0% found this document useful (0 votes)
93 views

Capturننe Machine Overview

The document provides details of a system dump capture from a Windows XP machine, including operating system information, installed applications, environment variables, and drive details.

Uploaded by

Romany Malak
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
93 views

Capturننe Machine Overview

The document provides details of a system dump capture from a Windows XP machine, including operating system information, installed applications, environment variables, and drive details.

Uploaded by

Romany Malak
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
You are on page 1/ 19

Capture Machine Overview

Dump started on 9/3/2097 at 16:0:54.93

Operating system: Windows XP Service Pack 2


User name: Administrator
Member of: None, Everyone, Administrators, Users, INTERACTIVE,
Authenticated Users,
<name lookup failed>, LOCAL,
Computer name: ZONA
IE version: 6.0.2900.2180
Drives: Drive C: Fixed NTFS serial 3965290071 [xEC598657], 91,948
MB user free, CASE_SENSITIVE_SEARCH CASE_PRESERVED_NAMES UNICODE_ON_DISK
PERSISTENT_ACLS FILE_COMPRESSION VOLUME_QUOTAS SUPPORTS_SPARSE_FILES
SUPPORTS_REPARSE_POINTS SUPPORTS_OBJECT_IDS SUPPORTS_ENCRYPTION NAMED_STREAMS
Drive D: Fixed NTFS serial 615490277 [x24AFA2E5], 59,616
MB user free, CASE_SENSITIVE_SEARCH CASE_PRESERVED_NAMES UNICODE_ON_DISK
PERSISTENT_ACLS FILE_COMPRESSION VOLUME_QUOTAS SUPPORTS_SPARSE_FILES
SUPPORTS_REPARSE_POINTS SUPPORTS_OBJECT_IDS SUPPORTS_ENCRYPTION NAMED_STREAMS
Drive E: Fixed FAT serial 3492769040 [xD02F6D10], 456 MB
user free, CASE_PRESERVED_NAMES UNICODE_ON_DISK
Drive F: Fixed NTFS serial 955992476 [x38FB499C], 632 MB
user free, CASE_SENSITIVE_SEARCH CASE_PRESERVED_NAMES UNICODE_ON_DISK
PERSISTENT_ACLS FILE_COMPRESSION VOLUME_QUOTAS SUPPORTS_SPARSE_FILES
SUPPORTS_REPARSE_POINTS SUPPORTS_OBJECT_IDS SUPPORTS_ENCRYPTION NAMED_STREAMS
Drive G: Fixed NTFS serial 352087739 [x14FC6EBB], 45,608
MB user free, CASE_SENSITIVE_SEARCH CASE_PRESERVED_NAMES UNICODE_ON_DISK
PERSISTENT_ACLS FILE_COMPRESSION VOLUME_QUOTAS SUPPORTS_SPARSE_FILES
SUPPORTS_REPARSE_POINTS SUPPORTS_OBJECT_IDS SUPPORTS_ENCRYPTION NAMED_STREAMS
Drive H: Fixed NTFS serial 1926774745 [x72D83FD9], 2,409
MB user free, CASE_SENSITIVE_SEARCH CASE_PRESERVED_NAMES UNICODE_ON_DISK
PERSISTENT_ACLS FILE_COMPRESSION VOLUME_QUOTAS SUPPORTS_SPARSE_FILES
SUPPORTS_REPARSE_POINTS SUPPORTS_OBJECT_IDS SUPPORTS_ENCRYPTION NAMED_STREAMS
Drive I: Fixed NTFS serial 3627193095 [xD8329307], 70,484
MB user free, CASE_SENSITIVE_SEARCH CASE_PRESERVED_NAMES UNICODE_ON_DISK
PERSISTENT_ACLS FILE_COMPRESSION VOLUME_QUOTAS SUPPORTS_SPARSE_FILES
SUPPORTS_REPARSE_POINTS SUPPORTS_OBJECT_IDS SUPPORTS_ENCRYPTION NAMED_STREAMS
Drive J: Fixed NTFS serial 1891298098 [x70BAEB32], 11,496
MB user free, CASE_SENSITIVE_SEARCH CASE_PRESERVED_NAMES UNICODE_ON_DISK
PERSISTENT_ACLS FILE_COMPRESSION VOLUME_QUOTAS SUPPORTS_SPARSE_FILES
SUPPORTS_REPARSE_POINTS SUPPORTS_OBJECT_IDS SUPPORTS_ENCRYPTION NAMED_STREAMS
Drive K: Fixed NTFS serial 1283870469 [x4C864F05], 53,766
MB user free, CASE_SENSITIVE_SEARCH CASE_PRESERVED_NAMES UNICODE_ON_DISK
PERSISTENT_ACLS FILE_COMPRESSION VOLUME_QUOTAS SUPPORTS_SPARSE_FILES
SUPPORTS_REPARSE_POINTS SUPPORTS_OBJECT_IDS SUPPORTS_ENCRYPTION NAMED_STREAMS
Drive L: <data unavailable>
Drive M: Removable FAT32 serial 2621145919 [x9C3B833F],
1,757 MB user free, CASE_PRESERVED_NAMES UNICODE_ON_DISK
Working dir: C:\Documents and Settings\Administrator
ADO version: 2.81.1117.0
Terminal services: Not running
Remote session: No
LUA enabled: No
LOCALE_SYSTEM_DEFAULT: 0401 ENU
LOCALE_USER_DEFAULT: 0409 ENU
Installed apps
System-wide 2nd Speech Center V3.00.050830, AddressBook, Adobe Flash
Player ActiveX,
Adobe Flash Player Plugin, Ares 2.0.9, BSplayer Pro
2.12.941, BuddyCheck 1.0.2,
CCleaner (remove only), Connection Manager,
DirectAnimation, DirectDrawEx,
doPDF 5.3 printer, Driver Magician 3.25, Driver Sweeper
1.0,
DXM_Runtime, Enable S3 for USB Device, FileLocator Pro
Version 4.0,
FileZilla Client 3.0.4.1, FlashGet 1.9.6.1073, Fontcore,
GoldWave v5.08, IE40,
IE4Data, IE5BAKEX, IE7Pro, IEData, InstallShield Uninstall
Information,
Easy Tune 6 B10.0301.1, Update Manager B09.1008.1,
AutoGreen B09.1014.2, KB884016,
KB884267, KB885353, KB886612, KB887078, KB887626, High
Definition Audio Driver Package - KB888111,
KB888656, KB889858, KB891122, KB892313, KB893240,
KB893241,
KB893803, Windows Installer 3.1 (KB893803), KB895181,
KB895316, KB895572, KB897586,
KB898549, KB900399, KB902344, KB907658, KB911565,
KB911854,
Hotfix for Windows XP (KB926239), LClock, Media Player
Classic, Microsoft .NET Framework 2.0,
Microsoft .NET Framework 3.0, MobileOptionPack, Mozilla
Firefox (2.0.0.11),
MPlayer2, Microsoft Compression Client Pack 1.0 for
Windows XP, MSI30-Beta1, MSI30-Beta2, MSI30-KB884016,
MSI30-RC1, MSI30-RC2, MSI30a-KB884016, MSI31-Beta, MSI31-
RC1,
MsJavaVM, NOD32 antivirus system, OutlookExpress,
PCHealth, PianoFX STUDIO 4.0,
Picasa 2, PowerISO, Recuva (remove only), Res2dinv, Revo
Uninstaller 1.40, RM Converter 3,
RocketDock 1.2.5, SchedulingAgent, ShockwaveFlash,
Teleport Pro,
Total Video Converter 3.02, Lernout & Hauspie TruVoice
American English TTS Engine, Visual Task Tips 2.3,
Windows Imaging Component, Win32Pad 1.5.10, Winamp (remove
only), Windows Media Format 11 runtime, Windows Media Player 11,
WinRAR archiver, WMCSetup, Windows Media Format 11
runtime, Windows Media Player 11, Microsoft User-Mode Driver Framework Feature Pack
1.0,
XnView 1.91.4, XML Paper Specification Shared Components
Pack 1.0, Yahoo! Toolbar, Yahoo! Messenger,
Yahoo! Toolbar, Yahoo! Install Manager, Nero ShowTime,
EasySaver B9.0904.1 , MSXML 6.0 Parser (KB933579),
Microsoft .NET Framework 3.0, Nero PhotoSnap Help,
Google Earth, Nero InfoTool Help,
Google Toolbar for Internet Explorer, Nero StartSmart
Help,
Foxit PDF Editor, Nero DriveSpeed,
Nero Recode, Foxit Reader,
ON_OFF Charge B10.0413.1, DMIView B8.0717.01,
Nero Vision, Easy Tune 6 B10.0301.1,
Windows Communication Foundation, Nero StartSmart OEM,
Update Manager B09.1008.1, Windows Live Messenger,
neroxml, TruDirect,
NeroExpress, Nero Vision Help,
Nero CoverDesigner, Microsoft .NET Framework 2.0,
Microsoft Visual C++ 2005 Redistributable, Nero
StartSmart,
Nero BurnRights, Windows Workflow Foundation,
Nero Express Help, Nero DiscSpeed,
Microsoft Office Professional Edition 2003, Microsoft
Visual C++ 2008 Redistributable - x86 9.0.30729.17,
Nero PhotoSnap, Geosoft Oasis montaj,
Browser Configuration Utility, ImagXpress,
Nero Recode Help, DolbyFiles,
@BIOS Ver.2.07, Advertising Center,
Nero 9 Essentials, InCD Help,
Windows Presentation Foundation, Nero ControlCenter,
AutoGreen B09.1014.2, REALTEK GbE & FE Ethernet PCI-E NIC
Driver,
VMware ThinApp, Nero DiscSpeed Help,
Nero CoverDesigner Help, Nero ShowTime,
Nero Online Upgrade, NOD32 FiX,
Google Toolbar for Internet Explorer, Nero DriveSpeed
Help,
Face_Wizard B09.1119.01, Nero Installer,
Intel(R) Graphics Media Accelerator Driver, Realtek High
Definition Audio Driver,
Q-Share Ver.1.2, Nero ControlCenter,
Nero BurnRights Help, Vista Codec Package,
Nero InfoTool,

Per-user <unavailable>

Environment strings: =::=::\


ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Administrator\
Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=ZONA
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Administrator
LOGONSERVER=\\ZONA
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Documents and Settings\Administrator;C:\Program
Files\VMware\VMware ThinApp;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 23 Stepping 10,
GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=170a
ProgramFiles=C:\Program Files
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
TS_ORIGIN=C:\Program Files\VMware\VMware ThinApp\Setup
Capture.exe
TS_SVCINIT=1
USERDOMAIN=ZONA
USERNAME=Administrator
USERPROFILE=C:\Documents and Settings\Administrator
windir=C:\WINDOWS

Current process:
Process ID: 3096
Minimum req'd operating system ver: 4.0
snapshot.exe
C:\Program Files\VMware\VMware ThinApp\snapshot.exe

FileDescription: Snapshot tool


FileVersion: 4.0.0-2200
InternalName: snapshot
LegalCopyright: Copyright 2006-2008 VMware, Inc.
OriginalFilename: snapshot.exe
ProductName: VMware ThinApp
ProductVersion: 4.0.0-2200

Priority class: Normal


Processor affinity mask: x3
System affinity mask: x3
Creation time: Tues 3 Oct 2097 16:00:49
Priority boost: Normal behavior

Modules:

Base Size Entry

x00400000 x0003E000 x004230CB snapshot.exe C:\Program Files\


VMware\VMware ThinApp\snapshot.exe
x7C900000 x000B0000 x7C913156 ntdll.dll C:\WINDOWS\system32\
ntdll.dll
x7C800000 x000F4000 x7C80B436 kernel32.dll C:\WINDOWS\system32\
kernel32.dll
x77D40000 x00090000 x77D50EB9 USER32.dll C:\WINDOWS\system32\
USER32.dll
x77F10000 x00046000 x77F163CA GDI32.dll C:\WINDOWS\system32\
GDI32.dll
x629C0000 x00009000 x629C2EAD LPK.DLL C:\WINDOWS\system32\
LPK.DLL
x74D90000 x0006B000 x74DCAEB6 USP10.dll C:\WINDOWS\system32\
USP10.dll
x77C10000 x00058000 x77C1F2A1 msvcrt.dll C:\WINDOWS\system32\
msvcrt.dll
x77DD0000 x0009B000 x77DD70D4 ADVAPI32.dll C:\WINDOWS\system32\
ADVAPI32.dll
x77E70000 x00091000 x77E76284 RPCRT4.dll C:\WINDOWS\system32\
RPCRT4.dll
x7C9C0000 x01999000 x7C9DFA10 SHELL32.dll C:\WINDOWS\system32\
SHELL32.dll
x77F60000 x00076000 x77F651D3 SHLWAPI.dll C:\WINDOWS\system32\
SHLWAPI.dll
x773D0000 x00102000 x773D42B3 comctl32.dll C:\WINDOWS\WinSxS\
x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\
comctl32.dll
x5D090000 x00097000 x5D0932DA comctl32.dll C:\WINDOWS\system32\
comctl32.dll
x774E0000 x0013C000 x774F20C1 ole32.dll C:\WINDOWS\system32\
ole32.dll
x77C00000 x00008000 x77C01135 VERSION.dll C:\WINDOWS\system32\
VERSION.dll
x5AD70000 x00038000 x5AD71626 uxtheme.dll C:\WINDOWS\system32\
uxtheme.dll
x10000000 x0000E000 x100017D9 YzShadow.dll C:\Program Files\
yzs\YzShadow.dll
x74720000 x0004B000 x747213A5 MSCTF.dll C:\WINDOWS\system32\
MSCTF.dll
x00BA0000 x00011000 x00BA30D6 UberIcon.dll C:\Program Files\
UberIcon\UberIcon.dll
x00BD0000 x00005000 x00BD1020 VttHooks.dll C:\Program Files\
VisualTaskTips\VttHooks.dll
x0FFD0000 x00028000 x0FFE34E1 rsaenh.dll C:\WINDOWS\system32\
rsaenh.dll
x76780000 x00009000 x76781170 shfolder.dll C:\WINDOWS\system32\
shfolder.dll
x769C0000 x000B3000 x769C15D4 USERENV.dll C:\WINDOWS\system32\
USERENV.dll
x5B860000 x00054000 x5B8689F8 netapi32.dll C:\WINDOWS\system32\
netapi32.dll
x77FE0000 x00011000 x77FE2131 Secur32.dll C:\WINDOWS\system32\
Secur32.dll
x76BF0000 x0000B000 x76BF10F1 psapi.dll C:\WINDOWS\system32\
psapi.dll
x02040000 x00037000 x020533C9 ConfigDump.dll C:\Program Files\
VMware\VMware ThinApp\ConfigDump.dll

32-bit processes:
x0000 idle system process
x0004 snapshot.exe C:\Program Files\VMware\VMware ThinApp\
snapshot.exe
x0204 smss.exe \SystemRoot\System32\smss.exe
x0258 winlogon.exe \??\C:\WINDOWS\system32\winlogon.exe
x0284 services.exe C:\WINDOWS\system32\services.exe
x0290 lsass.exe C:\WINDOWS\system32\lsass.exe
x0324 DF5Serv.exe C:\Program Files\Faronics\Deep Freeze\
Install C-0\DF5Serv.exe
x0348 svchost.exe C:\WINDOWS\system32\svchost.exe
x03AC svchost.exe C:\WINDOWS\System32\svchost.exe
x04D4 spoolsv.exe C:\WINDOWS\system32\spoolsv.exe
x054C BCUService.exe C:\Program Files\DeviceVM\Browser
Configuration Utility\BCUService.exe
x0584 ESSVR.EXE C:\Program Files\Gigabyte\EasySaver\
ESSVR.EXE
x05CC NBService.exe C:\Program Files\Common Files\Nero\Nero
BackItUp 4\NBService.exe
x05F8 Explorer.EXE C:\WINDOWS\Explorer.EXE
x0644 nod32krn.exe C:\Program Files\Eset\nod32krn.exe
x00DC nod32kui.exe C:\Program Files\Eset\nod32kui.exe
x0100 BCU.exe C:\Program Files\DeviceVM\Browser
Configuration Utility\BCU.exe
x0114 igfxtray.exe C:\WINDOWS\system32\igfxtray.exe
x01B8 hkcmd.exe C:\WINDOWS\system32\hkcmd.exe
x021C igfxpers.exe C:\WINDOWS\system32\igfxpers.exe
x0230 igfxsrvc.exe C:\WINDOWS\system32\igfxsrvc.exe
x022C RTHDCPL.EXE C:\WINDOWS\RTHDCPL.EXE
x047C GUI.exe C:\Program Files\GIGABYTE\ET6\GUI.exe
x02BC issch.exe C:\Program Files\Common Files\
InstallShield\UpdateService\issch.exe
x0538 RunUpd.exe C:\Program Files\GIGABYTE\GBTUpd\
RunUpd.exe
x05C8 ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
x05D8 LClock.exe C:\Program Files\LClock\LClock.exe
x05E0 td.exe C:\Program Files\topdesk\td.exe
x05E8 UberIcon Manager.exe C:\Program Files\UberIcon\UberIcon
Manager.exe
x060C VisualTaskTips.exe C:\Program Files\VisualTaskTips\
VisualTaskTips.exe
x05B8 YzShadow.exe C:\Program Files\yzs\YzShadow.exe
x0560 RocketDock.exe C:\Program Files\RocketDock\
RocketDock.exe
x02CC TruDirectTray.exe C:\Program Files\TruDirect\
TruDirectTray.exe
x0448 TopDesk.exe C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
7zS4.tmp\TopDesk.exe
x0934 Setup Capture.exe C:\Program Files\VMware\VMware ThinApp\
Setup Capture.exe
x0C18 snapshot.exe C:\Program Files\VMware\VMware ThinApp\
snapshot.exe

Shell folders:
ProgramFilesDir = C:\Program Files
Common StartMenu = C:\Documents and Settings\All Users\Start Menu
StartMenu = C:\Documents and Settings\Administrator\Start Menu
Common AppData = C:\Documents and Settings\All Users\Application Data
Local AppData = C:\Documents and Settings\Administrator\Local
Settings\Application Data
AppData = C:\Documents and Settings\Administrator\Application
Data
Common Desktop = C:\Documents and Settings\All Users\Desktop
Desktop = C:\Documents and Settings\Administrator\Desktop
Common Startup = C:\Documents and Settings\All Users\Start Menu\
Programs\Startup [default: C:\Documents and Settings\All Users\Start Menu\
Programs\StartUp]
Startup = C:\Documents and Settings\Administrator\Start Menu\
Programs\Startup [default: C:\Documents and Settings\Administrator\Start Menu\
Programs\StartUp]
Common Programs = C:\Documents and Settings\All Users\Start Menu\
Programs
Programs = C:\Documents and Settings\Administrator\Start Menu\
Programs
Common Favorites = C:\Documents and Settings\All Users\Favorites
Favorites = C:\Documents and Settings\Administrator\Favorites
SendTo = C:\Documents and Settings\Administrator\SendTo
Templates = C:\Documents and Settings\Administrator\Templates
Recent = C:\Documents and Settings\Administrator\Recent
NetHood = C:\Documents and Settings\Administrator\NetHood
Fonts = C:\WINDOWS\Fonts
My Pictures = C:\Documents and Settings\Administrator\My
Documents\My Pictures
My Videos = <unavailable> [default: C:\Documents and Settings\
Administrator\My Documents\My Videos]
Personal = C:\Documents and Settings\Administrator\My Documents
Profile = C:\Documents and Settings\Administrator
Profiles = <unavailable>
SystemSystem = C:\WINDOWS\system32
System services:
Alerter - Alerter
Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

ALG - Application Layer Gateway Service


Process ID: 1980
Shared process? No
State: Running
Flags: x00000000 Not running in system process

AppleChargerSrv - AppleChargerSrv
Process ID: 0
Shared process? <unknown>
State: Stopped
Flags: x00000000 Not running in system process

AppMgmt - Application Management


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

AresChatServer - Ares Chatroom server


Process ID: 0
Shared process? <unknown>
State: Stopped
Flags: x00000000 Not running in system process

aspnet_state - ASP.NET State Service


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

AudioSrv - Windows Audio


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

BCUService - Browser Configuration Utility Service


Process ID: 1356
Shared process? No
State: Running
Flags: x00000000 Not running in system process

BITS - Background Intelligent Transfer Service


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

Browser - Computer Browser


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

ClipSrv - ClipBook
Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

clr_optimization_v2.0.50727_32 - .NET Runtime Optimization Service


v2.0.50727_X86
Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

COMSysApp - COM+ System Application


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

CryptSvc - Cryptographic Services


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

DcomLaunch - DCOM Server Process Launcher


Process ID: 840
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

DF5Serv - DF5Serv
Process ID: 804
Shared process? <unknown>
State: Running
Flags: x00000000 Not running in system process

DFServ - DFServ
Process ID: 0
Shared process? <unknown>
State: Stopped
Flags: x00000000 Not running in system process

Dhcp - DHCP Client


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

dmadmin - Logical Disk Manager Administrative Service


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

dmserver - Logical Disk Manager


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

Dnscache - DNS Client


Process ID: 1004
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

ERSvc - Error Reporting Service


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

ES lite Service - ES lite Service for program management.


Process ID: 1412
Shared process? <unknown>
State: Running
Flags: x00000000 Not running in system process

Eventlog - Event Log


Process ID: 644
Shared process? Yes
State: Running
Flags: x00000001 Runs in a system process

EventSystem - COM+ Event System


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

FastUserSwitchingCompatibility - Fast User Switching Compatibility


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

FontCache3.0.0.0 - Windows Presentation Foundation Font Cache 3.0.0.0


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

gusvc - Google Updater Service


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

helpsvc - Help and Support


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process
HidServ - Human Interface Device Access
Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

HTTPFilter - HTTP SSL


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

IDriverT - InstallDriver Table Manager


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

idsvc - Windows CardSpace


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

lanmanserver - Server
Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

lanmanworkstation - Workstation
Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

LmHosts - TCP/IP NetBIOS Helper


Process ID: 1060
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

Messenger - Messenger
Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

MSDTC - Distributed Transaction Coordinator


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

MSIServer - Windows Installer


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process
Nero BackItUp Scheduler 4.0 - Nero BackItUp Scheduler 4.0
Process ID: 1484
Shared process? No
State: Running
Flags: x00000000 Not running in system process

NetDDE - Network DDE


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

NetDDEdsdm - Network DDE DSDM


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

Netlogon - Net Logon


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

Netman - Network Connections


Process ID: 940
Shared process? <unknown>
State: Running
Flags: x00000000 Not running in system process

NetTcpPortSharing - Net.Tcp Port Sharing Service


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

Nla - Network Location Awareness (NLA)


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

NOD32krn - NOD32 Kernel Service


Process ID: 1604
Shared process? <unknown>
State: Running
Flags: x00000000 Not running in system process

NtLmSsp - NT LM Security Support Provider


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

NtmsSvc - Removable Storage


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

ose - Office Source Engine


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

PlugPlay - Plug and Play


Process ID: 644
Shared process? Yes
State: Running
Flags: x00000001 Runs in a system process

PolicyAgent - IPSEC Services


Process ID: 656
Shared process? Yes
State: Running
Flags: x00000001 Runs in a system process

ProtectedStorage - Protected Storage


Process ID: 656
Shared process? <unknown>
State: Running
Flags: x00000001 Runs in a system process

RasAuto - Remote Access Auto Connection Manager


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

RasMan - Remote Access Connection Manager


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

RDSessMgr - Remote Desktop Help Session Manager


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

RemoteAccess - Routing and Remote Access


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

RemoteRegistry - Remote Registry


Process ID: 1060
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

RpcLocator - Remote Procedure Call (RPC) Locator


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

RpcSs - Remote Procedure Call (RPC)


Process ID: 888
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

SamSs - Security Accounts Manager


Process ID: 656
Shared process? Yes
State: Running
Flags: x00000001 Runs in a system process

SCardSvr - Smart Card


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

Schedule - Task Scheduler


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

seclogon - Secondary Logon


Process ID: 940
Shared process? <unknown>
State: Running
Flags: x00000000 Not running in system process

SENS - System Event Notification


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

SharedAccess - Windows Firewall/Internet Connection Sharing (ICS)


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

ShellHWDetection - Shell Hardware Detection


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

Spooler - Print Spooler


Process ID: 1236
Shared process? <unknown>
State: Running
Flags: x00000000 Not running in system process

srservice - System Restore Service


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

SSDPSRV - SSDP Discovery Service


Process ID: 1060
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

stisvc - Windows Image Acquisition (WIA)


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

SwPrv - MS Software Shadow Copy Provider


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

SysmonLog - Performance Logs and Alerts


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

TapiSrv - Telephony
Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

TermService - Terminal Services


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

Themes - Themes
Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

TlntSvr - Telnet
Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

upnphost - Universal Plug and Play Device Host


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

UPS - Uninterruptible Power Supply


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

usnjsvc - Messenger Sharing Folders USN Journal Reader service


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

VSS - Volume Shadow Copy


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

W32Time - Windows Time


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

winmgmt - Windows Management Instrumentation


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

WmdmPmSN - Portable Media Serial Number Service


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

Wmi - Windows Management Instrumentation Driver Extensions


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

WmiApSrv - WMI Performance Adapter


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

WMPNetworkSvc - Windows Media Player Network Sharing Service


Process ID: 0
Shared process? No
State: Stopped
Flags: x00000000 Not running in system process

wscsvc - Security Center


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process
wuauserv - Automatic Updates
Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

WudfSvc - Windows Driver Foundation - User-mode Driver Framework


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

WZCSVC - Wireless Zero Configuration


Process ID: 940
Shared process? Yes
State: Running
Flags: x00000000 Not running in system process

xmlprov - Network Provisioning Service


Process ID: 0
Shared process? Yes
State: Stopped
Flags: x00000000 Not running in system process

32-bit device drivers:


Kernel mode drivers:
Abiosdsk Abiosdsk
abp480n5 abp480n5
ACPI Microsoft ACPI Driver
ACPIEC ACPIEC
adpu160m adpu160m
aec Microsoft Kernel Acoustic Echo Canceller
AFD AFD
Aha154x Aha154x
aic78u2 aic78u2
aic78xx aic78xx
AliIde AliIde
Ambfilt Ambfilt
AMON AMON
amsint amsint
AppleCha AppleCharger
asc asc
asc3350p asc3350p
asc3550 asc3550
AsyncMac RAS Asynchronous Media Driver
atapi Standard IDE/ESDI Hard Disk Controller
Atdisk Atdisk
Atmarpc ATM ARP Client Protocol
audstub Audio Stub Driver
cbidf2k cbidf2k
cd20xrnt cd20xrnt
Cdaudio Cdaudio
Cdrom CD-ROM Driver
Changer Changer
CmdIde CmdIde
Cpqarray Cpqarray
dac960nt dac960nt
DeepFrz DeepFrz
Disk Disk Driver
dmboot dmboot
dmio Logical Disk Manager Driver
dmload dmload
DMusic Microsoft Kernel DLS Syntheiszer
dpti2o dpti2o
drmkaud Microsoft Kernel DRM Audio Descrambler
DtvAudio DtvAudio
DtvVideo DtvVideo
etdrv etdrv
Fdc Floppy Disk Controller Driver
Fips Fips
Flpydisk Floppy Disk Driver
Ftdisk Volume Manager Driver
gdrv gdrv
Gpc Generic Packet Classifier
HDAudBus Microsoft UAA Bus Driver for High Definition Audio
hidusb Microsoft HID Class Driver
hpn hpn
HTTP HTTP
i2omgmt i2omgmt
i2omp i2omp
i8042prt i8042 Keyboard and PS/2 Mouse Port Driver
ialm ialm
Imapi CD-Burning Filter Driver
ini910u ini910u
IntcAzAu Service for Realtek HD Audio (WDM)
IntelIde IntelIde
intelppm Intel Processor Driver
Ip6Fw IPv6 Windows Firewall Driver
IpFilter IP Traffic Filter Driver
IpInIp IP in IP Tunnel Driver
IpNat IP Network Address Translator
IPSec IPSEC driver
IRENUM IR Enumerator Service
isapnp PnP ISA/EISA Bus Driver
Kbdclass Keyboard Class Driver
kmixer Microsoft Kernel Wave Audio Mixer
KSecDD KSecDD
lbrtfdc lbrtfdc
Modem Modem
Monfilt Monfilt
Mouclass Mouse Class Driver
mouhid Mouse HID Driver
MountMgr MountMgr
mraid35x mraid35x
MSKSSRV Microsoft Streaming Service Proxy
MSPCLOCK Microsoft Streaming Clock Proxy
MSPQM Microsoft Streaming Quality Manager Proxy
mssmbios Microsoft System Management BIOS Driver
NDIS NDIS System Driver
NdisTapi Remote Access NDIS TAPI Driver
Ndisuio NDIS Usermode I/O Protocol
NdisWan Remote Access NDIS WAN Driver
NDProxy NDIS Proxy
NetBT NetBios over Tcpip
nod32drv nod32drv
Null Null
Parport Parallel port driver
PartMgr PartMgr
ParVdm ParVdm
PCI PCI Bus Driver
PCIDump PCIDump
PCIIde PCIIde
Pcmcia Pcmcia
PDCOMP PDCOMP
PDFRAME PDFRAME
PDRELI PDRELI
PDRFRAME PDRFRAME
perc2 perc2
perc2hib perc2hib
PptpMini WAN Miniport (PPTP)
Ptilink Direct Parallel Link Driver
PxHelp20 PxHelp20
ql1080 ql1080
Ql10wnt Ql10wnt
ql12160 ql12160
ql1240 ql1240
ql1280 ql1280
RasAcd Remote Access Auto Connection Driver
Rasl2tp WAN Miniport (L2TP)
RasPppoe Remote Access PPPOE Driver
Raspti Direct Parallel
RDPCDD RDPCDD
rdpdr Terminal Server Device Redirector Driver
RDPWD RDPWD
redbook Digital CD Audio Playback Filter Driver
RTLE8023 Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver
SCDEmu SCDEmu
Secdrv Secdrv
serenum Serenum Filter Driver
Serial Serial port driver
Sfloppy Sfloppy
Simbad Simbad
Sparrow Sparrow
splitter Microsoft Kernel Audio Splitter
swenum Software Bus Driver
swmidi Microsoft Kernel GS Wavetable Synthesizer
symc810 symc810
symc8xx symc8xx
sym_hi sym_hi
sym_u3 sym_u3
sysaudio Microsoft Kernel System Audio Device
Tcpip TCP/IP Protocol Driver
TDPIPE TDPIPE
TDTCP TDTCP
TermDD Terminal Device Driver
ultra ultra
Update Microcode Update Driver
usbehci Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
usbhub USB2 Enabled Hub
usbuhci Microsoft USB Universal Host Controller Miniport Driver
VgaSave VgaSave
VolSnap VolSnap
Wanarp Remote Access IP ARP Driver
WDICA WDICA
wdmaud Microsoft WINMM WDM Audio Compatibility Driver
WS2IFSL Windows Socket 2.0 Non-IFS Service Provider Support Environment
WudfPf Windows Driver Foundation - User-mode Driver Framework Platform
Driver
WudfRd Windows Driver Foundation - User-mode Driver Framework Reflector
GVTDrv GVTDrv
AODDrive AODDriver
USBSTOR USB Mass Storage Driver

155 kernel mode drivers

File system and filter drivers:


Cdfs Cdfs
Fastfat Fastfat
FltMgr FltMgr
MRxSmb MRxSmb
Msfs Msfs
Mup Mup
NetBIOS NetBIOS Interface
Npfs Npfs
Ntfs Ntfs
Rdbss Rdbss
sr System Restore Filter Driver
Srv Srv
Udfs Udfs

13 file system and filter drivers

Adapter drivers:

0 adapter drivers

Recognizer drivers:

0 recognizer drivers

168 device drivers

Dump ended on 93/2097 at 16:0:54.171

=========================================================================
=========================================================================

<end-of-dump>

You might also like