
m 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\System32\drprov.dll
### Microsoft Terminal Server Network Provider Microsoft Corporation Microsoft
Windows Operating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\ntshrui.dll
### Shell extensions for sharing Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\linkinfo.dll

### Windows Volume Tracking Microsoft Corporation Microsoft Windows Operating Sy


stem 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\shdoclc.dll
### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window
s Operating System 6.00.2900.5512
[Explorer's DLLs] C:\WINDOWS\system32\ieframe.dll
### Internet Explorer Microsoft Corporation Windows Internet Explorer 8.00.6001
.18702
[Explorer's DLLs] C:\WINDOWS\system32\msxml3.dll
### MSXML 3.0 SP10 Microsoft Corporation Microsoft(R) MSXML 3.0 SP10 8.100.105
4.0
[Explorer's DLLs] C:\WINDOWS\system32\xpsp2res.dll
### Service Pack 2 Messages Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\MSIMG32.dll
### GDIEXT Client DLL Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\themeui.dll
### Windows Theme API Microsoft Corporation Microsoft Windows Operating System 6
.00.2900.6437
[Explorer's DLLs] C:\WINDOWS\system32\Normaliz.dll
### Unicode Normalization DLL Microsoft Corporation Microsoft Windows Operating
System 6.0.5441.0
[Explorer's DLLs] C:\WINDOWS\system32\SHDOCVW.dll
### Shell Doc Object and Control Library Microsoft Corporation Microsoft Window
s Operating System 6.00.2900.6452
[Explorer's DLLs] C:\WINDOWS\system32\BROWSEUI.dll
### Shell Browser UI Library Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6452
[Explorer's DLLs] c:\windows\system32\POWRPROF.dll
### Power Profile Helper DLL Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.5512
[Explorer's DLLs] c:\windows\system32\eappcfg.dll
### Eap Peer Config Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512
[Explorer's DLLs] c:\windows\system32\dot3dlg.dll
### 802.3 UI Helper Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512
[Explorer's DLLs] c:\windows\system32\credui.dll
### Credential Manager User Interface Microsoft Corporation Microsoft Windows Op
erating System 5.1.2600.5512
[Explorer's DLLs] c:\windows\system32\netshell.dll
### Network Connections Shell Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\iertutil.dll
### Run time utility for Internet Explorer Microsoft Corporation Windows Intern
et Explorer 8.00.6001.18702
[Explorer's DLLs] C:\WINDOWS\system32\urlmon.dll
### OLE32 Extensions for Win32 Microsoft Corporation Windows Internet Explorer
8.00.6001.18702
[Explorer's DLLs] C:\WINDOWS\system32\WININET.dll
### Internet Extensions for Win32 Microsoft Corporation Windows Internet Explor
er 8.00.6001.18702
[Explorer's DLLs] C:\WINDOWS\System32\CRYPTUI.dll
### Microsoft Trust UI Provider Microsoft Corporation Microsoft Windows Operatin
g System 5.131.2600.5512
[Explorer's DLLs] c:\windows\system32\dot3api.dll
### 802.3 Autoconfiguration API Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\msi.dll

### Windows Installer Microsoft Corporation Windows Installer - Unicode 3.1.40


01.5512
[Explorer's DLLs] C:\WINDOWS\System32\winrnr.dll
### LDAP RnR Provider DLL Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Explorer's DLLs] c:\windows\system32\ATL.DLL
### ATL Module for Windows XP (Unicode) Microsoft Corporation Microsoft (R) Vi
sual C++ 6.05.2284
[Explorer's DLLs] C:\WINDOWS\system32\rasadhlp.dll
### Remote Access AutoDial Helper Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\rtutils.dll
### Routing Utilities Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\mswsock.dll
### Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation Micro
soft Windows Operating System 5.1.2600.5625
[Explorer's DLLs] C:\WINDOWS\AppPatch\AcGenral.DLL
### Windows Compatibility DLL Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\ShimEng.dll
### Shim Engine DLL Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\DNSAPI.dll
### DNS Client API DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.6089
[Explorer's DLLs] C:\WINDOWS\system32\MSVCP60.dll
### Microsoft (R) C++ Runtime Library Microsoft Corporation Microsoft (R) Visu
al C++ 6.02.3104.0
[Explorer's DLLs] C:\WINDOWS\system32\CLBCATQ.DLL
### Microsoft Corporation COM Services 03.00.00.4414
[Explorer's DLLs] C:\WINDOWS\system32\OLEAUT32.dll
### Microsoft Corporation 5.1.2600.6341
[Explorer's DLLs] C:\WINDOWS\system32\COMRes.dll
### Microsoft Corporation COM Services 03.00.00.4414
[Explorer's DLLs] C:\WINDOWS\system32\midimap.dll
### Microsoft MIDI Mapper Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\MSACM32.dll
### Microsoft ACM Audio Filter Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\msacm32.drv
### Microsoft Sound Mapper Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.0
[Explorer's DLLs] C:\WINDOWS\system32\wdmaud.drv
### WDM Audio driver mapper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\iphlpapi.dll
### IP Helper API Microsoft Corporation Microsoft Windows Operating System 5.1.2
600.5512
[Explorer's DLLs] C:\WINDOWS\system32\WLDAP32.dll
### Win32 LDAP API DLL Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\NTMARTA.DLL
### Windows NT MARTA provider Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\cscui.dll
### Client Side Caching UI Microsoft Corporation Microsoft Windows Operating Sys
tem 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\SAMLIB.dll

### SAM Library DLL Microsoft Corporation Microsoft Windows Operating System 5.1
.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\rsaenh.dll
### Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft W
indows Operating System 5.1.2600.5507
[Explorer's DLLs] C:\WINDOWS\system32\MPR.dll
### Multiple Provider Router DLL Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\cscdll.dll
### Offline Network Agent Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\uxtheme.dll
### Microsoft UxTheme Library Microsoft Corporation Microsoft Windows Operating
System 6.00.2900.5512
[Explorer's DLLs] C:\WINDOWS\system32\WINMM.dll
### MCI API DLL Microsoft Corporation Microsoft Windows Operating System 5.1.260
0.6160
[Explorer's DLLs] C:\WINDOWS\system32\WTSAPI32.dll
### Windows Terminal Server SDK APIs Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\msctfime.ime
### Microsoft Text Frame Work Service IME Microsoft Corporation Microsoft Windo
ws Operating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\Apphelp.dll
### Application Compatibility Client Library Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\ole32.dll
### Microsoft OLE for Windows Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.6435
[Explorer's DLLs] C:\WINDOWS\system32\sfc_os.dll
### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\sfc.dll
### Windows File Protection Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595
b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
### User Experience Controls Library Microsoft Corporation Microsoft Windows Ope
rating System 6.00.2900.6028
[Explorer's DLLs] C:\WINDOWS\system32\SHLWAPI.dll
### Shell Light-weight Utility Library Microsoft Corporation Microsoft Windows O
perating System 6.00.2900.5912
[Explorer's DLLs] C:\WINDOWS\system32\SHELL32.dll
### Windows Shell Common Dll Microsoft Corporation Microsoft Windows Operating S
ystem 6.00.2900.6242
[Explorer's DLLs] C:\WINDOWS\system32\comdlg32.dll
### Common Dialogs DLL Microsoft Corporation Microsoft Windows Operating System
6.00.2900.5512
[Explorer's DLLs] C:\WINDOWS\system32\ODBC32.dll
### Microsoft Data Access - ODBC Driver Manager Microsoft Corporation Microsof
t Data Access Components 3.525.3012.0
[Explorer's DLLs] C:\WINDOWS\system32\COMCTL32.dll
### Common Controls Library Microsoft Corporation Microsoft Windows Operating Sy
stem 6.00.2900.6028
[Explorer's DLLs] C:\WINDOWS\system32\MSGINA.dll
### Windows NT Logon GINA DLL Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\IMM32.DLL
### Windows XP IMM32 API Client DLL Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512

[Explorer's DLLs] C:\WINDOWS\system32\WS2HELP.dll


### Windows Socket 2.0 Helper for Windows NT Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\WS2_32.dll
### Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\IMAGEHLP.dll
### Windows NT Image Helper Microsoft Corporation Microsoft Windows Operating Sy
stem 5.1.2600.6479
[Explorer's DLLs] C:\WINDOWS\system32\WINTRUST.dll
### Microsoft Trust Verification APIs Microsoft Corporation Microsoft Windows Op
erating System 5.131.2600.6285
[Explorer's DLLs] C:\WINDOWS\system32\WINSTA.dll
### Winstation Library Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\VERSION.dll
### Version Checking and File Installation Libraries Microsoft Corporation Mic
rosoft Windows Operating System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\SETUPAPI.dll
### Windows Setup API Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\PSAPI.DLL
### Process Status Helper Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\USERENV.dll
### Userenv Microsoft Corporation Microsoft Windows Operating System 5.1.2600.55
12
[Explorer's DLLs] C:\WINDOWS\system32\NETAPI32.dll
### Net Win32 API DLL Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.6260
[Explorer's DLLs] C:\WINDOWS\system32\MSASN1.dll
### ASN.1 Runtime APIs Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5875
[Explorer's DLLs] C:\WINDOWS\system32\CRYPT32.dll
### Crypto API32 Microsoft Corporation Microsoft Windows Operating System 5.131.
2600.6459
[Explorer's DLLs] C:\WINDOWS\system32\msvcrt.dll
### Windows NT CRT DLL Microsoft Corporation Microsoft Windows Operating System
7.0.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\Secur32.dll
### Security Support Provider Interface Microsoft Corporation Microsoft Windows
Operating System 5.1.2600.5834
[Explorer's DLLs] C:\WINDOWS\system32\RPCRT4.dll
### Remote Procedure Call Runtime Microsoft Corporation Microsoft Windows Operat
ing System 5.1.2600.6477
[Explorer's DLLs] C:\WINDOWS\system32\ADVAPI32.dll
### Advanced Windows 32 Base API Microsoft Corporation Microsoft Windows Operati
ng System 5.1.2600.5755
[Explorer's DLLs] C:\WINDOWS\system32\sxs.dll
### Fusion 2.5 Microsoft Corporation Microsoft Windows Operating System 5.1.2600
.5512
[Explorer's DLLs] C:\WINDOWS\system32\USER32.dll
### Windows XP USER API Client DLL Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512
[Explorer's DLLs] C:\WINDOWS\system32\KERNEL32.dll
### Windows NT BASE API Client DLL Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.6532
[Explorer's DLLs] C:\WINDOWS\system32\GDI32.dll
### GDI Client DLL Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.6460

[Explorer's DLLs] C:\WINDOWS\system32\ntdll.dll


### NT Layer DLL Microsoft Corporation Microsoft Windows Operating System 5.1.26
00.6055
[Running Services] ALG
### Internal Name: ALG. Status: service is running. Actual File: C:\WINDOWS\Sy
stem32\alg.exe * Provides support for 3rd party protocol plug-ins for Internet C
onnection Sharing and the Windows Firewall. Application Layer Gateway Service Mi
crosoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] AntiVirSchedulerService
### Internal Name: AntiVirSchedulerService. Status: service is running. Actual
File: "C:\Program Files\Avira\AntiVir Desktop\sched.exe" * Service to schedule
Avira AntiVir Personal - Free Antivirus jobs and updates. Antivirus Scheduler Av
ira GmbH AntiVir Desktop 10.00.00.21
[Running Services] AntiVirService
### Internal Name: AntiVirService. Status: service is running. Actual File: "C
:\Program Files\Avira\AntiVir Desktop\avguard.exe" * Offers permanent protection
against viruses and malware with the AntiVir search engine. Antivirus On-Access
Service Avira GmbH AntiVir Desktop 10.00.01.58
[Running Services] AudioSrv
### Internal Name: AudioSrv. Status: service is running. Actual File: C:\WINDO
WS\System32\svchost.exe -k netsvcs * Manages audio devices for Windows-based pro
grams. If this service is stopped, audio devices and effects will not function p
roperly. If this service is disabled, any services that explicitly depend on it
will fail to start. Generic Host Process for Win32 Services Microsoft Corporatio
n Microsoft Windows Operating System 5.1.2600.5512
[Running Services] BITS
### Internal Name: BITS. Status: service is running. Actual File: C:\WINDOWS\s
ystem32\svchost.exe -k netsvcs * Transfers data between clients and servers in t
he background. If BITS is disabled, features such as Windows Update will not wor
k correctly. Generic Host Process for Win32 Services Microsoft Corporation Micro
soft Windows Operating System 5.1.2600.5512
[Running Services] Browser
### Internal Name: Browser. Status: service is running. Actual File: C:\WINDOW
S\system32\svchost.exe -k netsvcs * Maintains an updated list of computers on th
e network and supplies this list to computers designated as browsers. If this se
rvice is stopped, this list will not be updated or maintained. If this service i
s disabled, any services that explicitly depend on it will fail to start. Generi
c Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Running Services] COMSysApp
### Internal Name: COMSysApp. Status: service is running. Actual File: C:\WIND
OWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} * Man
ages the configuration and tracking of Component Object Model (COM)+-based compo
nents. If the service is stopped, most COM+-based components will not function p
roperly. If this service is disabled, any services that explicitly depend on it
will fail to start. COM Surrogate Microsoft Corporation Microsoft Windows Operatin
g System 5.1.2600.5512
[Running Services] CryptSvc
### Internal Name: CryptSvc. Status: service is running. Actual File: C:\WINDO
WS\system32\svchost.exe -k netsvcs * Provides three management services: Catalog
Database Service, which confirms the signatures of Windows files; Protected Roo
t Service, which adds and removes Trusted Root Certification Authority certifica
tes from this computer; and Key Service, which helps enroll this computer for ce
rtificates. If this service is stopped, these management services will not funct
ion properly. If this service is disabled, any services that explicitly depend o
n it will fail to start. Generic Host Process for Win32 Services Microsoft Corpo
ration Microsoft Windows Operating System 5.1.2600.5512
[Running Services] DcomLaunch
### Internal Name: DcomLaunch. Status: service is running. Actual File: C:\WIN
DOWS\system32\svchost -k DcomLaunch * Provides launch functionality for DCOM ser

vices. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Running Services] Dhcp
### Internal Name: Dhcp. Status: service is running. Actual File: C:\WINDOWS\s
ystem32\svchost.exe -k netsvcs * Manages network configuration by registering an
d updating IP addresses and DNS names. Generic Host Process for Win32 Services M
icrosoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] dmserver
### Internal Name: dmserver. Status: service is running. Actual File: C:\WINDO
WS\System32\svchost.exe -k netsvcs * Detects and monitors new hard disk drives a
nd sends disk volume information to Logical Disk Manager Administrative Service
for configuration. If this service is stopped, dynamic disk status and configura
tion information may become out of date. If this service is disabled, any servic
es that explicitly depend on it will fail to start. Generic Host Process for Win
32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] Dnscache
### Internal Name: Dnscache. Status: service is running. Actual File: C:\WINDO
WS\system32\svchost.exe -k NetworkService * Resolves and caches Domain Name Syst
em (DNS) names for this computer. If this service is stopped, this computer will
not be able to resolve DNS names and locate Active Directory domain controllers
. If this service is disabled, any services that explicitly depend on it will fa
il to start. Generic Host Process for Win32 Services Microsoft Corporation Micro
soft Windows Operating System 5.1.2600.5512
[Running Services] ERSvc
### Internal Name: ERSvc. Status: service is running. Actual File: C:\WINDOWS\
System32\svchost.exe -k netsvcs * Allows error reporting for services and applic
tions running in non-standard environments. Generic Host Process for Win32 Servi
ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] Eventlog
### Internal Name: Eventlog. Status: service is running. Actual File: C:\WINDO
WS\system32\services.exe * Enables event log messages issued by Windows-based pr
ograms and components to be viewed in Event Viewer. This service cannot be stopp
ed. Services and Controller app Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5755
[Running Services] EventSystem
### Internal Name: EventSystem. Status: service is running. Actual File: C:\WI
NDOWS\system32\svchost.exe -k netsvcs * Supports System Event Notification Servi
ce (SENS), which provides automatic distribution of events to subscribing Compon
ent Object Model (COM) components. If the service is stopped, SENS will close an
d will not be able to provide logon and logoff notifications. If this service is
disabled, any services that explicitly depend on it will fail to start. Generic
Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Running Services] FastUserSwitchingCompatibility
### Internal Name: FastUserSwitchingCompatibility. Status: service is running.
Actual File: C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides management f
or applications that require assistance in a multiple user environment. Generic
Host Process for Win32 Services Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Running Services] helpsvc
### Internal Name: helpsvc. Status: service is running. Actual File: C:\WINDOW
S\System32\svchost.exe -k netsvcs * Enables Help and Support Center to run on th
is computer. If this service is stopped, Help and Support Center will be unavail
able. If this service is disabled, any services that explicitly depend on it wil
l fail to start. Generic Host Process for Win32 Services Microsoft Corporation M
icrosoft Windows Operating System 5.1.2600.5512
[Running Services] HidServ
### Internal Name: HidServ. Status: service is running. Actual File: C:\WINDOW
S\System32\svchost.exe -k netsvcs * Enables generic input access to Human Interf

ace Devices (HID), which activates and maintains the use of predefined hot butto
ns on keyboards, remote controls, and other multimedia devices. If this service
is stopped, hot buttons controlled by this service will no longer function. If t
his service is disabled, any services that explicitly depend on it will fail to
start. Generic Host Process for Win32 Services Microsoft Corporation Microsoft Wi
ndows Operating System 5.1.2600.5512
[Running Services] Kingsoft_WPS_UpdateService
### Internal Name: Kingsoft_WPS_UpdateService. Status: service is running. Act
ual File: C:\Documents and Settings\xpsp3\Local Settings\Application Data\Kingso
ft\WPS Office\9.1.0.5234\wtoolex\wpsupdatesvr.exe * WPS Office Update Service. W
PS Office Expansion tool Zhuhai Kingsoft Office Software Co.,Ltd WPS Office 9,1,
0,5234
[Running Services] LanmanServer
### Internal Name: LanmanServer. Status: service is running. Actual File: C:\W
INDOWS\system32\svchost.exe -k netsvcs * Supports file, print, and named-pipe sh
aring over the network for this computer. If this service is stopped, these func
tions will be unavailable. If this service is disabled, any services that explic
itly depend on it will fail to start. Generic Host Process for Win32 Services Mi
crosoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] lanmanworkstation
### Internal Name: lanmanworkstation. Status: service is running. Actual File:
C:\WINDOWS\system32\svchost.exe -k netsvcs * Creates and maintains client netwo
rk connections to remote servers. If this service is stopped, these connections
will be unavailable. If this service is disabled, any services that explicitly d
epend on it will fail to start. Generic Host Process for Win32 Services Microsof
t Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] LmHosts
### Internal Name: LmHosts. Status: service is running. Actual File: C:\WINDOW
S\system32\svchost.exe -k LocalService * Enables support for NetBIOS over TCP/IP
(NetBT) service and NetBIOS name resolution. Generic Host Process for Win32 Ser
vices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] MSDTC
### Internal Name: MSDTC. Status: service is running. Actual File: C:\WINDOWS\
system32\msdtc.exe * Coordinates transactions that span multiple resource manage
rs, such as databases, message queues, and file systems. If this service is stop
ped, these transactions will not occur. If this service is disabled, any service
s that explicitly depend on it will fail to start. MS DTC console program Micro
soft Corporation Microsoft Distributed Transaction Coordinator 03.01.00.4414
[Running Services] Netman
### Internal Name: Netman. Status: service is running. Actual File: C:\WINDOWS
\System32\svchost.exe -k netsvcs * Manages objects in the Network and Dial-Up Co
nnections folder, in which you can view both local area network and remote conne
ctions. Generic Host Process for Win32 Services Microsoft Corporation Microsoft W
indows Operating System 5.1.2600.5512
[Running Services] Nla
### Internal Name: Nla. Status: service is running. Actual File: C:\WINDOWS\sy
stem32\svchost.exe -k netsvcs * Collects and stores network configuration and lo
cation information, and notifies applications when this information changes. Gen
eric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Opera
ting System 5.1.2600.5512
[Running Services] PlugPlay
### Internal Name: PlugPlay. Status: service is running. Actual File: C:\WINDO
WS\system32\services.exe * Enables a computer to recognize and adapt to hardware
changes with little or no user input. Stopping or disabling this service will r
esult in system instability. Services and Controller app Microsoft Corporation M
icrosoft Windows Operating System 5.1.2600.5755
[Running Services] PolicyAgent
### Internal Name: PolicyAgent. Status: service is running. Actual File: C:\WI
NDOWS\system32\lsass.exe * Manages IP security policy and starts the ISAKMP/Oakl
ey (IKE) and the IP security driver. LSA Shell (Export Version) Microsoft Corpor

ation Microsoft Windows Operating System 5.1.2600.5512


[Running Services] ProtectedStorage
### Internal Name: ProtectedStorage. Status: service is running. Actual File:
C:\WINDOWS\system32\lsass.exe * Provides protected storage for sensitive data, s
uch as private keys, to prevent access by unauthorized services, processes, or u
sers. LSA Shell (Export Version) Microsoft Corporation Microsoft Windows Operating
System 5.1.2600.5512
[Running Services] RasMan
### Internal Name: RasMan. Status: service is running. Actual File: C:\WINDOWS
\system32\svchost.exe -k netsvcs * Creates a network connection. Generic Host Pr
ocess for Win32 Services Microsoft Corporation Microsoft Windows Operating System
5.1.2600.5512
[Running Services] RemoteRegistry
### Internal Name: RemoteRegistry. Status: service is running. Actual File: C:
\WINDOWS\system32\svchost.exe -k LocalService * Enables remote users to modify r
egistry settings on this computer. If this service is stopped, the registry can
be modified only by users on this computer. If this service is disabled, any ser
vices that explicitly depend on it will fail to start. Generic Host Process for
Win32 Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5
512
[Running Services] RpcSs
### Internal Name: RpcSs. Status: service is running. Actual File: C:\WINDOWS\
system32\svchost -k rpcss * Provides the endpoint mapper and other miscellaneous
RPC services. Generic Host Process for Win32 Services Microsoft Corporation Mic
rosoft Windows Operating System 5.1.2600.5512
[Running Services] SamSs
### Internal Name: SamSs. Status: service is running. Actual File: C:\WINDOWS\
system32\lsass.exe * Stores security information for local user accounts. LSA Sh
ell (Export Version) Microsoft Corporation Microsoft Windows Operating System 5.1.
2600.5512
[Running Services] Schedule
### Internal Name: Schedule. Status: service is running. Actual File: C:\WINDO
WS\System32\svchost.exe -k netsvcs * Enables a user to configure and schedule au
tomated tasks on this computer. If this service is stopped, these tasks will not
be run at their scheduled times. If this service is disabled, any services that
explicitly depend on it will fail to start. Generic Host Process for Win32 Serv
ices Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] seclogon
### Internal Name: seclogon. Status: service is running. Actual File: C:\WINDO
WS\System32\svchost.exe -k netsvcs * Enables starting processes under alternate
credentials. If this service is stopped, this type of logon access will be unava
ilable. If this service is disabled, any services that explicitly depend on it w
ill fail to start. Generic Host Process for Win32 Services Microsoft Corporation
Microsoft Windows Operating System 5.1.2600.5512
[Running Services] SENS
### Internal Name: SENS. Status: service is running. Actual File: C:\WINDOWS\s
ystem32\svchost.exe -k netsvcs * Tracks system events such as Windows logon, net
work, and power events. Notifies COM+ Event System subscribers of these events.
Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512
[Running Services] SharedAccess
### Internal Name: SharedAccess. Status: service is running. Actual File: C:\W
INDOWS\system32\svchost.exe -k netsvcs * Provides network address translation, a
ddressing, name resolution and/or intrusion prevention services for a home or sm
all office network. Generic Host Process for Win32 Services Microsoft Corporatio
n Microsoft Windows Operating System 5.1.2600.5512
[Running Services] ShellHWDetection
### Internal Name: ShellHWDetection. Status: service is running. Actual File:
C:\WINDOWS\System32\svchost.exe -k netsvcs * Provides notifications for AutoPlay
hardware events. Generic Host Process for Win32 Services Microsoft Corporation

Microsoft Windows Operating System 5.1.2600.5512


[Running Services] ShutdownService
### Internal Name: ShutdownService. Status: service is running. Actual File: C
:\Auto Shutdown Genius\ShutdownSvr.exe *
[Running Services] Spooler
### Internal Name: Spooler. Status: service is running. Actual File: C:\WINDOW
S\system32\spoolsv.exe * Loads files to memory for later printing. Spooler SubSy
stem App Microsoft Corporation Microsoft Windows Operating System 5.1.2600.6024
[Running Services] srservice
### Internal Name: srservice. Status: service is running. Actual File: C:\WIND
OWS\system32\svchost.exe -k netsvcs * Performs system restore functions. To stop
service, turn off System Restore from the System Restore tab in My Computer->Pr
operties Generic Host Process for Win32 Services Microsoft Corporation Microsoft
Windows Operating System 5.1.2600.5512
[Running Services] SSDPSRV
### Internal Name: SSDPSRV. Status: service is running. Actual File: C:\WINDOW
S\system32\svchost.exe -k LocalService * Enables discovery of UPnP devices on yo
ur home network. Generic Host Process for Win32 Services Microsoft Corporation M
icrosoft Windows Operating System 5.1.2600.5512
[Running Services] TapiSrv
### Internal Name: TapiSrv. Status: service is running. Actual File: C:\WINDOW
S\System32\svchost.exe -k netsvcs * Provides Telephony API (TAPI) support for pr
ograms that control telephony devices and IP based voice connections on the loca
l computer and, through the LAN, on servers that are also running the service. G
eneric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Ope
rating System 5.1.2600.5512
[Running Services] TermService
### Internal Name: TermService. Status: service is running. Actual File: C:\WI
NDOWS\System32\svchost -k DComLaunch * Allows multiple users to be connected int
eractively to a machine as well as the display of desktops and applications to r
emote computers. The underpinning of Remote Desktop (including RD for Administra
tors), Fast User Switching, Remote Assistance, and Terminal Server. Generic Host
Process for Win32 Services Microsoft Corporation Microsoft Windows Operating Syst
em 5.1.2600.5512
[Running Services] Themes
### Internal Name: Themes. Status: service is running. Actual File: C:\WINDOWS
\System32\svchost.exe -k netsvcs * Provides user experience theme management. Ge
neric Host Process for Win32 Services Microsoft Corporation Microsoft Windows Oper
ating System 5.1.2600.5512
[Running Services] TrkWks
### Internal Name: TrkWks. Status: service is running. Actual File: C:\WINDOWS
\system32\svchost.exe -k netsvcs * Maintains links between NTFS files within a c
omputer or across computers in a network domain. Generic Host Process for Win32
Services Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] W32Time
### Internal Name: W32Time. Status: service is running. Actual File: C:\WINDOW
S\System32\svchost.exe -k netsvcs * Maintains date and time synchronization on a
ll clients and servers in the network. If this service is stopped, date and time
synchronization will be unavailable. If this service is disabled, any services
that explicitly depend on it will fail to start.
Generic Host Process for Win32 Services Microsoft Corporation Microsoft Windows O
perating System 5.1.2600.5512
[Running Services] WebClient
### Internal Name: WebClient. Status: service is running. Actual File: C:\WIND
OWS\system32\svchost.exe -k LocalService * Enables Windows-based programs to cre
ate, access, and modify Internet-based files. If this service is stopped, these
functions will not be available. If this service is disabled, any services that
explicitly depend on it will fail to start. Generic Host Process for Win32 Servi
ces Microsoft Corporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] winmgmt

### Internal Name: winmgmt. Status: service is running. Actual File: C:\WINDOW
S\system32\svchost.exe -k netsvcs * Provides a common interface and object model
to access management information about operating system, devices, applications
and services. If this service is stopped, most Windows-based software will not f
unction properly. If this service is disabled, any services that explicitly depe
nd on it will fail to start. Generic Host Process for Win32 Services Microsoft C
orporation Microsoft Windows Operating System 5.1.2600.5512
[Running Services] wscsvc
### Internal Name: wscsvc. Status: service is running. Actual File: C:\WINDOWS
\System32\svchost.exe -k netsvcs * Monitors system security settings and configu
rations. Generic Host Process for Win32 Services Microsoft Corporation Microsoft
Windows Operating System 5.1.2600.5512
[Running Services] wuauserv
### Internal Name: wuauserv. Status: service is running. Actual File: C:\WINDO
WS\system32\svchost.exe -k netsvcs * Enables the download and installation of Wi
ndows updates. If this service is disabled, this computer will not be able to us
e the Automatic Updates feature or the Windows Update Web site. Generic Host Pro
cess for Win32 Services Microsoft Corporation Microsoft Windows Operating System 5
.1.2600.5512
[Running Services] WZCSVC
### Internal Name: WZCSVC. Status: service is running. Actual File: C:\WINDOWS
\System32\svchost.exe -k netsvcs * Provides automatic configuration for the 802.
11 adapters Generic Host Process for Win32 Services Microsoft Corporation Micros
oft Windows Operating System 5.1.2600.5512
[Running Services] TuneUp.UtilitiesSvc
### Internal Name: TuneUp.UtilitiesSvc. Status: service is running. Actual Fil
e: "C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe" * This
service analyzes the usage of your computer in the background, enabling automati
c usage-dependent optimizations. All of its functions can be set in TuneUp Utili
ties. If you stop or disable this service, parts of TuneUp Utilities will not wo
rk anymore. TuneUp Utilities Service TuneUp Software TuneUp Utilities 2013 13.0.
2013.194
[Uninstall]
[Applications] :HKLM UnHackMe_is1="C:\Program Files\UnHackMe\unins000.exe" /SI
LENT
### UnHackMe 7.90 - (27) 01-2016
[Applications] :HKLM {C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
### TuneUp Utilities 2013 - (27) 01-2016
[Applications] :HKLM TuneUp Utilities 2013=C:\Program Files\TuneUp Utilities 2
013\TUInstallHelper.exe --Trigger-Uninstall
### TuneUp Utilities 2013 - (27) 01-2016
[Applications] :HKLM {A6F5703D-A4B1-4857-9EDD-DC0ABBBB0D96}
### TuneUp Utilities Language Pack (en-US) - (27) 01-2016
[Applications] :HKLM InstallBlock="C:\WINDOWS\Install-Block\uninstall.exe" "/U
:C:\Program Files\Bash Software\Install-Block\irunin.xml"
### Install-Block 2.0.6 - (27) 01-2016
[Applications] :HKLM Stop Software Installation Tool_is1="C:\Program Files\Sto
p Software Installation Tool\stopinst.exe" /uninstall
### Stop Software Installation Tool 5.1.1.2 - (27) 01-2016
[Applications] :HKLM {AC76BA86-0804-1033-1959-001824166751}=MsiExec.exe /I{AC7
6BA86-0804-1033-1959-001824166751}
### Adobe Refresh Manager - (27) 01-2016
[Applications] :HKLM KB2868626="C:\WINDOWS\$NtUninstallKB2868626$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2868626) - (26) 01-2016
[Applications] :HKLM KB2922229="C:\WINDOWS\$NtUninstallKB2922229$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2922229) - (26) 01-2016
[Applications] :HKLM KB951376-v2="C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst
\spuninst.exe"

### Security Update for Windows XP (KB951376-v2) - (26) 01-2016


[Applications] :HKLM KB952954="C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB952954) - (26) 01-2016
[Applications] :HKLM KB959426="C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB959426) - (26) 01-2016
[Applications] :HKLM KB2510581="C:\WINDOWS\$NtUninstallKB2510581$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2510581) - (26) 01-2016
[Applications] :HKLM KB975713="C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB975713) - (26) 01-2016
[Applications] :HKLM KB2879017="C:\WINDOWS\$NtUninstallKB2879017$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2879017) - (26) 01-2016
[Applications] :HKLM KB2909212="C:\WINDOWS\$NtUninstallKB2909212$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2909212) - (26) 01-2016
[Applications] :HKLM KB951978="C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuni
nst.exe"
### Update for Windows XP (KB951978) - (26) 01-2016
[Applications] :HKLM ie8="C:\WINDOWS\ie8\spuninst\spuninst.exe"
### Windows Internet Explorer 8 - (26) 01-2016
[Applications] :HKLM ie7
### - (26) 01-2016
[Applications] :HKLM IDNMitigationAPIs
### - (26) 01-2016
[Applications] :HKLM NLSDownlevelMapping
### - (26) 01-2016
[Applications] :HKLM KB946648="C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB946648) - (26) 01-2016
[Applications] :HKLM KB2387149="C:\WINDOWS\$NtUninstallKB2387149$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2387149) - (26) 01-2016
[Applications] :HKLM KB2712808="C:\WINDOWS\$NtUninstallKB2712808$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2712808) - (26) 01-2016
[Applications] :HKLM KB960859="C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB960859) - (26) 01-2016
[Applications] :HKLM KB2479943="C:\WINDOWS\$NtUninstallKB2479943$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2479943) - (26) 01-2016
[Applications] :HKLM KB2659262="C:\WINDOWS\$NtUninstallKB2659262$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2659262) - (26) 01-2016
[Applications] :HKLM KB2564958="C:\WINDOWS\$NtUninstallKB2564958$\spuninst\spu
ninst.exe"
### Security Update for Microsoft Windows (KB2564958) - (26) 01-2016
[Applications] :HKLM KB2916036="C:\WINDOWS\$NtUninstallKB2916036$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2916036) - (26) 01-2016
[Applications] :HKLM KB2934207="C:\WINDOWS\$NtUninstallKB2934207$\spuninst\spu
ninst.exe"
### Update for Windows XP (KB2934207) - (26) 01-2016
[Applications] :HKLM KB2478971="C:\WINDOWS\$NtUninstallKB2478971$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2478971) - (26) 01-2016

[Applications] :HKLM KB2544893-v2="C:\WINDOWS\$NtUninstallKB2544893-v2$\spunin


st\spuninst.exe"
### Security Update for Windows XP (KB2544893-v2) - (26) 01-2016
[Applications] :HKLM KB2834886="C:\WINDOWS\$NtUninstallKB2834886$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2834886) - (26) 01-2016
[Applications] :HKLM KB2536276-v2="C:\WINDOWS\$NtUninstallKB2536276-v2$\spunin
st\spuninst.exe"
### Security Update for Windows XP (KB2536276-v2) - (26) 01-2016
[Applications] :HKLM KB2585542="C:\WINDOWS\$NtUninstallKB2585542$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2585542) - (26) 01-2016
[Applications] :HKLM KB2631813="C:\WINDOWS\$NtUninstallKB2631813$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2631813) - (26) 01-2016
[Applications] :HKLM KB2296011="C:\WINDOWS\$NtUninstallKB2296011$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2296011) - (26) 01-2016
[Applications] :HKLM KB2691442="C:\WINDOWS\$NtUninstallKB2691442$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2691442) - (26) 01-2016
[Applications] :HKLM KB2900986="C:\WINDOWS\$NtUninstallKB2900986$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2900986) - (26) 01-2016
[Applications] :HKLM KB2115168="C:\WINDOWS\$NtUninstallKB2115168$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2115168) - (26) 01-2016
[Applications] :HKLM KB975558_WM8="C:\WINDOWS\$NtUninstallKB975558_WM8$\spunin
st\spuninst.exe"
### Security Update for Windows Media Player (KB975558) - (26) 01-2016
[Applications] :HKLM KB955759="C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuni
nst.exe"
### Update for Windows XP (KB955759) - (26) 01-2016
[Applications] :HKLM KB2847311="C:\WINDOWS\$NtUninstallKB2847311$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2847311) - (26) 01-2016
[Applications] :HKLM MPlayer2
### - (26) 01-2016
[Applications] :HKLM KB2378111_WM9="C:\WINDOWS\$NtUninstallKB2378111_WM9$\spun
inst\spuninst.exe"
### Security Update for Windows Media Player (KB2378111) - (26) 01-2016
[Applications] :HKLM KB974318="C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB974318) - (26) 01-2016
[Applications] :HKLM KB969059="C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB969059) - (26) 01-2016
[Applications] :HKLM KB2443105="C:\WINDOWS\$NtUninstallKB2443105$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2443105) - (26) 01-2016
[Applications] :HKLM KB2655992="C:\WINDOWS\$NtUninstallKB2655992$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2655992) - (26) 01-2016
[Applications] :HKLM KB2802968="C:\WINDOWS\$NtUninstallKB2802968$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2802968) - (26) 01-2016
[Applications] :HKLM KB2229593="C:\WINDOWS\$NtUninstallKB2229593$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2229593) - (26) 01-2016
[Applications] :HKLM KB950974="C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuni

nst.exe"
### Security Update for Windows XP (KB950974) - (26) 01-2016
[Applications] :HKLM KB2481109="C:\WINDOWS\$NtUninstallKB2481109$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2481109) - (26) 01-2016
[Applications] :HKLM KB2898715="C:\WINDOWS\$NtUninstallKB2898715$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2898715) - (26) 01-2016
[Applications] :HKLM KB2485663="C:\WINDOWS\$NtUninstallKB2485663$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2485663) - (26) 01-2016
[Applications] :HKLM KB2598479="C:\WINDOWS\$NtUninstallKB2598479$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2598479) - (26) 01-2016
[Applications] :HKLM KB2929961="C:\WINDOWS\$NtUninstallKB2929961$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2929961) - (26) 01-2016
[Applications] :HKLM KB2686509="C:\WINDOWS\$NtUninstallKB2686509$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2686509) - (26) 01-2016
[Applications] :HKLM KB982132="C:\WINDOWS\$NtUninstallKB982132$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB982132) - (26) 01-2016
[Applications] :HKLM KB2862335="C:\WINDOWS\$NtUninstallKB2862335$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2862335) - (26) 01-2016
[Applications] :HKLM KB971657="C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB971657) - (26) 01-2016
[Applications] :HKLM KB978338="C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB978338) - (26) 01-2016
[Applications] :HKLM KB954155_WM9="C:\WINDOWS\$NtUninstallKB954155_WM9$\spunin
st\spuninst.exe"
### Security Update for Windows Media Player (KB954155) - (26) 01-2016
[Applications] :HKLM KB2507938="C:\WINDOWS\$NtUninstallKB2507938$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2507938) - (26) 01-2016
[Applications] :HKLM KB2780091="C:\WINDOWS\$NtUninstallKB2780091$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2780091) - (26) 01-2016
[Applications] :HKLM KB972270="C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB972270) - (26) 01-2016
[Applications] :HKLM KB974112="C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB974112) - (26) 01-2016
[Applications] :HKLM KB956572="C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB956572) - (26) 01-2016
[Applications] :HKLM KB2904266="C:\WINDOWS\$NtUninstallKB2904266$\spuninst\spu
ninst.exe"
### Update for Windows XP (KB2904266) - (26) 01-2016
[Applications] :HKLM KB2347290="C:\WINDOWS\$NtUninstallKB2347290$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2347290) - (26) 01-2016
[Applications] :HKLM KB2876217="C:\WINDOWS\$NtUninstallKB2876217$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2876217) - (26) 01-2016
[Applications] :HKLM KB956844="C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuni

nst.exe"
### Security Update for Windows XP (KB956844) - (26) 01-2016
[Applications] :HKLM KB2483185="C:\WINDOWS\$NtUninstallKB2483185$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2483185) - (26) 01-2016
[Applications] :HKLM KB979687="C:\WINDOWS\$NtUninstallKB979687$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB979687) - (26) 01-2016
[Applications] :HKLM KB2930275="C:\WINDOWS\$NtUninstallKB2930275$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2930275) - (26) 01-2016
[Applications] :HKLM KB2864063="C:\WINDOWS\$NtUninstallKB2864063$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2864063) - (26) 01-2016
[Applications] :HKLM KB973869="C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB973869) - (26) 01-2016
[Applications] :HKLM KB975025="C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB975025) - (26) 01-2016
[Applications] :HKLM KB2719985="C:\WINDOWS\$NtUninstallKB2719985$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2719985) - (26) 01-2016
[Applications] :HKLM KB952004="C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB952004) - (26) 01-2016
[Applications] :HKLM KB974571="C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB974571) - (26) 01-2016
[Applications] :HKLM KB2862152="C:\WINDOWS\$NtUninstallKB2862152$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2862152) - (26) 01-2016
[Applications] :HKLM KB2592799="C:\WINDOWS\$NtUninstallKB2592799$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2592799) - (26) 01-2016
[Applications] :HKLM KB975560="C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB975560) - (26) 01-2016
[Applications] :HKLM KB973507="C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB973507) - (26) 01-2016
[Applications] :HKLM KB2770660="C:\WINDOWS\$NtUninstallKB2770660$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2770660) - (26) 01-2016
[Applications] :HKLM KB2535512="C:\WINDOWS\$NtUninstallKB2535512$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2535512) - (26) 01-2016
[Applications] :HKLM KB977816="C:\WINDOWS\$NtUninstallKB977816$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB977816) - (26) 01-2016
[Applications] :HKLM KB2850869="C:\WINDOWS\$NtUninstallKB2850869$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2850869) - (26) 01-2016
[Applications] :HKLM KB950762="C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB950762) - (26) 01-2016
[Applications] :HKLM KB2876331="C:\WINDOWS\$NtUninstallKB2876331$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2876331) - (26) 01-2016
[Applications] :HKLM KB2859537="C:\WINDOWS\$NtUninstallKB2859537$\spuninst\spu

ninst.exe"
### Security Update for Windows XP (KB2859537) - (26) 01-2016
[Applications] :HKLM KB2807986="C:\WINDOWS\$NtUninstallKB2807986$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2807986) - (26) 01-2016
[Applications] :HKLM KB2570947="C:\WINDOWS\$NtUninstallKB2570947$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2570947) - (26) 01-2016
[Applications] :HKLM KB952287="C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuni
nst.exe"
### Hotfix for Windows XP (KB952287) - (26) 01-2016
[Applications] :HKLM KB978695_WM9="C:\WINDOWS\$NtUninstallKB978695_WM9$\spunin
st\spuninst.exe"
### Security Update for Windows Media Player (KB978695) - (26) 01-2016
[Applications] :HKLM KB2820917="C:\WINDOWS\$NtUninstallKB2820917$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2820917) - (26) 01-2016
[Applications] :HKLM KB2603381="C:\WINDOWS\$NtUninstallKB2603381$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2603381) - (26) 01-2016
[Applications] :HKLM KB973904="C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB973904) - (26) 01-2016
[Applications] :HKLM KB2893294="C:\WINDOWS\$NtUninstallKB2893294$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2893294) - (26) 01-2016
[Applications] :HKLM KB2757638="C:\WINDOWS\$NtUninstallKB2757638$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2757638) - (26) 01-2016
[Applications] :HKLM KB973540_WM9="C:\WINDOWS\$NtUninstallKB973540_WM9$\spunin
st\spuninst.exe"
### Security Update for Windows Media Player (KB973540) - (26) 01-2016
[Applications] :HKLM KB2419632="C:\WINDOWS\$NtUninstallKB2419632$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2419632) - (26) 01-2016
[Applications] :HKLM KB2508429="C:\WINDOWS\$NtUninstallKB2508429$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2508429) - (26) 01-2016
[Applications] :HKLM KB2653956="C:\WINDOWS\$NtUninstallKB2653956$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2653956) - (26) 01-2016
[Applications] :HKLM KB974392="C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB974392) - (26) 01-2016
[Applications] :HKLM KB2749655="C:\WINDOWS\$NtUninstallKB2749655$\spuninst\spu
ninst.exe"
### Update for Windows XP (KB2749655) - (26) 01-2016
[Applications] :HKLM KB971029="C:\WINDOWS\$NtUninstallKB971029$\spuninst\spuni
nst.exe"
### Update for Windows XP (KB971029) - (26) 01-2016
[Applications] :HKLM KB2506212="C:\WINDOWS\$NtUninstallKB2506212$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2506212) - (26) 01-2016
[Applications] :HKLM KB2803821-v2_WM9="C:\WINDOWS\$NtUninstallKB2803821-v2_WM9
$\spuninst\spuninst.exe"
### Security Update for Windows Media Player (KB2803821-v2) - (26) 01-2016
[Applications] :HKLM KB952069_WM9="C:\WINDOWS\$NtUninstallKB952069_WM9$\spunin
st\spuninst.exe"
### Security Update for Windows Media Player (KB952069) - (26) 01-2016
[Applications] :HKLM KB977914="C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuni

nst.exe"
### Security Update for Windows XP (KB977914) - (26) 01-2016
[Applications] :HKLM KB2892075="C:\WINDOWS\$NtUninstallKB2892075$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2892075) - (26) 01-2016
[Applications] :HKLM KB2698365="C:\WINDOWS\$NtUninstallKB2698365$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2698365) - (26) 01-2016
[Applications] :HKLM KB2619339="C:\WINDOWS\$NtUninstallKB2619339$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2619339) - (26) 01-2016
[Applications] :HKLM KB2705219-v2="C:\WINDOWS\$NtUninstallKB2705219-v2$\spunin
st\spuninst.exe"
### Security Update for Windows XP (KB2705219-v2) - (26) 01-2016
[Applications] :HKLM KB978542="C:\WINDOWS\$NtUninstallKB978542$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB978542) - (26) 01-2016
[Applications] :HKLM KB979309="C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB979309) - (26) 01-2016
[Applications] :HKLM KB2727528="C:\WINDOWS\$NtUninstallKB2727528$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2727528) - (26) 01-2016
[Applications] :HKLM KB979482="C:\WINDOWS\$NtUninstallKB979482$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB979482) - (26) 01-2016
[Applications] :HKLM KB978706="C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB978706) - (26) 01-2016
[Applications] :HKLM KB981997="C:\WINDOWS\$NtUninstallKB981997$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB981997) - (26) 01-2016
[Applications] :HKLM KB2723135-v2="C:\WINDOWS\$NtUninstallKB2723135-v2$\spunin
st\spuninst.exe"
### Security Update for Windows XP (KB2723135-v2) - (26) 01-2016
[Applications] :HKLM KB960803="C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB960803) - (26) 01-2016
[Applications] :HKLM KB973815="C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuni
nst.exe"
### Update for Windows XP (KB973815) - (26) 01-2016
[Applications] :HKLM KB2862330="C:\WINDOWS\$NtUninstallKB2862330$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2862330) - (26) 01-2016
[Applications] :HKLM KB2813345="C:\WINDOWS\$NtUninstallKB2813345$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2813345) - (26) 01-2016
[Applications] :HKLM KB2509553="C:\WINDOWS\$NtUninstallKB2509553$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2509553) - (26) 01-2016
[Applications] :HKLM KB2676562="C:\WINDOWS\$NtUninstallKB2676562$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2676562) - (26) 01-2016
[Applications] :HKLM KB923789=C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe
C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
### Security Update for Windows XP (KB923789) - (26) 01-2016
[Applications] :HKLM KB982665="C:\WINDOWS\$NtUninstallKB982665$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB982665) - (26) 01-2016
[Applications] :HKLM KB2478960="C:\WINDOWS\$NtUninstallKB2478960$\spuninst\spu

ninst.exe"
### Security Update for Windows XP (KB2478960) - (26) 01-2016
[Applications] :HKLM KB2393802="C:\WINDOWS\$NtUninstallKB2393802$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2393802) - (26) 01-2016
[Applications] :HKLM KB923561="C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB923561) - (26) 01-2016
[Applications] :HKLM KB2620712="C:\WINDOWS\$NtUninstallKB2620712$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2620712) - (26) 01-2016
[Applications] :HKLM KB2566454="C:\WINDOWS\$NtUninstallKB2566454$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2566454) - (26) 01-2016
[Applications] :HKLM KB2661637="C:\WINDOWS\$NtUninstallKB2661637$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2661637) - (26) 01-2016
[Applications] :HKLM KB2914368="C:\WINDOWS\$NtUninstallKB2914368$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2914368) - (26) 01-2016
[Applications] :HKLM KB2584146="C:\WINDOWS\$NtUninstallKB2584146$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2584146) - (26) 01-2016
[Applications] :HKLM KB975467="C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuni
nst.exe"
### Security Update for Windows XP (KB975467) - (26) 01-2016
[Applications] :HKLM KB968389="C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuni
nst.exe"
### Update for Windows XP (KB968389) - (26) 01-2016
[Applications] :HKLM KB2423089="C:\WINDOWS\$NtUninstallKB2423089$\spuninst\spu
ninst.exe"
### Security Update for Windows XP (KB2423089) - (26) 01-2016
[Applications] :HKLM {8F1A2017-DF3D-44D3-BE79-C616CF5946D3}="C:\Program Files\
InstallShield Installation Information\{8F1A2017-DF3D-44D3-BE79-C616CF5946D3}\se
tup.exe" -runfromtemp -l0x0009 -removeonly
### RD9700 USB Ethernet Adapter - (26) 01-2016
[Applications] :HKLM Cheating-Death=C:\Program Files\Cheating-Death\UninstCD.e
xe
### Cheating-Death 4.32.0 - (26) 01-2016
[Applications] :HKLM Counter-Strike 1.6_is1="C:\Program Files\Counter-Strike 1
.6\unins001.exe" /SILENT
### Counter-Strike 1.6 - (26) 01-2016
[Applications] :HKLM KB898461="C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuni
nst.exe"
### Update for Windows XP (KB898461) - (26) 01-2016
[Applications] :HKLM {AC76BA86-7AD7-1033-7B44-AA1000000001}=MsiExec.exe /I{AC7
6BA86-7AD7-1033-7B44-AA1000000001}
### Adobe Reader X (10.1.0) - (25) 01-2016
[Applications] :HKLM Auto Shutdown Genius_is1="C:\Auto Shutdown Genius\unins00
0.exe" /SILENT
### Auto Shutdown Genius 3.0.1 - (25) 01-2016
[Applications] :HKLM HDMI=C:\WINDOWS\system32\igxpun.exe -uninstall
### Intel(R) Graphics Media Accelerator Driver - (25) 01-2016
[Applications] :HKLM Any Video Converter Ultimate_is1="C:\Program Files\AnvSof
t\Any Video Converter Ultimate\unins000.exe" /SILENT
### Any Video Converter Ultimate 4.5.8 - (25) 01-2016
[Applications] :HKLM Totalcmd=c:\totalcmd\tcuninst.exe
### Total Commander (Remove or Repair) - (25) 01-2016
[Applications] :HKLM Internet Download Manager=C:\Program Files\Internet Downl
oad Manager\Uninstall.exe

### Internet Download Manager - (25) 01-2016


[Applications] :HKLM WinRAR archiver=C:\Program Files\WinRAR\uninstall.exe
### WinRAR archiver - (25) 01-2016
[Applications] :HKLM KLiteCodecPack_is1="C:\Program Files\K-Lite Codec Pack\un
ins000.exe" /SILENT
### K-Lite Codec Pack 7.2.0 (Full) - (25) 01-2016
[Applications] :HKCU Kingsoft Office=C:\Documents and Settings\xpsp3\Local Set
tings\Application Data\Kingsoft\WPS Office\9.1.0.5234\utility\uninst.exe
### WPS Office (9.1.0.5234) - (23) 01-2016
[Applications] :HKLM {FB08F381-6533-4108-B7DD-039E11FBC27E}=Alcrmv.exe -r -m
### Realtek AC'97 Audio - (23) 01-2016
[Applications] :HKLM {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}=RunDll32 C:\PROGRA
~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Pro
gram Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-95810
8FE7DBC}\Setup.exe" -l0x9 -removeonly
### Realtek High Definition Audio Driver - (23) 01-2016
[Applications] :HKLM Opera 34.0.2036.36="C:\Program Files\Opera\Launcher.exe"
/uninstall
### Opera Stable 34.0.2036.36 - (23) 01-2016
[Applications] :HKLM Avira AntiVir Desktop=C:\Program Files\Avira\AntiVir Desk
top\setup.exe /REMOVE
### Avira AntiVir Personal - Free Antivirus - (23) 01-2016
[Applications] :HKLM {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}=MsiExec.exe /X{1F1
C2DFC-2D24-3E06-BCB8-725134ADF989}
### Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (23) 01-2
016
[Applications] :HKLM {350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}
### WebFldrs XP - (23) 01-2016
[Applications] :HKLM DXM_Runtime
### - (23) 01-2016
[Applications] :HKLM Branding=Rundll32 IedkCS32.dll,BrandCleanInstallStubs
### - (23) 01-2016
[Applications] :HKLM PCHealth=rundll32.exe setupapi.dll,InstallHinfSection Def
aultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
### - (23) 01-2016
[Applications] :HKLM AddressBook
### - (23) 01-2016
[Applications] :HKLM NetMeeting
### - (23) 01-2016
[Applications] :HKLM ICW
### - (23) 01-2016
[Applications] :HKLM DirectAnimation
### - (23) 01-2016
[Applications] :HKLM OutlookExpress
### - (23) 01-2016
[Applications] :HKLM IE40
### - (23) 01-2016
[Applications] :HKLM IEData
### - (23) 01-2016
[Applications] :HKLM IE5BAKEX
### - (23) 01-2016
[Applications] :HKLM IE4Data
### - (23) 01-2016
[Applications] :HKLM DirectDrawEx
### - (23) 01-2016
[Applications] :HKLM SchedulingAgent
### - (23) 01-2016
[Applications] :HKLM Fontcore
### - (23) 01-2016
[Applications] :HKLM MobileOptionPack

### - (23) 01-2016


[Applications] :HKLM Connection Manager
### - (23) 01-2016
[MD5]
[B916FFA1550280C42EDCA624913BA066][2
1156608 0E3F7B4D78495CED7037C084BE9
C02F02B9379F0
]C:\AUTO SHUTDOWN GENIUS\CONTROLMONITOR.EXE
[FF4789E3290331DF22FA0E149E9CE70C][2
581632 B35C970D7962D6158E2D67CB8A2
F753ECC804238
]C:\AUTO SHUTDOWN GENIUS\SHUTDOWNSVR.EXE
[622733F1AD2A719A709586E3220AC3A7][1
514408
]C:\DOCUMENTS AND SETTINGS\XPSP3\LOCAL SETTINGS\APPLICATION DAT
A\KINGSOFT\WPS OFFICE\9.1.0.5234\WTOOLEX\WPSNOTIFY.EXE
[F159D6AE81214F843123058A6D44A67D][1
481128
]C:\DOCUMENTS AND SETTINGS\XPSP3\LOCAL SETTINGS\APPLICATION DAT
A\KINGSOFT\WPS OFFICE\9.1.0.5234\WTOOLEX\WPSUPDATE.EXE
[C3DAA450AA9691B3125DDE0F7F2BA461][1
133480
]C:\DOCUMENTS AND SETTINGS\XPSP3\LOCAL SETTINGS\APPLICATION DAT
A\KINGSOFT\WPS OFFICE\9.1.0.5234\WTOOLEX\WPSUPDATESVR.EXE
[56443FBE48FE1F8EB15A68E3D72C5477][1
2310416 A6C0A6A0006A28C5C043B32C3AA
56584A701B7EF
]C:\PROGRA~1\UNHACKME\UNHACKME.EXE
[0B497C79824F8E1BF22FA6AACD3DE3A0][1
11608
]C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGIO.SYS
[C983E62B6FB74457D173BA93F66F6068][1
281768
]C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGNT.EXE
[F5B4C2F35A9D78EABF83978217C421A2][1
269480
]C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGUARD.EXE
[8C91BD35AE9AA8B628EEC5E637BB1D0F][1
76968
]C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVSHADOW.EXE
[B4837FE56D76B2E9EA90E5365CF6A2BE][1
136360
]C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\SCHED.EXE
[902C61F27C86B4A0C0BFF31F154DDBEB][2
86376
]C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\SHLEXT.DLL
[5764B0726D523B1D71946714AC9BBF11][2
692224 341740123B1EAE9EF3F9245D75F
E50B59EFD3578
]C:\PROGRAM FILES\BASH SOFTWARE\INSTALL-BLOCK\BSIBR.EXE
[D2ADA8AF0EE98F3F76536015D74EE4BF][1
63912
]C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELP
ERSHIM.DLL
[4EAF6F8F0B3BE33A0E3877EB7FFD48D4][1
1085656 7224E3586E6576C071A6141F307
3A831734B08D4
]C:\PROGRAM FILES\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
[6F2E3275F0815587C3F79EFFB6395C61][2
3179952
]C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
[041D17F36790D6B75DD3494D25C95CCE][1
181680
]C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL
[7896E733AF5A8DCE4B1C94C658AA3DF4][1
263600
]C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEMONITOR.EXE
[B60DDDD2D63CE41CB8C487FCFBB6419E][1
638816
]C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
[3E930C641079443D4DE036167A69CAA2][6
1695232
]C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
[1868932CA3427EB68C73A664FA2376F5][1
630392 947D524A964855FF3DC5B84D712
96291C5709EB2
]C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA.EXE
[07D459F5F889CEFB71A36508D12D8691][1
504952 51BDD0F8F16557F1EE68016527A
3571D08537707
]C:\PROGRAM FILES\OPERA\34.0.2036.36\OPERA_CRASHREPORTER.EXE
[62A0B124F2DFCF1C5694D4D864FABCE0][1
696440 DC00F7D361D6ECEEA97A44C5C9A
0D69115DE9361
]C:\PROGRAM FILES\OPERA\LAUNCHER.EXE
[D55250337B2A9C2C854C85D905FC3661][1
29536
]C:\PROGRAM FILES\TUNEUP UTILITIES 2013\SDSHELEX-WIN32.DLL
[42E59AED70580B4AB64CF5CB96ABBAB9][1
1869152
]C:\PROGRAM FILES\TUNEUP UTILITIES 2013\TUNEUPUTILITIESAPP32.EX
E
[94C4CD2D19B8C4137A46261F229FEC24][1
10088

]C:\PROGRAM FILES\TUNEUP UTILITIES 2013\TUNEUPUTILITIESDRIVER32


.SYS
[EED857823833EE42C20477F3FB20C5B6][1
1699680
]C:\PROGRAM FILES\TUNEUP UTILITIES 2013\TUNEUPUTILITIESSERVICE3
2.EXE
[16913F0D9A39635AAC067C03DE6E0612][1
596240 CD454389F23594679006C80487E
B7996066B466C
]C:\PROGRAM FILES\UNHACKME\HACKMON.EXE
[8E3F56E9801D8920FA1F2CA2A58E0C0D][1
10659640 8728F0D5B61696A53291B4B4BD2
BFADF25368F6F
]C:\PROGRAM FILES\UNHACKME\REANIMATOR.EXE
[56443FBE48FE1F8EB15A68E3D72C5477][1
2310416 A6C0A6A0006A28C5C043B32C3AA
56584A701B7EF
]C:\PROGRAM FILES\UNHACKME\UNHACKME.EXE
[0B0526CE79C2082400E661A0ABE52A14][1
218112
]C:\PROGRAM FILES\WINDOWS NT\ACCESSORIES\WORDPAD.EXE
[30A23A61E651C7487407CF74176C6AB1][2
141824
]C:\PROGRAM FILES\WINRAR\RAREXT.DLL
[78B807E8D2D8D4BDEF085D1B6AE2B175][1
3709856
]C:\TOTALCMD\TOTALCMD.EXE
[12896823FB95BFB3DC9B46BCAEDC9923][1
1033728
]C:\WINDOWS\EXPLORER.EXE
[0A429C99CAE89CBD00D0451A5402C3A1][1
208896
]C:\WINDOWS\INF\UNREGMP2.EXE
[AAC1D4EE39DF138C5D30AC5883E3B59F][6
558080
]C:\WINDOWS\NETWORK DIAGNOSTIC\XPNETDIAG.EXE
[B32A4DB8FA8BA07AFB1E86F8C9FB852E][1
769024
]C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HELPCTR.EXE
[A81135541C9D4EBCE43EFA8AD31395B4][1
169984
]C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.EXE
[4FCCA060DFE0C51A09DD5C3843888BCD][6
38400
]C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\PCHSVC.DLL
[0D034E8C4F88C5B2B0C1AF3CF438CC4F][1
86016
]C:\WINDOWS\SOUNDMAN.EXE
[0E2508EFB9BE47763AA086439844ABF2][2
151552
]C:\WINDOWS\SYSTEM32\AC3ACM.ACM
[E76F8807070ED04E7408A86D6D3A6137][1
617472
]C:\WINDOWS\SYSTEM32\ADVAPI32.DLL
[8C515081584A38AA007909CD02020B3D][6
44544
]C:\WINDOWS\SYSTEM32\ALG.EXE
[A9A3DAA780CA6C9671A19D52456705B4][6
17408
]C:\WINDOWS\SYSTEM32\ALRSVC.DLL
[D8849F77C0B66226335A59D26CB4EDC6][6
167936
]C:\WINDOWS\SYSTEM32\APPMGMTS.DLL
[DEF7A7882BEC100FE0B2CE2549188F9D][6
42496
]C:\WINDOWS\SYSTEM32\AUDIOSRV.DLL
[CFD4E51402DA9838B5A04AE680AF54A0][1
78336
]C:\WINDOWS\SYSTEM32\BROWSER.DLL
[02283EDE3F4575A208FDF45CA2E4A47B][1
1025024
]C:\WINDOWS\SYSTEM32\BROWSEUI.DLL
[1CFE720EB8D93A7158A4EBC3AB178BDE][6
5632
]C:\WINDOWS\SYSTEM32\CISVC.EXE
[34CBE729F38138217F9C80212A2A0C82][1
33280
]C:\WINDOWS\SYSTEM32\CLIPSRV.EXE
[6D778E0F95447E6546553EEEA709D03C][1
389120
]C:\WINDOWS\SYSTEM32\CMD.EXE
[5D3D1AB0EF4EA55B731863050482C111][6
47104
]C:\WINDOWS\SYSTEM32\CNBJMON.DLL
[1280A158C722FA95A80FB7AEBE78FA7D][1
792064
]C:\WINDOWS\SYSTEM32\COMRES.DLL
[636DF3FF20A1B69B3F9D21325E7115C7][1
603136
]C:\WINDOWS\SYSTEM32\CRYPT32.DLL
[C14350FC0D47D806699C4F907FC6785B][6
64512

]C:\WINDOWS\SYSTEM32\CRYPTNET.DLL
[3D4E199942E29207970E04315D02AD3B][6
62464
]C:\WINDOWS\SYSTEM32\CRYPTSVC.DLL
[515A7FAE2070C2B0242B2353443E2F11][1
101888
]C:\WINDOWS\SYSTEM32\CSCDLL.DLL
[085ED2E391A871C7BAE87E0228B546BA][1
326656
]C:\WINDOWS\SYSTEM32\CSCUI.DLL
[44F275C64738EA2056E3D9580C23B60F][6
6144
]C:\WINDOWS\SYSTEM32\CSRSS.EXE
[5F1D5F88303D4A4DBC8E5F97BA967CC3][1
15360
]C:\WINDOWS\SYSTEM32\CTFMON.EXE
[F099B129022170F2DF9E1C0185C9BCFB][6
1179648
]C:\WINDOWS\SYSTEM32\D3D8.DLL
[31B067C412FA1A9BAD3CA2A63D7DA440][6
8192
]C:\WINDOWS\SYSTEM32\D3D8THK.DLL
[A340CD71EB535A3DD751B5F28723E50C][6
279552
]C:\WINDOWS\SYSTEM32\DDRAW.DLL
[5E38D7684A49CACFB752B046357E0589][6
126976
]C:\WINDOWS\SYSTEM32\DHCPCSVC.DLL
[E2092F0A1D7ABC243F9C2362483D150D][6
19456
]C:\WINDOWS\SYSTEM32\DIMSNTFY.DLL
[0A9BA6AF531AFE7FA5E4FB973852D863][6
5120
]C:\WINDOWS\SYSTEM32\DLLHOST.EXE
[E46050330BD42F33609117F861E32D3C][6
224768
]C:\WINDOWS\SYSTEM32\DMADMIN.EXE
[57EDEC2E5F59F0335E92F35184BC8631][6
23552
]C:\WINDOWS\SYSTEM32\DMSERVER.DLL
[5F7E24FA9EAB896051FFB87F840730D2][1
45568
]C:\WINDOWS\SYSTEM32\DNSRSLVR.DLL
[0F0F6E687E5E15579EF4DA8DD6945814][6
132096
]C:\WINDOWS\SYSTEM32\DOT3SVC.DLL
[8FD99680A539792A30E97944FDAECF17][6
187776
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
[9859C0F6936E723E4892D7141B1327D5][6
11648
]C:\WINDOWS\SYSTEM32\DRIVERS\ACPIEC.SYS
[8BED39E3C35D6A489438B8141717A557][6
142592
]C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
[1E44BC1E83D8FD2305F8D452DB109CF9][1
138496
]C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
[D9026163ED32A13923A2C909897A6B87][2
4030144
]C:\WINDOWS\SYSTEM32\DRIVERS\ALCXWDM.SYS
[D7701D7E72243286CC88C9973D891057][6
37376
]C:\WINDOWS\SYSTEM32\DRIVERS\amdk6.sys
[8FCE268CDBDD83B23419D1F35F42C7B1][6
37760
]C:\WINDOWS\SYSTEM32\DRIVERS\amdk7.sys
[EFA78DCA6DE1B9E5DFA1834AD9DD6B20][2
32896
]C:\WINDOWS\SYSTEM32\DRIVERS\ANVSNDDRV.SYS
[B5B8A80875C1DEDEDA8B02765642C32F][6
60800
]C:\WINDOWS\SYSTEM32\DRIVERS\arp1394.sys
[B153AFFAC761E7F5FCFA822B9C4E97BC][6
14336
]C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
[9F3A2F5AA6875C72BF062C712CFA2674][6
96512
]C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
[9916C1225104BA14794209CFA8012159][6
59904
]C:\WINDOWS\SYSTEM32\DRIVERS\ATMARPC.SYS
[39A0A59180F19946374275745B21AEBA][6
31360
]C:\WINDOWS\SYSTEM32\DRIVERS\atmepvc.sys
[AE76348A2605FB197FA8FF1D6F547836][6
55808
]C:\WINDOWS\SYSTEM32\DRIVERS\atmlane.sys
[E7EF69B38D17BA01F914AE8F66216A38][6
352256

]C:\WINDOWS\SYSTEM32\DRIVERS\atmuni.sys
[D9F724AA26C010A217C97606B160ED68][6
3072
]C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS
[5B44C214F9CD9F590BE9125347610380][1
45416
]C:\WINDOWS\SYSTEM32\DRIVERS\avgntdd.sys
[47B879406246FFDCED59E18D331A0E7D][1
61960
]C:\WINDOWS\SYSTEM32\DRIVERS\AVGNTFLT.SYS
[87451AA7CC6B6A590EBCEA05E755075A][1
22360
]C:\WINDOWS\SYSTEM32\DRIVERS\avgntmgr.sys
[5FEDEF54757B34FB611B9EC8FB399364][1
137656
]C:\WINDOWS\SYSTEM32\DRIVERS\AVIPBB.SYS
[DA1F27D85E0D1525F6621372E7B685E9][6
4224
]C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS
[F934D1B230F84E1D19DD00AC5A7A83ED][6
71552
]C:\WINDOWS\SYSTEM32\DRIVERS\bridge.sys
[662BFD909447DD9CC15B1A1C366583B4][1
272128
]C:\WINDOWS\SYSTEM32\DRIVERS\bthport.sys
[90A673FC8E12A79AFBED2576F6A7AAF9][6
13952
]C:\WINDOWS\SYSTEM32\DRIVERS\CBIDF2K.SYS
[C1B486A7658353D33A10CC15211A873B][6
18688
]C:\WINDOWS\SYSTEM32\DRIVERS\CDAUDIO.SYS
[C885B02847F5D2FD45A24E219ED93B32][6
63744
]C:\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS
[1F4260CC5B42272D71F79E570A27A4FE][6
62976
]C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
[B562592B7F5759C99E179CA467ECFB4C][6
262528
]C:\WINDOWS\SYSTEM32\DRIVERS\cinemst2.sys
[FE47DD8FE6D7768FF94EBEC6C74B2719][6
49536
]C:\WINDOWS\SYSTEM32\DRIVERS\classpnp.sys
[9624293E55AD405415862B504CA95B73][6
11776
]C:\WINDOWS\SYSTEM32\DRIVERS\cpqdap01.sys
[F50D9BDBB25CCE075E514DC07472A22F][6
36736
]C:\WINDOWS\SYSTEM32\DRIVERS\crusoe.sys
[044452051F3E02E7963599FC8F4F3E25][6
36352
]C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
[E65E2353A5D74EA89971CB918EEEB2F6][6
14208
]C:\WINDOWS\SYSTEM32\DRIVERS\diskdump.sys
[D992FE1274BDE0F84AD826ACAE022A41][6
799744
]C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS
[7C824CF7BBDE77D95C08005717A95F6F][6
153344
]C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS
[E9317282A63CA4D188C0DF5E09C6AC5F][6
5888
]C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS
[8A208DFCF89792A484E76C40E5F50B45][6
52864
]C:\WINDOWS\SYSTEM32\DRIVERS\DMUSIC.SYS
[6CB08593487F5701D2D2254E693EAFCE][6
60160
]C:\WINDOWS\SYSTEM32\DRIVERS\drmk.sys
[8F5FCFF8E8848AFAC920905FBD9D33C8][6
2944
]C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
[FE97D0343ACFDEBDD578FC67CC91FA87][6
10496
]C:\WINDOWS\SYSTEM32\DRIVERS\dxapi.sys
[AC7280566A7BB85CB3291F04DDC1198E][6
71168
]C:\WINDOWS\SYSTEM32\DRIVERS\dxg.sys
[A73F5D6705B1D820C19B18782E176EFD][6
3328
]C:\WINDOWS\SYSTEM32\DRIVERS\dxgthk.sys
[38D332A6D56AF32635675F132548343E][6
143744
]C:\WINDOWS\SYSTEM32\DRIVERS\FASTFAT.SYS
[92CDD60B6730B9F50F6A1A0C1F8CDC81][6
27392
]C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
[D45926117EB9FA946A6AF572FBE1CAA3][6
44544

]C:\WINDOWS\SYSTEM32\DRIVERS\FIPS.SYS
[9D27E7B80BFCDF1CDD9B555862D5E7F0][6
20480
]C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
[B2CF4B0786F8212CB92ED2B50C6DB6B0][6
129792
]C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
[3E1E2BD4F39B0E2B7DC4F4D2BCC2779A][6
7936
]C:\WINDOWS\SYSTEM32\DRIVERS\fs_rec.sys
[455F778EE14368468560BD7CB8C854D0][6
12160
]C:\WINDOWS\SYSTEM32\DRIVERS\fsvga.sys
[6AC26732762483366C3969C9E4D2259D][6
125056
]C:\WINDOWS\SYSTEM32\DRIVERS\FTDISK.SYS
[573C7D0A32852B48F3058CFD8026F511][6
144384
]C:\WINDOWS\SYSTEM32\DRIVERS\hdaudbus.sys
[1AF592532532A402ED7C060F6954004F][1
36864
]C:\WINDOWS\SYSTEM32\DRIVERS\hidclass.sys
[C569EF030B11F896E123A30AC92678DB][1
25088
]C:\WINDOWS\SYSTEM32\DRIVERS\hidparse.sys
[CCF82C5EC8A7326C3066DE870C06DAF1][1
10368
]C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
[F6AACF5BCE2893E0C1754AFEB672E5C9][6
264832
]C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
[4A0B06AA8943C1E332520F7440C0AA30][6
52480
]C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
[48846B31BE5A4FA662CCFDE7A1BA86B9][1
5854752
]C:\WINDOWS\SYSTEM32\DRIVERS\IGXPMP32.SYS
[083A052659F5310DD8B6A6CB05EDCF8E][6
42112
]C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS
[B5466A9250342A7AA0CD1FBA13420678][6
5504
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
[8C953733D8F36EB2133F5BB58808B66B][6
36352
]C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
[3BB22519A194418D5FEC05D800A19AD0][6
36608
]C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW.SYS
[731F22BA402EE4B62748ADAF6363C182][6
32896
]C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
[B87AB476DCF76E72010632B5550955F5][6
20864
]C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS
[CC748EA12C6EFFDE940EE98098BF96BB][6
152832
]C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
[23C74D75E36E7158768DD63D92789A91][6
75264
]C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS
[C93C9FF7B04D772627A3646D89F7BF89][6
11264
]C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
[05A299EC56E52649B1CF2FC52D20F2D7][6
37248
]C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
[463C1EC80CD17420A542B7F36A36F128][6
24576
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
[9EF487A186DEA361AA06913A75B3FA99][1
14592
]C:\WINDOWS\SYSTEM32\DRIVERS\KBDHID.SYS
[692BCF44383D056AED41B045A323D378][6
172416
]C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS
[0753515F78DF7F271A5E61C20BCD36A1][6
141056
]C:\WINDOWS\SYSTEM32\DRIVERS\ks.sys
[B467646C54CC746128904E1654C750C1][1
92928
]C:\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS
[D1F8BE91ED4DDB671D42E473E3FE71AB][6
7680
]C:\WINDOWS\SYSTEM32\DRIVERS\mcd.sys
[A7DA20AB18A1BDAE28B0F349E57DA0D1][6
63744
]C:\WINDOWS\SYSTEM32\DRIVERS\mf.sys
[4AE068242760A1FB6E1A44BF4E16AFA6][6
4224

]C:\WINDOWS\SYSTEM32\DRIVERS\MNMDD.SYS
[DFCBAD3CEC1C5F964962AE10E0BCC8E1][6
30080
]C:\WINDOWS\SYSTEM32\DRIVERS\MODEM.SYS
[35C9E97194C8CFB8430125F8DBC34D04][6
23040
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
[B1C303E17FB9D46E87A98E4BA6769685][1
12160
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
[A80B9A0BAD1B73637DBCBBA7DF72D3FD][6
42368
]C:\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS
[70C14F5CCA5CF73F8A645C73A01D8726][6
92544
]C:\WINDOWS\SYSTEM32\DRIVERS\mqac.sys
[11D42BB6206F33FBB3BA0288D3EF81BD][6
180608
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
[7D304A5EB4344EBEEAB53A2FE3FFB9F0][1
456320
]C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
[C941EA2454BA8350021D774DAF0F1027][6
19072
]C:\WINDOWS\SYSTEM32\DRIVERS\MSFS.SYS
[0A02C63C8B144BD8C86B103DEE7C86A2][6
35072
]C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS
[D1575E71568F4D9E14CA56B7B0453BF1][6
7552
]C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
[325BB26842FC7CCC1FCCE2C457317F3E][6
5376
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
[BAD59648BA099DA4A17680B39730CB3D][6
4992
]C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
[AF5F4F3F14A8EA2C26DE30F7A1E17136][6
15488
]C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
[DE6A75F5C270E756C5508D94B6CF68F5][1
105472
]C:\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS
[1DF7F42665C94B825322FAE71721130D][6
182656
]C:\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS
[0109C4F3850DFBAB279542515386AE22][1
10496
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
[F927A4434C5028758A842943EF1A3849][6
14592
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
[EDC1531A49C80614B2CFDA43CA8659AB][6
91520
]C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
[2F597BB467E05B1FE3830EABD821B8E0][1
40960
]C:\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS
[5D81CF9A2F1A3A756B66CF684911CDF0][6
34688
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
[74B2B2F5BEA5E9A3DC021D685551BD3D][6
162816
]C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
[E9E47CFB2D461FA0FC75B7A74C6383EA][6
61824
]C:\WINDOWS\SYSTEM32\DRIVERS\nic1394.sys
[BE984D604D91C217355CDD3737AAD25D][6
12032
]C:\WINDOWS\SYSTEM32\DRIVERS\nikedrv.sys
[1E421A6BCF2203CC61B821ADA9DE878B][6
40320
]C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys
[3182D64AE053D6FB034F44B6DEF8034A][6
30848
]C:\WINDOWS\SYSTEM32\DRIVERS\NPFS.SYS
[78A08DD6A8D65E697C18E1DB01C5CDCA][6
574976
]C:\WINDOWS\SYSTEM32\DRIVERS\NTFS.SYS
[73C1E1F395918BC2C6DD67AF7591A3AD][6
2944
]C:\WINDOWS\SYSTEM32\DRIVERS\NULL.SYS
[B305F3FAD35083837EF46A0BBCE2FC57][6
12416
]C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFLT.SYS
[C99B3415198D1AAB7227F2C88FD664B9][6
32512
]C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFWD.SYS
[8B8B1BE2DBA4025DA6786C645F77F123][6
88320

]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys
[56D34A67C05E94E16377C60609741FF8][6
63232
]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnknb.sys
[C0BB7D1615E1ACBDC99757F6CEAF8CF0][6
55936
]C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkspx.sys
[36B9B950E3D2E100970A48D8BAD86740][6
163584
]C:\WINDOWS\SYSTEM32\DRIVERS\nwrdr.sys
[4BB30DDC53EBC76895E38694580CDFE9][6
3456
]C:\WINDOWS\SYSTEM32\DRIVERS\oprghdlr.sys
[C90018BAFDC7098619A4A95B046B30F3][6
42752
]C:\WINDOWS\SYSTEM32\DRIVERS\p3.sys
[5575FAF8F97CE5E713D108C2A58D7C7C][6
80128
]C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
[032F1C32A6A97C317AEFF9D64D2A1D8A][1
40304 50D027EB8240A4C0D4610E47A91
2DC8E4D6D88E5
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTIZAN.SYS
[BEB3BA25197665D82EC7065B724171C6][6
19712
]C:\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS
[70E98B3FD8E963A6A46A2E6247E0BEA1][6
6784
]C:\WINDOWS\SYSTEM32\DRIVERS\PARVDM.SYS
[A219903CCF74233761D92BEF471A07B1][6
68224
]C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
[CCF5F451BB1A5A2A522A76E670000FF0][1
3328
]C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
[52E60F29221D0D1AC16737E8DBF7C3E9][6
24960
]C:\WINDOWS\SYSTEM32\DRIVERS\pciidex.sys
[9E89EF60E9EE05E3F2EEF2DA7397F1C1][6
120192
]C:\WINDOWS\SYSTEM32\DRIVERS\PCMCIA.SYS
[E82A496C3961EFC6828B508C310CE98F][6
146048
]C:\WINDOWS\SYSTEM32\DRIVERS\portcls.sys
[A32BEBAF723557681BFC6BD93E98BD26][6
35840
]C:\WINDOWS\SYSTEM32\DRIVERS\processr.sys
[09298EC810B07E5D582CB3A3F9255424][6
69120
]C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS
[80D317BD1C3DBC5D4FE7B1678C60CADD][6
17792
]C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS
[FE0D99D6F31E4FAD8159F690D68DED9C][6
8832
]C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
[11B4A627BC9614B885C4969BFA5FF8A6][6
51328
]C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
[5BC962F2654137C9909C3D4603587DEE][6
41472
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
[EFEEC01B1D3CF84F16DDD24D9D9D8F99][6
48384
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
[FDBB1D60066FCFBB7452FD8F9829B242][6
16512
]C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS
[01524CD237223B18ADBB48F70083F101][6
34432
]C:\WINDOWS\SYSTEM32\DRIVERS\rawwan.sys
[1C36ADF2918FCB62E9BAE37A818AB13A][1
16512 317C6420723F2D7C74CA3160252
9F233B00E3CAA
]C:\WINDOWS\SYSTEM32\DRIVERS\RD9700.SYS
[7AD224AD1A1437FE28D89CF22B17780A][6
175744
]C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
[4912D5B403614CE99C28420F75353332][6
4224
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS
[15CABD0F7C00C47C70124907916AF3F1][6
196224
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
[43AF5212BD8FB5BA6EED9754358BD8F7][1
139784
]C:\WINDOWS\SYSTEM32\DRIVERS\RDPWD.SYS
[F828DD7E1419B6653894A8F97A0094C5][6
57600
]C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS
[A56FE08EC7473E8580A390BB1081CDD7][6
12032

]C:\WINDOWS\SYSTEM32\DRIVERS\rio8drv.sys
[0A854DF84C77A0BE205BFEAB2AE4F0EC][6
12032
]C:\WINDOWS\SYSTEM32\DRIVERS\riodrv.sys
[96F7A9A7BF0C9C0440A967440065D33C][1
203136
]C:\WINDOWS\SYSTEM32\DRIVERS\rmcast.sys
[601844CBCF617FF8C868130CA5B2039D][6
30592
]C:\WINDOWS\SYSTEM32\DRIVERS\rndismp.sys
[D8B0B4ADE32574B2D9C5CC34DC0DBBE7][6
5888
]C:\WINDOWS\SYSTEM32\DRIVERS\rootmdm.sys
[EB5608FD4F2961517AC9F5CAC88B023B][1
4620288
]C:\WINDOWS\SYSTEM32\DRIVERS\RtkHDAud.sys
[D507C1400284176573224903819FFDA3][1
20992
]C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.SYS
[76C465F570E90C28942D52CCB2580A10][6
96384
]C:\WINDOWS\SYSTEM32\DRIVERS\scsiport.sys
[8D04819A3CE51B9EB47E5689B44D43C4][6
79232
]C:\WINDOWS\SYSTEM32\DRIVERS\sdbus.sys
[90A3935D05B494A5A39D37E71F09A677][6
20480
]C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS
[0F29512CCD6BEAD730039FB4BD2C85CE][6
15744
]C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
[CCA207A8896D4C6A0C9CE29A4AE411A7][6
64512
]C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[0FA803C64DF0914B41F807EA276BF2A6][6
11904
]C:\WINDOWS\SYSTEM32\DRIVERS\sffdisk.sys
[D66D22D76878BF3483A6BE30183FB648][6
10240
]C:\WINDOWS\SYSTEM32\DRIVERS\sffp_mmc.sys
[C17C331E435ED8737525C86A7557B3AC][6
11008
]C:\WINDOWS\SYSTEM32\DRIVERS\sffp_sd.sys
[8E6B8C671615D126FDC553D1E2DE5562][6
11392
]C:\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS
[017DAECF0ED3AA731313433601EC40FA][6
14592
]C:\WINDOWS\SYSTEM32\DRIVERS\smclib.sys
[489703624DAC94ED943C2ABDA022A1CD][6
25344
]C:\WINDOWS\SYSTEM32\DRIVERS\sonydcam.sys
[AB8B92451ECB048A4D1DE7C3FFCB4A9F][6
6272
]C:\WINDOWS\SYSTEM32\DRIVERS\SPLITTER.SYS
[76BB022C2FB6902FD5BDD4F78FC13A5D][6
73472
]C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS
[47DDFC2F003F7F9F0592C6874962A2E7][1
357888
]C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
[A36EE93698802CD899F98BFD553D8185][1
28520
]C:\WINDOWS\SYSTEM32\DRIVERS\SSMDRV.SYS
[3E5D89099DED9E86E5639F411693218F][6
49408
]C:\WINDOWS\SYSTEM32\DRIVERS\stream.sys
[3941D127AEF12E93ADDF6FE6EE027E0F][6
4352
]C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
[8CE882BCC6CF8A62F2B2323D95CB3D01][6
56576
]C:\WINDOWS\SYSTEM32\DRIVERS\SWMIDI.SYS
[8B83F3ED0F1688B4958F77CD6D2BF290][6
60800
]C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS
[FD6093E3DECD925F1CFFC8A0DD539D72][6
14976
]C:\WINDOWS\SYSTEM32\DRIVERS\tape.sys
[9AEFA14BD6B182D61E3119FA5F436D3D][1
361600
]C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
[4E53BBCC4BE37D7A4BD6EF1098C89FF7][1
226880
]C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys
[0539D5E53587F82D1B4FD74C5BE205CF][6
19072
]C:\WINDOWS\SYSTEM32\DRIVERS\tdi.sys
[6471A66807F5E104E4885F5B67349397][6
12040

]C:\WINDOWS\SYSTEM32\DRIVERS\TDPIPE.SYS
[C56B6D0402371CF3700EB322EF3AAF61][6
21896
]C:\WINDOWS\SYSTEM32\DRIVERS\TDTCP.SYS
[88155247177638048422893737429D9E][6
40840
]C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS
[699450901C5CCFD82357CBC531CEDD23][6
51712
]C:\WINDOWS\SYSTEM32\DRIVERS\tosdvd.sys
[D74A8EC75305F1D3CFDE7C7FC1BD62A9][6
21376
]C:\WINDOWS\SYSTEM32\DRIVERS\tsbvcap.sys
[8F861EDA21C05857EB8197300A92501C][6
12288
]C:\WINDOWS\SYSTEM32\DRIVERS\tunmp.sys
[5787B80C2E3C5E2F56C2A233D91FA2C9][6
66048
]C:\WINDOWS\SYSTEM32\DRIVERS\UDFS.SYS
[9C193875A6A99F2AAB6A3E3816FA847F][1
12800 C2EC1D6902009188DE8645D94B0
2E83F1C48197E
]C:\WINDOWS\SYSTEM32\DRIVERS\UnHackMeDrv.sys
[402DDC88356B1BAC0EE3DD1580C76A31][6
384768
]C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS
[2A7A8AD9D39A2FAF9D9293B5DAFF3A4B][1
12928
]C:\WINDOWS\SYSTEM32\DRIVERS\usb8023.sys
[1C1A47B40C23358245AA8D0443B6935E][6
25600
]C:\WINDOWS\SYSTEM32\DRIVERS\usbcamd.sys
[CE97845D2E3F0D274B8BAC1ED07C6149][6
25728
]C:\WINDOWS\SYSTEM32\DRIVERS\usbcamd2.sys
[1B611611C28D2DF25BC057D79C6F13FC][1
32384
]C:\WINDOWS\SYSTEM32\DRIVERS\USBCCGP.SYS
[04FE5EF6ED4818EC4839EA5C611A6310][1
5376
]C:\WINDOWS\SYSTEM32\DRIVERS\usbd.sys
[4BAC8DF07F1D8434FC640E677A62204E][1
30336
]C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
[1AB3CDDE553B6E064D2E754EFE20285C][1
59520
]C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
[290913DC4F1125E5A82DE52579A44C43][6
15872
]C:\WINDOWS\SYSTEM32\DRIVERS\usbintel.sys
[6DF35CA139C3BC15CC74390ABB114EFE][1
144128
]C:\WINDOWS\SYSTEM32\DRIVERS\usbport.sys
[A32426D9B14A089EAA1D922E0C5801A9][1
26368
]C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
[26496F9DEE2D787FC3E61AD54821FFE6][1
20608
]C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
[55E01061C74A8CEFFF58DC36114A8D3F][6
58112
]C:\WINDOWS\SYSTEM32\DRIVERS\vdmindvd.sys
[0D3A8FAFCEACD8B7625CD549757A7DF1][6
20992
]C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS
[E28726B72C46821A28830E077D39A55B][6
81664
]C:\WINDOWS\SYSTEM32\DRIVERS\videoprt.sys
[4C8FCB5CC53AAB716D810740FE59D025][6
52352
]C:\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS
[E20B95BAEDB550F32DD489265C1DA1F6][6
34560
]C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
[6768ACF64B18196494413695F0C3A00F][6
83072
]C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS
[2F31B7F954BED437F2C75026C65CAF7B][6
4352
]C:\WINDOWS\SYSTEM32\DRIVERS\wmilib.sys
[6ABE6E225ADB5A751622A9CC3BC19CE8][6
12032
]C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
[4D83ED8BDDEC431FC8AD907B47CFB6E3][6
367616
]C:\WINDOWS\SYSTEM32\DSOUND.DLL
[2187855A7703ADEF0CEF9EE4285182CC][6
33792
]C:\WINDOWS\SYSTEM32\EAPSVC.DLL
[BC93B4A066477954555966D77FEC9ECB][6
23040

]C:\WINDOWS\SYSTEM32\ERSVC.DLL
[D4991D98F2DB73C60D042F1AEF79EFAE][1
253952
]C:\WINDOWS\SYSTEM32\ES.DLL
[A3B51C1211D3B1318A8BC34635AA65A6][2
73216
]C:\WINDOWS\SYSTEM32\FF_VFW.DLL
[E44733C30F7FE6A1CE7A6B1D2B335CFC][1
159744
]C:\WINDOWS\SYSTEM32\HKCMD.EXE
[3CB32D3B8CBE79899D63280BB7A83CD9][1
344064
]C:\WINDOWS\SYSTEM32\HNETCFG.DLL
[877C90686858D899B042BBA45E9B7F2C][1
199680
]C:\WINDOWS\SYSTEM32\IAC25_32.AX
[938B596D4170E4F9870A902DF2DEEF48][1
80384
]C:\WINDOWS\SYSTEM32\ICCVID.DLL
[3946A448C0AC5A94B325B9D679DF6CF4][1
210352
]C:\WINDOWS\SYSTEM32\IDMMBC.DLL
[729DA5D23A9AD20A6AA353156A126420][1
11063808
]C:\WINDOWS\SYSTEM32\IEFRAME.DLL
[1180852DBFADAFC375DBBA1F6B23EEE7][1
208896
]C:\WINDOWS\SYSTEM32\IGFXDEV.DLL
[2022C54B3A79A51C9538CE47D1F50BC3][1
131072
]C:\WINDOWS\SYSTEM32\IGFXPERS.EXE
[1D4F13DBB57C5152FC9A5DABBCFC78B4][1
249856
]C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE
[F38092DE1D6A8CBB11B6B6D0F07E268E][1
135168
]C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
[577E496F0D41411BF149394D80959D53][1
16384
]C:\WINDOWS\SYSTEM32\IMAADP32.ACM
[30DEAF54A9755BB8546168CFE8A6B5E1][6
150528
]C:\WINDOWS\SYSTEM32\IMAPI.EXE
[0DA85218E92526972A821587E6A8BF8F][6
110080
]C:\WINDOWS\SYSTEM32\IMM32.DLL
[57AA18B2896055E8CB269B19DD85E7F3][1
692736
]C:\WINDOWS\SYSTEM32\INETCOMM.DLL
[AF07DC9B7CC455629E732340C7B15F3A][6
94720
]C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL
[83F41D0D89645D7235C051AB1D9523AC][6
331264
]C:\WINDOWS\SYSTEM32\IPNATHLP.DLL
[43ECA1576906BA76FB3E329A338A3CAE][6
199168
]C:\WINDOWS\SYSTEM32\IR32_32.DLL
[948E1498C6438625247F94534AAA82FE][1
848384
]C:\WINDOWS\SYSTEM32\IR41_32.AX
[5F10DC19D92CCF6B719B494572F4F74B][6
755200
]C:\WINDOWS\SYSTEM32\IR50_32.DLL
[0EC5ECE8762728ED734258B22D348A32][6
138240
]C:\WINDOWS\SYSTEM32\ITSS.DLL
[C07552F5734B37F947289B51BC932376][1
48128
]C:\WINDOWS\SYSTEM32\IYUV_32.DLL
[1D7BA0CFBDB204B0A3BE40BFA79CE6F1][1
453512
]C:\WINDOWS\SYSTEM32\KB905474\WGASETUP.EXE
[A525C96C51D55111FDF3BEA9FFFFC7AE][1
301568
]C:\WINDOWS\SYSTEM32\KERBEROS.DLL
[8878BD685E490239777BFE51320B88E9][6
61440
]C:\WINDOWS\SYSTEM32\KMSVC.DLL
[9B9F1C38D559047B8AC0DBA2D5FEBDE9][6
4096
]C:\WINDOWS\SYSTEM32\KSUSER.DLL
[F3946B534CC197CBFFD9A2ECFD1F556F][1
307260
]C:\WINDOWS\SYSTEM32\L3CODECA.ACM
[22722B4E887BB95AB071542DE5A42C80][2
839680
]C:\WINDOWS\SYSTEM32\LAMEACM.ACM
[A7DB739AE99A796D91580147E919CC59][6
13824

]C:\WINDOWS\SYSTEM32\LMHSVC.DLL
[5677DFE438EC1F009273FC84FEED6B10][1
345600
]C:\WINDOWS\SYSTEM32\LOCALSPL.DLL
[AAED593F84AFA419BBAE8572AF87CF6A][6
75264
]C:\WINDOWS\SYSTEM32\LOCATOR.EXE
[9FAD7DFF67555FF1E06BC4A3893024A7][1
220672
]C:\WINDOWS\SYSTEM32\LOGON.SCR
[2081A5B5E4ABA206A0A8A1A97DF0FB23][1
514560
]C:\WINDOWS\SYSTEM32\LOGONUI.EXE
[012DF358CEBAA23ACB26D82077820817][6
22016
]C:\WINDOWS\SYSTEM32\LPK.DLL
[BF2466B3E18E970D8A976FB95FC1CA85][6
13312
]C:\WINDOWS\SYSTEM32\LSASS.EXE
[5C12660A97822F6E61576943B49AAAD6][1
18944
]C:\WINDOWS\SYSTEM32\MIDIMAP.DLL
[D18F1F0C101D06A1C1ADF26EED16FCDD][1
32768
]C:\WINDOWS\SYSTEM32\MNMSRVC.EXE
[7E699FF5F59B5D9DE5390E3C34C67CF5][6
53248
]C:\WINDOWS\SYSTEM32\MPRDIM.DLL
[9A3BD5F55AADFF859539142F6328A66E][1
20480
]C:\WINDOWS\SYSTEM32\MSACM32.DRV
[C5648BE5409E0AABDA8C9047BAC8F603][1
14848
]C:\WINDOWS\SYSTEM32\MSADP32.ACM
[55AEEA66C5E84E3FD6CD3E933397D478][1
282654
]C:\WINDOWS\SYSTEM32\MSAUD32.ACM
[5733177BCF16EE78B99543C9B0AB81EA][1
177152
]C:\WINDOWS\SYSTEM32\MSCTFIME.IME
[A137F1470499A205ABBB9AAFB3B6F2B1][1
6144
]C:\WINDOWS\SYSTEM32\MSDTC.EXE
[33271A2667334B9A8842C65A079EF375][1
9216
]C:\WINDOWS\SYSTEM32\MSG711.ACM
[B87F759738C52E8D6FBCDAAA84C6486F][1
118784
]C:\WINDOWS\SYSTEM32\MSG723.ACM
[3A9846E207DAFC13009C048A2F6F8C2A][1
19968
]C:\WINDOWS\SYSTEM32\MSGSM32.ACM
[986B1FF5814366D71E0AC5755C88F2D3][6
33792
]C:\WINDOWS\SYSTEM32\MSGSVC.DLL
[C6FD300A6100AC89BC4CB944C19FA2A9][1
188416
]C:\WINDOWS\SYSTEM32\MSH261.DRV
[7D529AA41EA993357F8C3D7E92C2372A][1
294912
]C:\WINDOWS\SYSTEM32\MSH263.DRV
[D469A0EBA2EF5C6BEE8065B7E3196E5E][1
5937152
]C:\WINDOWS\SYSTEM32\MSHTML.DLL
[5879D691E842574A20FE63817CB76DF9][1
78848
]C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
[AFFC87E2501FCE8F09D4C10BA6421CCF][6
4608
]C:\WINDOWS\SYSTEM32\MSIMG32.DLL
[C7E39EA41233E9F5B86C8DA3A9F1E4A8][1
52224
]C:\WINDOWS\SYSTEM32\MSPMSNSV.DLL
[777819E1514AA632364DE59F810B292C][1
11264
]C:\WINDOWS\SYSTEM32\MSRLE32.DLL
[517561A1113B04E51D936CD018DE1C1F][1
136192
]C:\WINDOWS\SYSTEM32\MSV1_0.DLL
[FCB4782D700268C1B82ECEF74CF1A3B9][1
28672
]C:\WINDOWS\SYSTEM32\MSVIDC32.DLL
[3F0CF84469AD2DC8382312814A223BCE][6
1428992
]C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL
[943337D786A56729263071623BBB9DE5][1
245248
]C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
[0F200BE1ED9DE188CA6407A3759BE7CF][1
17920

]C:\WINDOWS\SYSTEM32\MSYUV.DLL
[B857BA82860D7FF85AE29B095645563B][6
111104
]C:\WINDOWS\SYSTEM32\NETDDE.EXE
[13E67B55B3ABD7BF3FE7AAE5A0F9A9DE][6
198144
]C:\WINDOWS\SYSTEM32\NETMAN.DLL
[156F64A3345BD23C600655FB4D10BC08][6
435200
]C:\WINDOWS\SYSTEM32\NTMSSVC.DLL
[5652F6CE1D9E9D8068B9D29BC21B5409][6
84992
]C:\WINDOWS\SYSTEM32\OLEPRO32.DLL
[66CDF02D86C9F0B4300EE981A614D296][6
17920
]C:\WINDOWS\SYSTEM32\PING.EXE
[222DE7F5EDB9DDBE628384A1A8BE59CE][6
15360
]C:\WINDOWS\SYSTEM32\PJLMON.DLL
[0102140028FAD045756796E1C685D695][6
291328
]C:\WINDOWS\SYSTEM32\QAGENTRT.DLL
[574738F61FCA2935F5265DC4E5691314][6
409088
]C:\WINDOWS\SYSTEM32\QMGR.DLL
[6F9BEF24C578D5D6740E080BEDD6A448][6
7680
]C:\WINDOWS\SYSTEM32\RASADHLP.DLL
[92C4F48B62B0B876194584C3FF09CCB6][6
237056
]C:\WINDOWS\SYSTEM32\RASAPI32.DLL
[AD188BE7BDF94E8DF4CA0A55C00A5073][6
88576
]C:\WINDOWS\SYSTEM32\RASAUTO.DLL
[76A9A3CBEADD68CC57CDA5E1D7448235][6
186368
]C:\WINDOWS\SYSTEM32\RASMANS.DLL
[5B19B557B0C188210A56A6B699D90B8F][6
59904
]C:\WINDOWS\SYSTEM32\REGSVC.DLL
[6B27A5C03DFB94B4245739065431322C][1
401408
]C:\WINDOWS\SYSTEM32\RPCSS.DLL
[471B3F9741D762ABE75E9DEEA4787E47][6
132608
]C:\WINDOWS\SYSTEM32\RSVP.EXE
[72451FD61DDBB0A1FB071B7C3CDE5594][6
92672
]C:\WINDOWS\SYSTEM32\RSVPSP.DLL
[037B1E7798960E0420003D05BB577EE6][1
33280
]C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
[86D007E7A654B9A71D1D7D856B104353][6
95744
]C:\WINDOWS\SYSTEM32\SCARDSVR.EXE
[A86BB5E61BF3E39B62AB4C7E7085A084][6
181248
]C:\WINDOWS\SYSTEM32\SCECLI.DLL
[0F64207B49390C8063C36AE7CBF9C2DB][1
152576
]C:\WINDOWS\SYSTEM32\SCHANNEL.DLL
[0A9A7365A1CA4319AA7C1D6CD8E4EAFA][6
192512
]C:\WINDOWS\SYSTEM32\SCHEDSVC.DLL
[63FF9068E5BDA0BC9ECD38FBBB216E24][6
20480
]C:\WINDOWS\SYSTEM32\SCLGNTFY.DLL
[CBE612E2BB6A10E3563336191EDA1250][6
18944
]C:\WINDOWS\SYSTEM32\SECLOGON.DLL
[7FDD5D0684ECA8C1F68B4D99D124DCD0][6
39424
]C:\WINDOWS\SYSTEM32\SENS.DLL
[65DF52F5B8B6E9BBD183505225C37315][1
110592
]C:\WINDOWS\SYSTEM32\SERVICES.EXE
[3C37BF86641BDA977C3BF8A840F3B7FA][6
141312
]C:\WINDOWS\SYSTEM32\SESSMGR.EXE
[362BC5AF8EAF712832C58CC13AE05750][2
1614848
]C:\WINDOWS\SYSTEM32\SFCFILES.DLL
[4DC9D0547B7AEEE42241A1EC4580C484][1
1510400
]C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
[6843D54BC4A40CC8C5741AF750233D10][1
8462848
]C:\WINDOWS\SYSTEM32\SHELL32.DLL
[99BC0B50F511924348BE19C7C7313BBF][1
135168

]C:\WINDOWS\SYSTEM32\SHSVCS.DLL
[0DBB250A89E2E1C9281009AC269F0805][1
86016
]C:\WINDOWS\SYSTEM32\SL_ANET.ACM
[C7ABBC59B43274B1109DF6B24D617051][6
89600
]C:\WINDOWS\SYSTEM32\SMLOGSVC.EXE
[5F816C1F539266D2D4C78694239DA0B5][6
50688
]C:\WINDOWS\SYSTEM32\SMSS.EXE
[60784F891563FB1B767F70117FC2428F][1
58880
]C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
[3805DF0AC4296A34BA4BF93B346CC378][6
171008
]C:\WINDOWS\SYSTEM32\SRSVC.DLL
[F385F4B02C535BFFE1D70CAB80838123][6
96768
]C:\WINDOWS\SYSTEM32\SRVSVC.DLL
[0A5679B3714EDAB99E357057EE88FCA6][6
71680
]C:\WINDOWS\SYSTEM32\SSDPSRV.DLL
[50512FC9B7878E3C2C147BC17326A7DB][1
121856
]C:\WINDOWS\SYSTEM32\STOBJECT.DLL
[27C6D03BCDB8CFEB96B716F3D8BE3E18][6
14336
]C:\WINDOWS\SYSTEM32\SVCHOST.EXE
[C504A9FE17F997F8B1F8561D0A68DE52][1
300544
]C:\WINDOWS\SYSTEM32\SYSDM.CPL
[3CB78C17BB664637787C9A1C98F79C38][6
249856
]C:\WINDOWS\SYSTEM32\TAPISRV.DLL
[2CD1C3506A85B38E2D17E61ADED175C4][1
135680
]C:\WINDOWS\SYSTEM32\TASKMGR.EXE
[AE0382AD9C73D343D85E1A50C80B7C20][6
45568
]C:\WINDOWS\SYSTEM32\TCPMON.DLL
[FF3477C03BE7201C294C35F684B3479F][6
295424
]C:\WINDOWS\SYSTEM32\TERMSRV.DLL
[DB7205804759FF62C34E3EFD8A4CC76A][6
73216
]C:\WINDOWS\SYSTEM32\TLNTSVR.EXE
[55BCA12F7F523D35CA3CB833C725F54E][6
90112
]C:\WINDOWS\SYSTEM32\TRKWKS.DLL
[B08F8FFBA4570E21A71C38E00CC678E7][1
8704
]C:\WINDOWS\SYSTEM32\TSBYUV.DLL
[E8CD0D7E169ECCE2D4FD829DAAB786ED][1
8192
]C:\WINDOWS\SYSTEM32\TSSOFT32.ACM
[1EBAFEB9A3FBDC41B8D9C7F0F687AD91][6
185856
]C:\WINDOWS\SYSTEM32\UPNPHOST.DLL
[05365FB38FCA1E98F7A566AAAF5D1815][6
18432
]C:\WINDOWS\SYSTEM32\UPS.EXE
[05642AE6A7BDAA7541A7451F5A4C6512][1
1206784
]C:\WINDOWS\SYSTEM32\URLMON.DLL
[F26385E8BA4549B5186B774EC0E45D86][6
16896
]C:\WINDOWS\SYSTEM32\USBMON.DLL
[B26B135FF1B9F60C9388B4A7D16F600B][1
578560
]C:\WINDOWS\SYSTEM32\USER32.DLL
[A93AEE1928A9D7CE3E16D24EC7380F89][6
26112
]C:\WINDOWS\SYSTEM32\USERINIT.EXE
[7A2CC3719B255E6B5D74396183B7715B][1
218624
]C:\WINDOWS\SYSTEM32\UXTHEME.DLL
[7A9DB3A67C333BF0BD42E42B8596854B][6
289792
]C:\WINDOWS\SYSTEM32\VSSVC.EXE
[54AF4B1D5459500EF0937F6D33B1914F][6
175104
]C:\WINDOWS\SYSTEM32\W32TIME.DLL
[6100A808600F44D999CEBDEF8841C7A3][6
15872
]C:\WINDOWS\SYSTEM32\W3SSL.DLL
[378A0AEFB11D8B0DC8C27B9F7604B88D][1
473600
]C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL
[26D881D27CBE51D3614E68D7313EA026][6
273920

]C:\WINDOWS\SYSTEM32\WBEM\WBEMESS.DLL
[E0673F1106E62A68D2257E376079F821][6
126464
]C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
[2D0E4ED081963804CCC196A0929275B5][6
144896
]C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL
[3AAF9B35939FF9E58CCD18D41655C2FC][1
54272
]C:\WINDOWS\SYSTEM32\WDIGEST.DLL
[680B56A8B62D1BCF4A0B2AAAD03D88E4][1
23552
]C:\WINDOWS\SYSTEM32\WDMAUD.DRV
[CC8915DB4E33E8FB29CA0D2DBF75306E][1
236544
]C:\WINDOWS\SYSTEM32\WEBCHECK.DLL
[77A354E28153AD2D5E120A5A8687BC06][6
68096
]C:\WINDOWS\SYSTEM32\WEBCLNT.DLL
[477BB51076B926E1A68840C267540042][6
75776
]C:\WINDOWS\SYSTEM32\WIASCR.DLL
[8BAD69CBAC032D4BBACFCE0306174C30][6
333824
]C:\WINDOWS\SYSTEM32\WIASERVC.DLL
[ED0EF0A136DEC83DF69F04118870003E][1
507904
]C:\WINDOWS\SYSTEM32\WINLOGON.EXE
[D72B9EC3337B247A666F098F3D6B43DE][6
16896
]C:\WINDOWS\SYSTEM32\WINRNR.DLL
[A8888A5327621856C0CEC4E385F69309][1
132096
]C:\WINDOWS\SYSTEM32\WKSSVC.DLL
[2CC34E8BB667EEF78899546E12649196][6
92672
]C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL
[9789E95E1D88EEB4B922BF3EA7779C28][6
19968
]C:\WINDOWS\SYSTEM32\WS2HELP.DLL
[F92E1076C42FCD6DB3D72D8CFE9816D5][6
13824
]C:\WINDOWS\SYSTEM32\WSCNTFY.EXE
[7C278E6408D1DCE642230C0585A854D5][6
80896
]C:\WINDOWS\SYSTEM32\WSCSVC.DLL
[35321FB577CDC98CE3EB3A3EB9E4610A][6
6656
]C:\WINDOWS\SYSTEM32\WUAUSERV.DLL
[81DC3F549F44B1C1FFF022DEC9ECF30B][6
483840
]C:\WINDOWS\SYSTEM32\WZCSVC.DLL
[295D21F14C335B53CB8154E5B1F892B9][6
129024
]C:\WINDOWS\SYSTEM32\XMLPROV.DLL
[FE2571A8C9FFAB1D45502D6B0BF472AA][1
13312
]C:\WINDOWS\SYSTEM32\XP_EOS.EXE
[0C78DB5C15A86E8C2D999BD183C5743E][2
243200
]C:\WINDOWS\SYSTEM32\XVIDVFW.DLL
[C52757F1EA2812847EB65B72A8371794][2
237568
]C:\WINDOWS\SYSTEM32\YV12VFW.DLL
===
[MBR]
[MD5=D0D78552330424127A42FB11AC414640]
M8CO0LwAfPtQB1Af/L4bfL8bBlBXueUB86TLvb4HsQQ4bgB8CXUTg8UQ4vTNGIv1g8YQSXQZ
OCx09qC1B7QHi/CsPAB0/LsHALQOzRDr8ohOEOhGAHMq/kYQgH4EC3QLgH4EDHQFoLYHddKA
RgIGg0YIBoNWCgDoIQBzBaC2B+u8gT7+fVWqdAuAfhAAdMigtwfrqYv8HleL9cu/BQCKVgC0
CM0TciOKwSQ/mIreivxD9+OL0YbWsQbS7kL34jlWCncjcgU5RghzHLgBArsAfItOAotWAM0T
c1FPdE4y5IpWAM0T6+SKVgBgu6pVtEHNE3I2gftVqnUw9sEBdCthYGoAagD/dgr/dghqAGgA
fGoBahC0Qov0zRNhYXMOT3QLMuSKVgDNE+vWYfnDSW52YWxpZCBwYXJ0aXRpb24gdGFibGUA
RXJyb3IgbG9hZGluZyBvcGVyYXRpbmcgc3lzdGVtAE1pc3Npbmcgb3BlcmF0aW5nIHN5c3Rl
bQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAsRGM=
===
[PT]
A 0x7 NTFS, 63, 51199092
0xf Extended, 51199155, 105081165
===

[VBR]
61KQTlRGUyAgICAAAggAAAAAAAAA+AAAPwD/AD8AAAAAAAAAgACAAHM8DQMAAAAAAAAMAAAA
AADH0zAAAAAAAPYAAAABAAAAhvf6qDj7qHQAAAAA+jPAjtC8AHz7uMAHjtjoFgC4AA2OwDPb
xgYOABDoUwBoAA1oagLLihYkALQIzRNzBbn//4rxZg+2xkBmD7bRgOI/9+KGzcDtBkFmD7fJ
ZvfhZqMgAMO0QbuqVYoWJADNE3IPgftVqnUJ9sEBdAT+BhQAw2ZgHgZmoRAAZgMGHABmOwYg
AA+COgAeZmoAZlAGU2ZoEAABAIA+FAAAD4UMAOiz/4A+FAAAD4RhALRCihYkABYfi/TNE2ZY
WwdmWGZYH+stZjPSZg+3DhgAZvfx/sKKymaL0GbB6hD3NhoAhtaKFiQAiujA5AYKzLgBAs0T
D4IZAIzABSAAjsBm/wYQAP8ODgAPhW//Bx9mYcOg+AHoCQCg+wHoAwD76/60AYvwrDwAdAm0
DrsHAM0Q6/LDDQpBIGRpc2sgcmVhZCBlcnJvciBvY2N1cnJlZAANCk5UTERSIGlzIG1pc3Np
bmcADQpOVExEUiBpcyBjb21wcmVzc2VkAA0KUHJlc3MgQ3RybCtBbHQrRGVsIHRvIHJlc3Rh
cnQNCgAAAAAAAAAAAAAAAAAAg6CzyQAAVaoFAE4AVABMAEQAUgAEACQASQAzADAAAOAAAAAw
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAOsSkJAAAAAAAAAAAAAAAAAAAAAAjMiO2MHgBPqL4PvoA/5mD7cGCwBmD7YeDQBm9+Nm
o04CZosOQACA+QAPjw4A9tlmuAEAAABm0+DrCJBmoU4CZvfhZqNSAmYPtx4LAGYz0mb382aj
VgLocQRmiw5KAmaJDiICZgMOUgJmiQ4mAmYDDlICZokOKgJmAw5SAmaJDjoCZgMOUgJmiQ5C
Ama4kAAAAGaLDiIC6F8JZgvAD4RX/majLgJmuKAAAABmiw4mAuhGCWajMgJmuLAAAABmiw4q
Aug0CWajNgJmoS4CZgvAD4Qk/meAeAgAD4Ub/mdmjVAQZwNCBGdmD7ZIDGaJDmICZ2aLSAhm
iQ5eAmahXgJmD7cOCwBmM9Jm9/Fmo2YCZqFCAmYDBl4CZqNGAmaDPjICAA+EHQBmgz42AgAP
hMj9ZoseNgIeB2aLPkYCZqEqAui8AWYPtw4AAma4AgIAAOj+B2YLwA+EqAlnZosAHgdmiz46
AugxBmahOgJmuyAAAABmuQAAAABmugAAAADo1gBmhcAPhSMAZqE6Ama7gAAAAGa5AAAAAGa6
AAAAAOi2AGYLwA+FRADpVwlmM9JmuYAAAABmoToC6LwIZgvAD4RACR4HZos+OgLozQVmoToC
ZruAAAAAZrkAAAAAZroAAAAA6HIAZgvAD4QWCWdmD7dYDGaB4/8AAAAPhQsJZovYaAAgB2Yr
/2ahOgLo8gCKFiQAuOgDjsCNNgsAK8BoACBQywYeZmBmi9pmD7YODQBm9+FmoxAAZovDZvfh
ow4Ai9+D4w+MwGbB7wQDx1AH6A78ZmGQHwfDZwNAFGdmgzj/D4RMAGdmORgPhTMAZgvJD4UK
AGeAeAkAD4UjAMNnOkgJD4UaAGaL8GcDcArolwZmUR4HZov686dmWQ+FAQDDZ2aDeAQAD4QH
AGdmA0AE66tmK8DDZovz6GwGZ2YDAGf3QAwCAA+FNABnZo1QEGc6SkAPhRgAZ2aNckLoSQZm
UR4HZov786dmWQ+FAQDDZ4N4CAAPhAYAZwNACOvCZjPAw2eAewgAD4UcAAYeZmBnZo1TEGdm
iwpmi/NnA3IE86RmYZAfB8NmUGdmjVMQZoXAD4UKAGdmi0oIZkHrEZBnZotCGGYz0mb3Nk4C
ZovIZivAZl7oAQDDBh5mYGeAewgBD4QDAOmT+2aD+QAPhQYAZmGQHwfDZlNmUGZRZlZmVwbo
kQRmi9EHZl9mXmZZZoXAD4Q0AGY7yg+NAwBmi9Hogv5mK8pmi9pmi8JmD7YWDQBm9+JmD7cW
CwBm9+JmA/hmWGYDw2Zb659mhfYPhCv7ZlFmVwZnZg+2QwlmhcAPhCAAZtHgZivgZov8ZlRm
VmdmD7dzCmYD82aLyPOkZl7rA5BmUGZQZ2aLA2ZQZ2aLQxhmUGdmi1YgZoXSD4QLAGaL/h4H
ZovC6HEDZovGZlpmWWZCZlFmVug/BmaFwA+EuvpmXmZZZov+HgfoTgNmi8Zmi9lmWWZaZlFm
VmbR6ej4/WaFwA+Ek/pmXmZZZgPhB2ZfZllmi9BmWGZbZova6fX+Bh5mYCZnZg+3XwQmZ2YP
t08GZgvJD4Rh+mYD32aDwwJmgcf+AQAAZklmC8kPhBcAJmeLAyZniQdmg8MCZoHHAAIAAGZJ
6+JmYZAfB8MGHmZgZrgBAAAAZqMeAmahGgJmAwZSAmajWgJmAwZSAmajSgJmoTAAZg+2Hg0A
ZvfjZoseSgJmiQdmoxAAg8MEZqFWAmaJB6MOAIPDBGaJHkoCZoseGgIeB+g3+WaL++hR/2ah
GgJmuyAAAABmuQAAAABmugAAAADoEP1mC8APhBkBZovYHgdmiz4WAmYzwOii/WaLHhYCZoE/
gAAAAA+E6wADXwTr8GZTZotHEGb3JlYCZlBmM9JmD7YeDQBm9/NmUujcAGYLwA+EYflmiw5W
AmYPth4NAGb342ZaZgPCZoseSgJmiQeDwwRmD7YGDQBmK8JmO8EPhgMAZovBZokHZivIZloP
hHUAZgPCZlBmM9JmD7YeDQBm9/NmUeiCAGZZZgvAD4QF+WYPth4NAGb342aLHkoCZosXg8ME
ZgMXZjvQD4UVAGYPtgYNAGY7wQ+GAwBmi8FmAQfrpYPDBGaJHkoCZokHg8MEZg+2Bg0AZjvB
D4YDAGaLwWaJB+uCg8MEZv8GHgJmiR5KAmZbA18EZoE/gAAAAA+EDP9mYZAfB8Nmi9Bmiw4e
AmaLNloCZgM2UgJmUmZRZlJmix5aAmaLPlYCZosEZqMQAIPGBGaLBKMOAIPGBB4H6Lj3Ziv4
D4QIAPcmCwAD2OvZZos+WgIeB+i//WahWgJmu4AAAABmuQAAAABmi9HogftmC8APhBz4ZovY
ZlhmVugsAWZeZgvAD4QFAGZbZlvDZllmWuKEZjPAwwYeZmBmUGZRZjPSZg+2Hg0AZvfzZlJm
V+hT/2ZfZgvAD4TW92YPth4NAGb342ZaZgPCZqMQAGZZZg+2Hg0AZjvLD44TAIkeDgBmK8tm
WGYDw2ZQZlHrFJBmWGYDwWZQiQ4OAGa5AAAAAGZRBmZXi9+D4w+MwGbB7wQDx1AH6OD2Zl8H
ZgM+TgJmWWZYZoP5AA+PcP9mYZAfB8MGHmZgZvcmVgJmiw5WAuhV/+jS/GZhkB8HwwYeZmBm
9yZiAmaLHjICZosOYgJmizYmAh4HZos+QgLogfvop/xmYZAfB8NmUGZTZlFmix5GAmaLyGbB
6ANmg+EHZgPYZrgBAAAAZtPgZ4QDD4QEAPjrApD5ZllmW2ZYw2eAewgBD4QEAGYrwMNnZo1z
EGdmi1YIZjvCD4cLAGdmixZmO8IPgwQAZivAw2cDXhBmK/ZngDsAD4Q+AOiBAGYD8eg5AGYD
ymY7wQ+MIQBmi9FmUGdmD7YLZovBZoPgD2bB6QRmA9lmA9hmQ2ZY68RmK8hmK8JmA8bDZivA
w2YryWeKC4DhD2aD+QAPhQQAZivJw2ZTZlJmA9lnZg++E2ZJZktmg/kAD4QNAGbB4ghnihNm
S2ZJ6+tmi8pmWmZbw2ZTZlJmK9JnihNmg+IPZivJZ4oLwOkEZoP5AA+FCABmK8lmWmZbw2YD
2mYD2WdmD74TZklmS2aD+QAPhA0AZsHiCGeKE2ZLZknr62aLymZaZlvDZgvJD4UBAMNmUWZW
Z4M+YQ+MDABngz56D48EAGeDLiBmg8YC4uZmXmZZw2ZQZlFmi9BmoS4CZ2aNWBBnA0MEZ2aN
QBBmi9roRPlmC8APhAUAZllmWcNmoTICZgvAD4UIAGZZZllmM8DDZosWMgJnZo1SEGdmi0IY
ZjPSZvc2XgJmM/ZmUGZWZlhmXmY7xg+EOgBmVmZAZlBmSOgb/nLo6Ov9ZlpmXmZZZltmU2ZR
ZlZmUmahQgJnZo1AGOjQ+GYLwHTEZllmWWZZZlnDZllmWWYzwMNmUWZQZrgFAAAAHgdmi/no

jf1mi8FmuyAAAABmuQAAAABmugAAAADoM/hmW2ZZZoXAD4UVAGaLwWYPtw4MAma6DgIAAOgW
+OszkGYz0maLwWaLy2ZQZlPoIwBmW2ZfZgvAD4QXAB4H6DX9ZovHZg+3DgwCZroOAgAA6OH3
w2ZSZlFmuyAAAABmuQAAAABmugAAAADox/dmC8APhGMAZovYHgdmiz4WAmYzwOhZ+B4HZose
FgJmWWZaJmY5Dw+FDAAmZjlXCA+EMQDrE5AmZoM//w+ELwAmg38EAA+EJgAmZg+3RwQD2IvD
JQCAdMuMwAUACI7AgeP/f+u+JmaLRxDDZllmWmYzwMOg+QHp9POg+gHp7vMAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAA
===
[SIGN]
[622733F1AD2A719A709586E3220AC3A7] Zhuhai Kingsoft Office Software Co.,Ltd
[F159D6AE81214F843123058A6D44A67D] Zhuhai Kingsoft Office Software Co.,Ltd
[C3DAA450AA9691B3125DDE0F7F2BA461] Zhuhai Kingsoft Office Software Co.,Ltd
[56443FBE48FE1F8EB15A68E3D72C5477] Greatis Software LLC
[0B497C79824F8E1BF22FA6AACD3DE3A0] Avira GmbH
[C983E62B6FB74457D173BA93F66F6068] Avira GmbH
[F5B4C2F35A9D78EABF83978217C421A2] Avira GmbH
[8C91BD35AE9AA8B628EEC5E637BB1D0F] Avira GmbH
[B4837FE56D76B2E9EA90E5365CF6A2BE] Avira GmbH
[D2ADA8AF0EE98F3F76536015D74EE4BF] Adobe Systems, Incorporated
[4EAF6F8F0B3BE33A0E3877EB7FFD48D4] Adobe Systems, Incorporated
[041D17F36790D6B75DD3494D25C95CCE] Tonec Inc.
[7896E733AF5A8DCE4B1C94C658AA3DF4] Tonec Inc.
[B60DDDD2D63CE41CB8C487FCFBB6419E] Microsoft Windows
[1868932CA3427EB68C73A664FA2376F5] Opera Software ASA
[07D459F5F889CEFB71A36508D12D8691] Opera Software ASA
[62A0B124F2DFCF1C5694D4D864FABCE0] Opera Software ASA
[D55250337B2A9C2C854C85D905FC3661] TuneUp Software
[42E59AED70580B4AB64CF5CB96ABBAB9] TuneUp Software
[94C4CD2D19B8C4137A46261F229FEC24] TuneUp Software
[EED857823833EE42C20477F3FB20C5B6] TuneUp Software
[16913F0D9A39635AAC067C03DE6E0612] Greatis Software LLC
[8E3F56E9801D8920FA1F2CA2A58E0C0D] Greatis Software LLC
[56443FBE48FE1F8EB15A68E3D72C5477] Greatis Software LLC
[0B0526CE79C2082400E661A0ABE52A14] Microsoft Windows
[78B807E8D2D8D4BDEF085D1B6AE2B175] Ghisler Software GmbH
[12896823FB95BFB3DC9B46BCAEDC9923] Microsoft Windows
[0A429C99CAE89CBD00D0451A5402C3A1] Microsoft Windows
[B32A4DB8FA8BA07AFB1E86F8C9FB852E] Microsoft Windows
[A81135541C9D4EBCE43EFA8AD31395B4] Microsoft Windows
[0D034E8C4F88C5B2B0C1AF3CF438CC4F] Microsoft Windows

[E76F8807070ED04E7408A86D6D3A6137]
[CFD4E51402DA9838B5A04AE680AF54A0]
[02283EDE3F4575A208FDF45CA2E4A47B]
[34CBE729F38138217F9C80212A2A0C82]
[6D778E0F95447E6546553EEEA709D03C]
[1280A158C722FA95A80FB7AEBE78FA7D]
[636DF3FF20A1B69B3F9D21325E7115C7]
[515A7FAE2070C2B0242B2353443E2F11]
[085ED2E391A871C7BAE87E0228B546BA]
[5F1D5F88303D4A4DBC8E5F97BA967CC3]
[5F7E24FA9EAB896051FFB87F840730D2]
[1E44BC1E83D8FD2305F8D452DB109CF9]
[5B44C214F9CD9F590BE9125347610380]
[47B879406246FFDCED59E18D331A0E7D]
[87451AA7CC6B6A590EBCEA05E755075A]
[5FEDEF54757B34FB611B9EC8FB399364]
[662BFD909447DD9CC15B1A1C366583B4]
[1AF592532532A402ED7C060F6954004F]
[C569EF030B11F896E123A30AC92678DB]
[CCF82C5EC8A7326C3066DE870C06DAF1]
[48846B31BE5A4FA662CCFDE7A1BA86B9]
[9EF487A186DEA361AA06913A75B3FA99]
[B467646C54CC746128904E1654C750C1]
[B1C303E17FB9D46E87A98E4BA6769685]
[7D304A5EB4344EBEEAB53A2FE3FFB9F0]
[DE6A75F5C270E756C5508D94B6CF68F5]
[0109C4F3850DFBAB279542515386AE22]
[2F597BB467E05B1FE3830EABD821B8E0]
[032F1C32A6A97C317AEFF9D64D2A1D8A]
[CCF5F451BB1A5A2A522A76E670000FF0]
[1C36ADF2918FCB62E9BAE37A818AB13A]
[43AF5212BD8FB5BA6EED9754358BD8F7]
[96F7A9A7BF0C9C0440A967440065D33C]
[EB5608FD4F2961517AC9F5CAC88B023B]
[D507C1400284176573224903819FFDA3]
[47DDFC2F003F7F9F0592C6874962A2E7]
[A36EE93698802CD899F98BFD553D8185]
[9AEFA14BD6B182D61E3119FA5F436D3D]
[4E53BBCC4BE37D7A4BD6EF1098C89FF7]
[9C193875A6A99F2AAB6A3E3816FA847F]
[2A7A8AD9D39A2FAF9D9293B5DAFF3A4B]
[1B611611C28D2DF25BC057D79C6F13FC]
[04FE5EF6ED4818EC4839EA5C611A6310]
[4BAC8DF07F1D8434FC640E677A62204E]
[1AB3CDDE553B6E064D2E754EFE20285C]
[6DF35CA139C3BC15CC74390ABB114EFE]
[A32426D9B14A089EAA1D922E0C5801A9]
[26496F9DEE2D787FC3E61AD54821FFE6]
[D4991D98F2DB73C60D042F1AEF79EFAE]
[E44733C30F7FE6A1CE7A6B1D2B335CFC]
[3CB32D3B8CBE79899D63280BB7A83CD9]
[877C90686858D899B042BBA45E9B7F2C]
[938B596D4170E4F9870A902DF2DEEF48]
[3946A448C0AC5A94B325B9D679DF6CF4]
[729DA5D23A9AD20A6AA353156A126420]
[1180852DBFADAFC375DBBA1F6B23EEE7]
[2022C54B3A79A51C9538CE47D1F50BC3]
[1D4F13DBB57C5152FC9A5DABBCFC78B4]
[F38092DE1D6A8CBB11B6B6D0F07E268E]
[577E496F0D41411BF149394D80959D53]

Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Avira GmbH
Avira GmbH
Avira GmbH
Avira GmbH
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Greatis Software LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Avira GmbH
Microsoft Windows
Microsoft Windows
Greatis Software LLC
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Tonec Inc.
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows
Microsoft Windows

[57AA18B2896055E8CB269B19DD85E7F3]
[948E1498C6438625247F94534AAA82FE]
[C07552F5734B37F947289B51BC932376]
[1D7BA0CFBDB204B0A3BE40BFA79CE6F1]
[A525C96C51D55111FDF3BEA9FFFFC7AE]
[F3946B534CC197CBFFD9A2ECFD1F556F]
[5677DFE438EC1F009273FC84FEED6B10]
[9FAD7DFF67555FF1E06BC4A3893024A7]
[2081A5B5E4ABA206A0A8A1A97DF0FB23]
[5C12660A97822F6E61576943B49AAAD6]
[D18F1F0C101D06A1C1ADF26EED16FCDD]
[9A3BD5F55AADFF859539142F6328A66E]
[C5648BE5409E0AABDA8C9047BAC8F603]
[55AEEA66C5E84E3FD6CD3E933397D478]
[5733177BCF16EE78B99543C9B0AB81EA]
[A137F1470499A205ABBB9AAFB3B6F2B1]
[33271A2667334B9A8842C65A079EF375]
[B87F759738C52E8D6FBCDAAA84C6486F]
[3A9846E207DAFC13009C048A2F6F8C2A]
[C6FD300A6100AC89BC4CB944C19FA2A9]
[7D529AA41EA993357F8C3D7E92C2372A]
[D469A0EBA2EF5C6BEE8065B7E3196E5E]
[5879D691E842574A20FE63817CB76DF9]
[C7E39EA41233E9F5B86C8DA3A9F1E4A8]
[777819E1514AA632364DE59F810B292C]
[517561A1113B04E51D936CD018DE1C1F]
[FCB4782D700268C1B82ECEF74CF1A3B9]
[943337D786A56729263071623BBB9DE5]
[0F200BE1ED9DE188CA6407A3759BE7CF]
[6B27A5C03DFB94B4245739065431322C]
[037B1E7798960E0420003D05BB577EE6]
[0F64207B49390C8063C36AE7CBF9C2DB]
[65DF52F5B8B6E9BBD183505225C37315]
[4DC9D0547B7AEEE42241A1EC4580C484]
[6843D54BC4A40CC8C5741AF750233D10]
[99BC0B50F511924348BE19C7C7313BBF]
[0DBB250A89E2E1C9281009AC269F0805]
[60784F891563FB1B767F70117FC2428F]
[50512FC9B7878E3C2C147BC17326A7DB]
[C504A9FE17F997F8B1F8561D0A68DE52]
[2CD1C3506A85B38E2D17E61ADED175C4]
[B08F8FFBA4570E21A71C38E00CC678E7]
[E8CD0D7E169ECCE2D4FD829DAAB786ED]
[05642AE6A7BDAA7541A7451F5A4C6512]
[B26B135FF1B9F60C9388B4A7D16F600B]
[7A2CC3719B255E6B5D74396183B7715B]
[378A0AEFB11D8B0DC8C27B9F7604B88D]
[3AAF9B35939FF9E58CCD18D41655C2FC]
[680B56A8B62D1BCF4A0B2AAAD03D88E4]
[CC8915DB4E33E8FB29CA0D2DBF75306E]
[ED0EF0A136DEC83DF69F04118870003E]
[A8888A5327621856C0CEC4E385F69309]
[FE2571A8C9FFAB1D45502D6B0BF472AA]
===

Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft
Microsoft

Windows
Windows
Windows
Corporation
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows
Windows

Вам также может понравиться