Code:
*************************************************************
********************** Computer Info ************************
*************************************************************
Logged in user: Bob-PC\Bob
Computer Model: OptiPlex GX280
Computer Manufacturer: Dell Inc.
OS Name: Microsoft Windows 7 Home Premium |C:\Windows|\Device\Harddisk0\Partition1
OS Version: 6.1.7600
System Type: X86-based PC
Total Physical Memory: 2558 MB
Windows Directory: C:\Windows
BIOS Version: Phoenix ROM BIOS PLUS Version 1.10 A08
CPU: Intel(R) Pentium(R) 4 CPU 2.80GHz
Video Card: NVIDIA GeForce 7300 LE
Resolution: 1440 x 900 x 4294967296 colors
*************************************************************
*********************** UAC Status **************************
*************************************************************
UAC is currently enabled
*************************************************************
***************** Installed Applications ********************
*************************************************************
Adobe Reader 9.2 - Location: C:\Program Files\Adobe\Reader 9.0\Reader\
Microsoft Antimalware - Location: C:\Program Files\Microsoft Security Essentials
PVSonyDll - Location: C:\Windows\system32\
Microsoft Security Essentials - Location:
Microsoft Silverlight - Location: c:\Program Files\Microsoft Silverlight\
*************************************************************
************************* Services **************************
*************************************************************
------------------------------------------
Name: Application Experience
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Manual
State: Running
------------------------------------------
Name: Application Layer Gateway Service
Path: C:\Windows\System32\alg.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Application Identity
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Stopped
------------------------------------------
Name: Application Information
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Manual
State: Running
------------------------------------------
Name: Windows Audio Endpoint Builder
Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: Windows Audio
Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: ActiveX Installer (AxInstSV)
Path: C:\Windows\system32\svchost.exe -k AxInstSVGroup
StartMode: Manual
State: Stopped
------------------------------------------
Name: BitLocker Drive Encryption Service
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Base Filtering Engine
Path: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
StartMode: Auto
State: Running
------------------------------------------
Name: Background Intelligent Transfer Service
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Running
------------------------------------------
Name: Computer Browser
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Running
------------------------------------------
Name: Bluetooth Support Service
Path: C:\Windows\system32\svchost.exe -k bthsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Certificate Propagation
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Microsoft .NET Framework NGEN v2.0.50727_X86
Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: COM+ System Application
Path: C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
StartMode: Manual
State: Stopped
------------------------------------------
Name: Cryptographic Services
Path: C:\Windows\system32\svchost.exe -k NetworkService
StartMode: Auto
State: Running
------------------------------------------
Name: DCOM Server Process Launcher
Path: C:\Windows\system32\svchost.exe -k DcomLaunch
StartMode: Auto
State: Running
------------------------------------------
Name: Disk Defragmenter
Path: C:\Windows\system32\svchost.exe -k defragsvc
StartMode: Manual
State: Stopped
------------------------------------------
Name: DHCP Client
Path: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: DNS Client
Path: C:\Windows\system32\svchost.exe -k NetworkService
StartMode: Auto
State: Running
------------------------------------------
Name: Wired AutoConfig
Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Stopped
------------------------------------------
Name: Diagnostic Policy Service
Path: C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
StartMode: Auto
State: Running
------------------------------------------
Name: Extensible Authentication Protocol
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Encrypting File System (EFS)
Path: C:\Windows\System32\lsass.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Media Center Receiver Service
Path: C:\Windows\ehome\ehRecvr.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Media Center Scheduler Service
Path: C:\Windows\ehome\ehsched.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Event Log
Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: COM+ Event System
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Auto
State: Running
------------------------------------------
Name: Fax
Path: C:\Windows\system32\fxssvc.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Function Discovery Provider Host
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Manual
State: Running
------------------------------------------
Name: Function Discovery Resource Publication
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Auto
State: Running
------------------------------------------
Name: Windows Font Cache Service
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Presentation Foundation Font Cache 3.0.0.0
Path: C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Group Policy Client
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Human Interface Device Access
Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Running
------------------------------------------
Name: Health Key and Certificate Management
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: HomeGroup Listener
Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Running
------------------------------------------
Name: HomeGroup Provider
Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
StartMode: Manual
State: Running
------------------------------------------
Name: Windows CardSpace
Path: "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
StartMode: Manual
State: Stopped
------------------------------------------
Name: IKE and AuthIP IPsec Keying Modules
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: PnP-X IP Bus Enumerator
Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Stopped
------------------------------------------
Name: IP Helper
Path: C:\Windows\System32\svchost.exe -k NetSvcs
StartMode: Auto
State: Running
------------------------------------------
Name: CNG Key Isolation
Path: C:\Windows\system32\lsass.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: KtmRm for Distributed Transaction Coordinator
Path: C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation
StartMode: Manual
State: Stopped
------------------------------------------
Name: Server
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Workstation
Path: C:\Windows\System32\svchost.exe -k NetworkService
StartMode: Auto
State: Running
------------------------------------------
Name: Link-Layer Topology Discovery Mapper
Path: C:\Windows\System32\svchost.exe -k LocalService
StartMode: Manual
State: Stopped
------------------------------------------
Name: TCP/IP NetBIOS Helper
Path: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: Media Center Extender Service
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Disabled
State: Stopped
------------------------------------------
Name: Multimedia Class Scheduler
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Windows Firewall
Path: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
StartMode: Auto
State: Running
------------------------------------------
Name: Distributed Transaction Coordinator
Path: C:\Windows\System32\msdtc.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Microsoft iSCSI Initiator Service
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Installer
Path: C:\Windows\system32\msiexec.exe /V
StartMode: Manual
State: Running
------------------------------------------
Name: Microsoft Antimalware Service
Path: "c:\Program Files\Microsoft Security Essentials\MsMpEng.exe"
StartMode: Auto
State: Running
------------------------------------------
Name: Network Access Protection Agent
Path: C:\Windows\System32\svchost.exe -k NetworkService
StartMode: Manual
State: Stopped
------------------------------------------
Name: Netlogon
Path: C:\Windows\system32\lsass.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Network Connections
Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Running
------------------------------------------
Name: Network List Service
Path: C:\Windows\System32\svchost.exe -k LocalService
StartMode: Manual
State: Running
------------------------------------------
Name: Net.Tcp Port Sharing Service
Path: "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
StartMode: Disabled
State: Stopped
------------------------------------------
Name: Network Location Awareness
Path: C:\Windows\System32\svchost.exe -k NetworkService
StartMode: Auto
State: Running
------------------------------------------
Name: Network Store Interface Service
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Auto
State: Running
------------------------------------------
Name: NVIDIA Display Driver Service
Path: C:\Windows\system32\nvvsvc.exe
StartMode: Auto
State: Running
------------------------------------------
Name: Peer Networking Identity Manager
Path: C:\Windows\System32\svchost.exe -k LocalServicePeerNet
StartMode: Manual
State: Running
------------------------------------------
Name: Peer Networking Grouping
Path: C:\Windows\System32\svchost.exe -k LocalServicePeerNet
StartMode: Manual
State: Running
------------------------------------------
Name: Program Compatibility Assistant Service
Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Running
------------------------------------------
Name: Performance Logs & Alerts
Path: C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
StartMode: Manual
State: Stopped
------------------------------------------
Name: Plug and Play
Path: C:\Windows\system32\svchost.exe -k DcomLaunch
StartMode: Auto
State: Running
------------------------------------------
Name: PNRP Machine Name Publication Service
Path: C:\Windows\System32\svchost.exe -k LocalServicePeerNet
StartMode: Manual
State: Stopped
------------------------------------------
Name: Peer Name Resolution Protocol
Path: C:\Windows\System32\svchost.exe -k LocalServicePeerNet
StartMode: Manual
State: Running
------------------------------------------
Name: IPsec Policy Agent
Path: C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
StartMode: Manual
State: Stopped
------------------------------------------
Name: Power
Path: C:\Windows\system32\svchost.exe -k DcomLaunch
StartMode: Auto
State: Running
------------------------------------------
Name: User Profile Service
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Protected Storage
Path: C:\Windows\system32\lsass.exe
StartMode: Manual
State: Running
------------------------------------------
Name: Quality Windows Audio Video Experience
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Stopped
------------------------------------------
Name: Remote Access Auto Connection Manager
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Remote Access Connection Manager
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Routing and Remote Access
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Disabled
State: Stopped
------------------------------------------
Name: Remote Registry
Path: C:\Windows\system32\svchost.exe -k regsvc
StartMode: Manual
State: Stopped
------------------------------------------
Name: RPC Endpoint Mapper
Path: C:\Windows\system32\svchost.exe -k RPCSS
StartMode: Auto
State: Running
------------------------------------------
Name: Remote Procedure Call (RPC) Locator
Path: C:\Windows\system32\locator.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Remote Procedure Call (RPC)
Path: C:\Windows\system32\svchost.exe -k rpcss
StartMode: Auto
State: Running
------------------------------------------
Name: Security Accounts Manager
Path: C:\Windows\system32\lsass.exe
StartMode: Auto
State: Running
------------------------------------------
Name: Smart Card
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Stopped
------------------------------------------
Name: Task Scheduler
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Smart Card Removal Policy
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Backup
Path: C:\Windows\system32\svchost.exe -k SDRSVC
StartMode: Manual
State: Stopped
------------------------------------------
Name: Secondary Logon
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: System Event Notification Service
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Adaptive Brightness
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Stopped
------------------------------------------
Name: Remote Desktop Configuration
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Internet Connection Sharing (ICS)
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Disabled
State: Stopped
------------------------------------------
Name: Shell Hardware Detection
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: SNMP Trap
Path: C:\Windows\System32\snmptrap.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Print Spooler
Path: C:\Windows\System32\spoolsv.exe
StartMode: Auto
State: Running
------------------------------------------
Name: Software Protection
Path: C:\Windows\system32\sppsvc.exe
StartMode: Auto
State: Running
------------------------------------------
Name: SPP Notification Service
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Manual
State: Stopped
------------------------------------------
Name: SSDP Discovery
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Running
------------------------------------------
Name: Secure Socket Tunneling Protocol Service
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Image Acquisition (WIA)
Path: C:\Windows\system32\svchost.exe -k imgsvc
StartMode: Auto
State: Running
------------------------------------------
Name: Microsoft Software Shadow Copy Provider
Path: C:\Windows\System32\svchost.exe -k swprv
StartMode: Manual
State: Stopped
------------------------------------------
Name: Superfetch
Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: Tablet PC Input Service
Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Stopped
------------------------------------------
Name: Telephony
Path: C:\Windows\System32\svchost.exe -k NetworkService
StartMode: Manual
State: Stopped
------------------------------------------
Name: TPM Base Services
Path: C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Stopped
------------------------------------------
Name: Remote Desktop Services
Path: C:\Windows\System32\svchost.exe -k NetworkService
StartMode: Manual
State: Stopped
------------------------------------------
Name: Themes
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Thread Ordering Server
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Manual
State: Stopped
------------------------------------------
Name: Distributed Link Tracking Client
Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: Windows Modules Installer
Path: C:\Windows\servicing\TrustedInstaller.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Interactive Services Detection
Path: C:\Windows\system32\UI0Detect.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: UPnP Device Host
Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Running
------------------------------------------
Name: Desktop Window Manager Session Manager
Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: Credential Manager
Path: C:\Windows\system32\lsass.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Virtual Disk
Path: C:\Windows\System32\vds.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Volume Shadow Copy
Path: C:\Windows\system32\vssvc.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Time
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Manual
State: Stopped
------------------------------------------
Name: Block Level Backup Engine Service
Path: "C:\Windows\system32\wbengine.exe"
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Biometric Service
Path: C:\Windows\system32\svchost.exe -k WbioSvcGroup
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Connect Now - Config Registrar
Path: C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
StartMode: Manual
State: Running
------------------------------------------
Name: Windows Color System
Path: C:\Windows\system32\svchost.exe -k wcssvc
StartMode: Manual
State: Stopped
------------------------------------------
Name: Diagnostic Service Host
Path: C:\Windows\System32\svchost.exe -k LocalService
StartMode: Manual
State: Running
------------------------------------------
Name: Diagnostic System Host
Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Running
------------------------------------------
Name: WebClient
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Event Collector
Path: C:\Windows\system32\svchost.exe -k NetworkService
StartMode: Manual
State: Stopped
------------------------------------------
Name: Problem Reports and Solutions Control Panel Support
Path: C:\Windows\System32\svchost.exe -k netsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Error Reporting Service
Path: C:\Windows\System32\svchost.exe -k WerSvcGroup
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Defender
Path: C:\Windows\System32\svchost.exe -k secsvcs
StartMode: Manual
State: Stopped
------------------------------------------
Name: WinHTTP Web Proxy Auto-Discovery Service
Path: C:\Windows\system32\svchost.exe -k LocalService
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Management Instrumentation
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Windows Remote Management (WS-Management)
Path: C:\Windows\System32\svchost.exe -k NetworkService
StartMode: Manual
State: Stopped
------------------------------------------
Name: WLAN AutoConfig
Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Stopped
------------------------------------------
Name: WMI Performance Adapter
Path: C:\Windows\system32\wbem\WmiApSrv.exe
StartMode: Manual
State: Stopped
------------------------------------------
Name: Windows Media Player Network Sharing Service
Path: "C:\Program Files\Windows Media Player\wmpnetwk.exe"
StartMode: Auto
State: Running
------------------------------------------
Name: Parental Controls
Path: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
StartMode: Manual
State: Stopped
------------------------------------------
Name: Portable Device Enumerator Service
Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Manual
State: Running
------------------------------------------
Name: Security Center
Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: Windows Search
Path: C:\Windows\system32\SearchIndexer.exe /Embedding
StartMode: Auto
State: Running
------------------------------------------
Name: Windows Update
Path: C:\Windows\system32\svchost.exe -k netsvcs
StartMode: Auto
State: Running
------------------------------------------
Name: Windows Driver Foundation - User-mode Driver Framework
Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
StartMode: Auto
State: Running
------------------------------------------
Name: WWAN AutoConfig
Path: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
StartMode: Manual
State: Stopped
------------------------------------------
*************************************************************
******************** Installed Codecs ***********************
*************************************************************
------------------------------------------
Name: C:\Windows\system32\IYUV_32.DLL Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: iyuv_32
------------------------------------------
Name: C:\Windows\system32\TSBYUV.DLL Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: tsbyuv
------------------------------------------
Name: C:\Windows\system32\MSYUV.DLL Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: msyuv
------------------------------------------
Name: C:\Windows\system32\MSADP32.ACM Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: msadp32
------------------------------------------
Name: C:\Windows\system32\MSGSM32.ACM Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: msgsm32
------------------------------------------
Name: C:\Windows\system32\MSG711.ACM Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: msg711
------------------------------------------
Name: C:\Windows\system32\IMAADP32.ACM Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: imaadp32
------------------------------------------
Name: C:\Windows\system32\MSRLE32.DLL Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: msrle32
------------------------------------------
Name: C:\Windows\system32\MSVIDC32.DLL Description:
Version: 6.1.7600.16385
Path: \windows\system32\
FileName: msvidc32
------------------------------------------
Name: C:\Windows\system32\L3CODECA.ACM Description: Fraunhofer IIS MPEG Layer-3 Codec
Version: 1.9.0.401
Path: \windows\system32\
FileName: l3codeca
------------------------------------------
Name: C:\Windows\system32\ICCVID.DLL Description:
Version: 1.10.0.12
Path: \windows\system32\
FileName: iccvid
------------------------------------------
*************************************************************
*********************** Hot Fixes ***************************
*************************************************************
Description: Security Update
HotFixID: KB973525
------------------------------------------
Description: Update
HotFixID: KB974332
------------------------------------------
Description: Update
HotFixID: KB974431
------------------------------------------
Description: Security Update
HotFixID: KB974571
------------------------------------------
Description: Update
HotFixID: KB975364
------------------------------------------
Description: Hotfix
HotFixID: KB975467
------------------------------------------
Description: Update
HotFixID: KB976098
------------------------------------------
Description: Security Update
HotFixID: KB976325
------------------------------------------
*************************************************************
************************* Event Log *************************
*************************************************************
Application - 1/7/2010 2:15:57 PM: The Software Protection service has stopped.
------------------------------------------
Application - 1/7/2010 2:28:38 PM: The Software Protection service is starting.
------------------------------------------
Application - 1/7/2010 2:28:38 PM: Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
------------------------------------------
Application - 1/7/2010 2:28:39 PM: The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 01f5fc37-a99e-45c5-b65e-d762f3518ead, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 2e7d060d-4714-40f2-9896-1e4f15b612ad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 3b965dfc-31d9-4903-886f-873a0382776c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 586bc076-c93d-429a-afe5-a69fbc644e88, 1, 1 [(0 )(1 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/phone/1.0 0x00000000 0)(?)(?)(?)])(2 )]
5: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6a7d5d8a-92af-4e6a-af4b-8fddaec800e5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9ab82e0c-ffc9-4107-baa1-c65a8bd3ccc3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9f83d90f-a151-4665-ae69-30b3f63ec659, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: d2c04e90-c3dd-4260-b0f3-f845f5d27d64, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
------------------------------------------
Application - 1/7/2010 2:28:39 PM: The Software Protection service has started.
6.1.7600.16385
------------------------------------------
Application - 1/7/2010 2:33:42 PM: Windows Installer reconfigured the product. Product Name: Adobe Reader 9.2. Product Version: 9.2.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
------------------------------------------
Application - 1/7/2010 2:33:42 PM: Windows Installer reconfigured the product. Product Name: Microsoft Malware Protection. Product Version: 2.0.6212.2. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
------------------------------------------
Application - 1/7/2010 2:33:43 PM: Windows Installer reconfigured the product. Product Name: PVSonyDll. Product Version: 1.00.0001. Product Language: 1033. Manufacturer: NVIDIA Corporation. Reconfiguration success or error status: 0.
------------------------------------------
Application - 1/7/2010 2:33:43 PM: Windows Installer reconfigured the product. Product Name: Microsoft Security Essentials. Product Version: 1.0.1611.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
------------------------------------------
Application - 1/7/2010 2:33:43 PM: Windows Installer reconfigured the product. Product Name: Microsoft Silverlight. Product Version: 3.0.40818.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
------------------------------------------
Security - 1/7/2010 11:54:24 AM: An attempt was made to register a security event source.
Subject :
Security ID: S-1-5-18
Account Name: BOB-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Process:
Process ID: 0xdd0
Process Name: C:\Windows\System32\VSSVC.exe
Event Source:
Source Name: VSSAudit
Event Source ID: 0x2f942a
------------------------------------------
Security - 1/7/2010 11:54:24 AM: An attempt was made to unregister a security event source.
Subject
Security ID: S-1-5-18
Account Name: BOB-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Process:
Process ID: 0xdd0
Process Name: C:\Windows\System32\VSSVC.exe
Event Source:
Source Name: VSSAudit
Event Source ID: 0x2f942a
------------------------------------------
Security - 1/7/2010 11:54:44 AM: An account was successfully logged on.
Subject:
Security ID: S-1-5-18
Account Name: BOB-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x1ec
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
------------------------------------------
Security - 1/7/2010 11:54:44 AM: Special privileges assigned to new logon.
Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
------------------------------------------
Security - 1/7/2010 11:54:59 AM: An account was successfully logged on.
Subject:
Security ID: S-1-5-18
Account Name: BOB-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x1ec
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
------------------------------------------
Security - 1/7/2010 11:54:59 AM: Special privileges assigned to new logon.
Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
------------------------------------------
Security - 1/7/2010 2:33:42 PM: An account was successfully logged on.
Subject:
Security ID: S-1-5-18
Account Name: BOB-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x1ec
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
------------------------------------------
Security - 1/7/2010 2:33:42 PM: Special privileges assigned to new logon.
Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
------------------------------------------
Security - 1/7/2010 2:34:03 PM: An account was successfully logged on.
Subject:
Security ID: S-1-5-18
Account Name: BOB-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x1ec
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
------------------------------------------
Security - 1/7/2010 2:34:03 PM: Special privileges assigned to new logon.
Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
------------------------------------------
System - 1/7/2010 2:11:20 PM: Driver Management concluded the process to install driver FileRepository\hidserv.inf_x86_neutral_32c4c73e5497e483\hidserv.inf for Device Instance ID HID\VID_045E&PID_00DD&MI_01\7&1219B7D7&0&0000 with the following status: 0x0.
------------------------------------------
System - 1/7/2010 2:15:57 PM: The Software Protection service entered the stopped state.
------------------------------------------
System - 1/7/2010 2:20:54 PM: The Application Experience service entered the stopped state.
------------------------------------------
System - 1/7/2010 2:27:07 PM: The WinHTTP Web Proxy Auto-Discovery Service service entered the stopped state.
------------------------------------------
System - 1/7/2010 2:28:38 PM: The Software Protection service entered the running state.
------------------------------------------
System - 1/7/2010 2:28:41 PM: The Application Experience service entered the running state.
------------------------------------------
System - 1/7/2010 2:32:53 PM: The Diagnostic System Host service entered the running state.
------------------------------------------
System - 1/7/2010 2:32:55 PM: The Program Compatibility Assistant service successfully performed phase two initialization.
------------------------------------------
System - 1/7/2010 2:33:42 PM: The Windows Installer service entered the running state.
------------------------------------------
System - 1/7/2010 2:34:04 PM: The Windows Modules Installer service entered the running state.
------------------------------------------
*************************************************************
**************** Windows Experience Index *******************
*************************************************************
CPU Score: 3.7
Disk Score: 5.4
Graphics Score: 3.1
Direct 3D Score: 3.1
Memory Score: 4.5
WEI Score: 3.1
*************************************************************
************************* Users *****************************
*************************************************************
------------------------------------------
Name: Administrator Domain: Bob-PC
FullName: Description: Built-in account for administering the computer/domain
Disabled: True
Status: Degraded
LocalAccount: True
PasswordChangeable: True
PasswordExpires: False
PasswordRequired: True
------------------------------------------
Name: Bob Domain: Bob-PC
FullName: Description:
Disabled: False
Status: OK
LocalAccount: True
PasswordChangeable: True
PasswordExpires: False
PasswordRequired: False
------------------------------------------
Name: Guest Domain: Bob-PC
FullName: Description: Built-in account for guest access to the computer/domain
Disabled: True
Status: Degraded
LocalAccount: True
PasswordChangeable: False
PasswordExpires: False
PasswordRequired: False
------------------------------------------
Name: HomeGroupUser$ Domain: Bob-PC
FullName: HomeGroupUser$ Description: Built-in account for homegroup access to the computer
Disabled: False
Status: OK
LocalAccount: True
PasswordChangeable: True
PasswordExpires: False
PasswordRequired: True
------------------------------------------
*************************************************************
************************** Memory ***************************
*************************************************************
------------------------------------------
Manufacturer: 7F7F7F0B00000000
Model:
Name: Physical Memory
Bank Label:
Capacity: 512 MB
Description: Physical Memory
Tag: Physical Memory 0
------------------------------------------
Manufacturer: 7F7F7F0B00000000
Model:
Name: Physical Memory
Bank Label:
Capacity: 1024 MB
Description: Physical Memory
Tag: Physical Memory 1
------------------------------------------
Manufacturer: 0000000000000000
Model:
Name: Physical Memory
Bank Label:
Capacity: 512 MB
Description: Physical Memory
Tag: Physical Memory 2
------------------------------------------
Manufacturer: CE00000000000000
Model:
Name: Physical Memory
Bank Label:
Capacity: 512 MB
Description: Physical Memory
Tag: Physical Memory 3
------------------------------------------
*************************************************************
************************ Video Card *************************
*************************************************************
Brand: NVIDIA
Model: NVIDIA GeForce 7300 LE
Adapter DAC Type: Integrated RAMDAC
Adapter RAM: 64 MB
Current BitsPerPixel: 32
Current Number Of Colors: 4294967296
Current Refresh Rate: 59
Driver Date: 09/27/2009 00:00:00
Driver Version: 8.16.11.9107
MaxRefreshRate: 75
MinRefreshRate: 56
Status: OK
Video Memory Type: 2
Video Mode Description: 1440 x 900 x 4294967296 colors
Video Processor: GeForce 7300 LE
*************************************************************
************************** Drives ***************************
*************************************************************
Model: WDC WD800JD-75MSA3 ATA Device
Description: Disk drive
InterfaceType: IDE
Partitions: 1
SCSIBus: 0
SCSILogicalUnit: 0
SCSIPort: 1
SCSITargetId: 0
SectorsPerTrack: 63
Size: 75 GB
Status: OK
------------------------------------------
Model: Canon MP470 series USB Device
Description: Disk drive
InterfaceType: USB
Partitions: 0
SCSIBus:
SCSILogicalUnit:
SCSIPort:
SCSITargetId:
SectorsPerTrack:
Size: 0 GB
Status: OK
------------------------------------------
Model: WDC WD20 00BEVS-00UST0 USB Device
Description: Disk drive
InterfaceType: USB
Partitions: 1
SCSIBus:
SCSILogicalUnit:
SCSIPort:
SCSITargetId:
SectorsPerTrack: 63
Size: 186 GB
Status: OK
------------------------------------------
*************************************************************
************************ CD/DVD Rom *************************
*************************************************************
Name: HL-DT-ST RW/DVD GCC-4481B ATA Device
Description: CD-ROM Drive
LastErrorCode:
Manufacturer: (Standard CD-ROM drives)
Media Type: CD Writer
------------------------------------------
*************************************************************
************************* IDE/SATA **************************
*************************************************************
------------------------------------------
Manufacturer: Intel
Name: Intel(R) 82801FB/FBM Ultra ATA Storage Controllers - 266F
Last Error Code:
Status: OK
------------------------------------------
Manufacturer: (Standard IDE ATA/ATAPI controllers)
Name: ATA Channel 0
Last Error Code:
Status: OK
------------------------------------------
Manufacturer: (Standard IDE ATA/ATAPI controllers)
Name: ATA Channel 0
Last Error Code:
Status: OK
------------------------------------------
Manufacturer: Intel
Name: Intel(R) 82801FB Ultra ATA Storage Controllers - 2651
Last Error Code:
Status: OK
------------------------------------------
*************************************************************
************************** Network **************************
*************************************************************
Windows IP Configuration
Host Name . . . . . . . . . . . . : Bob-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom NetXtreme 57xx Gigabit Controller
Physical Address. . . . . . . . . : 00-11-43-A0-A3-FA
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::30c8:d811:7516:b19d%11(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.2.7(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Thursday, January 07, 2010 10:09:19 AM
Lease Expires . . . . . . . . . . : Friday, January 08, 2010 10:09:19 AM
Default Gateway . . . . . . . . . : 192.168.2.1
DHCP Server . . . . . . . . . . . : 192.168.2.1
DHCPv6 IAID . . . . . . . . . . . : 234885443
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-12-D7-CF-06-00-11-43-A0-A3-FA
DNS Servers . . . . . . . . . . . : 192.168.2.1
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter isatap.{DB30418E-370B-4418-9FCF-DA60A1F980A7}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 9:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e50:ccc:c927:bc71:cf52(Preferred)
Link-local IPv6 Address . . . . . : fe80::ccc:c927:bc71:cf52%13(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled
*************************************************************
********************* Systerm Restore ***********************
*************************************************************
------------------------------------------
Description: Windows Update
Creation Time: 01/07/2010 15:32:28
SequenceNumber: 1
------------------------------------------
Description: Windows Update
Creation Time: 01/07/2010 15:42:49
SequenceNumber: 2
------------------------------------------
Description: Windows Update
Creation Time: 01/07/2010 16:02:41
SequenceNumber: 3
------------------------------------------
Description: Installed Adobe Reader 9.2.
Creation Time: 01/07/2010 17:53:52
SequenceNumber: 4
------------------------------------------
*************************************************************
******************** Running Processes **********************
*************************************************************
------------------------------------------
Name: System Idle Process
------------------------------------------
Name: System
------------------------------------------
Name: smss.exe
------------------------------------------
Name: csrss.exe
------------------------------------------
Name: wininit.exe
------------------------------------------
Name: csrss.exe
------------------------------------------
Name: winlogon.exe
------------------------------------------
Name: services.exe
------------------------------------------
Name: lsass.exe
------------------------------------------
Name: lsm.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: nvvsvc.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: MsMpEng.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: spoolsv.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: nvvsvc.exe
------------------------------------------
Name: taskhost.exe
------------------------------------------
Name: dwm.exe
------------------------------------------
Name: explorer.exe
------------------------------------------
Name: msseces.exe
------------------------------------------
Name: wmpnetwk.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: svchost.exe
------------------------------------------
Name: SearchIndexer.exe
------------------------------------------
Name: audiodg.exe
------------------------------------------
Name: WUDFHost.exe
------------------------------------------
Name: sppsvc.exe
------------------------------------------
Name: iexplore.exe
------------------------------------------
Name: iexplore.exe
------------------------------------------
Name: FlashUtil10d.exe
------------------------------------------
Name: iexplore.exe
------------------------------------------
Name: 6023d1219438947-vistaforums-sysinfo-tool-vistaforums-sysinfo[1].exe
------------------------------------------
Name: WmiPrvSE.exe
------------------------------------------
Name: WmiPrvSE.exe
------------------------------------------
Name: msiexec.exe
------------------------------------------
Name: TrustedInstaller.exe
------------------------------------------
Name: dllhost.exe
------------------------------------------
Name: VSSVC.exe
------------------------------------------
Name: svchost.exe
------------------------------------------