GeekPolice
Welcome to GeekPolice.net!

From "wow" to "whoa" - we're teaching practical technology and helping others with tech support. Join our family here!

You are viewing the forum as a "Guest" which doesn't give you member privileges to ask questions or post comments.

Take 30 seconds to register or log in below and unlock the limitations of this website to discover new computer knowledge!

MBR:\...\PHYSICALDRIVE0

Page 1 of 2 1, 2  Next

View previous topic View next topic Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Mon Sep 12, 2011 7:25 pm

Sorry it took so long. I had to learn how to download and burn the iso image file.

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Basic Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: Inspiron 530
Logical Drives Mask: 0x0000001d

Kernel Drivers (total 109):
0x81C1C000 \SystemRoot\system32\ntkrnlpa.exe
0x81FD5000 \SystemRoot\system32\hal.dll
0x80409000 \SystemRoot\system32\kdcom.dll
0x80410000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x80480000 \SystemRoot\system32\PSHED.dll
0x80491000 \SystemRoot\system32\BOOTVID.dll
0x80499000 \SystemRoot\system32\CLFS.SYS
0x804DA000 \SystemRoot\system32\CI.dll
0x8060D000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8067E000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8068C000 \SystemRoot\system32\drivers\acpi.sys
0x806D2000 \SystemRoot\system32\drivers\WMILIB.SYS
0x806DB000 \SystemRoot\system32\drivers\msisadrv.sys
0x806E3000 \SystemRoot\system32\drivers\pci.sys
0x8070A000 \SystemRoot\System32\drivers\partmgr.sys
0x80719000 \SystemRoot\system32\drivers\volmgr.sys
0x80728000 \SystemRoot\System32\drivers\volmgrx.sys
0x80772000 \SystemRoot\system32\DRIVERS\intelide.sys
0x80779000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x80787000 \SystemRoot\system32\drivers\pciide.sys
0x8078E000 \SystemRoot\System32\drivers\mountmgr.sys
0x8079E000 \SystemRoot\system32\drivers\atapi.sys
0x807A6000 \SystemRoot\system32\drivers\ataport.SYS
0x807C4000 \SystemRoot\system32\drivers\fltmgr.sys
0x805BA000 \SystemRoot\system32\drivers\fileinfo.sys
0x807F6000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x82206000 \SystemRoot\System32\Drivers\ksecdd.sys
0x82277000 \SystemRoot\system32\drivers\ndis.sys
0x82382000 \SystemRoot\system32\drivers\msrpc.sys
0x823AD000 \SystemRoot\system32\drivers\NETIO.SYS
0x87807000 \SystemRoot\System32\drivers\tcpip.sys
0x878F1000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x87A05000 \SystemRoot\System32\Drivers\Ntfs.sys
0x87B15000 \SystemRoot\system32\drivers\volsnap.sys
0x87B56000 \SystemRoot\System32\Drivers\SmartDefragDriver.sys
0x87B5D000 \SystemRoot\System32\Drivers\mup.sys
0x87B6C000 \SystemRoot\System32\drivers\ecache.sys
0x87B93000 \SystemRoot\system32\drivers\disk.sys
0x87BA4000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x87BC5000 \SystemRoot\system32\drivers\crcdisk.sys
0x87BEE000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8790C000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x87915000 \SystemRoot\system32\DRIVERS\e1e6032.sys
0x87950000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8795B000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x87999000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8AE0E000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8AE9B000 \SystemRoot\system32\DRIVERS\fdc.sys
0x8AEA6000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8AEBE000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8AEED000 \SystemRoot\system32\DRIVERS\storport.sys
0x8AF2E000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8AF39000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8AF50000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8AF5B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8AF7E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8AF8D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8AFA1000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8AFB6000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8AFC6000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8AFD1000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8AFDC000 \SystemRoot\system32\DRIVERS\swenum.sys
0x879A8000 \SystemRoot\system32\DRIVERS\ks.sys
0x8AFDE000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8AFE8000 \SystemRoot\system32\DRIVERS\umbus.sys
0x805CA000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x879D2000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8AFF5000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x879E3000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8AE00000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8AE07000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x879F3000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x823E8000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x87BF9000 \SystemRoot\System32\Drivers\Null.SYS
0x87B4E000 \SystemRoot\System32\Drivers\Beep.SYS
0x823F1000 \SystemRoot\System32\drivers\vga.sys
0x8B00D000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8B02E000 \SystemRoot\System32\drivers\watchdog.sys
0x8B03A000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8B042000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8B04D000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8B05B000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8B064000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8B07A000 \SystemRoot\system32\DRIVERS\smb.sys
0x8B08E000 \SystemRoot\system32\drivers\afd.sys
0x8B0D6000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8B108000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x8B111000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8B127000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8B135000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8B171000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8B17B000 \SystemRoot\System32\Drivers\dfsc.sys
0x91400000 \SystemRoot\System32\win32k.sys
0x8B19A000 \SystemRoot\System32\drivers\Dxapi.sys
0x91610000 \SystemRoot\System32\drivers\dxg.sys
0x91640000 \SystemRoot\System32\TSDDD.dll
0x916C0000 \SystemRoot\System32\framebuf.dll
0x8B1A4000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8B1B1000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8B1BC000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x8B1C4000 \SystemRoot\system32\DRIVERS\bowser.sys
0x8B1DD000 \SystemRoot\System32\drivers\mpsdrv.sys
0x87BCE000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x93806000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9383F000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x93857000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x93869000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x93871000 \SystemRoot\system32\DRIVERS\udfs.sys
0x77820000 \Windows\System32\ntdll.dll

Processes (total 23):
0 System Idle Process
4 System
348 C:\Windows\System32\smss.exe
416 csrss.exe
452 csrss.exe
460 C:\Windows\System32\wininit.exe
488 C:\Windows\System32\winlogon.exe
536 C:\Windows\System32\services.exe
548 C:\Windows\System32\lsass.exe
556 C:\Windows\System32\lsm.exe
712 C:\Windows\System32\svchost.exe
772 C:\Windows\System32\svchost.exe
856 C:\Windows\System32\svchost.exe
884 C:\Windows\System32\svchost.exe
908 C:\Windows\System32\svchost.exe
956 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1052 C:\Windows\System32\svchost.exe
1232 C:\Windows\System32\svchost.exe
1652 C:\Windows\explorer.exe
396 C:\Windows\System32\wbem\unsecapp.exe
720 WmiPrvSE.exe
1376 C:\Users\dummy\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`83000000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000000`03000000 (NTFS)

PhysicalDrive0 Model Number: ST3250310AS, Rev: 3.ADA

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Windows Vista MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!

Well, it looks like it is now reading the Windows Vista MBR code Right On!
That being the case could you help with my BSoD? Stop message: 0x0000008E (0xC000005, 0x81E46BDC, 0x8B71691C, 0x00000000).

Not only do I not know what the letters mean I don't know how to go about fixing them. Since I can only run in Safe mode, every setting that is changed returns to the default when system is restarted. Getting Windows to start normally is now impossible. The BSoD happens on the user login page. This started about 2 weeks ago, along with memory dumps every time. I've tried changing the dump file settings and taking ownership of same.When I restart the comp. all the settings return to default settings. Which means I have no dump files again.
I really hope you can help anyway. I would love to be able to give you dump file information, but I don't have any.
Thank you for trying to help me keep what little sanity I have left!!









Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Wed Sep 14, 2011 7:45 am

Was the BSOD happening while the MBR was infected?

After fixing the MBR, did it continue happening?


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Thu Sep 15, 2011 7:26 pm

Yes to both questions. It seems to be independent of the MBR infection.

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Fri Sep 16, 2011 8:20 am

-1. Run MEMTEST for 5 passes: [You must be registered and logged in to see this link.]
-2. Run System File Checker, Start > type in sfc /scannow and hit Enter

Let me know the results of it.

Note: it's important to run MEMTEST for 5 passes, because sometimes only one or two passes won't spot the issue.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Sat Sep 17, 2011 2:45 am

Got 5 passes from MemTest. The scannow program scanned and then the window just closed. I'm not sure if this was because it didn't find anything, but I figured you would know.
Thanx!!

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Sat Sep 17, 2011 6:46 am

Please download the latest version of Kaspersky GetSystemInfo (GSI) from [You must be registered and logged in to see this link.] and save it to your Desktop.

Note: please close all other applications running on your system.

Double click GetSystemInfo.exe to open it. It will display an agreement. Click on I Agree to continue.

Click the Settings button.



Set the slider to Maximum.



IMPORTANT! Then, click Customize - choose Driver / Ports tab and uncheck Scan Ports.




On the General tab, make sure all of the boxes are checked.




On the Misc tab, make sure all the checkboxes are checked.

Then, click OK on the windows that you launched.



Click Create Report to run it.


It will begin scanning.

It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop.

It should automatically upload it to [You must be registered and logged in to see this link.] If it does not, then please submit it manually by going to the site and doing the upload process.

It will redirect to a page, where it will provide a sharing URL for specialists. Copy and paste the url of the GSI Parser report in your next reply.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Mon Sep 19, 2011 8:26 pm

[You must be registered and logged in to see this link.]

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Tue Sep 20, 2011 12:12 pm

How many antivirus programs do you have currently running?


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Tue Sep 20, 2011 6:09 pm

IOBit Security 360. I had been running avast and then I thought I uninstalled it. Found out it was still in the registry as a start up program. I used IOBit uninstaller to get rid of the rest of the program in the registry. I think that is all Let me think . Once the problems are fixed, I will run avgfree edition.

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Wed Sep 21, 2011 10:23 am

What ones have you installed in the past? Please list all, no matter if they are still installed...


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Thu Sep 22, 2011 2:46 am

Windows security, which quit running awhile ago. Avast 4, upgraded to Avast5 (hate it!). Downloaded AVG free and tried to install it in safe mode. It loaded but only partially. Uninstalled it. IOBit Security 360.

I believe that is all No way!

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Fri Sep 23, 2011 9:46 am

Windows security, which quit running awhile ago.
Windows security? Do you mean Windows Defender? Microsoft Security Essentials? Which one?

Answer that, then we will have to completely remove all of those AV programs...


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Sat Sep 24, 2011 3:43 am

Just Windows Defender.

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Mon Sep 26, 2011 10:04 am

Follow this page to remove all security applications you've had: [You must be registered and logged in to see this link.]

Let me know when done...


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Tue Sep 27, 2011 12:20 am

Its done I think

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Wed Sep 28, 2011 9:50 am

How is the computer running after that?


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Fri Sep 30, 2011 10:47 pm

It made no difference. Still starting in safe mode after getting BSoD trying to start normally.

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Sat Oct 01, 2011 10:36 am

Please download [You must be registered and logged in to see this link.] by DragonMaster Jay and save it to your Desktop.
  • Right-click on SpiderKill.zip and click Extract All. Follow the prompts and read carefully, to save it to your Desktop.
  • Double-click on the SpiderKill folder, and then double-click on SpiderKill.bat and follow all the prompts in the program.
  • Within a minute, it will save its log titled SpiderKill.txt. Please post that in your next reply. You may have to use two or three posts to be able to fit the information in.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Sun Oct 02, 2011 9:44 pm

SpiderKill by DragonMaster Jay


Microsoft Windows [Version 6.0.6002]

********************Drivers list********************


Volume in drive C is OS
Volume Serial Number is FAD5-45CE

Directory of C:\Windows\System32\Drivers

09/26/2011 09:16 PM .
09/26/2011 09:16 PM ..
07/18/2008 05:26 PM 4,782 1028_Dell_INS_530.mrk
11/02/2006 01:55 AM 53,376 1394bus.sys
04/10/2009 11:32 PM 265,688 acpi.sys
01/20/2008 07:32 PM 422,968 adp94xx.sys
01/20/2008 07:32 PM 300,600 adpahci.sys
01/20/2008 07:32 PM 101,432 adpu160m.sys
01/20/2008 07:32 PM 149,560 adpu320.sys
04/10/2009 09:47 PM 273,920 afd.sys
01/20/2008 07:32 PM 56,376 AGP440.sys
01/20/2008 07:32 PM 17,464 aliide.sys
01/20/2008 07:32 PM 57,400 AMDAGP.SYS
01/20/2008 07:32 PM 17,976 amdide.sys
01/20/2008 07:32 PM 41,472 amdk7.sys
01/20/2008 07:32 PM 44,032 amdk8.sys
01/20/2008 07:32 PM 79,416 arc.sys
01/20/2008 07:32 PM 79,928 arcsas.sys
01/20/2008 07:33 PM 17,408 asyncmac.sys
04/10/2009 11:32 PM 19,944 atapi.sys
04/10/2009 11:32 PM 109,032 ataport.sys
11/02/2006 12:36 AM 2,028,032 atikmdag.sys
10/01/2006 02:10 PM 328,162 ativcaxx.cpa
10/01/2006 02:10 PM 929 ativcaxx.vp
10/01/2006 02:10 PM 2,096 ativokxx.vp
10/01/2006 02:10 PM 2,096 ativpkxx.vp
10/15/2006 02:11 PM 34,656 ativvpxx.vp
01/13/2010 10:14 PM 278,984 atksgt.sys
01/20/2008 07:32 PM 28,216 battc.sys
01/20/2008 07:32 PM 12,288 bdasup.sys
01/20/2008 07:33 PM 6,144 beep.sys
01/20/2008 07:32 PM 45,568 blbdrive.sys
01/20/2008 07:33 PM 69,632 bowser.sys
11/02/2006 01:24 AM 13,568 BrFiltLo.sys
11/02/2006 01:24 AM 5,248 BrFiltUp.sys
04/10/2009 10:42 PM 93,696 bridge.sys
11/02/2006 01:25 AM 71,808 BrSerId.sys
11/02/2006 01:24 AM 62,336 BrSerWdm.sys
11/02/2006 01:24 AM 12,160 BrUsbMdm.sys
11/02/2006 01:24 AM 11,904 BrUsbSer.sys
11/02/2006 01:55 AM 39,936 bthmodem.sys
01/20/2008 07:33 PM 70,144 cdfs.sys
10/17/2007 12:00 AM 9,072 cdr4_xp.sys
10/17/2007 12:00 AM 9,200 cdralw2k.sys
04/10/2009 09:39 PM 67,072 cdrom.sys
07/24/2011 11:27 PM 54,016 cgscfs.sys
01/20/2008 07:32 PM 35,328 circlass.sys
04/10/2009 11:32 PM 125,928 Classpnp.sys
01/20/2008 07:32 PM 19,000 cmdide.sys
01/20/2008 07:32 PM 20,792 compbatt.sys
04/10/2009 11:32 PM 35,304 crashdmp.sys
01/20/2008 07:32 PM 24,632 crcdisk.sys
01/20/2008 07:32 PM 40,960 crusoe.sys
09/29/2006 12:14 PM 144,360 del1028.cty
04/10/2009 09:14 PM 75,264 dfsc.sys
04/10/2009 11:32 PM 53,736 disk.sys
04/10/2009 09:39 PM 19,456 Diskdump.sys
11/02/2006 02:50 AM 71,272 djsvs.sys
01/20/2008 07:32 PM 130,048 drmk.sys
01/20/2008 07:32 PM 5,632 drmkaud.sys
04/10/2009 11:32 PM 27,624 Dumpata.sys
01/20/2008 07:34 PM 13,312 dxapi.sys
04/10/2009 09:23 PM 76,288 dxg.sys
09/24/2009 06:27 PM 634,880 dxgkrnl.sys
04/29/2007 01:42 AM 228,224 e1e6032.sys
01/20/2008 07:32 PM 118,784 E1G60I32.sys
04/10/2009 11:32 PM 141,288 ecache.sys
01/20/2008 07:32 PM 342,584 elxstor.sys
05/11/2010 08:02 AM en-US
01/20/2008 07:32 PM 6,656 errdev.sys
08/12/2011 12:18 AM etc
04/10/2009 09:13 PM 136,704 exfat.sys
04/10/2009 09:13 PM 142,848 fastfat.sys
01/20/2008 07:32 PM 25,088 fdc.sys
01/20/2008 07:33 PM 58,936 fileinfo.sys
01/20/2008 07:34 PM 27,648 filetrace.sys
01/20/2008 07:32 PM 20,480 flpydisk.sys
04/10/2009 11:32 PM 190,424 fltMgr.sys
01/20/2008 07:33 PM 12,800 fs_rec.sys
04/10/2009 11:32 PM 99,816 FWPKCLNT.SYS
01/20/2008 07:32 PM 61,496 GAGP30KX.SYS
09/18/2006 02:26 PM 3,440,660 gm.dls
09/18/2006 02:26 PM 646 gmreadme.txt
04/10/2009 09:42 PM 561,152 hdaudbus.sys
11/02/2006 01:55 AM 29,184 hidbth.sys
04/10/2009 09:42 PM 39,424 hidclass.sys
11/02/2006 01:55 AM 21,504 hidir.sys
01/20/2008 07:32 PM 25,472 hidparse.sys
04/10/2009 09:42 PM 12,800 hidusb.sys
01/20/2008 07:32 PM 40,504 HpCISSs.sys
10/18/2006 11:08 AM 258,048 HSXHWBS2.sys
10/18/2006 11:08 AM 659,968 HSX_CNXT.sys
10/18/2006 11:09 AM 986,624 HSX_DPV.sys
11/03/2009 12:41 PM 411,648 http.sys
01/20/2008 07:32 PM 19,000 i2omgmt.sys
01/20/2008 07:32 PM 30,264 i2omp.sys
01/20/2008 07:32 PM 54,784 i8042prt.sys
04/26/2007 03:41 AM 304,920 iaStor.sys
01/20/2008 07:32 PM 235,064 iaStorV.sys
02/11/2008 08:36 PM 2,302,976 igdkmd32.sys
11/02/2006 02:50 AM 41,576 iirsp.sys
01/20/2008 07:32 PM 17,976 intelide.sys
01/20/2008 07:32 PM 41,472 intelppm.sys
01/20/2008 07:34 PM 47,616 ipfltdrv.sys
01/20/2008 07:32 PM 64,512 IPMIDrv.sys
01/20/2008 07:34 PM 100,864 ipnat.sys
03/09/2007 03:04 PM 31,072 iqvw32.sys
01/20/2008 07:34 PM 95,744 irda.sys
01/20/2008 07:33 PM 13,312 irenum.sys
12/07/2009 05:59 PM 61,328 is3srv.sys
01/20/2008 07:32 PM 49,720 isapnp.sys
11/02/2006 02:50 AM 35,944 iteatapi.sys
11/02/2006 02:50 AM 35,944 iteraid.sys
01/20/2008 07:32 PM 35,384 kbdclass.sys
04/10/2009 09:38 PM 17,408 kbdhid.sys
08/05/2011 07:07 AM 6,472 kgpcpy.cfg
04/10/2009 09:38 PM 149,504 ks.sys
06/15/2009 04:15 PM 439,864 ksecdd.sys
06/17/2009 09:56 AM 35,472 LHidFilt.Sys
01/13/2010 10:14 PM 25,416 lirsgt.sys
01/20/2008 07:34 PM 47,104 lltdio.sys
06/17/2009 09:56 AM 37,392 LMouFilt.Sys
01/20/2008 07:32 PM 96,312 lsi_fc.sys
01/20/2008 07:32 PM 89,656 lsi_sas.sys
01/20/2008 07:32 PM 96,312 lsi_scsi.sys
01/20/2008 07:34 PM 84,480 luafv.sys
06/17/2009 09:56 AM 28,560 LUsbFilt.sys
07/06/2011 07:52 PM 22,712 mbam.sys
07/06/2011 07:52 PM 41,272 mbamswissarmy.sys
01/20/2008 07:34 PM 18,944 mcd.sys
06/19/2006 02:26 PM 12,672 mdmxsdk.sys
01/20/2008 07:32 PM 31,288 megasas.sys
01/20/2008 07:32 PM 386,616 MegaSR.sys
01/20/2008 07:34 PM 31,744 modem.sys
01/20/2008 07:32 PM 41,984 monitor.sys
01/20/2008 07:32 PM 34,360 mouclass.sys
01/20/2008 07:32 PM 15,872 mouhid.sys
01/20/2008 07:33 PM 57,400 mountmgr.sys
01/20/2008 07:32 PM 105,016 mpio.sys
01/20/2008 07:34 PM 64,000 mpsdrv.sys
11/02/2006 02:49 AM 33,384 Mraid35x.sys
04/10/2009 09:14 PM 114,688 mrxdav.sys
12/04/2009 08:56 AM 105,984 mrxsmb.sys
12/04/2009 08:56 AM 212,992 mrxsmb10.sys
04/10/2009 09:14 PM 79,360 mrxsmb20.sys
01/20/2008 07:32 PM 28,728 msahci.sys
01/20/2008 07:32 PM 94,776 msdsm.sys
01/20/2008 07:33 PM 22,528 msfs.sys
07/14/2009 10:45 AM 3

MsftWdf_Kernel_01009_Inbox_Critical.Wdf
01/20/2008 07:32 PM 16,440 msisadrv.sys
04/10/2009 11:32 PM 180,712 msiscsi.sys
01/20/2008 07:34 PM 8,192 mskssrv.sys
01/20/2008 07:34 PM 5,888 mspclock.sys
01/20/2008 07:34 PM 5,504 mspqm.sys
04/10/2009 11:32 PM 161,752 msrpc.sys
01/20/2008 07:32 PM 31,288 mssmbios.sys
01/20/2008 07:34 PM 6,016 mstee.sys
04/10/2009 11:32 PM 48,104 mup.sys
04/10/2009 11:32 PM 527,848 ndis.sys
01/20/2008 07:34 PM 20,992 ndistapi.sys
01/20/2008 07:34 PM 16,896 ndisuio.sys
04/10/2009 09:46 PM 121,344 ndiswan.sys
01/20/2008 07:34 PM 49,664 ndproxy.sys
01/20/2008 07:34 PM 35,840 netbios.sys
04/10/2009 09:45 PM 185,856 netbt.sys
04/10/2009 11:32 PM 223,208 netio.sys
11/02/2006 02:50 AM 45,160 nfrd960.sys
04/10/2009 09:14 PM 35,328 npfs.sys
01/20/2008 07:34 PM 16,384 nsiproxy.sys
04/10/2009 11:32 PM 1,083,880 ntfs.sys
11/02/2006 12:36 AM 20,608 ntrigdigi.sys
01/20/2008 07:33 PM 4,608 null.sys
01/20/2008 07:32 PM 102,968 nvraid.sys
01/20/2008 07:32 PM 45,112 nvstor.sys
01/20/2008 07:32 PM 109,112 NV_AGP.SYS
04/10/2009 09:43 PM 148,480 nwifi.sys
11/02/2006 01:55 AM 62,080 ohci1394.sys
04/10/2009 09:45 PM 72,192 pacer.sys
11/02/2006 01:51 AM 79,360 parport.sys
04/10/2009 11:32 PM 54,248 partmgr.sys
11/02/2006 01:51 AM 8,704 parvdm.sys
04/10/2009 11:32 PM 149,480 pci.sys
04/10/2009 11:32 PM 14,312 pciide.sys
04/10/2009 11:32 PM 43,496 pciidex.sys
11/02/2006 02:51 AM 167,528 pcmcia.sys
02/23/2010 12:17 PM 47,360 pcouffin.sys
11/02/2006 02:04 AM 878,080 PEAuth.sys
04/10/2009 09:42 PM 167,936 portcls.sys
01/20/2008 07:32 PM 40,960 processr.sys
11/14/2007 01:00 AM 43,840 pxhelp20.sys
01/20/2008 07:32 PM 1,122,360 ql2300.sys
11/02/2006 02:50 AM 106,088 ql40xx.sys
01/20/2008 07:32 PM 31,232 qwavedrv.sys
01/20/2008 07:34 PM 11,776 rasacd.sys
01/20/2008 07:34 PM 76,288 rasl2tp.sys
04/10/2009 09:46 PM 41,472 raspppoe.sys
01/20/2008 07:34 PM 62,976 raspptp.sys
04/10/2009 09:46 PM 69,120 rassstp.sys
04/10/2009 09:14 PM 225,280 rdbss.sys
01/20/2008 07:33 PM 6,144 RDPCDD.sys
01/20/2008 07:32 PM 248,832 rdpdr.sys
01/20/2008 07:34 PM 6,144 RDPENCDD.sys
04/10/2009 09:51 PM 180,736 rdpwd.sys
04/10/2009 09:45 PM 113,664 rmcast.sys
04/10/2009 09:46 PM 33,280 RNDISMP.sys
01/20/2008 07:34 PM 8,192 rootmdm.sys
01/20/2008 07:34 PM 60,416 rspndr.sys
01/24/2008 11:06 AM 2,054,872 RTKVHDA.sys
11/02/2006 02:50 AM 76,392 sbp2port.sys
01/20/2008 07:33 PM 142,904 scsiport.sys
11/01/2006 11:37 PM 20,480 secdrv.sys
11/02/2006 01:51 AM 17,920 serenum.sys
11/02/2006 01:51 AM 83,456 serial.sys
01/20/2008 07:32 PM 19,968 sermouse.sys
01/20/2008 07:32 PM 13,312 sffdisk.sys
01/20/2008 07:32 PM 12,288 sffp_mmc.sys
01/20/2008 07:32 PM 11,776 sffp_sd.sys
01/20/2008 07:32 PM 13,312 sfloppy.sys
01/20/2008 07:32 PM 55,864 SISAGP.SYS
01/20/2008 07:32 PM 41,016 sisraid2.sys
01/20/2008 07:32 PM 74,808 sisraid4.sys
02/23/2011 04:52 PM 16,184 SmartDefragDriver.sys
04/10/2009 09:45 PM 66,560 smb.sys
01/20/2008 07:34 PM 17,408 smclib.sys
01/20/2008 07:33 PM 21,048 spldr.sys
04/10/2009 07:52 PM 684,032 spsys.sys
12/11/2009 04:43 AM 302,080 srv.sys
09/14/2009 02:29 AM 144,896 srv2.sys
12/11/2009 04:43 AM 98,816 srvnet.sys
04/10/2009 11:32 PM 122,344 Storport.sys
04/10/2009 09:42 PM 52,992 stream.sys
01/20/2008 07:32 PM 15,288 swenum.sys
11/02/2006 02:50 AM 35,944 symc8xx.sys
11/02/2006 02:49 AM 31,848 sym_hi.sys
11/02/2006 02:50 AM 34,920 sym_u3.sys
12/07/2009 05:59 PM 61,328 SZKG.sys
05/12/2010 06:01 PM 59,280 SZKGFS.sys
01/20/2008 07:34 PM 24,576 tape.sys
12/08/2009 01:01 PM 904,776 tcpip.sys
12/08/2009 10:26 AM 30,720 tcpipreg.sys
01/20/2008 07:33 PM 20,992 tdi.sys
01/20/2008 07:33 PM 17,920 tdpipe.sys
01/20/2008 07:33 PM 29,184 tdtcp.sys
04/10/2009 09:45 PM 72,192 tdx.sys
04/10/2009 11:32 PM 53,224 termdd.sys
01/20/2008 07:34 PM 23,552 tssecsrv.sys
01/20/2008 07:34 PM 15,360 TUNMP.SYS
01/20/2008 07:34 PM 23,040 tunnel.sys
01/20/2008 07:32 PM 59,448 UAGP35.SYS
04/10/2009 09:13 PM 226,816 udfs.sys
01/20/2008 07:32 PM 60,984 ULIAGPKX.SYS
01/20/2008 07:32 PM 238,648 uliahci.sys
11/02/2006 02:50 AM 98,408 ulsata.sys
01/20/2008 07:32 PM 115,816 ulsata2.sys
01/20/2008 07:32 PM 34,816 umbus.sys
11/19/2009 10:14 AM UMDF
01/20/2008 07:33 PM 7,680 umpass.sys
04/10/2009 09:46 PM 15,872 usb8023.sys
12/14/2010 07:51 PM 41,984 usbaapl.sys
04/10/2009 09:42 PM 25,856 USBCAMD.sys
04/10/2009 09:42 PM 25,856 USBCAMD2.sys
01/20/2008 07:32 PM 73,216 usbccgp.sys
11/02/2006 01:55 AM 68,608 usbcir.sys
01/20/2008 07:32 PM 5,888 usbd.sys
04/10/2009 09:42 PM 39,936 usbehci.sys
04/10/2009 09:43 PM 196,096 usbhub.sys
05/07/2001 03:56 AM 19,805 usbio.sys
11/02/2006 01:55 AM 19,456 usbohci.sys
04/10/2009 09:42 PM 226,304 usbport.sys
01/20/2008 07:32 PM 18,944 usbprint.sys
04/10/2009 09:42 PM 65,536 USBSTOR.SYS
01/20/2008 07:32 PM 23,552 usbuhci.sys
01/20/2008 07:34 PM 25,088 vga.sys
01/20/2008 07:32 PM 26,112 vgapnp.sys
01/20/2008 07:32 PM 56,888 VIAAGP.SYS
01/20/2008 07:32 PM 41,472 viac7.sys
01/20/2008 07:32 PM 20,024 viaide.sys
01/20/2008 07:33 PM 110,080 videoprt.sys
01/20/2008 07:32 PM 52,792 volmgr.sys
04/10/2009 11:33 PM 292,840 volmgrx.sys
04/10/2009 11:32 PM 226,280 volsnap.sys
01/20/2008 07:32 PM 130,616 vsmraid.sys
11/02/2006 01:52 AM 20,608 wacompen.sys
01/20/2008 07:34 PM 62,464 wanarp.sys
04/10/2009 09:22 PM 33,280 watchdog.sys
01/20/2008 07:32 PM 22,072 wd.sys
07/14/2009 10:45 AM 445,008 Wdf01000.sys
07/14/2009 10:45 AM 38,480 WdfLdr.sys
01/20/2008 07:32 PM 11,264 wmiacpi.sys
01/20/2008 07:33 PM 17,976 wmilib.sys
01/20/2008 07:32 PM 39,936 WpdUsb.sys
01/20/2008 07:34 PM 15,872 ws2ifsl.sys
01/20/2008 07:34 PM 51,200 WUDFPf.sys
01/20/2008 07:34 PM 83,328 WUDFRd.sys
08/04/2006 05:39 PM 386,560 XAudio.exe
08/04/2006 05:39 PM 8,192 XAudio.sys
291 File(s) 38,492,299 bytes

Directory of C:\Windows\System32\Drivers\en-US

05/11/2010 08:02 AM .
05/11/2010 08:02 AM ..
11/02/2006 05:38 AM 9,728 acpi.sys.mui
11/02/2006 05:38 AM 8,704 afd.sys.mui
11/02/2006 05:39 AM 3,072 AGP440.sys.mui
11/02/2006 05:39 AM 3,072 AMDAGP.SYS.mui
11/02/2006 05:38 AM 2,560 amdide.sys.mui
11/02/2006 05:38 AM 14,848 amdk7.sys.mui
11/02/2006 05:38 AM 14,848 amdk8.sys.mui
11/02/2006 05:38 AM 3,072 ati2mpad.sys.mui
11/02/2006 05:39 AM 3,584 ati2mtag.sys.mui
11/02/2006 05:38 AM 3,072 atikmdag.sys.mui
01/20/2008 07:35 PM 5,120 b57nd60x.sys.mui
11/02/2006 05:38 AM 7,680 battc.sys.mui
11/02/2006 05:38 AM 5,120 bcm4sbxp.sys.mui
11/02/2006 05:38 AM 2,560 BrParwdm.sys.mui
11/02/2006 05:38 AM 10,240 BrSerId.sys.mui
11/02/2006 05:38 AM 5,120 bthpan.sys.mui
04/10/2009 11:22 PM 8,192 bthport.sys.mui
11/02/2006 05:39 AM 3,072 cmbp0wdm.sys.mui
11/02/2006 05:38 AM 14,848 crusoe.sys.mui
11/02/2006 05:39 AM 3,072 cxbp0wdm.sys.mui
11/02/2006 05:38 AM 3,072 Dot4usb.sys.mui
10/08/2009 04:12 PM 4,096 dxgkrnl.sys.mui
11/02/2006 05:38 AM 5,120 e100b325.sys.mui
01/20/2008 07:35 PM 19,968 e1e6032.sys.mui
01/20/2008 07:35 PM 16,896 E1G60I32.sys.mui
11/02/2006 05:38 AM 5,120 fltmgr.sys.mui
11/02/2006 05:38 AM 3,072 GAGP30KX.SYS.mui
11/02/2006 05:39 AM 3,584 gpr400.sys.mui
11/02/2006 05:39 AM 4,096 grserial.sys.mui
04/10/2009 11:24 PM 4,096 hdaudbus.sys.mui
11/02/2006 05:38 AM 3,584 hidbth.sys.mui
11/03/2009 02:46 PM 36,864 http.sys.mui
11/02/2006 05:38 AM 10,752 i8042prt.sys.mui
11/02/2006 05:38 AM 14,848 intelppm.sys.mui
11/02/2006 05:38 AM 6,144 IPMIDrv.sys.mui
11/02/2006 05:38 AM 4,096 ipnat.sys.mui
11/02/2006 05:39 AM 4,096 isapnp.sys.mui
11/02/2006 05:38 AM 4,608 kbdclass.sys.mui
11/02/2006 05:38 AM 3,072 kbdhid.sys.mui
11/02/2006 05:38 AM 9,728 ltmdmnt.sys.mui
01/20/2008 07:35 PM 6,656 luafv.sys.mui
11/02/2006 05:38 AM 4,096 modem.sys.mui
11/02/2006 05:38 AM 4,608 mouclass.sys.mui
11/02/2006 05:38 AM 3,072 mouhid.sys.mui
01/20/2008 07:35 PM 20,480 mpio.sys.mui
11/02/2006 05:38 AM 4,096 msdsm.sys.mui
11/02/2006 05:39 AM 3,584 mssmbios.sys.mui
11/02/2006 05:38 AM 65,536 ntfs.sys.mui
11/02/2006 05:38 AM 4,096 ntrigdigi.sys.mui
11/02/2006 05:39 AM 5,120 nv4_mini.sys.mui
11/02/2006 05:39 AM 3,072 NV_AGP.SYS.mui
11/02/2006 05:38 AM 12,288 ohci1394.sys.mui
11/02/2006 05:38 AM 3,584 pacer.sys.mui
11/02/2006 05:38 AM 4,096 parport.sys.mui
11/02/2006 05:38 AM 3,072 parvdm.sys.mui
11/02/2006 05:39 AM 8,704 pci.sys.mui
11/02/2006 05:38 AM 4,608 pcmcia.sys.mui
11/02/2006 05:39 AM 3,072 pnpmem.sys.mui
11/02/2006 05:38 AM 14,848 processr.sys.mui
11/02/2006 05:39 AM 4,096 pscr.sys.mui
11/02/2006 05:39 AM 3,072 qwavedrv.sys.mui
11/02/2006 05:38 AM 3,584 RNDISMP.sys.mui
11/02/2006 05:39 AM 3,584 rndismpx.sys.mui
11/02/2006 05:39 AM 4,096 scmstcs.sys.mui
11/02/2006 05:39 AM 4,096 SCR111.sys.mui
11/02/2006 05:39 AM 3,584 scsiport.sys.mui
11/02/2006 05:38 AM 10,752 serial.sys.mui
11/02/2006 05:38 AM 5,632 sermouse.sys.mui
11/02/2006 05:38 AM 3,072 serscan.sys.mui
11/02/2006 05:39 AM 3,072 SISAGP.SYS.mui
11/02/2006 05:38 AM 3,072 srv.sys.mui
11/02/2006 05:39 AM 3,072 stcusb.sys.mui
01/20/2008 07:35 PM 5,120 tpm.sys.mui
11/02/2006 05:38 AM 3,072 UAGP35.SYS.mui
11/02/2006 05:39 AM 3,072 ULIAGPKX.SYS.mui
11/02/2006 05:38 AM 3,584 umbus.sys.mui
11/02/2006 05:39 AM 3,072 VIAAGP.SYS.mui
11/02/2006 05:38 AM 14,848 viac7.sys.mui
01/20/2008 07:35 PM 32,768 volsnap.sys.mui
11/02/2006 05:39 AM 4,608 wacompen.sys.mui
11/02/2006 05:38 AM 2,560 wd.sys.mui
07/14/2009 10:52 AM 2,560 wdf01000.sys.mui
11/02/2006 05:38 AM 5,632 yk60x86.sys.mui
83 File(s) 612,864 bytes

Directory of C:\Windows\System32\Drivers\etc

08/12/2011 12:18 AM .
08/12/2011 12:18 AM ..
08/12/2011 12:18 AM 27 hosts
09/18/2006 02:41 PM 3,683 lmhosts.sam
09/18/2006 02:41 PM 407 networks
09/18/2006 02:41 PM 1,358 protocol
09/18/2006 02:41 PM 17,244 services
5 File(s) 22,719 bytes

Directory of C:\Windows\System32\Drivers\UMDF

11/19/2009 10:14 AM .
11/19/2009 10:14 AM ..
11/19/2009 10:13 AM en-US
09/30/2009 06:01 PM 227,840 WpdFs.dll
04/10/2009 11:28 PM 664,576 WpdMtpDr.dll
2 File(s) 892,416 bytes

Directory of C:\Windows\System32\Drivers\UMDF\en-US

11/19/2009 10:13 AM .
11/19/2009 10:13 AM ..
09/30/2009 06:08 PM 3,072 wpdmtpdr.dll.mui
1 File(s) 3,072 bytes

Total Files Listed:
382 File(s) 40,023,370 bytes
14 Dir(s) 93,716,373,504 bytes free


***********************Hidden Drivers********************
Volume in drive C is OS
Volume Serial Number is FAD5-45CE

Directory of C:\Windows\System32\Drivers

05/11/2010 03:54 AM 0

MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
11/10/2009 04:40 AM 0

Msft_Kernel_LHidFilt_01005.Wdf
11/10/2009 04:40 AM 0

Msft_Kernel_LMouFilt_01005.Wdf
11/10/2009 04:40 AM 0

Msft_Kernel_LUsbFilt_01005.Wdf
05/11/2010 03:54 AM 0

Msft_Kernel_nnfwdk_01009.Wdf
11/09/2009 09:27 PM 0

Msft_User_WpdFs_01_00_00.Wdf
11/19/2009 10:12 AM 0

Msft_User_WpdFs_01_07_00.Wdf
08/22/2009 04:14 PM 0

Msft_User_WpdMtpDr_01_00_00.Wdf
8 File(s) 0 bytes
0 Dir(s) 93,716,381,696 bytes free


*********************Processes*******************


PROCESS PID PRIO PATH
smss.exe 348 Normal C:\Windows\System32

\smss.exe
csrss.exe 416 Normal C:\Windows\system32

\csrss.exe
csrss.exe 452 Normal C:\Windows\system32

\csrss.exe
wininit.exe 460 High C:\Windows\system32

\wininit.exe
winlogon.exe 488 High C:\Windows\system32

\winlogon.exe
services.exe 536 Normal C:\Windows\system32

\services.exe
lsass.exe 548 Normal C:\Windows\system32

\lsass.exe
lsm.exe 556 Normal C:\Windows\system32\lsm.exe
svchost.exe 712 Normal C:\Windows\system32

\svchost.exe
svchost.exe 772 Normal C:\Windows\system32

\svchost.exe
svchost.exe 860 Normal C:\Windows\System32

\svchost.exe
svchost.exe 884 Normal C:\Windows\system32

\svchost.exe
svchost.exe 908 Normal C:\Windows\System32

\svchost.exe
svchost.exe 956 Normal C:\Windows\system32

\svchost.exe
svchost.exe 976 Normal C:\Windows\system32

\svchost.exe
svchost.exe 1052 Normal C:\Windows\system32

\svchost.exe
svchost.exe 1232 Normal C:\Windows\system32

\svchost.exe
Explorer.EXE 1600 Normal C:\Windows\Explorer.EXE
unsecapp.exe 404 Normal C:\Windows\system32

\wbem\unsecapp.exe
wmiprvse.exe 984 Normal C:\Windows\system32

\wbem\wmiprvse.exe
cmd.exe 1648 Normal C:\Windows\system32\cmd.exe
processes.exe 220 Normal

C:\Users\dummy\Desktop\SpiderKill\SpiderKill\processes.exe


*********************Modules of explorer.exe and

svchost.exe*******************
Module information for 'Explorer.EXE'(1600)
MODULE BASE SIZE PATH
Explorer.EXE 510000 2936832 C:\Windows\Explorer.EXE

6.0.6000.16386 (vista_rtm.061101-2205) Windows

Explorer
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
SHLWAPI.dll 77360000 364544 C:\Windows\system32

\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Light-weight Utility Library
SHELL32.dll 764b0000 11599872 C:\Windows\system32

\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Shell Common Dll
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
SHDOCVW.dll 73850000 1081344 C:\Windows\system32

\SHDOCVW.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Doc Object and Control Library
UxTheme.dll 74b30000 258048 C:\Windows\system32

\UxTheme.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft UxTheme Library
POWRPROF.dll 74f30000 106496 C:\Windows\system32

\POWRPROF.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Power Profile Helper DLL
dwmapi.dll 73f20000 49152 C:\Windows\system32

\dwmapi.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft Desktop Window Manager API
gdiplus.dll 741e0000 1748992

C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf

1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll

5.2.6002.18005 (lh_sp2rtm.090410-1830) Microsoft GDI+
slc.dll 75290000 237568 C:\Windows\system32\slc.dll

6.0.6002.18005 (lh_sp2rtm.090410-1830) Software

Licensing Client Dll
PROPSYS.dll 74120000 765952 C:\Windows\system32

\PROPSYS.dll 7.00.6002.18005 (lh_sp2rtm.090410-

1830) Microsoft Property System
BROWSEUI.dll 73700000 1335296 C:\Windows\system32

\BROWSEUI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Browser UI Library
IMM32.dll 75f10000 122880 C:\Windows\system32

\IMM32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
DUser.dll 74aa0000 196608 C:\Windows\system32

\DUser.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows DirectUser Engine
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
comctl32.dll 74830000 1695744

C:\Windows\WinSxS\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de

0\comctl32.dll 5.82 (longhorn_rtm.080118-1840) Common

Controls Library
WindowsCodecs.dll 73600000 999424 C:\Windows\system32

\WindowsCodecs.dll 7.0.6002.18107

(vistasp2_gdr_win7ip_dgt(wmbla).090924-1550) Microsoft

Windows Codecs Library
apphelp.dll 73bb0000 180224 C:\Windows\system32

\apphelp.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Application Compatibility Client Library
CLBCatQ.DLL 772d0000 540672 C:\Windows\system32

\CLBCatQ.DLL 2001.12.6931.18000

(longhorn_rtm.080118-1840) COM+ Configuration Catalog
EhStorShell.dll 73580000 126976 C:\Windows\system32

\EhStorShell.dll 5.2.3790.1830 Windows Enhanced

Storage Shell Extension
IconCodecService.dll 735e0000 24576 C:\Windows\system32

\IconCodecService.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Converts a PNG part of the icon to a legacy bmp icon
rsaenh.dll 74e70000 241664 C:\Windows\system32

\rsaenh.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft Enhanced Cryptographic Provider
timedate.cpl 733c0000 729088 C:\Windows\system32

\timedate.cpl 6.0.6001.18000 (longhorn_rtm.080118-

1840) Time Date Control Panel Applet
ATL.DLL 74b10000 81920 C:\Windows\system32\ATL.DLL

3.05.2284 ATL Module for Windows XP

(Unicode)
NETAPI32.dll 75520000 483328 C:\Windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
OLEACC.dll 73f80000 249856 C:\Windows\system32

\OLEACC.dll 7.0.6002.18155

(vistasp2_gdr_win7ip_uia(wmbla).091008-1406) Active

Accessibility Core Component
WINBRAND.dll 74d90000 880640 C:\Windows\system32

\WINBRAND.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Branding Resources
USERENV.dll 75890000 122880 C:\Windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
Secur32.dll 75870000 81920 C:\Windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
shacct.dll 74390000 90112 C:\Windows\System32

\shacct.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Shell Accounts Classes
SAMLIB.dll 75490000 69632 C:\Windows\System32

\SAMLIB.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

SAM Library DLL
msshsq.dll 73350000 245760 C:\Windows\System32

\msshsq.dll 7.00.6002.18005 (lh_sp2rtm.090410-

1830) Structured Query
NaturalLanguage6.dll 731b0000 815104 C:\Windows\System32

\NaturalLanguage6.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Natural Language Development Platform 6
CRYPT32.dll 752f0000 991232 C:\Windows\System32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 C:\Windows\System32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
NLSData0009.dll 72790000 4886528 C:\Windows\System32

\NLSData0009.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft English Natural Language Server Data and Code
NLSLexicons0009.dll 72500000 2650112 C:\Windows\System32

\NLSLexicons0009.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft English Natural Language Server Data and Code
authui.dll 74540000 1998848 C:\Windows\system32

\authui.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Authentication UI
MSIMG32.dll 74d00000 20480 C:\Windows\system32

\MSIMG32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

GDIEXT Client DLL
LINKINFO.dll 749d0000 36864 C:\Windows\system32

\LINKINFO.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Volume Tracking
ieframe.dll 71f30000 6094848 C:\Windows\system32

\ieframe.dll 7.00.6000.16386 (vista_rtm.061101-

2205) Internet Explorer
iertutil.dll 759e0000 282624 C:\Windows\system32

\iertutil.dll 7.00.6002.18005 (lh_sp2rtm.090410-

1830) Run time utility for Internet Explorer
WININET.dll 75f30000 856064 C:\Windows\system32

\WININET.dll 7.00.6000.16386 (vista_rtm.061101-

2205) Internet Extensions for Win32
Normaliz.dll 773c0000 12288 C:\Windows\system32

\Normaliz.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Unicode Normalization DLL
WINMM.dll 73fc0000 204800 C:\Windows\system32

\WINMM.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MCI API DLL
wdmaud.drv 73320000 192512 C:\Windows\system32

\wdmaud.drv 6.0.6000.16386 (vista_rtm.061101-2205)

Winmm audio system driver
ksuser.dll 740f0000 16384 C:\Windows\system32

\ksuser.dll 6.0.6000.16386 (vista_rtm.061101-2205)

User CSA Library
MMDevAPI.DLL 732f0000 163840 C:\Windows\system32

\MMDevAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

MMDevice API
AVRT.dll 74500000 28672 C:\Windows\system32

\AVRT.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multimedia Realtime Runtime
ExplorerFrame.dll 744f0000 36864 C:\Windows\system32

\ExplorerFrame.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

ExplorerFrame
urlmon.dll 76380000 1220608 C:\Windows\system32

\urlmon.dll 7.00.6001.18000 (longhorn_rtm.080118-

1840) OLE32 Extensions for Win32
stobject.dll 73050000 598016 C:\Windows\system32

\stobject.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Systray shell service object
BatMeter.dll 72f90000 745472 C:\Windows\system32

\BatMeter.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Battery Meter Helper DLL
SETUPAPI.dll 76140000 1613824 C:\Windows\system32

\SETUPAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Setup API
WTSAPI32.dll 74c00000 40960 C:\Windows\system32

\WTSAPI32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Terminal Server SDK APIs
WINSTA.dll 75840000 151552 C:\Windows\system32

\WINSTA.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Winstation Library
FunctionDiscoveryFolder.dll 71d20000 2146304

C:\Windows\system32\FunctionDiscoveryFolder.dll

6.0.6002.18005 (lh_sp2rtm.090410-1830) Function Discovery

Folder
bthprops.cpl 72ee0000 667648 C:\Windows\system32

\bthprops.cpl 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Bluetooth Control Panel Applet
NTMARTA.DLL 74d10000 135168 C:\Windows\system32

\NTMARTA.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Windows NT MARTA provider
WLDAP32.dll 760f0000 299008 C:\Windows\system32

\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Win32 LDAP API DLL
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
ntshrui.dll 732a0000 303104 C:\Windows\system32

\ntshrui.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell extensions for sharing
cscapi.dll 744e0000 45056 C:\Windows\system32

\cscapi.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Offline Files Win32 API
es.dll 73110000 286720 C:\Windows\system32\es.dll

2001.12.6932.18005 (lh_sp2rtm.090410-1830) COM+
SndVolSSO.dll 72e80000 196608 C:\Windows\System32

\SndVolSSO.dll 6.0.6000.16386 (vista_rtm.061101-2205)

SCA Volume
msiltcfg.dll 744d0000 28672 C:\Windows\system32

\msiltcfg.dll 4.0.6000.16386 (vista_rtm.061101-2205)

Windows Installer Configuration API Stub
VERSION.dll 751c0000 32768 C:\Windows\system32

\VERSION.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Version Checking and File Installation Libraries
msi.dll 72c50000 2256896 C:\Windows\system32\msi.dll

4.5.6002.18005 Windows Installer
netshell.dll 71620000 3190784 C:\Windows\System32

\netshell.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network Connections Shell
IPHLPAPI.DLL 753f0000 102400 C:\Windows\System32

\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

IP Helper API
dhcpcsvc.DLL 75210000 217088 C:\Windows\System32

\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCP Client Service
DNSAPI.dll 754b0000 180224 C:\Windows\System32

\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Client API DLL
WINNSI.DLL 752e0000 28672 C:\Windows\System32

\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Store Information RPC interface
dhcpcsvc6.DLL 751e0000 139264 C:\Windows\System32

\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCPv6 Client
nlaapi.dll 74c10000 61440 C:\Windows\System32

\nlaapi.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Location Awareness 2
pnidui.dll 71a80000 1830912 C:\Windows\system32

\pnidui.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network System Icon
QUtil.dll 73280000 94208 C:\Windows\system32

\QUtil.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Quarantine Utilities
wevtapi.dll 75250000 262144 C:\Windows\system32

\wevtapi.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Eventing Consumption and Configuration API
wlanutil.dll 744c0000 24576 C:\Windows\system32

\wlanutil.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Wireless LAN 802.11 Utility DLL
igfxsrvc.dll 2f60000 69632 C:\Windows\system32

\igfxsrvc.dll 7.14.10.1437 igfxsrvc Module
WINTRUST.dll 74a00000 184320 C:\Windows\system32

\WINTRUST.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft Trust Verification APIs
imagehlp.dll 75e50000 167936 C:\Windows\system32

\imagehlp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT Image Helper
npmproxy.dll 73ee0000 32768 C:\Windows\System32

\npmproxy.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network List Manager Proxy
Wlanapi.dll 710c0000 73728 C:\Windows\system32

\Wlanapi.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows WLAN AutoConfig Client Side API DLL
OneX.DLL 708d0000 1556480 C:\Windows\system32

\OneX.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) IEEE 802.1X supplicant library
eappprxy.dll 73980000 57344 C:\Windows\system32

\eappprxy.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft EAPHost Peer Client DLL
eappcfg.dll 71090000 147456 C:\Windows\system32

\eappcfg.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Eap Peer Config
bcrypt.dll 750f0000 282624 C:\Windows\system32

\bcrypt.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows Cryptographic Primitives Library
AltTab.dll 735f0000 53248 C:\Windows\System32

\AltTab.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Shell Alt Tab
wpdshserviceobj.dll 70fe0000 102400 C:\Windows\system32

\wpdshserviceobj.dll 6.0.6002.18112

(vistasp2_gdr_win7ip_wpd(wmbla).090930-1800) Windows Portable

Device Shell Service Object
PortableDeviceTypes.dll 708a0000 176128

C:\Windows\system32\PortableDeviceTypes.dll 6.0.6002.18112

(vistasp2_gdr_win7ip_wpd(wmbla).090930-1800) Windows Portable

Device (Parameter) Types Component
PortableDeviceApi.dll 70760000 352256 C:\Windows\system32

\PortableDeviceApi.dll 6.0.6002.18112

(vistasp2_gdr_win7ip_wpd(wmbla).090930-1800) Windows Portable

Device API Components
SXS.DLL 75780000 389120 C:\Windows\system32\SXS.DLL

6.0.6000.16386 (vista_rtm.061101-2205) Fusion

2.5
taskschd.dll 706c0000 368640 C:\Windows\system32

\taskschd.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Task Scheduler COM API
XmlLite.dll 74510000 192512 C:\Windows\system32

\XmlLite.dll 1.2.1009.0 Microsoft XmlLite

Library
mstask.dll 70680000 212992 C:\Windows\System32

\mstask.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Task Scheduler interface DLL
NTDSAPI.dll 75450000 98304 C:\Windows\System32

\NTDSAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Active Directory Domain Services API
COMDLG32.dll 75dd0000 471040 C:\Windows\system32

\COMDLG32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Common Dialogs DLL
srchadmin.dll 70570000 315392 C:\Windows\System32

\srchadmin.dll 7.00.6002.18005 (lh_sp2rtm.090410-

1830) Indexing Options
webcheck.dll 70640000 245760 C:\Windows\system32

\webcheck.dll 7.00.6000.16386 (vista_rtm.061101-

2205) Web Site Monitor
SyncCenter.dll 6fef0000 2211840 C:\Windows\System32

\SyncCenter.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Sync Center
QAgent.dll 70840000 188416 C:\Windows\System32

\QAgent.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Quarantine Agent Proxy
fwpuclnt.dll 743b0000 614400 C:\Windows\System32

\fwpuclnt.dll 6.0.6000.16386 (vista_rtm.061101-2205)

FWP/IPsec User-Mode API
imapi2.dll 704b0000 393216 C:\Windows\system32

\imapi2.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Image Mastering API v2
wbemprox.dll 71930000 45056 C:\Windows\system32

\wbem\wbemprox.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI
wbemcomn.dll 73be0000 372736 C:\Windows\system32

\wbemcomn.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) WMI
wbemsvc.dll 71080000 65536 C:\Windows\system32

\wbem\wbemsvc.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI
fastprox.dll 70130000 626688 C:\Windows\system32

\wbem\fastprox.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI Custom Marshaller
MLANG.dll 71580000 196608 C:\Windows\system32

\MLANG.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Multi Language Support DLL
actxprxy.dll 734c0000 339968 C:\Windows\System32

\actxprxy.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) ActiveX Interface Marshaling Library
UnlockerCOM.dll 10000000 28672 C:\Program

Files\Unlocker\UnlockerCOM.dll
mbamext.dll 739b0000 94208 C:\Program

Files\Malwarebytes' Anti-Malware\mbamext.dll 1.50.1.0000

Malwarebytes' Anti-Malware
SASCTXMN.DLL 26c0000 61440 C:\Program

Files\SUPERAntiSpyware\SASCTXMN.DLL 1, 0, 0, 1004

SUPERAntiSpyware Context Menu Extension
IS360Ext.dll 26d0000 36864 C:\Program

Files\IObit\IObit Security 360\IS360Ext.dll 1, 0, 1, 0

IS360Ext
syncui.dll 73550000 188416 C:\Windows\system32

\syncui.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Briefcase
SYNCENG.dll 739d0000 90112 C:\Windows\system32

\SYNCENG.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Briefcase Engine
ASCv4ExtMenu.dll 28a0000 143360 C:\Program

Files\IObit\Advanced SystemCare 4\ASCv4ExtMenu.dll 1, 0, 1,

1 ASCv4ExtMenu Module
7-zip.dll 2c90000 81920 C:\Program Files\7-Zip\7-

zip.dll 4.65 7-Zip Shell Extension
MPR.dll 75430000 81920 C:\Windows\system32\MPR.dll

6.0.6000.16386 (vista_rtm.061101-2205) Multiple

Provider Router DLL
ntlanman.dll 715c0000 77824 C:\Windows\System32

\ntlanman.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft® Lan Manager
drprov.dll 72c40000 32768 C:\Windows\System32

\drprov.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Terminal Server Network Provider
davclnt.dll 71560000 73728 C:\Windows\System32

\davclnt.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Web DAV Client DLL
zipfldr.dll 71190000 356352 C:\Windows\system32

\zipfldr.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Compressed (zipped) Folders
thumbcache.dll 71370000 90112 C:\Windows\system32

\thumbcache.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Thumbnail Cache

Module information for 'svchost.exe'(712)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\system32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
umpnpmgr.dll 74c90000 233472 c:\windows\system32

\umpnpmgr.dll 6.0.6000.16386 (vista_rtm.061101-2205)

User-mode Plug-and-Play Service
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
USERENV.dll 75890000 122880 c:\windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
Secur32.dll 75870000 81920 c:\windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
POWRPROF.dll 74f30000 106496 C:\Windows\system32

\POWRPROF.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Power Profile Helper DLL
GPAPI.dll 74d70000 86016 C:\Windows\system32

\GPAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Group Policy Client API
slc.dll 75290000 237568 C:\Windows\system32\slc.dll

6.0.6002.18005 (lh_sp2rtm.090410-1830) Software

Licensing Client Dll
rpcss.dll 74b70000 565248 c:\windows\system32

\rpcss.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Distributed COM Services
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
FirewallAPI.dll 74c20000 417792 c:\windows\system32

\FirewallAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Firewall API
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
VERSION.dll 751c0000 32768 c:\windows\system32

\VERSION.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Version Checking and File Installation Libraries
CRYPT32.dll 752f0000 991232 C:\Windows\system32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 C:\Windows\system32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
credssp.dll 751d0000 28672 C:\Windows\system32

\credssp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) TS Single Sign On Security Package
schannel.dll 74ee0000 282624 C:\Windows\system32

\schannel.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) TLS / SSL Security Provider
NETAPI32.dll 75520000 483328 C:\Windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
SETUPAPI.dll 76140000 1613824 C:\Windows\system32

\SETUPAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Setup API
CLBCatQ.DLL 772d0000 540672 C:\Windows\system32

\CLBCatQ.DLL 2001.12.6931.18000

(longhorn_rtm.080118-1840) COM+ Configuration Catalog
Cabinet.dll 73c80000 86016 C:\Windows\system32

\Cabinet.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft® Cabinet File API
WINSTA.dll 75840000 151552 C:\Windows\system32

\WINSTA.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Winstation Library
NTMARTA.DLL 74d10000 135168 C:\Windows\system32

\NTMARTA.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Windows NT MARTA provider
WLDAP32.dll 760f0000 299008 C:\Windows\system32

\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Win32 LDAP API DLL
SAMLIB.dll 75490000 69632 C:\Windows\system32

\SAMLIB.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

SAM Library DLL
WTSAPI32.dll 74c00000 40960 C:\Windows\system32

\WTSAPI32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Terminal Server SDK APIs
Module information for 'svchost.exe'(772)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\system32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
rpcss.dll 74b70000 565248 c:\windows\system32

\rpcss.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Distributed COM Services
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
Secur32.dll 75870000 81920 c:\windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
FirewallAPI.dll 74c20000 417792 c:\windows\system32

\FirewallAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Firewall API
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
VERSION.dll 751c0000 32768 c:\windows\system32

\VERSION.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Version Checking and File Installation Libraries
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
CRYPT32.dll 752f0000 991232 C:\Windows\system32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 C:\Windows\system32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
USERENV.dll 75890000 122880 C:\Windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
credssp.dll 751d0000 28672 C:\Windows\system32

\credssp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) TS Single Sign On Security Package
schannel.dll 74ee0000 282624 C:\Windows\system32

\schannel.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) TLS / SSL Security Provider
NETAPI32.dll 75520000 483328 C:\Windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
rsaenh.dll 74e70000 241664 C:\Windows\system32

\rsaenh.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft Enhanced Cryptographic Provider
wpclsp.dll 74cd0000 81920 C:\Windows\system32

\wpclsp.dll 1.0.0.1 WPC LSP
SHELL32.dll 764b0000 11599872 C:\Windows\system32

\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Shell Common Dll
SHLWAPI.dll 77360000 364544 C:\Windows\system32

\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Light-weight Utility Library
comctl32.dll 74830000 1695744

C:\Windows\WinSxS\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de

0\comctl32.dll 5.82 (longhorn_rtm.080118-1840) Common

Controls Library
mswsock.dll 74ff0000 241664 C:\Windows\system32

\mswsock.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Windows Sockets 2.0 Service Provider
wshtcpip.dll 74cf0000 20480 C:\Windows\System32

\wshtcpip.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv4)
wship6.dll 751a0000 20480 C:\Windows\System32

\wship6.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv6)
fwpuclnt.dll 743b0000 614400 C:\Windows\system32

\fwpuclnt.dll 6.0.6000.16386 (vista_rtm.061101-2205)

FWP/IPsec User-Mode API
CLBCatQ.DLL 772d0000 540672 C:\Windows\system32

\CLBCatQ.DLL 2001.12.6931.18000

(longhorn_rtm.080118-1840) COM+ Configuration Catalog
Module information for 'svchost.exe'(860)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\System32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
wevtsvc.dll 74730000 1032192 c:\windows\system32

\wevtsvc.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Event Logging Service
USERENV.dll 75890000 122880 c:\windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
Secur32.dll 75870000 81920 c:\windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
VERSION.dll 751c0000 32768 c:\windows\system32

\VERSION.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Version Checking and File Installation Libraries
GPAPI.dll 74d70000 86016 c:\windows\system32

\GPAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Group Policy Client API
slc.dll 75290000 237568 c:\windows\system32\slc.dll

6.0.6002.18005 (lh_sp2rtm.090410-1830) Software

Licensing Client Dll
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
CRYPT32.dll 752f0000 991232 C:\Windows\System32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 C:\Windows\System32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
credssp.dll 751d0000 28672 C:\Windows\System32

\credssp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) TS Single Sign On Security Package
schannel.dll 74ee0000 282624 C:\Windows\system32

\schannel.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) TLS / SSL Security Provider
NETAPI32.dll 75520000 483328 C:\Windows\System32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
mswsock.dll 74ff0000 241664 C:\Windows\system32

\mswsock.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Windows Sockets 2.0 Service Provider

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Sun Oct 02, 2011 9:45 pm

wshtcpip.dll 74cf0000 20480 C:\Windows\System32

\wshtcpip.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv4)
wship6.dll 751a0000 20480 C:\Windows\System32

\wship6.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv6)
lmhsvc.dll 74b00000 32768 c:\windows\system32

\lmhsvc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

TCPIP NetBios Transport Services DLL
IPHLPAPI.DLL 753f0000 102400 c:\windows\system32

\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

IP Helper API
dhcpcsvc.DLL 75210000 217088 c:\windows\system32

\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCP Client Service
DNSAPI.dll 754b0000 180224 c:\windows\system32

\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Client API DLL
WINNSI.DLL 752e0000 28672 c:\windows\system32

\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Store Information RPC interface
dhcpcsvc6.DLL 751e0000 139264 c:\windows\system32

\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCPv6 Client
Module information for 'svchost.exe'(884)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\system32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
NTMARTA.DLL 74d10000 135168 C:\Windows\system32

\NTMARTA.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Windows NT MARTA provider
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
WLDAP32.dll 760f0000 299008 C:\Windows\system32

\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Win32 LDAP API DLL
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
SAMLIB.dll 75490000 69632 C:\Windows\system32

\SAMLIB.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

SAM Library DLL
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
profsvc.dll 74ad0000 167936 c:\windows\system32

\profsvc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

ProfSvc
SYSNTFY.dll 757e0000 28672 c:\windows\system32

\SYSNTFY.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Notifications Dynamic Link Library
USERENV.dll 75890000 122880 c:\windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
Secur32.dll 75870000 81920 c:\windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
nlaapi.dll 74c10000 61440 c:\windows\system32

\nlaapi.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Location Awareness 2
IPHLPAPI.DLL 753f0000 102400 c:\windows\system32

\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

IP Helper API
dhcpcsvc.DLL 75210000 217088 c:\windows\system32

\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCP Client Service
DNSAPI.dll 754b0000 180224 c:\windows\system32

\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Client API DLL
WINNSI.DLL 752e0000 28672 c:\windows\system32

\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Store Information RPC interface
dhcpcsvc6.DLL 751e0000 139264 c:\windows\system32

\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCPv6 Client
ATL.DLL 74b10000 81920 c:\windows\system32\ATL.DLL

3.05.2284 ATL Module for Windows XP

(Unicode)
ikeext.dll 73e70000 454656 c:\windows\system32

\ikeext.dll 6.0.6000.16386 (vista_rtm.061101-2205)

IKE extension
AUTHZ.dll 75620000 90112 c:\windows\system32

\AUTHZ.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Authorization Framework
fwpuclnt.dll 743b0000 614400 c:\windows\system32

\fwpuclnt.dll 6.0.6000.16386 (vista_rtm.061101-2205)

FWP/IPsec User-Mode API
ncrypt.dll 75140000 217088 C:\Windows\system32

\ncrypt.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows cryptographic library
CRYPT32.dll 752f0000 991232 C:\Windows\system32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 C:\Windows\system32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
BCRYPT.dll 750f0000 282624 C:\Windows\system32

\BCRYPT.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows Cryptographic Primitives Library
mswsock.dll 74ff0000 241664 C:\Windows\system32

\mswsock.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Windows Sockets 2.0 Service Provider
wshtcpip.dll 74cf0000 20480 C:\Windows\System32

\wshtcpip.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv4)
wship6.dll 751a0000 20480 C:\Windows\System32

\wship6.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv6)
wpclsp.dll 74cd0000 81920 C:\Windows\system32

\wpclsp.dll 1.0.0.1 WPC LSP
NETAPI32.dll 75520000 483328 C:\Windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
SHELL32.dll 764b0000 11599872 C:\Windows\system32

\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Shell Common Dll
SHLWAPI.dll 77360000 364544 C:\Windows\system32

\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Light-weight Utility Library
comctl32.dll 74830000 1695744

C:\Windows\WinSxS\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de

0\comctl32.dll 5.82 (longhorn_rtm.080118-1840) Common

Controls Library
rsaenh.dll 74e70000 241664 C:\Windows\system32

\rsaenh.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft Enhanced Cryptographic Provider
wmisvc.dll 73c40000 172032 c:\windows\system32

\wbem\wmisvc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

WMI
wbemcomn.dll 73be0000 372736 C:\Windows\system32

\wbemcomn.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) WMI
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
CLBCatQ.DLL 772d0000 540672 C:\Windows\system32

\CLBCatQ.DLL 2001.12.6931.18000

(longhorn_rtm.080118-1840) COM+ Configuration Catalog
VSSAPI.DLL 73d00000 1093632 C:\Windows\system32

\VSSAPI.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft® Volume Shadow Copy Requestor/Writer Services API

DLL
vsstrace.dll 74100000 81920 C:\Windows\system32

\vsstrace.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft® Volume Shadow Copy Requestor/Writer tracing

DLL
XmlLite.dll 74510000 192512 C:\Windows\system32

\XmlLite.dll 1.2.1009.0 Microsoft XmlLite

Library
MPR.dll 75430000 81920 C:\Windows\system32\MPR.dll

6.0.6000.16386 (vista_rtm.061101-2205) Multiple

Provider Router DLL
SETUPAPI.dll 76140000 1613824 C:\Windows\system32

\SETUPAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Setup API
wbemcore.dll 6fcd0000 757760 C:\Windows\system32

\wbem\wbemcore.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Management Instrumentation
esscli.dll 70520000 274432 C:\Windows\system32

\wbem\esscli.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI
FastProx.dll 70130000 626688 C:\Windows\system32

\wbem\FastProx.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI Custom Marshaller
NTDSAPI.dll 75450000 98304 C:\Windows\system32

\NTDSAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Active Directory Domain Services API
wbemsvc.dll 71080000 65536 C:\Windows\system32

\wbem\wbemsvc.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI
wmiutils.dll 73190000 94208 C:\Windows\system32

\wbem\wmiutils.dll 6.0.6000.16386 (vista_rtm.061101-2205)

WMI
repdrvfs.dll 719e0000 278528 C:\Windows\system32

\wbem\repdrvfs.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI Repository Driver
wmiprvsd.dll 71000000 512000 C:\Windows\system32

\wbem\wmiprvsd.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI
NCObjAPI.DLL 754e0000 61440 C:\Windows\system32

\NCObjAPI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840)
wbemess.dll 71980000 356352 C:\Windows\system32

\wbem\wbemess.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

WMI
ncprov.dll 73990000 65536 C:\Windows\system32

\wbem\ncprov.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Non-COM WMI Event Provision APIs
wbemcons.dll 73970000 65536 C:\Windows\system32

\wbem\wbemcons.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) WMI Standard Event Consumers
WTSAPI32.dll 74c00000 40960 C:\Windows\system32

\WTSAPI32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Terminal Server SDK APIs
Module information for 'svchost.exe'(908)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\System32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
NTMARTA.DLL 74d10000 135168 C:\Windows\System32

\NTMARTA.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Windows NT MARTA provider
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
WLDAP32.dll 760f0000 299008 C:\Windows\system32

\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Win32 LDAP API DLL
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
SAMLIB.dll 75490000 69632 C:\Windows\System32

\SAMLIB.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

SAM Library DLL
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
USERENV.dll 75890000 122880 c:\windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
Secur32.dll 75870000 81920 c:\windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
SETUPAPI.dll 76140000 1613824 C:\Windows\system32

\SETUPAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Setup API
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
wudfsvc.dll 74a80000 65536 c:\windows\system32

\wudfsvc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Driver Foundation - User-mode Driver Framework

Service
WUDFPlatform.dll 74a30000 196608 c:\windows\system32

\WUDFPlatform.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Driver Foundation - User-mode Platform Library
VERSION.dll 751c0000 32768 c:\windows\system32

\VERSION.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Version Checking and File Installation Libraries
wevtapi.dll 75250000 262144 c:\windows\system32

\wevtapi.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Eventing Consumption and Configuration API
WINTRUST.dll 74a00000 184320 C:\Windows\System32

\WINTRUST.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft Trust Verification APIs
CRYPT32.dll 752f0000 991232 C:\Windows\System32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 C:\Windows\System32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
imagehlp.dll 75e50000 167936 C:\Windows\system32

\imagehlp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT Image Helper
netman.dll 71a30000 286720 c:\windows\system32

\netman.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network Connections Manager
RASAPI32.dll 71cd0000 303104 c:\windows\system32

\RASAPI32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Remote Access API
rasman.dll 71cb0000 81920 c:\windows\system32

\rasman.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Access Connection Manager
NETAPI32.dll 75520000 483328 c:\windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
TAPI32.dll 715e0000 200704 c:\windows\system32

\TAPI32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft® Windows(TM) Telephony API Client DLL
SHLWAPI.dll 77360000 364544 C:\Windows\system32

\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Light-weight Utility Library
rtutils.dll 73960000 49152 c:\windows\system32

\rtutils.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Routing Utilities
WINMM.dll 73fc0000 204800 c:\windows\system32

\WINMM.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MCI API DLL
OLEACC.dll 73f80000 249856 c:\windows\system32

\OLEACC.dll 7.0.6002.18155

(vistasp2_gdr_win7ip_uia(wmbla).091008-1406) Active

Accessibility Core Component
SHELL32.dll 764b0000 11599872 C:\Windows\system32

\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Shell Common Dll
WINNSI.DLL 752e0000 28672 c:\windows\system32

\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Store Information RPC interface
comctl32.dll 74830000 1695744

C:\Windows\WinSxS\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de

0\comctl32.dll 5.82 (longhorn_rtm.080118-1840) Common

Controls Library
CLBCatQ.DLL 772d0000 540672 C:\Windows\system32

\CLBCatQ.DLL 2001.12.6931.18000

(longhorn_rtm.080118-1840) COM+ Configuration Catalog
rsaenh.dll 74e70000 241664 C:\Windows\System32

\rsaenh.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft Enhanced Cryptographic Provider
netshell.dll 71620000 3190784 C:\Windows\System32

\netshell.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network Connections Shell
IPHLPAPI.DLL 753f0000 102400 C:\Windows\System32

\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

IP Helper API
dhcpcsvc.DLL 75210000 217088 C:\Windows\System32

\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCP Client Service
DNSAPI.dll 754b0000 180224 C:\Windows\System32

\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Client API DLL
dhcpcsvc6.DLL 751e0000 139264 C:\Windows\System32

\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCPv6 Client
nlaapi.dll 74c10000 61440 C:\Windows\System32

\nlaapi.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Location Awareness 2
RASDLG.dll 71480000 843776 C:\Windows\System32

\RASDLG.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Access Common Dialog API
MPRAPI.dll 71160000 106496 C:\Windows\System32

\MPRAPI.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT MP Router Administration DLL
ACTIVEDS.dll 71120000 217088 C:\Windows\System32

\ACTIVEDS.dll 6.0.6000.16386 (vista_rtm.061101-2205)

ADs Router Layer DLL
adsldpc.dll 710e0000 208896 C:\Windows\System32

\adsldpc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

ADs LDAP Provider C DLL
credui.dll 73390000 188416 C:\Windows\System32

\credui.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Credential Manager User Interface
ATL.DLL 74b10000 81920 C:\Windows\System32\ATL.DLL

3.05.2284 ATL Module for Windows XP

(Unicode)
slc.dll 75290000 237568 C:\Windows\System32\slc.dll

6.0.6002.18005 (lh_sp2rtm.090410-1830) Software

Licensing Client Dll
Module information for 'svchost.exe'(956)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\system32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
NTMARTA.DLL 74d10000 135168 C:\Windows\system32

\NTMARTA.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Windows NT MARTA provider
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
WLDAP32.dll 760f0000 299008 C:\Windows\system32

\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Win32 LDAP API DLL
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
SAMLIB.dll 75490000 69632 C:\Windows\system32

\SAMLIB.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

SAM Library DLL
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
dnsrslvr.dll 749e0000 98304 c:\windows\system32

\dnsrslvr.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Caching Resolver Service
DNSAPI.dll 754b0000 180224 c:\windows\system32

\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Client API DLL
dhcpcsvc.DLL 75210000 217088 c:\windows\system32

\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCP Client Service
Secur32.dll 75870000 81920 c:\windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
WINNSI.DLL 752e0000 28672 c:\windows\system32

\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Store Information RPC interface
dhcpcsvc6.DLL 751e0000 139264 c:\windows\system32

\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCPv6 Client
IPHLPAPI.DLL 753f0000 102400 c:\windows\system32

\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

IP Helper API
mswsock.dll 74ff0000 241664 C:\Windows\system32

\mswsock.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Windows Sockets 2.0 Service Provider
wship6.dll 751a0000 20480 C:\Windows\System32

\wship6.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv6)
wshtcpip.dll 74cf0000 20480 C:\Windows\System32

\wshtcpip.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv4)
cryptsvc.dll 73f50000 139264 c:\windows\system32

\cryptsvc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Cryptographic Services
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
VSSAPI.DLL 73d00000 1093632 c:\windows\system32

\VSSAPI.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft® Volume Shadow Copy Requestor/Writer Services API

DLL
ATL.DLL 74b10000 81920 c:\windows\system32\ATL.DLL

3.05.2284 ATL Module for Windows XP

(Unicode)
vsstrace.dll 74100000 81920 c:\windows\system32

\vsstrace.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft® Volume Shadow Copy Requestor/Writer tracing

DLL
AUTHZ.dll 75620000 90112 c:\windows\system32

\AUTHZ.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Authorization Framework
XmlLite.dll 74510000 192512 c:\windows\system32

\XmlLite.dll 1.2.1009.0 Microsoft XmlLite

Library
NETAPI32.dll 75520000 483328 c:\windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
MPR.dll 75430000 81920 c:\windows\system32\MPR.dll

6.0.6000.16386 (vista_rtm.061101-2205) Multiple

Provider Router DLL
SETUPAPI.dll 76140000 1613824 C:\Windows\system32

\SETUPAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Setup API
CRYPT32.dll 752f0000 991232 c:\windows\system32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 c:\windows\system32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
USERENV.dll 75890000 122880 c:\windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
nlasvc.dll 73ef0000 176128 c:\windows\system32

\nlasvc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network Location Awareness 2
wevtapi.dll 75250000 262144 c:\windows\system32

\wevtapi.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Eventing Consumption and Configuration API
ncsi.dll 73f30000 106496 c:\windows\system32

\ncsi.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Connectivity Status Indicator
WINHTTP.dll 73ca0000 393216 c:\windows\system32

\WINHTTP.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows HTTP Services
SHLWAPI.dll 77360000 364544 C:\Windows\system32

\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Light-weight Utility Library
WTSAPI32.dll 74c00000 40960 c:\windows\system32

\WTSAPI32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Terminal Server SDK APIs
bcrypt.dll 750f0000 282624 c:\windows\system32

\bcrypt.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows Cryptographic Primitives Library
CFGMGR32.dll 744b0000 32768 c:\windows\system32

\CFGMGR32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Configuration Manager Forwarder DLL
comctl32.dll 74830000 1695744

C:\Windows\WinSxS\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de

0\comctl32.dll 5.82 (longhorn_rtm.080118-1840) Common

Controls Library
credssp.dll 751d0000 28672 C:\Windows\system32

\credssp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) TS Single Sign On Security Package
schannel.dll 74ee0000 282624 C:\Windows\system32

\schannel.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) TLS / SSL Security Provider
ssdpapi.dll 740b0000 49152 C:\Windows\system32

\ssdpapi.dll 6.0.6000.16386 (vista_rtm.061101-2205)

SSDP Client API DLL
WINSTA.dll 75840000 151552 C:\Windows\system32

\WINSTA.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Winstation Library
ESENT.dll 739f0000 1474560 C:\Windows\system32

\ESENT.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Extensible Storage Engine for Microsoft(R) Windows(R)
pnrpnsp.dll 730f0000 73728 C:\Windows\system32

\pnrpnsp.dll 6.0.6000.16386 (vista_rtm.061101-2205)

PNRP Name Space Provider
winrnr.dll 73ba0000 32768 C:\Windows\System32

\winrnr.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

LDAP RnR Provider DLL
mdnsNSP.dll 735a0000 151552 C:\Program

Files\Bonjour\mdnsNSP.dll 2.0.4.0 Bonjour

Namespace Provider
rasadhlp.dll 73c70000 24576 C:\Windows\system32

\rasadhlp.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Remote Access AutoDial Helper
SHELL32.dll 764b0000 11599872 C:\Windows\system32

\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Shell Common Dll
CRYPTNET.dll 71960000 110592 C:\Windows\system32

\CRYPTNET.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Crypto Network Related API
SensApi.dll 73180000 24576 C:\Windows\system32

\SensApi.dll 6.0.6000.16386 (vista_rtm.061101-2205)

SENS Connectivity API DLL
Module information for 'svchost.exe'(976)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\system32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
NTMARTA.DLL 74d10000 135168 C:\Windows\system32

\NTMARTA.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Windows NT MARTA provider
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
WLDAP32.dll 760f0000 299008 C:\Windows\system32

\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Win32 LDAP API DLL
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
SAMLIB.dll 75490000 69632 C:\Windows\system32

\SAMLIB.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

SAM Library DLL
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
nsisvc.dll 74a90000 32768 c:\windows\system32

\nsisvc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network Store Interface RPC server
secur32.dll 75870000 81920 C:\Windows\system32

\secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
CRYPT32.dll 752f0000 991232 C:\Windows\system32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 C:\Windows\system32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
USERENV.dll 75890000 122880 C:\Windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
credssp.dll 751d0000 28672 C:\Windows\system32

\credssp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) TS Single Sign On Security Package
schannel.dll 74ee0000 282624 C:\Windows\system32

\schannel.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) TLS / SSL Security Provider
NETAPI32.dll 75520000 483328 C:\Windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
wkssvc.dll 740c0000 172032 c:\windows\system32

\wkssvc.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Workstation Service DLL
IPHLPAPI.DLL 753f0000 102400 c:\windows\system32

\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

IP Helper API
dhcpcsvc.DLL 75210000 217088 c:\windows\system32

\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCP Client Service
DNSAPI.dll 754b0000 180224 c:\windows\system32

\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Client API DLL
WINNSI.DLL 752e0000 28672 c:\windows\system32

\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Store Information RPC interface
dhcpcsvc6.DLL 751e0000 139264 c:\windows\system32

\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCPv6 Client
NTDSAPI.dll 75450000 98304 c:\windows\system32

\NTDSAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Active Directory Domain Services API
WINBRAND.dll 74d90000 880640 c:\windows\system32

\WINBRAND.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Branding Resources
netprofm.dll 73b60000 245760 c:\windows\system32

\netprofm.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network List Manager
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
GPAPI.dll 74d70000 86016 c:\windows\system32

\GPAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Group Policy Client API
slc.dll 75290000 237568 c:\windows\system32\slc.dll

6.0.6002.18005 (lh_sp2rtm.090410-1830) Software

Licensing Client Dll
nlaapi.dll 74c10000 61440 c:\windows\system32

\nlaapi.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Location Awareness 2
rsaenh.dll 74e70000 241664 C:\Windows\system32

\rsaenh.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft Enhanced Cryptographic Provider
CLBCatQ.DLL 772d0000 540672 C:\Windows\system32

\CLBCatQ.DLL 2001.12.6931.18000

(longhorn_rtm.080118-1840) COM+ Configuration Catalog
npmproxy.dll 73ee0000 32768 C:\Windows\System32

\npmproxy.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network List Manager Proxy
WINTRUST.dll 74a00000 184320 C:\Windows\system32

\WINTRUST.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft Trust Verification APIs
imagehlp.dll 75e50000 167936 C:\Windows\system32

\imagehlp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT Image Helper
Module information for 'svchost.exe'(1052)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\system32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
bfe.dll 74450000 348160 c:\windows\system32\bfe.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) Base

Filtering Engine
AUTHZ.dll 75620000 90112 c:\windows\system32

\AUTHZ.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Authorization Framework
Secur32.dll 75870000 81920 c:\windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
mpssvc.dll 74000000 417792 c:\windows\system32

\mpssvc.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Microsoft Protection Service
FirewallAPI.dll 74c20000 417792 c:\windows\system32

\FirewallAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Firewall API
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
VERSION.dll 751c0000 32768 c:\windows\system32

\VERSION.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Version Checking and File Installation Libraries
nlaapi.dll 74c10000 61440 c:\windows\system32

\nlaapi.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Location Awareness 2
IPHLPAPI.DLL 753f0000 102400 c:\windows\system32

\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

IP Helper API
dhcpcsvc.DLL 75210000 217088 c:\windows\system32

\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCP Client Service
DNSAPI.dll 754b0000 180224 c:\windows\system32

\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Client API DLL
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
WINNSI.DLL 752e0000 28672 c:\windows\system32

\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Store Information RPC interface
dhcpcsvc6.DLL 751e0000 139264 c:\windows\system32

\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCPv6 Client
CRYPT32.dll 752f0000 991232 c:\windows\system32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 c:\windows\system32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
USERENV.dll 75890000 122880 c:\windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
bcrypt.dll 750f0000 282624 c:\windows\system32

\bcrypt.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows Cryptographic Primitives Library
WTSAPI32.dll 74c00000 40960 c:\windows\system32

\WTSAPI32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Terminal Server SDK APIs
SHLWAPI.dll 77360000 364544 C:\Windows\system32

\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Light-weight Utility Library
fwpuclnt.dll 743b0000 614400 c:\windows\system32

\fwpuclnt.dll 6.0.6000.16386 (vista_rtm.061101-2205)

FWP/IPsec User-Mode API
comctl32.dll 74830000 1695744

C:\Windows\WinSxS\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de

0\comctl32.dll 5.82 (longhorn_rtm.080118-1840) Common

Controls Library
credssp.dll 751d0000 28672 C:\Windows\system32

\credssp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) TS Single Sign On Security Package
schannel.dll 74ee0000 282624 C:\Windows\system32

\schannel.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) TLS / SSL Security Provider
NETAPI32.dll 75520000 483328 C:\Windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
GPAPI.dll 74d70000 86016 C:\Windows\system32

\GPAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Group Policy Client API
slc.dll 75290000 237568 C:\Windows\system32\slc.dll

6.0.6002.18005 (lh_sp2rtm.090410-1830) Software

Licensing Client Dll
wfapigp.dll 74a60000 32768 C:\Windows\system32

\wfapigp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Firewall GPO Helper dll
ntmarta.dll 74d10000 135168 C:\Windows\system32

\ntmarta.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows NT MARTA provider
WLDAP32.dll 760f0000 299008 C:\Windows\system32

\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Win32 LDAP API DLL
SAMLIB.dll 75490000 69632 C:\Windows\system32

\SAMLIB.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

SAM Library DLL
wpclsp.dll 74cd0000 81920 C:\Windows\system32

\wpclsp.dll 1.0.0.1 WPC LSP
SHELL32.dll 764b0000 11599872 C:\Windows\system32

\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Shell Common Dll
mswsock.dll 74ff0000 241664 C:\Windows\system32

\mswsock.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Windows Sockets 2.0 Service Provider
wshtcpip.dll 74cf0000 20480 C:\Windows\System32

\wshtcpip.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv4)
wship6.dll 751a0000 20480 C:\Windows\System32

\wship6.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv6)
CLBCatQ.DLL 772d0000 540672 C:\Windows\system32

\CLBCatQ.DLL 2001.12.6931.18000

(longhorn_rtm.080118-1840) COM+ Configuration Catalog
rsaenh.dll 74e70000 241664 C:\Windows\system32

\rsaenh.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Microsoft Enhanced Cryptographic Provider
npmproxy.dll 73ee0000 32768 C:\Windows\System32

\npmproxy.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Network List Manager Proxy
Module information for 'svchost.exe'(1232)
MODULE BASE SIZE PATH
svchost.exe 120000 32768 C:\Windows\system32

\svchost.exe 6.0.6000.16386 (vista_rtm.061101-2205)

Host Process for Windows Services
ntdll.dll 77170000 1208320 C:\Windows\system32

\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) NT Layer DLL
kernel32.dll 77090000 901120 C:\Windows\system32

\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows NT BASE API Client DLL
msvcrt.dll 762d0000 696320 C:\Windows\system32

\msvcrt.dll 7.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows NT CRT DLL
ADVAPI32.dll 75c60000 811008 C:\Windows\system32

\ADVAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Advanced Windows 32 Base API
RPCRT4.dll 76010000 798720 C:\Windows\system32

\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Remote Procedure Call Runtime
ipsecsvc.dll 73e10000 372736 c:\windows\system32

\ipsecsvc.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows IPsec SPD Server DLL
AUTHZ.dll 75620000 90112 c:\windows\system32

\AUTHZ.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Authorization Framework
ole32.dll 75a30000 1331200 C:\Windows\system32

\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft OLE for Windows
GDI32.dll 77040000 307200 C:\Windows\system32

\GDI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

GDI Client DLL
USER32.dll 75d30000 643072 C:\Windows\system32

\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Multi-User Windows USER API Client DLL
IPHLPAPI.DLL 753f0000 102400 c:\windows\system32

\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

IP Helper API
dhcpcsvc.DLL 75210000 217088 c:\windows\system32

\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCP Client Service
DNSAPI.dll 754b0000 180224 c:\windows\system32

\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

DNS Client API DLL
WS2_32.dll 772a0000 184320 C:\Windows\system32

\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Windows Socket 2.0 32-Bit DLL
NSI.dll 760e0000 24576 C:\Windows\system32\NSI.dll

6.0.6001.18000 (longhorn_rtm.080118-1840) NSI

User-mode interface DLL
Secur32.dll 75870000 81920 c:\windows\system32

\Secur32.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) Security Support Provider Interface
WINNSI.DLL 752e0000 28672 c:\windows\system32

\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-

1840) Network Store Information RPC interface
dhcpcsvc6.DLL 751e0000 139264 c:\windows\system32

\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

DHCPv6 Client
CRYPT32.dll 752f0000 991232 c:\windows\system32

\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Crypto API32
MSASN1.dll 75470000 73728 c:\windows\system32

\MSASN1.dll 6.0.6002.18106 (vistasp2_gdr.090903-

2340) ASN.1 Runtime APIs
USERENV.dll 75890000 122880 c:\windows\system32

\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Userenv
fwpuclnt.dll 743b0000 614400 c:\windows\system32

\fwpuclnt.dll 6.0.6000.16386 (vista_rtm.061101-2205)

FWP/IPsec User-Mode API
OLEAUT32.dll 75e80000 577536 C:\Windows\system32

\OLEAUT32.dll 6.0.6002.18005 6.0.6002.18005
FirewallAPI.dll 74c20000 417792 c:\windows\system32

\FirewallAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Firewall API
VERSION.dll 751c0000 32768 c:\windows\system32

\VERSION.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Version Checking and File Installation Libraries
FwRemoteSvr.DLL 74a70000 40960 c:\windows\system32

\FwRemoteSvr.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Windows Firewall Remote APIs Server
WLDAP32.dll 760f0000 299008 C:\Windows\system32

\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Win32 LDAP API DLL
PSAPI.DLL 759d0000 28672 C:\Windows\system32

\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205)

Process Status Helper
IMM32.DLL 75f10000 122880 C:\Windows\system32

\IMM32.DLL 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Multi-User Windows IMM32 API Client DLL
MSCTF.dll 75b90000 819200 C:\Windows\system32

\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205)

MSCTF Server DLL
LPK.DLL 75b80000 36864 C:\Windows\system32\LPK.DLL

6.0.6002.18051 (vistasp2_gdr.090615-0258)

Language Pack
USP10.dll 76fc0000 512000 C:\Windows\system32

\USP10.dll 1.0626.6002.18005 (lh_sp2rtm.090410-

1830) Uniscribe Unicode script processor
CLBCatQ.DLL 772d0000 540672 C:\Windows\system32

\CLBCatQ.DLL 2001.12.6931.18000

(longhorn_rtm.080118-1840) COM+ Configuration Catalog
SHLWAPI.dll 77360000 364544 C:\Windows\system32

\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Shell Light-weight Utility Library
comctl32.dll 74830000 1695744

C:\Windows\WinSxS\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de

0\comctl32.dll 5.82 (longhorn_rtm.080118-1840) Common

Controls Library
wpclsp.dll 74cd0000 81920 C:\Windows\system32

\wpclsp.dll 1.0.0.1 WPC LSP
NETAPI32.dll 75520000 483328 C:\Windows\system32

\NETAPI32.dll 6.0.6002.18005 (lh_sp2rtm.090410-1830)

Net Win32 API DLL
SHELL32.dll 764b0000 11599872 C:\Windows\system32

\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) Windows Shell Common Dll
mswsock.dll 74ff0000 241664 C:\Windows\system32

\mswsock.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Microsoft Windows Sockets 2.0 Service Provider
wshtcpip.dll 74cf0000 20480 C:\Windows\System32

\wshtcpip.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv4)
wship6.dll 751a0000 20480 C:\Windows\System32

\wship6.dll 6.0.6000.16386 (vista_rtm.061101-2205)

Winsock2 Helper DLL (TL/IPv6)
credssp.dll 751d0000 28672 C:\Windows\system32

\credssp.dll 6.0.6001.18000 (longhorn_rtm.080118-

1840) TS Single Sign On Security Package
schannel.dll 74ee0000 282624 C:\Windows\system32

\schannel.dll 6.0.6002.18051 (vistasp2_gdr.090615-

0258) TLS / SSL Security Provider



******************************************
EOF

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Wed Oct 05, 2011 11:53 am

Jotti File Submission:
  • Please go to [You must be registered and logged in to see this link.]

  • Copy and paste the following file path into the "File to upload & scan"box on the top of the page:

    • C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys


  • Click on the submit button

  • Please post the results (URL) in your next reply.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Thu Oct 06, 2011 5:53 am

[You must be registered and logged in to see this link.]

Not all of them scanned. Should I try again?

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Thu Oct 06, 2011 9:12 am

When you can, yes...


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Fri Oct 07, 2011 1:01 am

[You must be registered and logged in to see this link.]


Still only 15 of the 20 scanned. The other ones sent a message of "Operation timed out"

Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Sun Oct 09, 2011 2:58 pm

Sorry this is wasting time...

go to [You must be registered and logged in to see this link.] and try it there...


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Qaytu on Thu Nov 17, 2011 2:47 pm

Here is information from Virus total.

MD5 : cc48f88fe17bb8e5eb6fa1a8a9477006
SHA1 : e023a8ba2ddcdadb00c8af9f3c4f1057d5443a0a
SHA256: c707a9bdba208ac476466ec25850e976dc123dd65c7151dadc0cfe1b7bf0cd16
ssdeep: 192:g0gwnDIZOCCg88D3vp4mLkwE7hpu+1Ylw0yowJL/8Qpkqs1INTrQx+ebCfu12IZR:b83Cg8
q4Dh/j0YJLu1CUnbCW/6jk
File size : 16184 bytes
First seen: 2011-03-10 18:10:58
Last seen : 2011-11-17 19:29:59
TrID:
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: IObit Information Technology
VeriSign Class 3 Code Signing 2009-2 CA
Class 3 Public Primary Certification Authority
signing date.: 9:52 23/02/2011
verified.....: -

PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x503E
timedatestamp....: 0x4D64C75B (Wed Feb 23 08:37:47 2011)
machinetype......: 0x14c (I386)

[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x15C0, 0x1600, 6.13, 1ff00b938e829f47fc76ac9d23d1f2bf
.rdata, 0x3000, 0x1B8, 0x200, 3.71, ae6ff710b3d9146162ba4c2e72874945
.data, 0x4000, 0x310, 0x200, 0.24, 312651a6f76490d97aff95c683a68247
INIT, 0x5000, 0x2E8, 0x400, 4.38, 45e506cc153ba817964d9bf35593b912
.reloc, 0x6000, 0x162, 0x200, 4.20, aeac947ed92a1cf8e2bb678fbe8718ce

[[ 1 import(s) ]]
ntoskrnl.exe: _vsnwprintf, memset, ExFreePoolWithTag, ZwQueryValueKey, RtlInitUnicodeString, ExAllocatePoolWithTag, ZwClose, ZwOpenKey, IofCompleteRequest, IoDeleteDevice, IoDeleteSymbolicLink, MmGetSystemRoutineAddress, wcsstr, ZwEnumerateValueKey, IoCreateFileSpecifyDeviceObjectHint, ZwWaitForSingleObject, ZwFsControlFile, _wcsicmp, memcpy, IoCreateSymbolicLink, IoCreateDevice, IoRegisterBootDriverReinitialization, InitSafeBootMode, KeTickCount, KeBugCheckEx, RtlUnwind

ExifTool:
file metadata
CodeSize: 6656
EntryPoint: 0x503e
FileSize: 16 kB
FileType: Win32 EXE
ImageVersion: 6.1
InitializedDataSize: 2048
LinkerVersion: 9.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 6.1
PEType: PE32
Subsystem: Native
SubsystemVersion: 6.0
TimeStamp: 2011:02:23 09:37:47+01:00
UninitializedDataSize: 0


Qaytu
Novice
Novice

Status :
Online
Offline

Posts : 33
Joined : 2011-08-12
Gender : Female
OS : Vista 2nd update
Points : 19832
# Likes : 0

View user profile

Back to top Go down

Re: MBR:\...\PHYSICALDRIVE0

Post by Dr Jay on Fri Nov 18, 2011 8:33 am

Please download [You must be registered and logged in to see this link.] and save it to your Desktop. Do NOT perform a scan yet

  • Double-click on drweb-cureit.exe to start the program.
    An Express Scan of your PC notice will appear.
  • Under Start the Express Scan Now, Click OK to start the scan.
    This is a short scan that will scan the files currently running in memory.
    If something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan tab and UNcheck Heuristic analysis
  • Back at the main window, click Custom Scan, then Select drives (a red dot will show which drives have been chosen).
  • Then click the Start/Stop Scanning button (green arrow on the right, and the scan will start.
  • When finished, a message will be displayed at the bottom advising if any viruses were found.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found.
    If so, click it, then click the next icon right below and select Move incurable.
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit when you have finished.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Administrator
Administrator

Status :
Online
Offline

Posts : 13705
Joined : 2009-09-06
Gender : Male
OS : Windows 10 Home & Pro
Points : 144815
# Likes : 10

View user profile

Back to top Go down

Page 1 of 2 1, 2  Next

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum