PDA

View Full Version : HELP! I've been HIJACKED!



TheOnlyBigDog
2008-08-22, 03:46
I ran S&D and it found a "MY811Toolbar" and as always proceeded to remove it. But as soon as I reboot, it's back dragging me all over the internet. Trying to work offline and somehow reset my entire system. I tried everthing. I have the full version of SuperAntiSpyware and several other programs. But S&D is the only proggie that is finding it. Thanks in advance. TheOnlyBigDog:sad:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:59:06 PM, on 8/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Common Files\smsse.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/status&s=cr8kMx1bHMmXFhyuqFoV20YGjus
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Embarq Toolbar - {4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C} - C:\PROGRA~1\EMBARQ~1\EMBARQ~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: The Pirate Bay Toolbar - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Embarq Toolbar - {4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C} - C:\PROGRA~1\EMBARQ~1\EMBARQ~1.DLL
O3 - Toolbar: The Pirate Bay Toolbar - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\Program Files\CDG Ripper\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?bddddd47547245459cb187e1ed5beb84
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?bddddd47547245459cb187e1ed5beb84
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15035/CTPID.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{406908A1-9718-4063-BEF7-E5A3B1D2D742}: NameServer = 65.41.120.51,208.13.143.36
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 16663 bytes

Shaba
2008-08-25, 08:35
Hi TheOnlyBigDog

Please post next spybot report :)

TheOnlyBigDog
2008-08-25, 09:21
My811.Toolbar: [SBI $DE17AB60] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1343024091-1123561945-839522115-1003\Software\XTTB00001


--- Spybot - Search & Destroy version: 1.6.0 (build: 20080729) ---

2008-07-30 blindman.exe (1.0.0.8)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-07-30 SDFiles.exe (1.6.0.4)
2008-07-30 SDMain.exe (1.0.0.6)
2008-07-30 SDShred.exe (1.0.2.3)
2008-07-30 SDUpdate.exe (1.6.0.9)
2008-07-30 SDWinSec.exe (1.0.0.12)
2008-07-30 SpybotSD.exe (1.6.0.31)
2008-08-18 TeaTimer.exe (1.6.2.23)
2007-10-03 unins000.exe (51.41.0.0)
2008-08-08 unins001.exe (51.49.0.0)
2008-07-30 Update.exe (1.6.0.7)
2008-07-30 advcheck.dll (1.6.1.12)
2007-04-02 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-07-30 SDHelper.dll (1.6.0.12)
2008-06-19 sqlite3.dll
2008-07-30 Tools.dll (2.1.5.7)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2008-08-05 Includes\Adware.sbi (*)
2008-08-19 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-06-03 Includes\Dialer.sbi (*)
2008-08-05 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-08-19 Includes\Hijackers.sbi (*)
2008-08-19 Includes\HijackersC.sbi (*)
2008-08-05 Includes\Keyloggers.sbi (*)
2008-08-12 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-08-20 Includes\Malware.sbi (*)
2008-08-19 Includes\MalwareC.sbi (*)
2008-08-05 Includes\PUPS.sbi (*)
2008-08-19 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-08-19 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-08-12 Includes\Spyware.sbi (*)
2008-08-12 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-08-05 Includes\Trojans.sbi (*)
2008-08-20 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



--- System information ---
Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
/ Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
/ Windows / SP1: Microsoft National Language Support Downlevel APIs
/ Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
/ Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
/ Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
/ Windows Media Player 9: Security Update for Windows Media Player 9 (KB936782)
/ Windows XP: Security Update for Windows XP (KB923689)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB939653)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB950759)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB953838)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB885884
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: High Definition Audio Driver Package - KB888111
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Hotfix for Windows XP (KB896344)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Update for Windows XP (KB900485)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Update for Windows XP (KB904942)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Update for Windows XP (KB908531)
/ Windows XP / SP3: Update for Windows XP (KB910437)
/ Windows XP / SP3: Update for Windows XP (KB911164)
/ Windows XP / SP3: Update for Windows XP (KB911280)
/ Windows XP / SP3: Security Update for Windows XP (KB911562)
/ Windows XP / SP3: Security Update for Windows XP (KB911927)
/ Windows XP / SP3: Security Update for Windows XP (KB913580)
/ Windows XP / SP3: Security Update for Windows XP (KB914388)
/ Windows XP / SP3: Security Update for Windows XP (KB914389)
/ Windows XP / SP3: Hotfix for Windows XP (KB914440)
/ Windows XP / SP3: Hotfix for Windows XP (KB915865)
/ Windows XP / SP3: Update for Windows XP (KB916595)
/ Windows XP / SP3: Security Update for Windows XP (KB917344)
/ Windows XP / SP3: Security Update for Windows XP (KB917953)
/ Windows XP / SP3: Security Update for Windows XP (KB918118)
/ Windows XP / SP3: Security Update for Windows XP (KB918439)
/ Windows XP / SP3: Security Update for Windows XP (KB919007)
/ Windows XP / SP3: Security Update for Windows XP (KB920213)
/ Windows XP / SP3: Update for Windows XP (KB920342)
/ Windows XP / SP3: Security Update for Windows XP (KB920670)
/ Windows XP / SP3: Security Update for Windows XP (KB920683)
/ Windows XP / SP3: Security Update for Windows XP (KB920685)
/ Windows XP / SP3: Update for Windows XP (KB920872)
/ Windows XP / SP3: Security Update for Windows XP (KB921503)
/ Windows XP / SP3: Update for Windows XP (KB922582)
/ Windows XP / SP3: Security Update for Windows XP (KB922819)
/ Windows XP / SP3: Security Update for Windows XP (KB923191)
/ Windows XP / SP3: Security Update for Windows XP (KB923414)
/ Windows XP / SP3: Security Update for Windows XP (KB923980)
/ Windows XP / SP3: Security Update for Windows XP (KB924270)
/ Windows XP / SP3: Security Update for Windows XP (KB924496)
/ Windows XP / SP3: Security Update for Windows XP (KB924667)
/ Windows XP / SP3: Update for Windows XP (KB925720)
/ Windows XP / SP3: Update for Windows XP (KB925876)
/ Windows XP / SP3: Security Update for Windows XP (KB925902)
/ Windows XP / SP3: Hotfix for Windows XP (KB926239)
/ Windows XP / SP3: Security Update for Windows XP (KB926255)
/ Windows XP / SP3: Security Update for Windows XP (KB926436)
/ Windows XP / SP3: Security Update for Windows XP (KB927779)
/ Windows XP / SP3: Security Update for Windows XP (KB927802)
/ Windows XP / SP3: Update for Windows XP (KB927891)
/ Windows XP / SP3: Security Update for Windows XP (KB928255)
/ Windows XP / SP3: Security Update for Windows XP (KB928843)
/ Windows XP / SP3: Security Update for Windows XP (KB929123)
/ Windows XP / SP3: Security Update for Windows XP (KB930178)
/ Windows XP / SP3: Update for Windows XP (KB930916)
/ Windows XP / SP3: Security Update for Windows XP (KB931261)
/ Windows XP / SP3: Security Update for Windows XP (KB931784)
/ Windows XP / SP3: Security Update for Windows XP (KB932168)
/ Windows XP / SP3: Update for Windows XP (KB932823-v3)
/ Windows XP / SP3: Update for Windows XP (KB933360)
/ Windows XP / SP3: Security Update for Windows XP (KB933729)
/ Windows XP / SP3: Security Update for Windows XP (KB935839)
/ Windows XP / SP3: Security Update for Windows XP (KB935840)
/ Windows XP / SP3: Security Update for Windows XP (KB936021)
/ Windows XP / SP3: Security Update for Windows XP (KB937143)
/ Windows XP / SP3: Security Update for Windows XP (KB937894)
/ Windows XP / SP3: Security Update for Windows XP (KB938127)
/ Windows XP / SP3: Update for Windows XP (KB938828)
/ Windows XP / SP3: Security Update for Windows XP (KB938829)
/ Windows XP / SP3: Security Update for Windows XP (KB939653)
/ Windows XP / SP3: Security Update for Windows XP (KB941202)
/ Windows XP / SP3: Security Update for Windows XP (KB941568)
/ Windows XP / SP3: Security Update for Windows XP (KB941644)
/ Windows XP / SP3: Security Update for Windows XP (KB941693)
/ Windows XP / SP3: Update for Windows XP (KB942763)
/ Windows XP / SP3: Security Update for Windows XP (KB943055)
/ Windows XP / SP3: Security Update for Windows XP (KB943460)
/ Windows XP / SP3: Security Update for Windows XP (KB943485)
/ Windows XP / SP3: Security Update for Windows XP (KB944338)
/ Windows XP / SP3: Security Update for Windows XP (KB944653)
/ Windows XP / SP3: Security Update for Windows XP (KB945553)
/ Windows XP / SP3: Security Update for Windows XP (KB946026)
/ Windows XP / SP3: Security Update for Windows XP (KB947864)
/ Windows XP / SP3: Security Update for Windows XP (KB948590)
/ Windows XP / SP3: Security Update for Windows XP (KB948881)
/ Windows XP / SP3: Security Update for Windows XP (KB950749)
/ Windows XP / SP4: Security Update for Windows XP (KB946648)
/ Windows XP / SP4: Security Update for Windows XP (KB950759)
/ Windows XP / SP4: Security Update for Windows XP (KB950760)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Update for Windows XP (KB951072-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951376)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951698)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Hotfix for Windows XP (KB952287)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB953839)
/ XML Paper Specification Shared Components Pack 1.0: XML Paper Specification Shared Components Pack 1.0


--- Startup entries list ---
Located: HK_LM:Run, Babylon Client
command: C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
file: C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
size: 3551456
MD5: DDB78E613CF70A5DC50797E99A4ADB72

Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 58728
MD5: B76FCE8AA8705A8A0DC240D83BD29AD4

Located: HK_LM:Run, CTHelper
command: CTHELPER.EXE
file: C:\WINDOWS\CTHELPER.EXE
size: 17920
MD5: 866346F3D82F0CA2C7D80AFF41A6E1D3

Located: HK_LM:Run, ISUSPM
command: "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
file: C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
size: 213936
MD5: 2BAD84B393AF47006D80BA2F03B18029

Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\NvCpl.dll
size: 8466432
MD5: 1E7BD636B297830582A5587CFD779784

Located: HK_LM:Run, NvMediaCenter
command: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
file: C:\WINDOWS\system32\NvMcTray.dll
size: 81920
MD5: 33423165FDC8CCE60FF2659AF2F7BF70

Located: HK_LM:Run, nwiz
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 1626112
MD5: C6B1971E12A35FB69D64D01B915E1AA1

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 385024
MD5: F89DA660C511652EE511FE3AB2F04BFC

Located: HK_LM:Run, TkBellExe
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-1343024091-1123561945-839522115-1003...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, DW4
where: S-1-5-21-1343024091-1123561945-839522115-1003...
command: "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
file: C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
size: 715888
MD5: 5B2B3C5C3274B32C499E005AD44B0760

Located: HK_CU:Run, MSMSGS
where: S-1-5-21-1343024091-1123561945-839522115-1003...
command: "C:\Program Files\Messenger\msmsgs.exe" /background
file: C:\Program Files\Messenger\msmsgs.exe
size: 1694208
MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259

Located: HK_CU:Run, SUPERAntiSpyware
where: S-1-5-21-1343024091-1123561945-839522115-1003...
command: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
file: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
size: 1506544
MD5: 24A3D7D9DD5555F409CF909600D32D60

Located: Startup (disabled), Adobe Reader Speed Launch (DISABLED)
command: C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE
file: C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE
size: 39792
MD5: 8B9145D229D4E89D15ACB820D4A3A90F

Located: Startup (disabled), Adobe Reader Synchronizer (DISABLED)
command: C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE
file: C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE
size: 738968
MD5: 1C1C6ABBC3408A373C731EC3F41EAE16

Located: Startup (disabled), DualCoreCenter (DISABLED)
command: C:\PROGRA~1\MSI\DUALCO~1\STARTU~1.EXE
file: C:\PROGRA~1\MSI\DUALCO~1\STARTU~1.EXE
size: 192512
MD5: 4B5A0F4632CFA836D055E8C1CE217245

Located: Startup (disabled), InterVideo WinCinema Manager (DISABLED)
command: C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE
file: C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE
size: 270336
MD5: 46A6365179EE6C91A6B483B36794049A

Located: Startup (disabled), Logitech Desktop Messenger (DISABLED)
command: C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LOGITE~1.EXE -startup
file: C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LOGITE~1.EXE
size: 67128
MD5: 68A51D792E28FF88D924D8C445327532

Located: Startup (disabled), Microsoft Office (DISABLED)
command: C:\PROGRA~1\MICROS~3\Office10\OSA.EXE -b -l
file: C:\PROGRA~1\MICROS~3\Office10\OSA.EXE
size: 83360
MD5: 5BC65464354A9FD3BEAA28E18839734A

Located: Startup (disabled), PlexTools Professional (DISABLED)
command: C:\PROGRA~1\Plextor\PlexTool.exe Startup
file: C:\PROGRA~1\Plextor\PlexTool.exe
size: 6610944
MD5: D59E2B2046533AAD68CE4DEE085B7913

Located: Startup (disabled), SecureDoc (DISABLED)
command: C:\PROGRA~1\MSI\SECURE~1\Logon.exe
file: C:\PROGRA~1\MSI\SECURE~1\Logon.exe
size: 82944
MD5: 43DB2C2C39E0ADF3AA7B44CD7A93362C

Located: Startup (disabled), AutoMate 5 Event Watcher (DISABLED)
command:
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: Startup (disabled), Reality Fusion GameCam SE (DISABLED)
command: C:\PROGRA~1\REALIT~1\REALIT~1\Program\RFTRay.exe
file: C:\PROGRA~1\REALIT~1\REALIT~1\Program\RFTRay.exe
size: 323584
MD5: 3C1A904E6CD00A1FC12092A6E0A3ED99

Located: Startup (disabled), VirtuaGirl (DISABLED)
command: C:\PROGRA~1\Vg\Vg.exe
file: C:\PROGRA~1\Vg\Vg.exe
size: 286720
MD5: DFFAE4178C24985580CF7ACD05E7B8A8

Located: WinLogon, !SASWinLogon
command: C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
file: C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
size: 294912
MD5: 3B2F85D8C913CE452ADE4A0D24299FEA

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!



--- Browser helper object list ---
{055FD26D-3A88-4e15-963D-DC8493744B1D} (XTTBPos00)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: XTTBPos00
CLSID name: XTTBPos00 Class
Path: C:\PROGRA~1\ICQTOO~1\
Long name: toolbaru.dll
Short name:
Date (created): 10/1/2007 2:27:58 AM
Date (last access): 8/24/2008 11:59:46 PM
Date (last write): 12/25/2006 1:40:44 AM
Filesize: 701952
Attributes: archive
MD5: AA5C6EF83EDB52FBA853FCB8BBB90F49
CRC32: A2EE5A05
Version: 2.0.20.11

{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} (Winamp Toolbar Loader)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: Winamp Toolbar Loader
CLSID name: Winamp Toolbar Loader
Path: C:\Program Files\Winamp Toolbar\
Long name: winamptb.dll
Short name:
Date (created): 3/19/2008 3:36:36 PM
Date (last access): 8/25/2008 12:00:04 AM
Date (last write): 3/19/2008 3:36:36 PM
Filesize: 1267040
Attributes: archive
MD5: 26455931D03F5A4922C36D6D736E7B16
CRC32: E378366E
Version: 5.1.20.3

{34ea1c70-42cc-42c5-aa29-ec58b95a343e} (myBabylon Toolbar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: myBabylon Toolbar
Path: C:\Program Files\myBabylon\
Long name: tbmyBa.dll
Short name:
Date (created): 8/23/2008 12:05:10 PM
Date (last access): 8/25/2008 12:00:06 AM
Date (last write): 8/5/2008 2:13:54 AM
Filesize: 1610264
Attributes: archive
MD5: 7E5375194F08B61E0D24C83999EBD078
CRC32: 4A0B0C8F
Version: 4.5.187.7

{4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C} (Embarq Toolbar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Embarq Toolbar
Path: C:\PROGRA~1\EMBARQ~1\
Long name: embarqtoolbar.dll
Short name: EMBARQ~1.DLL
Date (created): 6/8/2007 4:13:00 PM
Date (last access): 8/25/2008 12:00:08 AM
Date (last write): 6/8/2007 4:13:00 PM
Filesize: 1897472
Attributes: archive
MD5: 37F91C14A835043F4E457E47CF9BB961
CRC32: 4E72CECA
Version: 5.0.1.0

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} (Yahoo! IE Services Button)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Yahoo! IE Services Button
Path: C:\Program Files\Yahoo!\Common\
Long name: yiesrvc.dll
Short name:
Date (created): 10/31/2006 1:33:52 PM
Date (last access): 8/25/2008 12:00:18 AM
Date (last write): 10/31/2006 1:33:52 PM
Filesize: 198136
Attributes: archive
MD5: F8981F09E8DA4FDB7F6B6E2B5361AEAE
CRC32: 2CDBBB6C
Version: 2006.10.31.3

{7E853D72-626A-48EC-A868-BA8D5E23E045} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:

{9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Windows Live Sign-in Helper
Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
Long name: WindowsLiveLogin.dll
Short name: WINDOW~1.DLL
Date (created): 8/31/2006 8:33:06 PM
Date (last access): 8/25/2008 12:00:22 AM
Date (last write): 8/31/2006 8:33:06 PM
Filesize: 322368
Attributes: archive
MD5: E43F7CFDEE2B00A22C96C168147B20D3
CRC32: 2AEACC43
Version: 4.100.313.1

{a33fa729-d155-4b23-842b-2c665ecabdb6} (The Pirate Bay Toolbar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: The Pirate Bay Toolbar
Path: C:\Program Files\The_Pirate_Bay\
Long name: tbThe1.dll
Short name:
Date (created): 7/8/2008 2:57:22 PM
Date (last access): 8/24/2008 11:59:58 PM
Date (last write): 7/8/2008 2:57:26 PM
Filesize: 1569304
Attributes: archive
MD5: 57B36B398D9742A8382BCEE3E2E5DECB
CRC32: C7C8956F
Version: 4.5.186.6

{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
info link: http://toolbar.google.com/
info source: TonyKlein
Path: c:\program files\google\
Long name: GoogleToolbar1.dll
Short name: GOOGLE~1.DLL
Date (created): 4/16/2008 7:49:00 PM
Date (last access): 8/25/2008 12:00:36 AM
Date (last write): 4/16/2008 7:49:00 PM
Filesize: 2554944
Attributes: readonly archive
MD5: C898A8FC22C86857A58147351A534D5C
CRC32: 45F483F8
Version: 4.0.1602.1060

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Google Toolbar Notifier BHO
Path: C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\
Long name: swg.dll
Short name:
Date (created): 4/8/2008 4:52:00 PM
Date (last access): 8/25/2008 12:00:48 AM
Date (last write): 4/8/2008 4:52:00 PM
Filesize: 734704
Attributes: archive
MD5: F1D0608833F726C8FF84E11A46843CDE
CRC32: 0AF4F0EF
Version: 3.0.1225.9868

{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Windows Live Toolbar Helper
Path: C:\Program Files\Windows Live Toolbar\
Long name: msntb.dll
Short name:
Date (created): 10/19/2007 12:20:48 PM
Date (last access): 8/25/2008 12:00:50 AM
Date (last write): 10/19/2007 12:20:48 PM
Filesize: 546320
Attributes: archive
MD5: CEE1BE1DA21300208D07FBEAE9EA2B51
CRC32: 12446524
Version: 3.1.0.146

{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} (SingleInstance Class)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: SingleInstance Class
Path: C:\Program Files\Yahoo!\Companion\Installs\cpn1\
Long name: YTSingleInstance.dll
Short name: YTSING~1.DLL
Date (created): 7/15/2008 6:46:06 AM
Date (last access): 8/25/2008 12:00:56 AM
Date (last write): 7/15/2008 6:46:06 AM
Filesize: 160496
Attributes: archive
MD5: FF51867CAB8F352FE28558694BD688AC
CRC32: 151C194C
Version: 2008.6.2.1



--- ActiveX list ---
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
Installer:
Codebase: file:///C:/WINDOWS/Java/classes/xmldso.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla

{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool)
DPF name:
CLSID name: Office Genuine Advantage Validation Tool
Installer: C:\WINDOWS\Downloaded Program Files\OGAControl.inf
Codebase: http://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
Path: C:\WINDOWS\system32\
Long name: OGACheckControl.DLL
Short name: OGACHE~1.DLL
Date (created): 3/5/2007 2:34:28 PM
Date (last access): 8/25/2008 12:05:30 AM
Date (last write): 3/5/2007 2:34:28 PM
Filesize: 676224
Attributes: archive
MD5: B221B218126BC9409257F39837BAB90C
CRC32: 60F920AA
Version: 1.6.21.0

{0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate)
DPF name:
CLSID name: Creative Software AutoUpdate
Installer: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\CTSUEng.inf
Codebase: http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
description:
classification: Legitimate
known filename: CTSUEng.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\DOWNLO~1\CONFLICT.1\
Long name: CTSUEng.ocx
Short name:
Date (created): 6/8/2007 4:33:12 PM
Date (last access): 8/22/2008 8:39:04 PM
Date (last write): 6/8/2007 4:33:12 PM
Filesize: 231200
Attributes: archive
MD5: 987047E9CD80B5793F3109B9EC6BAEE5
CRC32: 9FA03E57
Version: 1.50.16.0

{0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility)
DPF name:
CLSID name: PCPitstop Utility
Installer: C:\WINDOWS\Downloaded Program Files\PCPitstop.inf
Codebase: http://pcpitstop.com/pcpitstop/PCPitStop.CAB
description: Gateway tools
classification: Legitimate
known filename: PCPITSTOP.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\Downloaded Program Files\
Long name: PCPitstop.dll
Short name: PCPITS~1.DLL
Date (created): 10/1/2007 12:21:12 PM
Date (last access): 8/22/2008 8:39:04 PM
Date (last write): 10/1/2007 12:21:12 PM
Filesize: 345816
Attributes: archive
MD5: 773032254F447D5527A17C380D59AFF9
CRC32: 805A9CE8
Version: 1.0.0.179

{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object)
DPF name:
CLSID name: CKAVWebScan Object
Installer: C:\WINDOWS\Downloaded Program Files\kavwebscan.inf
Codebase: http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\
Long name: kavwebscan.dll
Short name: KAVWEB~1.DLL
Date (created): 8/29/2007 3:49:54 PM
Date (last access): 8/22/2008 8:45:30 PM
Date (last write): 8/29/2007 3:49:54 PM
Filesize: 950272
Attributes: archive
MD5: BC915C49931CE46222F9B0A7EFB56CEE
CRC32: 11048171
Version: 5.0.98.0

{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support)
DPF name:
CLSID name: Installation Support
Installer:
Codebase: C:\Program Files\Yahoo!\Common\Yinsthelper.dll
description: Yahoo! Installation helper
classification: Legitimate
known filename: %SystemRoot%\Downloaded Program Files\yinsthelper.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Yahoo!\Common\
Long name: YInstHelper.dll
Short name: YINSTH~1.DLL
Date (created): 3/15/2007 7:13:06 PM
Date (last access): 8/22/2008 8:29:22 PM
Date (last write): 3/15/2007 7:13:06 PM
Filesize: 209448
Attributes: archive
MD5: 4380A4799E826AF03FD975B4A71E9268
CRC32: 423BF1F7
Version: 2007.3.15.1

{459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class)
DPF name:
CLSID name: get_atlcom Class
Installer:
Codebase: http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
Path: C:\WINDOWS\Downloaded Program Files\
Long name: IEGetPlugin.ocx
Short name: IEGETP~1.OCX
Date (created): 11/29/2007 2:48:26 PM
Date (last access): 8/22/2008 8:39:04 PM
Date (last write): 11/29/2007 2:48:32 PM
Filesize: 91256
Attributes: archive
MD5: 26B81790C8EDF4D4DAE174E37C8BF1A4
CRC32: 2B0C93E5
Version: 1.2.0.24

{56762DEC-6B0D-4AB4-A8AD-989993B5D08B} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\OnlineScanner.inf
Codebase: http://www.eset.eu/buxus/docs/OnlineScanner.cab

{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_03
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre1.6.0_03\bin\
Long name: npjpi160_03.dll
Short name: NPJPI1~1.DLL
Date (created): 9/25/2007 12:31:44 AM
Date (last access): 8/22/2008 8:22:44 PM
Date (last write): 9/25/2007 2:11:34 AM
Filesize: 132496
Attributes: archive
MD5: D6A4682A6FF41832A3F1A7AB9AE08199
CRC32: 9080B537
Version: 6.0.30.5

{B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class)
DPF name:
CLSID name: SABScanProcesses Class
Installer: C:\WINDOWS\Downloaded Program Files\sabspx.inf
Codebase: http://www.superadblocker.com/activex/sabspx.cab
description:
classification: Legitimate
known filename: sabspx.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: sabspx.dll
Short name:
Date (created): 9/4/2007 4:59:42 PM
Date (last access): 8/22/2008 8:39:04 PM
Date (last write): 9/4/2007 4:59:42 PM
Filesize: 380144
Attributes: archive
MD5: B2BA62258E77D34B4EA0A30ED408BBB9
CRC32: 0DD48706
Version: 1.0.0.1044

{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_03
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
Path: C:\Program Files\Java\jre1.6.0_03\bin\
Long name: npjpi160_03.dll
Short name: NPJPI1~1.DLL
Date (created): 9/25/2007 12:31:44 AM
Date (last access): 8/25/2008 12:16:38 AM
Date (last write): 9/25/2007 2:11:34 AM
Filesize: 132496
Attributes: archive
MD5: D6A4682A6FF41832A3F1A7AB9AE08199
CRC32: 9080B537
Version: 6.0.30.5

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_03
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre1.6.0_03\bin\
Long name: npjpi160_03.dll
Short name: NPJPI1~1.DLL
Date (created): 9/25/2007 12:31:44 AM
Date (last access): 8/25/2008 12:16:38 AM
Date (last write): 9/25/2007 2:11:34 AM
Filesize: 132496
Attributes: archive
MD5: D6A4682A6FF41832A3F1A7AB9AE08199
CRC32: 9080B537
Version: 6.0.30.5

{F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package)
DPF name:
CLSID name: Creative Software AutoUpdate Support Package
Installer: C:\WINDOWS\Downloaded Program Files\CTPID.inf
Codebase: http://www.creative.com/softwareupdate/su/ocx/15035/CTPID.cab
description:
classification: Legitimate
known filename: CTPID.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\DOWNLO~1\CONFLICT.1\
Long name: CTPID.ocx
Short name:
Date (created): 1/11/2008 3:58:38 PM
Date (last access): 8/22/2008 8:39:04 PM
Date (last write): 1/16/2008 2:35:32 PM
Filesize: 37616
Attributes: archive
MD5: 90957451F49E0357C65D5924A37B4168
CRC32: BA79917A
Version: 1.0.43.0

{FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control)
DPF name:
CLSID name: DownloadManager Control
Installer: C:\WINDOWS\Downloaded Program Files\DownloadManagerV2.inf
Codebase: http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
description:
classification: Open for discussion
known filename: DOWNLO~1.OCX
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\DOWNLO~1\
Long name: DownloadManagerV2.ocx
Short name: DOWNLO~1.OCX
Date (created): 6/22/2007 7:31:26 AM
Date (last access): 8/22/2008 8:39:04 PM
Date (last write): 6/22/2007 7:31:26 AM
Filesize: 512000
Attributes: archive
MD5: F27771E55D2520E0010886FA8284043E
CRC32: 58D96150
Version: 2.2.1.6



--- Process list ---
PID: 0 ( 0) [System]
PID: 1152 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 1200 (1152) \??\C:\WINDOWS\system32\csrss.exe
size: 6144
PID: 1224 (1152) \??\C:\WINDOWS\system32\winlogon.exe
size: 502272
PID: 1268 (1224) C:\WINDOWS\system32\services.exe
size: 108032
MD5: C6CE6EEC82F187615D1002BB3BB50ED4
PID: 1280 (1224) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: 84885F9B82F4D55C6146EBF6065D75D2
PID: 1456 (1268) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1500 (1268) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1592 (1268) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1680 (1268) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1748 (1268) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1836 (1268) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
size: 181608
MD5: 76C495A19F694E18BCE9713B3587948E
PID: 1880 (1268) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
size: 206552
MD5: 5815052B868B96CAE6CE3D4C53E971EB
PID: 1904 (1268) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
size: 173160
MD5: 08FA56B7C13B4CBF0E5D351AECAD92B1
PID: 1972 (1268) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
size: 197992
MD5: CF1A0433BB97C839484DD359691DD521
PID: 276 (1268) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
PID: 704 ( 676) C:\WINDOWS\Explorer.EXE
size: 1033216
MD5: 97BD6515465659FF8F3B7BE375B2EA87
PID: 748 ( 732) C:\Program Files\Common Files\smsse.exe
size: 17920
MD5: 862D6CF3B634EF8E9037120C54FBD238
PID: 800 (1268) C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
size: 100032
MD5: 7768CE75C5CBF0D8F441CE2BBD806B7F
PID: 824 (1268) C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
size: 198168
MD5: 1778EBA872274C1226D869CD9486847E
PID: 852 (1268) C:\WINDOWS\system32\CTsvcCDA.exe
size: 44032
MD5: 3C8B6609712F4FF78E521F6DCFC4032B
PID: 936 (1268) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
size: 20543
MD5: B81F8778F5BB485F3B75114F0C99A49F
PID: 968 (1268) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
size: 138680
MD5: D213C2B1CE0FAEAB59EC0C55B4493F94
PID: 1024 ( 732) C:\Program Files\Internet Explorer\iexplore.exe
size: 625664
MD5: 64E376A47763DAEABCDA14BD5B6EA286
PID: 1044 (1268) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
size: 112152
MD5: 213822072085B5BBAD9AF30AB577D817
PID: 1144 (1268) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
size: 322120
MD5: 11F714F85530A2BD134074DC30E99FCA
PID: 1488 ( 936) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
size: 20543
MD5: B81F8778F5BB485F3B75114F0C99A49F
PID: 1644 (1024) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8
PID: 1760 (1268) C:\Program Files\Norton AntiVirus\navapsvc.exe
size: 177264
MD5: 8FC8458BCB585617AAC9E17A558D9155
PID: 1860 (1268) C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
size: 46704
MD5: 96DB6F2D69F787C61A46CC86D6CFE69F
PID: 1324 (1268) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
size: 65599
MD5: 68C060CE0BD72DD66313356BA698BFF2
PID: 508 (1268) C:\WINDOWS\system32\nvsvc32.exe
size: 155716
MD5: E9E110CDF6A063A5F9B841C36FB5CC95
PID: 532 (1268) C:\WINDOWS\system32\PSIService.exe
size: 174656
MD5: 64E413BA0C529AA40C3924BBCC4153DB
PID: 1004 (1268) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
size: 242544
MD5: D2B096CD2F56FAC6EEEED9A77DDF6DC8
PID: 1432 (1268) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1780 (1268) C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
size: 817304
MD5: 287136B3EA7D2FAB893B5CAE47E75EFD
PID: 1868 (1268) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
size: 67056
MD5: 4BD2C322118A2470B450492A0C3302F9
PID: 2060 (1268) C:\WINDOWS\system32\MsPMSPSv.exe
size: 53248
MD5: 668056D5C3C11AB7D266819A96B964E8
PID: 2140 (1268) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
size: 172032
MD5: AF65875403A3BC39F299390387651C4F
PID: 2180 (1268) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
size: 135227
MD5: 4D864C3526C573E54FBDA663A7855FE2
PID: 2984 (1268) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: F1958FBF86D5C004CF19A5951A9514B7
PID: 3048 (1456) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
size: 115024
MD5: 44CDED85B91EEF32E9CBCA348371F6BB
PID: 3516 ( 704) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
size: 213936
MD5: 2BAD84B393AF47006D80BA2F03B18029
PID: 3580 ( 704) C:\WINDOWS\CTHELPER.EXE
size: 17920
MD5: 866346F3D82F0CA2C7D80AFF41A6E1D3
PID: 3716 ( 704) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 58728
MD5: B76FCE8AA8705A8A0DC240D83BD29AD4
PID: 3768 ( 704) C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
size: 3551456
MD5: DDB78E613CF70A5DC50797E99A4ADB72
PID: 3900 ( 704) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
size: 1506544
MD5: 24A3D7D9DD5555F409CF909600D32D60
PID: 3936 ( 704) C:\Program Files\Messenger\msmsgs.exe
size: 1694208
MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259
PID: 3852 ( 704) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 4891984
MD5: 9C8F0F34F66BB845B42F70E92A972B5F
PID: 4 ( 0) System


--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 8/25/2008 12:16:38 AM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.yahoo.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.yahoo.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.yahoo.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.yahoo.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://www.google.com/ie
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


--- Winsock Layered Service Provider list ---
Protocol 0: NVIDIA App Filter over [MSAFD Tcpip [TCP/IP]]
GUID: {C9DEB131-E695-47FB-B724-B67B891E2D9F}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 1: NVIDIA App Filter over [MSAFD Tcpip [UDP/IP]]
GUID: {C9DEB131-E695-47FB-B724-B67B891E2D9F}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 2: NVIDIA App Filter over [MSAFD Tcpip [RAW/IP]]
GUID: {C9DEB131-E695-47FB-B724-B67B891E2D9F}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll

Protocol 8: NVIDIA App Filter
GUID: {561A1E9F-D78B-40E3-866D-4CE5CF6BB83F}
Filename: %SYSTEMROOT%\system32\nvappfilter.dll



--- Uninstall list ---
16 Big Fish Games (16 Big Fish Games)
uninstall cmd: "C:\WINDOWS\16 Big Fish Games\uninstall.exe" "/U:C:\Program Files\16 Big Fish Games\Uninstall\uninstall.xml"
contact: Support Department

2nd Speech Center 3.2.7.406 (2nd Speech Center_is1)
install location: C:\Program Files\2nd Speech Center\
uninstall cmd: "C:\Program Files\2nd Speech Center\unins000.exe"
publisher: Zero2000.com
help link: http://www.zero2000.com

3D Bungalow Aquarium Screensaver 1.1 (3D Bungalow Aquarium Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Bungalow Aquarium Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Bungalow Aquarium Screensaver\unins000.exe"

3D Formula 1 Screensaver 1.1 (3D Formula 1 Screensaver_is1)
install location: C:\Program Files\3D Formula 1 Screensaver\
uninstall cmd: "C:\Program Files\3D Formula 1 Screensaver\unins000.exe"

3D Grandfather Clock Screensaver 1.0 (3D Grandfather Clock Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Grandfather Clock Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Grandfather Clock Screensaver\unins000.exe"

3D Haunted Halloween Screensaver 1.0 (3D Haunted Halloween Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Haunted Halloween Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Haunted Halloween Screensaver\unins000.exe"

3D Matrix Corridors Screensaver 1.0 (3D Matrix Corridors Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Matrix Corridors Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Matrix Corridors Screensaver\unins000.exe"

3D Matrix Screensaver 1.1 (3D Matrix Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Matrix Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Matrix Screensaver\unins000.exe"

3D Merry Christmas Screensaver 1.0 (3D Merry Christmas Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Merry Christmas Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Merry Christmas Screensaver\unins000.exe"

3D Spooky Halloween Screensaver 1.0 (3D Spooky Halloween Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Spooky Halloween Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Spooky Halloween Screensaver\unins000.exe"

3D Titanic Screensaver 1.0 (3D Titanic Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Titanic Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Titanic Screensaver\unins000.exe"

3D Waterfall Screensaver 1.0 (3D Waterfall Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Waterfall Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Waterfall Screensaver\unins000.exe"

3D Wild Dolphin Screensaver 1.0 (3D Wild Dolphin Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\3D Wild Dolphin Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\3D Wild Dolphin Screensaver\unins000.exe"

Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) 05/27/2006 1.3.2.0 (53F13DB4D9611FD63BE580F06F0729BF236ABE68)
uninstall cmd: C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_6FE44FCD212D4A086C7BC0C98B9A619782073FB7\amdk8.inf
publisher: Advanced Micro Devices

TheOnlyBigDog
2008-08-25, 09:22
(AddressBook)

Adobe Acrobat 8.1.2 Professional 8.1.2 (Adobe Acrobat 8 Professional - English, Français, Deutsch)
version (major): 8
install date: 5/14/2008
install location: C:\Program Files\Adobe\Acrobat 8.0\
uninstall cmd: msiexec /I {AC76BA86-1033-F400-7760-000000000003}
publisher: Adobe Systems
contact: Customer Support
help link: http://www.adobe.com/support/main.html
help telephone:
readme: [INSTALLDIR]Readme.htm

Adobe Flash Player ActiveX 9.0.124.0 (Adobe Flash Player ActiveX)
uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
publisher: Adobe Systems Incorporated
help link: http://www.adobe.com/go/flashplayer_support/

Adobe Flash Player Plugin 9.0.124.0 (Adobe Flash Player Plugin)
uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
publisher: Adobe Systems Incorporated

Aimersoft Video Converter(Build 1.0.20) (Aimersoft Video Converter_is1)
install location: C:\Program Files\Aimersoft\Video Converter\
uninstall cmd: "C:\Program Files\Aimersoft\Video Converter\unins000.exe"
publisher: Aimersoft Software
help link: http://www.aimersoft.com/support.html

Antares Microphone Modeler 1.31 DirectX (Antares Microphone Modeler 1.31 DirectX)
uninstall cmd: C:\PROGRA~1\MicModDX\UNWISE.EXE C:\PROGRA~1\MicModDX\INSTALL.LOG

Aplus All Media to MP3 (Aplus All Media to MP3_is1)
install location: C:\Program Files\Aplus All Media to MP3\
uninstall cmd: "C:\Program Files\Aplus All Media to MP3\unins000.exe"
publisher: Aplus Software Inc
help link: http://www.tomp4.com

Army of Darkness 3D Screensaver 1.0 (Army of Darkness 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Army of Darkness 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Army of Darkness 3D Screensaver\unins000.exe"

Astro Gemini Screensaver Manager 1.2 (Astro Gemini Screensaver Manager_is1)
install location: C:\Program Files\Astro Gemini Software\Screensaver Manager 2.0\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Screensaver Manager 2.0\unins000.exe"

Atlantis 3D Screensaver 1.0 (Atlantis 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Atlantis 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Atlantis 3D Screensaver\unins000.exe"

Atomix.Atomix MP3 v2.3 (Atomix.Atomix MP3 v2.3)
uninstall cmd: C:\PROGRA~1\ATOMIX~1\UNWISE.EXE C:\PROGRA~1\ATOMIX~1\INSTALL.LOG

(Audio Stream Recorder2)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8EF5F498-7FB5-11D6-9963-00A0C92C4EC3}\setup.exe" -l0x9 /remove

Creative Audio Console (AudioConSole)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9 /remove

(AudioHQ)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD851F7E-F887-405D-9E1C-488811113EF3}\setup.exe" -l0x9 /remove

AVS4YOU Software Navigator 1.2 (AVS4YOU Software Navigator_is1)
install date: 20080621
install location: C:\Program Files\AVS4YOU\AVSSoftwareNavigator\
uninstall cmd: "C:\Program Files\AVS4YOU\AVSSoftwareNavigator\unins000.exe"
publisher: Online Media Technologies Ltd.
help link: http://www.avs4you.com/support.aspx

AVS Video Converter 6 (AVS4YOU Video Converter 6_is1)
install date: 20080621
install location: C:\Program Files\AVS4YOU\AVSVideoConverter6\
uninstall cmd: "C:\Program Files\AVS4YOU\AVSVideoConverter6\unins000.exe"
publisher: Online Media Technologies Ltd.
help link: http://www.avs4you.com/support.aspx

Babylon (Babylon)
uninstall cmd: C:\Program Files\Babylon\Babylon-Pro\Utils\uninstbb.exe

Bejeweled 2 Deluxe (Bejeweled 2 Deluxe)
uninstall cmd: C:\WINDOWS\iun6002ev.exe "C:\Program Files\Bejeweled 2 Deluxe\irunin.ini"

Bejeweled Deluxe 1.862 (Bejeweled Deluxe 1.862)

Belarc Advisor 7.2 (Belarc Advisor)
uninstall cmd: C:\PROGRA~1\Belarc\Advisor\Uninstall.exe C:\PROGRA~1\Belarc\Advisor\INSTALL.LOG

BookWorm Deluxe 1.02 (BookWorm Deluxe 1.02)
uninstall cmd: C:\Program Files\PopCap Games\BookWorm Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\BookWorm Deluxe\Install.log"

(Branding)

Cakewalk.Pro.Audio.9.03-TcC (Cakewalk.Pro.Audio.9.03-TcC)
uninstall cmd: C:\audio\cw9\UNWISE.EXE C:\audio\cw9\INSTALL.LOG

Canon iP1600 (CANONBJ_Deinstall_CNMCP75.DLL)
uninstall cmd: C:\WINDOWS\system32\CNMCP75.exe "-PRINTERNAMECanon iP1600" "-HELPERDLLC:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600 Installer\Inst2\cnmis.dll" "-RCDLLcnmi0409.dll"

CCleaner (remove only) (CCleaner)
uninstall cmd: "C:\Program Files\CCleaner\uninst.exe"

CDG Ripper 1.012 (CDG_Ripper_100)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\CDG Ripper\irunin.ini"

Christmas Eve 3D Screensaver 1.0 (Christmas Eve 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Christmas Eve 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Christmas Eve 3D Screensaver\unins000.exe"

Christmas Time 3D Screensaver 1.0 (Christmas Time 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Christmas Time 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Christmas Time 3D Screensaver\unins000.exe"

Cities of Earth 3D Screensaver v. 2.1 (Cities of Earth 3D Screensaver_is1)
install location: C:\Program Files\Cities of Earth\
uninstall cmd: "C:\Program Files\Cities of Earth\unins000.exe"
publisher: Screenomania.com
help link: http://www.screenomania.com/contacts.html

CompuHost 1.0 (CompuHost - Computerized Karaoke Hosting Solution_is1)
install location: C:\Program Files\CompuHost\
uninstall cmd: "C:\Program Files\CompuHost\unins000.exe"
publisher: Invicion Software Solutions
help link: http://www.karaokeware.com

(Connection Manager)

Cool Edit Pro 2.0 (Cool Edit Pro 2.0)
uninstall cmd: C:\Program Files\coolpro2\cep2unin.exe

Codec Pack - All In 1 6.0.2.6 (Cool's_Codec_pack_4.12)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"

(Creative MediaSource)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x9 /remove

(Creative MediaSource AudioSync Plugin)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDC05F7-83E4-4611-AD3C-A6EB2100332A}\setup.exe" -l0x9 /remove

(Creative MediaSource CD-ROM Burner Plugin)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD549B7B-3532-4160-80D4-3E3DD39A9AE5}\setup.exe" -l0x9 /remove

(Creative MediaSource Detector)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x9 /remove

(Creative MediaSource DVD-Audio Player)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{169F8893-C1C5-4847-972C-EA1E008112AC}\setup.exe" -l0x9 /remove

(Creative MediaSource Go!)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\setup.exe" -l0x9 /remove

(Creative MediaSource NOMAD II/MG Plugin)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{881A74B3-3D17-4842-B9AF-0761C6E6C4B5}\setup.exe" -l0x9 /remove

(Creative MediaSource NOMAD Jukebox 2/3/Zen Plugin)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B5BAAFAE-3561-463D-8E3F-91761A57ADB8}\setup.exe" -l0x9 /remove

(Creative MediaSource NOMAD Jukebox Plugin)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1888DAFD-C634-4BC4-865C-3455E24F6177}\setup.exe" -l0x9 /remove

(Creative MediaSource NOMAD MuVo Plugin)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{869D88A5-BD6C-4E39-8536-D95259EAD7E8}\setup.exe" -l0x9 /remove

(Creative MediaSource Player Skin Pack)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x9 /remove

(Creative MediaSource RemoteControl Plugin)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5933921D-4253-40B6-B4D9-B7D680F1B6EC}\setup.exe" -l0x9 /remove

(Creative MiniDisc Center)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC157741-3285-4D6A-B934-9174587A3493}\setup.exe" -l0x9 /remove

(Creative Restore Defaults)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A4D2983-4662-4387-BE3D-4CFC2FA9C100}\setup.exe" -l0x9 /remove

(Creative WaveStudio)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9 /remove

Cucusoft MPEG/AVI to DVD/VCD/SVCD/MPEG Converter Pro 4.53 (Cucusoft MPEG/AVI to DVD/VCD/SVCD/MPEG Converter Pro_is1)
install location: C:\Program Files\Cucusoft\avi-dvd-pro\
uninstall cmd: "C:\Program Files\Cucusoft\avi-dvd-pro\unins000.exe"
publisher: Cucusoft, Inc.
help link: http://www.avi-vcd.com

(Desktop Architect)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Desktop Architect\Uninst.isu"

(Diagnostics_Audigy2)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9154ED7C-926E-49CC-B677-0CF3C5267457}\setup.exe" -l0x9 /remove

Dinosaurs 3D Screensaver 1.0 (Dinosaurs 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Dinosaurs 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Dinosaurs 3D Screensaver\unins000.exe"

(DirectAnimation)

(DirectDrawEx)

DualCoreCenter (DualCoreCenter_is1)
install location: C:\Program Files\MSI\DualCoreCenter\
uninstall cmd: "C:\Program Files\MSI\DualCoreCenter\unins000.exe"
publisher: MSI, Inc.
help link: http://www.msi.com.tw/

DVD Shrink 3.1.7 (DVD Shrink_is1)
uninstall cmd: "C:\Program Files\DVD Shrink\unins000.exe"
publisher: DVD Shrink
help link: http://www.dvdshrink.org

(DXM_Runtime)

Earth 3D Space Tour screensaver v1.1 (Earth 3D Space Tour screensaver_is1)
uninstall cmd: "C:\Program Files\3D Space Tour\Earth 3D\unins000.exe"
publisher: FP Software lab
help link: http://www.fpsoftlab.com/support.htm

(EAX)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove

Egypt 3D Screensaver 1.0 (Egypt 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Egypt 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Egypt 3D Screensaver\unins000.exe"

Egyptian Pyramids 3D Screensaver 1.0 (Egyptian Pyramids 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Egyptian Pyramids 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Egyptian Pyramids 3D Screensaver\unins000.exe"

Embarq Toolbar (embarqtoolbar)
uninstall cmd: C:\Program Files\embarqtoolbar\uninstall.exe /S

EncoderMcg 1.006 (EncoderMcg 1.006)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\CAVS\Encoder Mcg\UnEncMcg1006.isu"

(EQUALIZER)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9 /remove

Eraser 5.7 (Eraser_is1)
uninstall cmd: "C:\Program Files\Eraser\unins000.exe"
publisher: Heidi Computers Ltd
help link: http://www.heidi.ie/eraser/

eXtreme Movie Manager 6.1.9.0 - Full Install! (eXtreme Movie Manager .NET Edition_is1)
install date: 20080429
install location: C:\Program Files\eXtreme Movie Manager\
uninstall cmd: "C:\Program Files\eXtreme Movie Manager\unins000.exe"
publisher: BinaryWorks.it Software
help link: http://www.binaryworks.it/extrememoviemanager/

EZ-2-Serve 2.0 (EZ-2-Serve)
uninstall cmd: "c:\EZ-2-Serve\uninstall.exe"

ffdshow (remove only) (ffdshow)

Fish Aquarium 3D Screensaver 1.0 (Fish Aquarium 3D Screensaver_is1)
install location: C:\Program Files\Fish Aquarium 3D Screensaver\
uninstall cmd: "C:\Program Files\Fish Aquarium 3D Screensaver\unins000.exe"

Flower Clock 3D Screensaver 1.0 (Flower Clock 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Flower Clock 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Flower Clock 3D Screensaver\unins000.exe"

(Fontcore)

Forest Life 3D Screensaver 1.2 (Forest Life 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Forest Life 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Forest Life 3D Screensaver\unins000.exe"

Garden Flowers 3D Screensaver 1.0 (Garden Flowers 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Garden Flowers 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Garden Flowers 3D Screensaver\unins000.exe"

Golden Autumn 3D Screensaver 1.0 (Golden Autumn 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Golden Autumn 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Golden Autumn 3D Screensaver\unins000.exe"

GoodMEM (GoodMEM)
uninstall cmd: C:\Program Files\MSI\GoodMEM\Uninstal.exe

Google Desktop 5.7.0806.10245 (Google Desktop)
uninstall cmd: C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
publisher: Google
help link: http://desktop.google.com/help.html?hl=en

Google Updater 2.2.1111.1511 (Google Updater)
uninstall cmd: "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
publisher: Google Inc.
help link: http://pack.google.com:80/pack-support?hl=en&gl=us

Green Valley 3D Screensaver 1.0 (Green Valley 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Green Valley 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Green Valley 3D Screensaver\unins000.exe"

Halloween in the Attic 3D Screensaver 1.0 (Halloween in the Attic 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Halloween in the Attic 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Halloween in the Attic 3D Screensaver\unins000.exe"

HijackThis 2.0.2 2.0.2 (HijackThis)
uninstall cmd: "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
publisher: TrendMicro

(ICW)

Microsoft Internationalized Domain Names Mitigation APIs (IDNMitigationAPIs)
install date: 20071127
uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
publisher: Microsoft Corporation

(IE40)

(IE4Data)

(IE5BAKEX)

Windows Internet Explorer 7 20070813.185237 (ie7)
install date: 20080628
uninstall cmd: "C:\WINDOWS\ie7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://www.microsoft.com/ie

(IEData)

Insaniquarium Deluxe 1.0 (Insaniquarium_Deluxe_1.0)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\Insaniquarium Deluxe\irunin.ini"

(InstallShield Uninstall Information)

NVIDIA ForceWare Network Access Manager 2.03.6531 (InstallShield_{1F6423DE-7959-4178-80E0-023C7EAA5347})
version: 33757571
version (major): 2
version (minor): 3
estimated size: 19698
install date: 20070922
install location: C:\Program Files\NVIDIA Corporation\NetworkAccessManager\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\_is1DE\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
publisher: NVIDIA Corporation

InterVideo WinDVD 8 8.0-B6.109 (InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85})
version: 134217728
version (major): 8
estimated size: 150536
install date: 20071215
install location: C:\Program Files\InterVideo\DVD8\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\pftF~tmp\
uninstall cmd: C:\Program Files\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe -runfromtemp -l0x0409
publisher: InterVideo Inc.
contact: http://www.intervideo.com/jsp/Support.jsp/
help link: support@intervideo.com

Microstudio (InstallShield_{36351D2E-6B31-4B7A-949E-FF63E4B2FBED})
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{36351D2E-6B31-4B7A-949E-FF63E4B2FBED}

ASPI Drivers 1.16 (InstallShield_{B2FBB314-4D74-4E66-B467-268C31E80612})
version: 17825792
version (major): 1
version (minor): 16
estimated size: 36
install date: 20071016
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\_is2B\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{B2FBB314-4D74-4E66-B467-268C31E80612}
publisher: Micro Technology Unlimited
comments: ASPI Drivers
contact: Customer Support Department
help link: http://www.mtu.com/
help telephone: 919-870-0344
readme: Readme.txt

Microstudio 2.3.1.5 (InstallShield_{BC2AE2D7-E990-4179-B2F3-4322DA9929C6})
version: 33751041
version (major): 2
version (minor): 3
estimated size: 1148
install date: 20070922
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\_isC6\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BC2AE2D7-E990-4179-B2F3-4322DA9929C6}
publisher: Micro Technology Unlimited
comments: Microstudio v2.315
contact: Customer Support Department
help link: www.mtu.com
help telephone: 1-919-870-0344
readme: manual/microstudio2315-manual.htm

Ulead VideoStudio 11 11.0.0.0000 (InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9})
version: 184549376
version (major): 11
estimated size: 197393
install date: 20071216
install location: C:\Program Files\Ulead Systems\Ulead VideoStudio 11\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\pft3B.tmp\
uninstall cmd: C:\Program Files\InstallShield Installation Information\{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}\setup.exe -runfromtemp -l0x0409
publisher: InterVideo Digital Technology Corporation

Japanese Garden 3D Screensaver 1.0 (Japanese Garden 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Japanese Garden 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Japanese Garden 3D Screensaver\unins000.exe"

Jewel Quest (remove only) (Jewel Quest)
uninstall cmd: "C:\Program Files\iWin.com Games\Jewel Quest\Uninstall.exe"

Karaoke Builder Studio 3.x (Karaoke Builder Studio 3.x)
uninstall cmd: C:\KBStudio\UNWISE.EXE C:\KBStudio\INSTALL.LOG

Karaoke Home Producer (Karaoke Home Producer)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Micro Technology Unlimited\Karaoke Home Producer\Uninst.isu"

Karaoke Zip Scanner (Karaoke Zip Scanner)
install location: C:\Program Files\Karaoke Zip Scanner
uninstall cmd: "C:\Documents and Settings\All Users\Application Data\{174BEB07-CB76-4EAC-91FD-95CD34E9901B}\KaraokeZipScannerSetup.exe" REMOVE=TRUE MODIFY=FALSE
publisher: ActiveAsp Software
comments: Copyright © 2008 ActiveAsp Software. All rights reserved.
contact: ActiveAsp Software
help link: http://www.activeaspsoftware.net/

Kaspersky Online Scanner 5.0 (Kaspersky Online Scanner)
install location: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner
uninstall cmd: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
publisher: Kaspersky Lab
contact: Customer Support Department
help link: http://support.kaspersky.com/helpdesk.html?LANG=en

Windows XP Hotfix - KB873339 20041117.092459 (KB873339)
uninstall cmd: C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=873339

(KB884016)

(KB884267)

(KB885353)

Windows XP Hotfix - KB885835 20041027.181713 (KB885835)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=885835

Windows XP Hotfix - KB885836 20041028.173203 (KB885836)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=885836

Windows XP Hotfix - KB885884 20040924.025457 (KB885884)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=885884

Windows XP Hotfix - KB886185 20041021.090540 (KB886185)
uninstall cmd: C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=886185

(KB886612)

(KB887078)

Windows XP Hotfix - KB887472 20041014.162858 (KB887472)
uninstall cmd: C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=887472

(KB887626)

High Definition Audio Driver Package - KB888111 20040219.000000 (KB888111WXPSP2)
uninstall cmd: C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=KB888111

Windows XP Hotfix - KB888302 20041207.111426 (KB888302)
uninstall cmd: C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=888302

(KB888656)

(KB889858)

Security Update for Windows XP (KB890046) 1 (KB890046)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=890046

Windows XP Hotfix - KB890859 1 (KB890859)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=890859

(KB891122)

Windows XP Hotfix - KB891781 20050110.165439 (KB891781)
uninstall cmd: C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=891781

Windows Genuine Advantage Validation Tool (KB892130) (KB892130)
install date: 20071201
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=892130

(KB892313)

(KB893240)

(KB893241)

Security Update for Windows XP (KB893756) 1 (KB893756)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=893756

Windows Installer 3.1 (KB893803) 3.1 (KB893803)
uninstall cmd: "C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=42467

Windows Installer 3.1 (KB893803) 3.1 (KB893803v2)
uninstall cmd: "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=42467

Update for Windows XP (KB894391) 1 (KB894391)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=894391

(KB895181)

(KB895316)

(KB895572)

Hotfix for Windows XP (KB896344) 2 (KB896344)
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896344$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896344

Security Update for Windows XP (KB896358) 1 (KB896358)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896358

Security Update for Windows XP (KB896423) 1 (KB896423)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896423

Security Update for Windows XP (KB896428) 1 (KB896428)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896428

(KB897586)

Update for Windows XP (KB898461) 1 (KB898461)
install date: 20070927
uninstall cmd: "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=898461

(KB898549)

Security Update for Windows XP (KB899587) 1 (KB899587)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=899587

Security Update for Windows XP (KB899591) 1 (KB899591)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=899591

(KB900399)

Update for Windows XP (KB900485) 2 (KB900485)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=900485

Security Update for Windows XP (KB900725) 1 (KB900725)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=900725

Security Update for Windows XP (KB901017) 1 (KB901017)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=901017

Security Update for Windows XP (KB901214) 1 (KB901214)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=901214

(KB902344)

Security Update for Windows XP (KB902400) 1 (KB902400)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=902400

Security Update for Windows XP (KB904706) 2 (KB904706)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=904706

Update for Windows XP (KB904942) 2 (KB904942)
install date: 20071127
uninstall cmd: "C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=904942

Security Update for Windows XP (KB905414) 1 (KB905414)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=905414

Security Update for Windows XP (KB905749) 1 (KB905749)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=905749

(KB907658)

Security Update for Windows XP (KB908519) 1 (KB908519)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=908519

Update for Windows XP (KB908531) 2 (KB908531)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=908531

Microsoft Base Smart Card Cryptographic Service Provider Package (KB909520)
uninstall cmd: "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
publisher: Microsoft Corporation

Update for Windows XP (KB910437) 1 (KB910437)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=910437

Update for Windows XP (KB911164) 1 (KB911164)
install date: 20070923
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911164

Update for Windows XP (KB911280) 2 (KB911280)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911280

Security Update for Windows XP (KB911562) 1 (KB911562)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911562

Security Update for Windows Media Player (KB911564) (KB911564)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=911564

(KB911565)

(KB911854)

Security Update for Windows XP (KB911927) 1 (KB911927)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911927

Security Update for Windows XP (KB913580) 1 (KB913580)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=913580

Security Update for Windows XP (KB914388) 1 (KB914388)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=914388

Security Update for Windows XP (KB914389) 1 (KB914389)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=914389

Hotfix for Windows XP (KB914440) 12 (KB914440)
install date: 20071127
uninstall cmd: "C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=914440

Hotfix for Windows XP (KB915865) 10 (KB915865)
install date: 20071127
uninstall cmd: "C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=915865

Update for Windows XP (KB916595) 1 (KB916595)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=916595

Security Update for Windows XP (KB917344) 1 (KB917344)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=917344

Security Update for Windows XP (KB917953) 1 (KB917953)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=917953

Security Update for Windows XP (KB918118) 1 (KB918118)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=918118

Security Update for Windows XP (KB918439) 1 (KB918439)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=918439

Security Update for Windows XP (KB919007) 1 (KB919007)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=919007

Security Update for Windows XP (KB920213) 1 (KB920213)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920213

Update for Windows XP (KB920342) 1 (KB920342)
install date: 20080515
uninstall cmd: "C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920342

Security Update for Windows XP (KB920670) 1 (KB920670)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920670

Security Update for Windows XP (KB920683) 1 (KB920683)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920683

Security Update for Windows XP (KB920685) 1 (KB920685)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920685

Update for Windows XP (KB920872) 1 (KB920872)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920872

Security Update for Windows XP (KB921503) 1 (KB921503)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=921503

Update for Windows XP (KB922582) 1 (KB922582)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=922582

Security Update for Windows XP (KB922819) 1 (KB922819)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=922819

Security Update for Windows XP (KB923191) 1 (KB923191)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923191

Security Update for Windows XP (KB923414) 1 (KB923414)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923414

Security Update for Windows XP (KB923689) (KB923689)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923689

Security Update for Windows XP (KB923980) 1 (KB923980)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923980

Security Update for Windows XP (KB924270) 1 (KB924270)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924270

Security Update for Windows XP (KB924496) 1 (KB924496)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924496

Security Update for Windows XP (KB924667) 1 (KB924667)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924667

Security Update for Windows Media Player 6.4 (KB925398) (KB925398_WMP64)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=925398

Update for Windows XP (KB925720) 1 (KB925720)
install date: 20071006
uninstall cmd: "C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=925720

Update for Windows XP (KB925876) 1 (KB925876)
install date: 20080515
uninstall cmd: "C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=925876

Security Update for Windows XP (KB925902) 1 (KB925902)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=925902

Hotfix for Windows XP (KB926239) 2 (KB926239)
install date: 20071018
uninstall cmd: "C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926239

Security Update for Windows XP (KB926255) 1 (KB926255)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926255

Security Update for Windows XP (KB926436) 1 (KB926436)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926436

Security Update for Windows XP (KB927779) 1 (KB927779)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=927779

Security Update for Windows XP (KB927802) 1 (KB927802)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=927802

Update for Windows XP (KB927891) 3 (KB927891)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=927891

Security Update for Windows XP (KB928255) 1 (KB928255)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=928255

Security Update for Windows XP (KB928843) 1 (KB928843)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=928843

Security Update for Windows XP (KB929123) 1 (KB929123)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=929123

Hotfix for Windows Media Format 11 SDK (KB929399) (KB929399)
install date: 20071020
uninstall cmd: "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=929399

Security Update for Windows XP (KB930178) 1 (KB930178)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=930178

Update for Windows XP (KB930916) 1 (KB930916)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=930916

Security Update for Windows XP (KB931261) 1 (KB931261)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931261

Security Update for Windows XP (KB931784) 1 (KB931784)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931784

Security Update for CAPICOM (KB931906) 2.1.0.2 (KB931906)
uninstall cmd: MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931906

Security Update for Windows XP (KB932168) 1 (KB932168)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=932168

Update for Windows XP (KB932823-v3) 3 (KB932823-v3)
install date: 20080628
uninstall cmd: "C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=932823-v3

Update for Windows XP (KB933360) 1 (KB933360)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933360

Security Update for Windows XP (KB933729) 1 (KB933729)
install date: 20071011
uninstall cmd: "C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933729

Security Update for Windows XP (KB935839) 1 (KB935839)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=935839

Security Update for Windows XP (KB935840) 1 (KB935840)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=935840

Security Update for Windows XP (KB936021) 1 (KB936021)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=936021

Security Update for Windows Media Player 11 (KB936782) (KB936782_WMP11)
install date: 20071020
uninstall cmd: "C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=936782

Security Update for Windows Media Player 9 (KB936782) (KB936782_WMP9)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=936782

Security Update for Windows XP (KB937143) 1 (KB937143)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=937143

Security Update for Windows XP (KB937894) 1 (KB937894)
install date: 20071213
uninstall cmd: "C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=937894

Security Update for Windows XP (KB938127) 1 (KB938127)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938127

Security Update for Windows Internet Explorer 7 (KB938127) 1 (KB938127-IE7)
install date: 20080628
uninstall cmd: "C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938127

Update for Windows XP (KB938828) 1 (KB938828)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938828

Security Update for Windows XP (KB938829) 1 (KB938829)
install date: 20070928
uninstall cmd: "C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938829

Security Update for Windows XP (KB939653) 1 (KB939653)
install date: 20071011
uninstall cmd: "C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=939653

Hotfix for Windows Media Player 11 (KB939683) (KB939683)
install date: 20071020
uninstall cmd: "C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=939683

Security Update for Windows XP (KB941202) 1 (KB941202)
install date: 20071011
uninstall cmd: "C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941202

Security Update for Windows XP (KB941568) 1 (KB941568)
install date: 20071213
uninstall cmd: "C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941568

Security Update for Windows XP (KB941569) (KB941569)
install date: 20071213
uninstall cmd: "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941569

Security Update for Windows XP (KB941644) 1 (KB941644)
install date: 20080109
uninstall cmd: "C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941644

Security Update for Windows XP (KB941693) 1 (KB941693)
install date: 20080409
uninstall cmd: "C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941693

Update for Windows XP (KB942763) 1 (KB942763)
install date: 20071213
uninstall cmd: "C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=942763

Security Update for Windows XP (KB943055) 1 (KB943055)
install date: 20080307
uninstall cmd: "C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943055

Security Update for Windows XP (KB943460) 1 (KB943460)
install date: 20071127
uninstall cmd: "C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943460

Security Update for Windows XP (KB943485) 1 (KB943485)
install date: 20080109
uninstall cmd: "C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943485

Security Update for Windows XP (KB944338) 1 (KB944338)
install date: 20080506
uninstall cmd: "C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=944338

Security Update for Windows XP (KB944653) 1 (KB944653)
install date: 20071213
uninstall cmd: "C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=944653

Security Update for Windows XP (KB945553) 1 (KB945553)
install date: 20080409
uninstall cmd: "C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=945553

Security Update for Windows XP (KB946026) 1 (KB946026)
install date: 20080307
uninstall cmd: "C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=946026

Security Update for Windows XP (KB946648) 1 (KB946648)
install date: 20080822
uninstall cmd: "C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=946648

Security Update for Windows XP (KB947864) 1 (KB947864)
install date: 20080506
uninstall cmd: "C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=947864

Security Update for Windows XP (KB948590) 1 (KB948590)
install date: 20080409
uninstall cmd: "C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=948590

Security Update for Windows XP (KB948881) 1 (KB948881)
install date: 20080409
uninstall cmd: "C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=948881

Security Update for Windows XP (KB950749) 1 (KB950749)
install date: 20080514
uninstall cmd: "C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950749

Security Update for Windows XP (KB950759) 1 (KB950759)
install date: 20080611
uninstall cmd: "C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950759

Security Update for Windows Internet Explorer 7 (KB950759) 1 (KB950759-IE7)
install date: 20080628
uninstall cmd: "C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950759

Security Update for Windows XP (KB950760) 1 (KB950760)
install date: 20080611
uninstall cmd: "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950760

Security Update for Windows XP (KB950762) 1 (KB950762)
install date: 20080611
uninstall cmd: "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950762

Security Update for Windows XP (KB950974) 1 (KB950974)
install date: 20080822
uninstall cmd: "C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950974

Security Update for Windows XP (KB951066) 1 (KB951066)
install date: 20080822
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951066

Update for Windows XP (KB951072-v2) 2 (KB951072-v2)
install date: 20080822
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951072

Security Update for Windows XP (KB951376) 1 (KB951376)
install date: 20080611
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951376

Security Update for Windows XP (KB951376-v2) 2 (KB951376-v2)
install date: 20080620
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951376

Security Update for Windows XP (KB951698) 1 (KB951698)
install date: 20080611
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951698

Security Update for Windows XP (KB951748) 1 (KB951748)
install date: 20080709
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951748

Hotfix for Windows XP (KB952287) 1 (KB952287)
install date: 20080822
uninstall cmd: "C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952287

Security Update for Windows XP (KB952954) 1 (KB952954)
install date: 20080822
uninstall cmd: "C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952954

Security Update for Windows Internet Explorer 7 (KB953838) 1 (KB953838-IE7)
install date: 20080822
uninstall cmd: "C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=953838

Security Update for Windows XP (KB953839) 1 (KB953839)
install date: 20080822
uninstall cmd: "C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=953839

TheOnlyBigDog
2008-08-25, 09:24
Keyrite (Keyrite)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Micro Technology Unlimited\Keyrite\Uninst.isu"

KJ Pro (KJ Pro)
uninstall cmd: "C:\Program Files\Kjpro\uninstall.exe" C:\PROGRA~1\Kjpro\install.log

Lighthouse 3D Screensaver 1.2 (Lighthouse 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Lighthouse 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Lighthouse 3D Screensaver\unins000.exe"

List Magic v1.0 (List Magic_is1)
uninstall cmd: "C:\Program Files\mp3oholic\ListMagic\unins000.exe"
publisher: mp3oholic
help link: http://www.omenscripts.org

LiveReg (Symantec Corporation) 3.0.0 (LiveReg)
install location: C:\Program Files\Common Files\Symantec Shared\LiveReg
uninstall cmd: C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe /REMOVE
publisher: Symantec Corporation

LiveUpdate 3.0 (Symantec Corporation) 3.0.0.171 (LiveUpdate)
install location: "C:\Program Files\Symantec\LiveUpdate"
uninstall cmd: "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
publisher: Symantec Corporation

Microsoft .NET Framework 1.1 Hotfix (KB928366) (M928366)
uninstall cmd: "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"

Magic Forest 3D screensaver 1.0 (Magic Forest 3D screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Magic Forest 3D screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Magic Forest 3D screensaver\unins000.exe"

Magic ISO Maker v5.4 (build 0256) (Magic ISO Maker v5.4 (build 0256))
uninstall cmd: C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG

Magic Video Converter 8.0.8.25 (Magic Video Converter_is1)
install location: C:\Program Files\Magic Video Converter\
uninstall cmd: "C:\Program Files\Magic Video Converter\unins000.exe"

Magic Video Studio 8.0.8.24 (Magic Video Studio_is1)
install location: C:\Program Files\Magic Video Studio\
uninstall cmd: "C:\Program Files\Magic Video Studio\unins000.exe"

Marine Life 3D Screensaver 1.0 (Marine Life 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Marine Life 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Marine Life 3D Screensaver\unins000.exe"

Max DVD to AVI Converter 4.0 (Max DVD to AVI Converter 4.0_is1)
uninstall cmd: "C:\Program Files\Max DVD to AVI Converter 4.0\unins000.exe"
publisher: PowerImage, Inc.
help link: http://www.dvd-converter.com

Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033))
uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm

Microsoft .NET Framework 3.5 (Pre-Release Version) (Microsoft .NET Framework 3.5 (Pre-Release Version))
install location: C:\WINDOWS\Microsoft.NET\Framework\v3.5\
uninstall cmd: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 (Pre-Release Version)\setup.exe
publisher: Microsoft

mIRC (mIRC)
uninstall cmd: "C:\RealmEX\mIRC.ExCurSioN.exe" -uninstall

(MobileOptionPack)

Mountain Lake 3D Screensaver 1.0 (Mountain Lake 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Mountain Lake 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Mountain Lake 3D Screensaver\unins000.exe"

Movie DVD Ripper v3.5.1 (Movie DVD Ripper_is1)
install date: 20080625
install location: C:\Program Files\Movie DVD Ripper\
uninstall cmd: "C:\Program Files\Movie DVD Ripper\unins000.exe"

Mozilla Firefox (3.0.1) 3.0.1 (en-US) (Mozilla Firefox (3.0.1))
install location: C:\Program Files\Mozilla Firefox
uninstall cmd: C:\Program Files\Mozilla Firefox\uninstall\helper.exe
publisher: Mozilla
comments: Mozilla Firefox

MP3 WAV Converter 3.26 (MP3 WAV Converter 3.26)
uninstall cmd: C:\PROGRA~1\MP3WAV~1\UNWISE.EXE C:\PROGRA~1\MP3WAV~1\INSTALL.LOG

Mp3+G Toolz 2 (Mp3+G Toolz 2)
uninstall cmd: C:\PROGRA~1\MP3_GT~1\UNWISE.EXE C:\PROGRA~1\MP3_GT~1\INSTALL.LOG

(MPlayer2)

Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1)
install date: 20071018
uninstall cmd: "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=74087

MSI Live Update 3 (MSI Live Update 3)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\Live Update 3\Uninst.isu"

(MSI30-Beta1)

(MSI30-Beta2)

(MSI30-KB884016)

(MSI30-RC1)

(MSI30-RC2)

(MSI30a-KB884016)

(MSI31-Beta)

(MSI31-RC1)

(MsJavaVM)

myBabylon Toolbar (myBabylon Toolbar)
uninstall cmd: C:\PROGRA~1\MYBABY~1\UNWISE.EXE C:\PROGRA~1\MYBABY~1\INSTALL.LOG
help link:

(Nero - Burning Rom!UninstallKey)
uninstall cmd: C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL

(NeroBackItUp!UninstallKey)
uninstall cmd: C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL

(NeroMediaHome!UninstallKey)
uninstall cmd: C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL

(NeroRecode!UninstallKey)
uninstall cmd: C:\WINDOWS\UNRecode.exe /UNINSTALL

(NeroShowTime!UninstallKey)
uninstall cmd: C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL

(NeroVision!UninstallKey)
uninstall cmd: C:\WINDOWS\UNNeroVision.exe /UNINSTALL

(NetMeeting)

Night City 3D Screensaver 1.0 (Night City 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Night City 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Night City 3D Screensaver\unins000.exe"

Microsoft National Language Support Downlevel APIs (NLSDownlevelMapping)
install date: 20071127
uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
publisher: Microsoft Corporation

Norton Spyware Scan provided by Yahoo! (Norton Spyware Scan provided by Yahoo!)
uninstall cmd: C:\PROGRA~1\Yahoo!\Common\unynss.exe

NVIDIA Drivers (NVIDIA Drivers)
uninstall cmd: C:\WINDOWS\system32\nvudisp.exe UninstallGUI

(OutlookExpress)

(PCHealth)
uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf

Pirate Ship 3D Screensaver 1.2 (Pirate Ship 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Pirate Ship 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Pirate Ship 3D Screensaver\unins000.exe"

Planet Earth 3D Screensaver 1.1 (Planet Earth 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Planet Earth 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Planet Earth 3D Screensaver\unins000.exe"

PowerDVD (PowerDVD)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\CyberLink\PowerDVD\Uninst.isu"

SierraHome Print Artist 8.0 (Print Artist 8.0)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Sierra\Print Artist 8.0\Uninst.isu" -c"C:\Sierra\Print Artist 8.0\Uninstpa.DLL"

RAR Password Cracker (remove only) (RAR Password Cracker)
uninstall cmd: C:\Program Files\RAR Password Cracker\uninstall.exe

(RealJukebox 1.0)
uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

RealPlayer (RealPlayer 6.0)
uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

RegCure 1.3.0.2 1.3.0.2 (RegCure)
uninstall cmd: C:\Program Files\RegCure\uninst.exe
publisher: RegCure, Inc.

Rocket Mania 1.01 (Rocket Mania 1.01)
uninstall cmd: C:\Program Files\PopCap Games\Rocket Mania Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Rocket Mania Deluxe\Install.log"

(RoxBox)

Sax & Dottys Show Hoster (Sax & Dottys Show Hoster)
uninstall cmd: C:\PROGRA~1\SAX&DO~2\UNWISE.EXE C:\PROGRA~1\SAX&DO~2\INSTALL.LOG

(SB Audigy 2 Getting Started Demo)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{77ACE67A-0D21-4CEF-8A97-ED20A61B978B}\setup.exe" -l0x9 /remove

SBMAV Disk cleaner (SBMAV Disk cleaner)
uninstall cmd: C:\Program Files\SBMAV Disk cleaner\uninstall.exe

(SchedulingAgent)

School of Magic 3D Screensaver 1.0 (School of Magic 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\School of Magic 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\School of Magic 3D Screensaver\unins000.exe"

Sea Storm 3D Screensaver 1.0 (Sea Storm 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Sea Storm 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Sea Storm 3D Screensaver\unins000.exe"

Sea Voyage 3D Screensaver 1.0 (Sea Voyage 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Sea Voyage 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Sea Voyage 3D Screensaver\unins000.exe"

SecureDoc (SecureDoc)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\SecureDoc\Uninst.isu"

(Sevinst)

(SFBM)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7201B853-5833-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove

9.0.124.0 (ShockwaveFlash)

Solar System 3D Screensaver 1.4 (Solar System 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Solar System 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Solar System 3D Screensaver\unins000.exe"

(Sound Blaster Audigy 2 ZS)

(Sound Blaster Audigy 2 ZS Windows Drivers)
uninstall cmd: "C:\Program Files\Creative\SBAudigy2ZS\Program\SETUP.EXE" /S /U /W

Space Tunnels 3D Screensaver 1.0 (Space Tunnels 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Space Tunnels 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Space Tunnels 3D Screensaver\unins000.exe"

(SPEAKER)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove

(SPKR_CALIBRATOR)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{236FADD8-58FD-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove

Spybot - Search & Destroy 1.5.2.20 (Spybot - Search & Destroy_is1)
install date: 20080209
uninstall cmd: "C:\WINDOWS\unins000.exe"
publisher: Safer Networking Ltd.
help link: http://www.safer-networking.org/

Star Wars 3D Screensaver 1.3 (Star Wars 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Star Wars 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Star Wars 3D Screensaver\unins000.exe"

Sun 3D Screensaver 1.0 (Sun 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Sun 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Sun 3D Screensaver\unins000.exe"

(SURMIXER)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove

Sword of Valor 3D Screensaver 1.0 (Sword of Valor 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Sword of Valor 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Sword of Valor 3D Screensaver\unins000.exe"

Norton AntiVirus 2005 (Symantec Corporation) 11.0.1 (SymSetup.{C6F5B6CF-609C-428E-876F-CA83176C021B})
install location: C:\Program Files\Norton AntiVirus
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005
uninstall cmd: C:\Program Files\Common Files\Symantec Shared\SymSetup\{C6F5B6CF-609C-428E-876F-CA83176C021B}.exe /X
publisher: Symantec Corporation

Creative System Information (SysInfo)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{87499F38-FD69-4A2B-B41A-BAB8DE9B94FE}\setup.exe" -l0x9 /remove

The Weather Channel Desktop (The Weather Channel Desktop)
uninstall cmd: C:\Program Files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe

The_Pirate_Bay Toolbar (The_Pirate_Bay Toolbar)
uninstall cmd: C:\PROGRA~1\THE_PI~1\UNWISE.EXE C:\PROGRA~1\THE_PI~1\INSTALL.LOG
help link:

(THX_Console)
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3549608-69D3-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9 /remove

Treasure Vault 3D Screensaver 2.0 (Treasure Vault 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Treasure Vault 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Treasure Vault 3D Screensaver\unins000.exe"

Valentine's Day 3D Screensaver 1.0 (Valentine's Day 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Valentine's Day 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Valentine's Day 3D Screensaver\unins000.exe"

Video Edit Magic 3.36 (Video Edit Magic_is1)
install location: C:\Program Files\Deskshare\Video Edit Magic 3\
uninstall cmd: "C:\Program Files\Deskshare\Video Edit Magic 3\unins000.exe"
publisher: Deskshare Inc.
help link: http://www.deskshare.com/contact_us.aspx

VirtuaGirl (VirtuaGirl)
uninstall cmd: C:\PROGRA~1\Vg\UNWISE.EXE C:\PROGRA~1\Vg\INSTALL.LOG

VirtuaGirl 2 (VirtuaGirl 2)
uninstall cmd: C:\PROGRA~1\Vg\UNWISE.EXE C:\PROGRA~1\Vg\INSTALL.LOG

Virtual Assistant Online (Virtual Assistant Online)
uninstall cmd: C:\PROGRA~1\EMBARQ\UNWISE.EXE C:\PROGRA~1\EMBARQ\INSTALL.LOG

Weather Services (Weather Services)
uninstall cmd: C:\WINDOWS\system32\control.exe C:\PROGRA~1\THEWEA~1\Framework\wxfw.cpl,4

Windows Genuine Advantage Validation Tool (KB892130) 1.7.0069.2 (WGA)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=892130

Windows Imaging Component 3.0.0.0 (WIC)
install date: 20071005
uninstall cmd: "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
publisher: Microsoft Corporation

Wild West 3D Screensaver 1.0 (Wild West 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Wild West 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Wild West 3D Screensaver\unins000.exe"

Winamp (remove only) (Winamp)
uninstall cmd: "C:\Program Files\Winamp\UninstWA.exe"

Winamp Toolbar for Internet Explorer 5.1.20.3 (Winamp Toolbar)
uninstall cmd: "C:\Program Files\Winamp Toolbar\uninstall.exe"
publisher: AOL LLC
help link: http://forums.winamp.com

CDG Ripper 1.00 (WinCDG_Pro_2_2.42)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\CDG Ripper\irunin.ini"

Windows Live Toolbar 03.01.0146 (Windows Live Toolbar)
uninstall cmd: "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750}
publisher: Microsoft Corporation

Windows Media Format 11 runtime (Windows Media Format Runtime)
uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
help link: http://go.microsoft.com/fwlink/?LinkId=62768

Windows Media Player 11 (Windows Media Player)
uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall

WinRAR archiver (WinRAR archiver)
uninstall cmd: C:\Program Files\WinRAR\uninstall.exe

Winter 3D Screensaver 1.0 (Winter 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Winter 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Winter 3D Screensaver\unins000.exe"

Winter Night 3D Screensaver 1.0 (Winter Night 3D Screensaver_is1)
install location: C:\Program Files\Astro Gemini Software\Winter Night 3D Screensaver\
uninstall cmd: "C:\Program Files\Astro Gemini Software\Winter Night 3D Screensaver\unins000.exe"

WinZip 9.0 (6028) (WinZip)
version (major): 9
install location: C:\PROGRA~1\WINZIP\
uninstall cmd: "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
publisher: WinZip Computing, Inc.
help link: http://www.winzip.com/xsupport.htm

(WMCSetup)

Windows Media Format 11 runtime (WMFDist11)
install date: 20071018
uninstall cmd: "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:

Windows Media Player 11 (wmp11)
install date: 20071018
uninstall cmd: "C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:

Microsoft User-Mode Driver Framework Feature Pack 1.0 (Wudf01000)
install date: 20071018
uninstall cmd: "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
comments: Build Number 5716

Xilisoft DVD Ripper Ultimate 5.0.36.0603 (Xilisoft DVD Ripper Ultimate 5)
uninstall cmd: C:\Program Files\Xilisoft\DVD Ripper Ultimate 5\Uninstall.exe
publisher: Xilisoft
help link: http://www.xilisoft.com

XML Paper Specification Shared Components Pack 1.0 (XpsEPSC)
install date: 20071005
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=test

Yahoo! Anti-Spy (Yahoo! Anti-Spy)
uninstall cmd: C:\PROGRA~1\Yahoo!\Common\unypsr.exe

Yahoo! Toolbar (Yahoo! Companion)
uninstall cmd: C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

Yahoo! Browser Services (Yahoo! Extras)
uninstall cmd: C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S

Yahoo! Internet Mail (Yahoo! Mail)
uninstall cmd: C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll

Yahoo! Mail Advisor (Yahoo! Mail Advisor)
uninstall cmd: C:\PROGRA~1\Yahoo!\Common\UNINST~1.EXE

Yahoo! Messenger (Yahoo! Messenger)
uninstall cmd: C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
publisher: Yahoo! Inc.

Yahoo! Search Protection (Yahoo! Search Defender)
uninstall cmd: C:\PROGRA~1\Yahoo!\SEARCH~1\UNINST~1.EXE

(Yahoo! Toolbar)
uninstall cmd: C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

Yahoo! Install Manager (YInstHelper)
uninstall cmd: C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL

Zuma Deluxe 1.0 (Zuma Deluxe 1.0)
uninstall cmd: C:\Program Files\PopCap Games\Zuma Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Zuma Deluxe\Install.log"

MSXML 6.0 Parser (KB933579) 6.10.1200.0 ({0A869A65-8C94-4F7C-A5C7-972D3C8CED9E})
version: 101319856
version (major): 6
version (minor): 10
estimated size: 1333
install date: 20070928
install source: c:\77813f2921cb67543031ba0e9eb5b11c\
uninstall cmd: MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/933579

Security Update for CAPICOM (KB931906) 2.1.0.2 ({0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A})
version: 33619968
version (major): 2
version (minor): 1
estimated size: 770
install date: 20071010
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
publisher: Microsoft Corporation

CD+G AutoName 0.1.0 ({10F9F5C7-0C42-11D6-8255-000102030406})
version: 65536
version (minor): 1
estimated size: 9279
install date: 20071016
install source: C:\WINDOWS\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{10F9F5C7-0C42-11D6-8255-000102030406}
publisher: Your Company Name

({11C98E1A-EC91-4B38-B44C-C562292D8453})

Try Corel Snapfire muvee autoProducer add on 1.00.0000 ({12665B01-3F3A-4433-B179-9D8E352D7547})
version: 16777216
version (major): 1
estimated size: 106
install date: 20071208
install location: C:\Program Files\Common Files\Corel\Modules\muvee Module\
install source: C:\Documents and Settings\All Users\Application Data\Corel\Downloads\540220149_400013\1170190174522\SFP120_EN_DE_FR_ES_IT_NL_COREL_Up\muvee\
publisher: Corel Corporation

({169F8893-C1C5-4847-972C-EA1E008112AC})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{169F8893-C1C5-4847-972C-EA1E008112AC}\setup.exe" -l0x9

Microsoft Works 6-9 Converter 9.7.0621 ({172423F9-522A-483A-AD65-03600CE4CA4F})
version: 151454317
version (major): 9
version (minor): 7
estimated size: 6757
install date: 20080516
install source: C:\Documents and Settings\BURNING ADDICTION\My Documents\
uninstall cmd: MsiExec.exe /X{172423F9-522A-483A-AD65-03600CE4CA4F}
publisher: Microsoft Corporation
comments: Converter for Microsoft Works 6-9 Word Processor files.
help link: http://go.microsoft.com/fwlink/?LinkId=6831

({1888DAFD-C634-4BC4-865C-3455E24F6177})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1888DAFD-C634-4BC4-865C-3455E24F6177}\setup.exe" -l0x9

AutoUpdate 1.1 ({18D10072035C4515918F7E37EAFAACFC})
install location: C:\Program Files\DivX\AutoUpdate

Cool & Quiet ({1ADE1AA0-7F82-4BB1-B1BD-727DE438057B})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}\setup.exe" -l0x9

Google Earth 4.3.7284.3916 ({1D14373E-7970-4F2F-A467-ACA4F0EA21E3})
version: 67312756
version (major): 4
version (minor): 3
estimated size: 25868
install date: 20080729
install location: C:\Program Files\Google\Google Earth\
install source: C:\WINDOWS\TEMP\7ZipSfx.000\
uninstall cmd: MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
publisher: Google

NVIDIA ForceWare Network Access Manager 2.03.6531 ({1F6423DE-7959-4178-80E0-023C7EAA5347})
version: 33757571
version (major): 2
version (minor): 3
estimated size: 19698
install date: 20070922
install location: C:\Program Files\NVIDIA Corporation\NetworkAccessManager\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\_is1DE\
publisher: NVIDIA Corporation

InterVideo WinDVD 8 8.0-B6.109 ({20471B27-D702-4FE8-8DEC-0702CC8C0A85})
version: 134217728
version (major): 8
estimated size: 150536
install date: 20071215
install location: C:\Program Files\InterVideo\DVD8\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\pftF~tmp\
publisher: InterVideo Inc.
contact: http://www.intervideo.com/jsp/Support.jsp/
help link: support@intervideo.com

Symantec 11.0.1 ({228F6876-A313-40A3-91C0-C3CBE6997D09})
version: 184549377
version (major): 11
estimated size: 2956
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\Support\MSRedist\
uninstall cmd: MsiExec.exe /I{228F6876-A313-40A3-91C0-C3CBE6997D09}
publisher: Symantec Corp

Google Toolbar for Internet Explorer ({2318C2B1-4965-11d4-9B18-009027A5CD4F})
uninstall cmd: regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"

({236FADD8-58FD-11D6-A285-00A0CC51B2FE})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{236FADD8-58FD-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9

Microsoft SQL Server 2005 Tools Express Edition 9.2.3042.00 ({2750B389-A2D2-4953-99CA-27C1F2A8E6FD})
version: 151129058
version (major): 9
version (minor): 2
estimated size: 43352
install date: 20070922
install source: C:\~sqltmp\express\Setup\
uninstall cmd: MsiExec.exe /I{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=52152

Internet Worm Protection 11.0.1 ({2908F0CB-C1D4-447F-97A2-CFC135C9F8D4})
version: 184549377
version (major): 11
estimated size: 11241
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\NAV\
uninstall cmd: MsiExec.exe /I{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4}
publisher: Symantec Corp

RegAlyzer 1.5.8.10 ({296B2D8E-CE82-92AF-B2E8-A646E7CB78A2}_is1)
install date: 20080821
install location: C:\Program Files\Safer Networking\RegAlyzer\
uninstall cmd: "C:\Program Files\Safer Networking\RegAlyzer\unins000.exe"
publisher: Safer Networking Limited
help link: http://forums.spybot.info/forumdisplay.php?f=6

FileAlyzer 1.6.0.4 ({29D3773E-54F4-23C2-D523-236A4453B844}_is1)
install date: 20080821
install location: C:\Program Files\Safer Networking\FileAlyzer\
uninstall cmd: "C:\Program Files\Safer Networking\FileAlyzer\unins000.exe"
publisher: Safer Networking Limited
help link: http://forums.spybot.info/forumdisplay.php?f=5

Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) 9.2.3042.00 ({2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F})
version: 151129058
version (major): 9
version (minor): 2
estimated size: 210752
install date: 20070922
install source: C:\~sqltmp\express\Setup\
uninstall cmd: MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=52152

3.0.20070525 ({2CCBABCB-6427-4A55-B091-49864623C43F})
version: 20070525
version (major): 3

SymNet 5.4.0 ({2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2})
version: 84148224
version (major): 5
version (minor): 4
estimated size: 508
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\Support\SymNet\
uninstall cmd: MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
publisher: Symantec Corporation

2.0.14.583 ({2FCE4FC5-6930-40E7-A4F1-F862207424EF})
version (major): 2
install location: C:\Program Files\InterVideo\WCreator2
uninstall cmd: "C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
publisher: InterVideo Inc.
contact: support@intervideo.com
help link: http://www.intervideo.com/jsp/Support.jsp

Java(TM) 6 Update 3 1.6.0.30 ({3248F0A8-6813-11D6-A77B-00B0D0160030})
version: 17170432
version (major): 1
version (minor): 6
estimated size: 113966
install date: 20071202
install source: http://javadl.sun.com/webapps/download/GetFile/1.6.0_03-b05/windows-i586/
uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
publisher: Sun Microsystems, Inc.
contact: http://java.com
help link: http://java.com
readme: C:\Program Files\Java\jre1.6.0_03\README.txt

EN 13.1 ({32A72502-BC2C-4C39-ACEA-BC3D463F0697})
version: 218169344
version (major): 13
version (minor): 1
estimated size: 89996
install date: 20071216
install location: C:\Program Files\Corel\CorelDRAW Graphics Suite 13\
install source: C:\Program Files\Corel\CorelDRAW Graphics Suite X3 Setup Files\CGS13\
uninstall cmd: MsiExec.exe /I{32A72502-BC2C-4C39-ACEA-BC3D463F0697}
publisher: Corel Corporation
comments:
contact: Corel Customer Service
help link: http://www.corel.com
help telephone: U.S. 1-800-772-6735 Outside U.S. +441628 581601, UK: 0870 774 0202
readme: file:///C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\EN\Readme.html

Windows Live Toolbar Extension (Windows Live Toolbar) 03.01.0146 ({341201D4-4F61-4ADB-987E-9CCE4D83A58D})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 609
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\1195c730202f8bbe4d15fba28cc6a229\img\
uninstall cmd: MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
publisher: Microsoft Corporation

Norton AntiVirus Help 11.00.00 ({34EEB1F5-E939-40A1-A6BA-957282A4B2C8})
version: 184549376
version (major): 11
estimated size: 892
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\Support\Help\
uninstall cmd: MsiExec.exe /I{34EEB1F5-E939-40A1-A6BA-957282A4B2C8}
publisher: Symantec Corp.

({34F0D55F-C386-4195-9A5B-961D3F6ACD46})
install location: C:\Program Files\InterVideo\MediaOne Gallery

WebFldrs XP 9.50.7523 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227})
version: 154279267
version (major): 9
version (minor): 50
estimated size: 2472
install date: 20070922
install source: C:\WINDOWS\system32\
publisher: Microsoft Corporation
help link: http://www.microsoft.com/windows

Windows Live Outlook Toolbar (Windows Live Toolbar) 03.01.0146 ({35E1A8C8-6646-4101-B0AA-42D1EB2AB3AE})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 549
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\b0f85ed8866f6ddb1be1f0a4d5ac14bc\img\
uninstall cmd: MsiExec.exe /X{35E1A8C8-6646-4101-B0AA-42D1EB2AB3AE}
publisher: Microsoft Corporation

JMB36X Raid Configurer 1.00.0000 ({3A1B5D40-41E9-43FA-8C7B-A8667F5586EF})
version: 16777216
install date: 20070922
install source: L:\Drivers\RAID\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}\setup.exe" -l0x9 -removeonly
publisher: JMICRON Technology Corp.

Karaoke Go Round 3.0 ({3D969CD5-1FD7-4943-89F6-CD39CA8CB961})
version: 50331648
version (major): 3
estimated size: 236230
install date: 20070923
install location: C:\Program Files\Karaoke-Go-Round3
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\mia1\
publisher: ActiveAsp Software

({40602E2C-AB5C-4887-8093-3BFE5B8B95B3})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40602E2C-AB5C-4887-8093-3BFE5B8B95B3}\setup.exe" REMOVEALL

Wal-Mart Digital Photo Manager 1.2.0.70 ({41FE2866-7D7D-4EDF-9C7A-F1F6A346BA83})
version: 16908288
version (major): 1
version (minor): 2
estimated size: 11026
install date: 20080626
install location: C:\Program Files\Wal-Mart\Wal-Mart Digital Photo Manager\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{41FE2866-7D7D-4EDF-9C7A-F1F6A346BA83}
publisher: Wal-Mart Stores, Inc.
help link: http://www.walmart.com

({435E969D-867E-4364-8E74-3DC8A69C5BDB})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9

QuickCam 5.5.0 ({43A9F944-0398-425E-9E22-201F65FE0CCA})
version: 84213760
version (major): 5
version (minor): 5
estimated size: 132328
install date: 20070925
install source: M:\quickcam\
uninstall cmd: MsiExec.exe /I{43A9F944-0398-425E-9E22-201F65FE0CCA}
publisher: Logitech, Inc.
comments: 9am to 4pm Monday to Friday (Pacific Time Zone)
contact: Logitech Customer Support
help link: http://support.logitech.com
help telephone: USA: (702) 269-3457 UK: +44 (0) 1344-894301

Tabbed Browsing (Windows Live Toolbar) 03.01.0146 ({47FBF7F9-FBD3-43EF-823B-7684D56C1962})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 1635
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\c1938309d69cdcb33194d5e863eba0aa\img\
uninstall cmd: MsiExec.exe /X{47FBF7F9-FBD3-43EF-823B-7684D56C1962}
publisher: Microsoft Corporation

Windows Live Sign-in Assistant 4.100.313.1 ({49672EC2-171B-47B4-8CE7-50D7806360D7})
version: 73662777
version (major): 4
version (minor): 100
estimated size: 1220
install date: 20071009
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
publisher: Microsoft Corporation

Music Alarm 1.00.14 ({4999E00F-EB5E-402E-B5AE-BB5710F77EEB})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4999E00F-EB5E-402E-B5AE-BB5710F77EEB}\setup.exe" -l0x9

FontNav 5.0 ({4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE})
version: 83886080
version (major): 5
estimated size: 3500
install date: 20071216
install source: C:\Program Files\Corel\CorelDRAW Graphics Suite X3 Setup Files\CGS13\
uninstall cmd: MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}
publisher: Corel Corporation
comments:
contact: Corel Customer Service
help link: http://www.corel.com
help telephone: U.S. 1-800-772-6735 Outside U.S. +441628 581601, UK: 0870 774 0202

({5210ED6D-52A9-11D6-A285-00A0CC51B2FE})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9

InterVideo DeviceService 1.0.0 ({521AAD14-5030-44BB-8B0E-5CE65FCE57E0})
version: 16777216
version (major): 1
estimated size: 13056
install date: 20071129
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\pftE5B~tmp\3rdPartyApp\DeviceService\
uninstall cmd: MsiExec.exe /I{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}
publisher: InterVideo
contact: InterVideo

({530AFAFF-6F0A-48BB-88D0-04F9658322D3})

OneCare Advisor (Windows Live Toolbar) 03.01.0072 ({53B2CFE9-A508-4457-B2CA-5D253536BFB7})
version: 50397256
version (major): 3
version (minor): 1
estimated size: 5045
install date: 20071010
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{53B2CFE9-A508-4457-B2CA-5D253536BFB7}
publisher: Microsoft Corporation

Form Fill (Windows Live Toolbar) 03.01.0146 ({548B3DC6-2300-47E1-BA7B-74AD25F8DEBF})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 614
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\dc872c586f605af8e8bd9c1285d00126\img\
uninstall cmd: MsiExec.exe /X{548B3DC6-2300-47E1-BA7B-74AD25F8DEBF}
publisher: Microsoft Corporation

MRename 1.7 1.7.516 ({555C6C10-43C9-4174-B898-80D9BC51E41B})
version: 17236484
version (major): 1
version (minor): 7
estimated size: 1620
install date: 20080417
install source: C:\RealmEX\download\Speakeasy\MRename 1.7.516\
uninstall cmd: MsiExec.exe /I{555C6C10-43C9-4174-B898-80D9BC51E41B}
publisher: Home Office
comments: Integrated tool for renaming multiple files.
contact: rajko@fly.srk.fer.hr

neroxml 1.0.0 ({56C049BE-79E9-4502-BEA7-9754A3E60F9B})
version: 16777216
version (major): 1
estimated size: 48
install date: 20071206
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\NERO13890\Redist\
uninstall cmd: MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
publisher: Nero AG
contact: Nero AG

Creative MediaSource ({56F3E1FF-54FE-4384-A153-6CCABA097814})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\SETUP.EXE" -l0x9 /remove

Windows Live Messenger 8.1.0178.00 ({571700F0-DB9D-4B3A-B03D-35A14BB5939F})
version: 134283442
version (major): 8
version (minor): 1
estimated size: 31823
install date: 20071009
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
publisher: Microsoft Corporation

AsusUpdate ({587178E7-B1DF-494E-9838-FA4DD36E873C})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{587178E7-B1DF-494E-9838-FA4DD36E873C}\setup.exe" -l0x9

({5933921D-4253-40B6-B4D9-B7D680F1B6EC})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5933921D-4253-40B6-B4D9-B7D680F1B6EC}\setup.exe" -l0x9

({5CDC05F7-83E4-4611-AD3C-A6EB2100332A})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDC05F7-83E4-4611-AD3C-A6EB2100332A}\setup.exe" -l0x9

({5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x9

Microsoft .NET Framework 2.0 Service Pack 1 2.1.20706 ({5DEDD928-2CBE-35E9-B002-85232EDB120A})
version: 33640674
version (major): 2
version (minor): 1
estimated size: 190748
install date: 20071005
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\dotnetfx3520706.01\1033\dotnetfx20\
uninstall cmd: MsiExec.exe /I{5DEDD928-2CBE-35E9-B002-85232EDB120A}
publisher: Microsoft

PlexTools Professional V2.32a 2.32.0001 ({5F928EE1-ED35-4E6E-8FF8-325DD71927FD})
version: 35651585
version (major): 2
version (minor): 32
estimated size: 10189
install date: 20070922
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\_is174\
uninstall cmd: MsiExec.exe /X{5F928EE1-ED35-4E6E-8FF8-325DD71927FD}
publisher: Plextor Europe S.A. / N.V.

({62369F2F77534556AEF4C58152E3BDE5})

CorelDRAW Graphics Suite X3 13.2 ({63218538-4A69-497F-8455-904261B0E9E4})
version: 218234880
version (major): 13
version (minor): 2
estimated size: 407290
install date: 20071216
install location: C:\Program Files\Corel\CorelDRAW Graphics Suite 13\
install source: C:\Program Files\Corel\CorelDRAW Graphics Suite X3 Setup Files\CGS13\
uninstall cmd: MsiExec.exe /I{63218538-4A69-497F-8455-904261B0E9E4}
publisher: Corel Corporation
comments:
contact: Corel Customer Service
help link: http://www.corel.com
help telephone: U.S. 1-800-772-6735 Outside U.S. +441628 581601, UK: 0800 376 9271
readme: file:///C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Languages\EN\Readme.html

Corel Paint Shop Pro Photo X2 12.001.0000 ({64E72FB1-2343-4977-B4A8-262CD53D0BD3})
version: 201392128
version (major): 12
version (minor): 1
estimated size: 360825
install date: 20071216
install location: C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\
install source: C:\Program Files\Corel\Corel Paint Shop Pro Photo X2 - Installation Files\
uninstall cmd: MsiExec.exe /X{64E72FB1-2343-4977-B4A8-262CD53D0BD3}
publisher: Corel Corporation
comments: Installs Paint Shop Pro Photo X2
contact: Corel Customer Service
help link: http://www.corel.com/support
help telephone: U.S. 1-800-772-6735 Outside U.S. +441628 581601, UK: 0870 774 0202

Popup Blocker (Windows Live Toolbar) 03.01.0146 ({66A7A386-6F35-41A7-A731-101F0C0153C8})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 3383
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\d6bc914ef270f26973b550c0a709896d\img\
uninstall cmd: MsiExec.exe /X{66A7A386-6F35-41A7-A731-101F0C0153C8}
publisher: Microsoft Corporation

({67AEFC4C-69E4-11D7-85F4-00E018013273})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x9

Windows Live Toolbar Feed Detector (Windows Live Toolbar) 03.01.0146 ({68108E66-D13A-4EE8-A6F4-40E4B90C2A26})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 446
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\2aac4cc163ef1966fc97e64fa293d68c\img\
uninstall cmd: MsiExec.exe /X{68108E66-D13A-4EE8-A6F4-40E4B90C2A26}
publisher: Microsoft Corporation

Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) 8.1.2 ({6846389C-BAC0-4374-808E-B120F86AF5D7})
version: 134283266
version (major): 8
version (minor): 1
estimated size: 12930
install date: 20080709
install location: C:\Program Files\Adobe\Security Update\
install source: C:\Documents and Settings\BURNING ADDICTION\Local Settings\Application Data\Adobe\Updater5\Install\acrobat8pro-EFG\
uninstall cmd: MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
publisher: Adobe Systems, Inc
comments: Your Comments
contact: Customer Support Department
help link: http://www.Adobe.com
help telephone: 1-555-555-4505

AI Gear 1.00.13 ({6B568B64-0BDE-4FB2-A1AB-8A41DF033C57})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6B568B64-0BDE-4FB2-A1AB-8A41DF033C57}\setup.exe" -l0x9

({6CCDF4E6-D2AE-4DD8-80FD-F9AFF951AEAE})

QuickTime 7.4.0.91 ({6EC874C2-F950-4B7E-A5B7-B1066D6B74AA})
version: 117702656
version (major): 7
version (minor): 4
estimated size: 78256
install date: 20080205
install location: C:\Program Files\QuickTime\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: 1-800-275-2273

({7201B853-5833-11D6-A285-00A0CC51B2FE})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7201B853-5833-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9

Microsoft Visual C++ 2005 Redistributable 8.0.56336 ({7299052b-02a4-4627-81f2-1818da5d550d})
version: 134274064
version (major): 8
estimated size: 5330
install date: 20071127
install source: C:\Documents and Settings\BURNING ADDICTION\Desktop\Adobe Premiere Elements 4.0\VC2005\
uninstall cmd: MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
publisher: Microsoft Corporation

Roxio Easy Media Creator 7 Basic DVD Edition 7.2.0.15 ({747D1B34-A1FC-4EF3-A6AE-E86F39CEFDE5})
version: 117571584
version (major): 7
version (minor): 2
estimated size: 434812
install date: 20070922
install source: L:\EasyMediaCreator\
uninstall cmd: MsiExec.exe /I{747D1B34-A1FC-4EF3-A6AE-E86F39CEFDE5}
publisher: Roxio, Inc.
comments: Master installer for The Digital Media Suite
help link: http://www.roxio.com/en/support/
readme: C:\Program Files\Roxio\Easy Media Creator 7\EMC7BasicEditionReadMe.html

AI Booster 2.03.11 ({74BF0A46-DF67-4D86-B038-BF0E51871B66})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{74BF0A46-DF67-4D86-B038-BF0E51871B66}\setup.exe" -l0x9

The Cleaner 4.1 ({750C0D4F-E731-4104-9A51-A5E579CE3867}_is1)
uninstall cmd: "C:\Program Files\The Cleaner\unins000.exe"
publisher: MooSoft Development Inc
help link: http://www.moosoft.com/thecleaner/support.php

Nero 7 Ultra Edition 7.03.0647 ({7516254D-7F98-49DD-8209-5D2208BD1033})
version: 117637767
version (major): 7
version (minor): 3
estimated size: 619041
install date: 20071206
install location: C:\Program Files\Nero\Nero 7\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\NERO13890\
uninstall cmd: MsiExec.exe /X{7516254D-7F98-49DD-8209-5D2208BD1033}
publisher: Nero AG
comments: Nero AG
contact: techsupport@nero.com retail-support@nero.com chinese-techsupport@nero.com
help link: techsupport@nero.com retail-support@nero.com chinese-techsupport@nero.com
help telephone: xxxxxxxxxxxxxx

6.6.1 ({7585478E9D9B42108671C12F8714CEFE})
install location: C:\Program Files\DivX\DivX Converter
uninstall cmd: C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
publisher: DivX, Inc.

Map Button (Windows Live Toolbar) 03.01.0146 ({7745B7A9-F323-4BB9-9811-01BF57A028DA})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 543
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\e95260fe8f089c25d1b281a319d6ebcb\img\
uninstall cmd: MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA}
publisher: Microsoft Corporation

SPBBC 1.00.0000 ({77772678-817F-4401-9301-ED1D01A8DA56})
version: 16777216
version (major): 1
estimated size: 1423
install date: 20071202
install location: C:\Program Files\Norton AntiVirus\
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\Support\SPBBC\
uninstall cmd: MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
publisher: Your Company Name

({77ACE67A-0D21-4CEF-8A97-ED20A61B978B})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{77ACE67A-0D21-4CEF-8A97-ED20A61B978B}\setup.exe" -l0x9

Windows Live Favorites for Windows Live Toolbar 03.01.0146 ({786C4AD1-DCBA-49A6-B0EF-B317A344BD66})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 1879
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\7f4e6f18fb62e85546ea7d7bca676015\img\
uninstall cmd: MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
publisher: Microsoft Corporation
contact: Microsoft Corporation

({7A900EAB-DA37-4554-AF19-9C337476D05D})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x9

Corel Snapfire Plus 1.201.0000 ({7ADE3A47-B425-45E9-8FF6-11BE2B775645})
version: 29949952
version (major): 1
version (minor): 201
estimated size: 205206
install date: 20071208
install source: L:\Software\SnapFire\Corel Snapfire Plus\
uninstall cmd: MsiExec.exe /X{7ADE3A47-B425-45E9-8FF6-11BE2B775645}
publisher: Corel Corporation

1.00 ({7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408})
version: 16777216
install location: C:\Program Files\Creative\AudioConSole
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9

({869D88A5-BD6C-4E39-8536-D95259EAD7E8})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{869D88A5-BD6C-4E39-8536-D95259EAD7E8}\setup.exe" -l0x9

({87499F38-FD69-4A2B-B41A-BAB8DE9B94FE})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{87499F38-FD69-4A2B-B41A-BAB8DE9B94FE}\setup.exe" -l0x9

({881A74B3-3D17-4842-B9AF-0761C6E6C4B5})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{881A74B3-3D17-4842-B9AF-0761C6E6C4B5}\setup.exe" -l0x9

DivX Player 6.8.2 ({8ADFC4160D694100B5B8A22DE9DCABD9})
install location: C:\Program Files\DivX\DivX Player
uninstall cmd: C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER

InterVideo Launcher ({8AEEE6D6-C95D-465A-B8D3-B7AE2FA7B8B4})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AEEE6D6-C95D-465A-B8D3-B7AE2FA7B8B4}\setup.exe" REMOVEALL

Ulead GIF Animator 5 ({8AF3E926-ED59-11D4-A44B-0000E86D2305})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AF3E926-ED59-11D4-A44B-0000E86D2305}\Setup.exe"

Microsoft .NET Framework 3.5 (Pre-Release Version) 3.5.20706 ({8E7D9374-438A-3E7F-95A2-99B7D67838EB})
version: 50680034
version (major): 3
version (minor): 5
estimated size: 48557
install date: 20071005
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\IXP03699.tmp\dotnetfx35\x86\
uninstall cmd: MsiExec.exe /I{8E7D9374-438A-3E7F-95A2-99B7D67838EB}
publisher: Microsoft

({8EF5F498-7FB5-11D6-9963-00A0C92C4EC3})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8EF5F498-7FB5-11D6-9963-00A0C92C4EC3}\setup.exe" -l0x9

Logitech Desktop Messenger 2.52.18 ({900B1197-53F5-4F46-A882-2CFFFE2EEDCB})
version: 23265379
install location: C:\Program Files\Logitech\Desktop Messenger
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\setup.exe" -l0x9 UNINSTALL
publisher: Logitech, Inc.
contact: Logitech Customer Support
help link: www.logitech.com/support

Microsoft Office XP Web Components 10.0.6626.0 ({90260409-6000-11D3-8CFE-0050048383C9})
version: 167778786
version (major): 10
estimated size: 46445
install date: 20080311
install source: C:\unzipped\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP\
uninstall cmd: MsiExec.exe /I{90260409-6000-11D3-8CFE-0050048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support

Microsoft Office XP Professional with FrontPage 10.0.6626.0 ({90280409-6000-11D3-8CFE-0050048383C9})
version: 167778786
version (major): 10
estimated size: 677215
install date: 20080821
install source: C:\unzipped\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP\
uninstall cmd: MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Office\Office10\1033\OFREAD10.HTM

({9154ED7C-926E-49CC-B677-0CF3C5267457})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9154ED7C-926E-49CC-B677-0CF3C5267457}\setup.exe" -l0x9

DVD Decoder Pak for Windows XP 1.0.0 ({92C5DB3D-9D6F-4324-BB11-57825F4C2635})
version: 16777216
version (major): 1
estimated size: 1803
install date: 20071028
install source: C:\unzipped\DVD Decoder Pack for Windows XP Media Player\
uninstall cmd: MsiExec.exe /X{92C5DB3D-9D6F-4324-BB11-57825F4C2635}
publisher: roddy2000@hotbox.ru
contact: roddy2000@hotbox.ru
help link: www.corbina.ru/~roddy

MediaOne Gallery ({940BA8B7-0058-0002-3238-BFD081926B93})

InterVideo Promotion Agent ({95392E65-0900-0001-3030-1EEC2624019E})

2.5-B9.61 ({96BF9A2A-1835-4DEE-A94F-9EA4F77976BF})
version (major): 2
version (minor): 5
install location: C:\Program Files\InterVideo\DVDCopy 2
uninstall cmd: "C:\Program Files\InstallShield Installation Information\{96BF9A2A-1835-4DEE-A94F-9EA4F77976BF}\setup.exe" --u:{96BF9A2A-1835-4DEE-A94F-9EA4F77976BF}
publisher: InterVideo Inc.
contact: support@intervideo.com
help link: http://www.intervideo.com/jsp/Support.jsp

({9A4D2983-4662-4387-BE3D-4CFC2FA9C100})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A4D2983-4662-4387-BE3D-4CFC2FA9C100}\setup.exe" -l0x9

Sound Blaster Audigy 2 ZS ({9E2514D9-DC24-4634-B348-61F3EF0F1628})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E2514D9-DC24-4634-B348-61F3EF0F1628}\SETUP.EXE" -l0x9

({A1185190-514F-11D6-A285-00A0CC51B2FE})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9

Microsoft Visual C++ 2005 Redistributable 8.0.50727.42 ({A49F249F-0C91-497F-86DF-B2585E8E76B7})
version: 134268455
version (major): 8
estimated size: 4584
install date: 20071215
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
publisher: Microsoft Corporation

RunAlyzer 0.7.3.13 ({A5181519-9F3D-4372-ABC6-C333C2F3A816}_is1)
install date: 20080821
install location: C:\Program Files\Safer Networking\RunAlyzer\
uninstall cmd: "C:\Program Files\Safer Networking\RunAlyzer\unins000.exe"
publisher: Safer Networking Limited
help link: http://forums.spybot.info/forumdisplay.php?f=8

Norton Spyware Scan 2.0.98.0 ({AAE10BE5-F398-41C1-9AAF-A59EBF17DFDE})
version: 33554530
version (major): 2
estimated size: 15949
install date: 20080107
install location: C:\Program Files\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\_isF\
publisher: Symantec Corporation
comments: Yahoo!

TheOnlyBigDog
2008-08-25, 09:27
({AC157741-3285-4D6A-B934-9174587A3493})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC157741-3285-4D6A-B934-9174587A3493}\setup.exe" -l0x9

Adobe Acrobat 8 Professional - English, Français, Deutsch 8.1.2 ({AC76BA86-1033-F400-7760-000000000003})
version: 134283266
version (major): 8
version (minor): 1
estimated size: 1969571
install date: 20080514
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\Adobe Acrobat 8\
publisher: Adobe Systems
comments:
contact: Customer Support
help link: http://www.adobe.com/support/main.html
help telephone:
readme: [INSTALLDIR]Readme.htm

Adobe Acrobat 8.1.2 Security Update 1 (KB403742) ({AC76BA86-1033-F400-7760-000000000003}_Adobe Acrobat 8 Professional - English, Français, Deutsch)
help link: http://www.adobe.com/go/kb403742

Adobe Reader 8.1.2 8.1.2 ({AC76BA86-7AD7-1033-7B44-A81200000003})
version: 134283266
version (major): 8
version (minor): 1
estimated size: 88543
install date: 20080206
install source: C:\Documents and Settings\BURNING ADDICTION\Local Settings\Application Data\Adobe\Updater5\Install\reader8rdr-en_US\
uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
publisher: Adobe Systems Incorporated
comments:
contact: Customer Support
help link: http://www.adobe.com/support/main.html
readme: [INSTALLDIR]Reader\Readme.htm

Adobe Reader 8.1.2 Security Update 1 (KB403742) ({AC76BA86-7AD7-1033-7B44-A81200000003}_Adobe Reader 8.1.2)
help link: http://www.adobe.com/go/kb403742

PowerBackup 2.5 ({ADD5DB49-72CF-11D8-9D75-000129760D75})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ADD5DB49-72CF-11D8-9D75-000129760D75}\setup.exe" -uninstall

DivX Converter 6.6.1 ({B13A7C41581B411290FBC0395694E2A9})
install location: C:\Program Files\DivX\DivX Converter
uninstall cmd: C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
publisher: DivX, Inc.

ASPI Drivers 1.16 ({B2FBB314-4D74-4E66-B467-268C31E80612})
version: 17825792
version (major): 1
version (minor): 16
estimated size: 36
install date: 20071016
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\_is2B\
publisher: Micro Technology Unlimited
comments: ASPI Drivers
contact: Customer Support Department
help link: http://www.mtu.com/
help telephone: 919-870-0344
readme: Readme.txt

({B3549608-69D3-11D7-AB2D-0090271A23A2})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3549608-69D3-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9

Karaoke Zip Scanner 1.0.0.0 ({B3A8C2A6-61EA-4C99-8D9F-9C224F1740F8})
version: 16777216
version (major): 1
estimated size: 2641
install date: 20080425
install location: C:\Program Files\Karaoke Zip Scanner
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\mia1\
uninstall cmd: C:\Documents and Settings\All Users\Application Data\{174BEB07-CB76-4EAC-91FD-95CD34E9901B}\KaraokeZipScannerSetup.exe
publisher: ActiveAsp Software

Spybot - Search & Destroy 1.6.0 ({B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1)
install date: 20080808
install location: C:\Program Files\Spybot - Search & Destroy\
uninstall cmd: "C:\Program Files\Spybot - Search & Destroy\unins001.exe"
publisher: Safer Networking Limited
help link: http://www.safer-networking.org/index.php?page=support

({B5BAAFAE-3561-463D-8E3F-91761A57ADB8})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B5BAAFAE-3561-463D-8E3F-91761A57ADB8}\setup.exe" -l0x9

Microsoft XML Parser 8.20.8730.4 ({B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE})
version: 135537178
version (major): 8
version (minor): 20
estimated size: 792
install date: 20070922
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\IXP000.TMP\
publisher: Microsoft Corporation

DivX Web Player 1.4.0 ({B7050CBDB2504B34BC2A9CA0A692CC29})
install location: C:\Program Files\DivX\DivX Web Player
uninstall cmd: C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
publisher: DivX,Inc.

({BB8AE808-F003-4C7F-B56B-8C80EEAFFE23})
install location: C:\Program Files\Ulead Systems\Ulead VideoStudio 11\AVControl
uninstall cmd: "C:\Program Files\InstallShield Installation Information\{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}\setup.exe" --u:{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}
publisher: InterVideo Inc.
contact: support@intervideo.com
help link: http://www.intervideo.com/jsp/Support.jsp

Microstudio 2.3.1.5 ({BC2AE2D7-E990-4179-B2F3-4322DA9929C6})
version: 33751041
version (major): 2
version (minor): 3
estimated size: 1148
install date: 20070922
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\_isC6\
publisher: Micro Technology Unlimited
comments: Microstudio v2.315
contact: Customer Support Department
help link: www.mtu.com
help telephone: 1-919-870-0344
readme: manual/microstudio2315-manual.htm

EVGA Display Driver 1.00.000 ({BEF3EFE7-5159-436D-9BF0-CCC633179EB4})
version: 16777216
install date: 20070922
install source: L:\Drivers\XP2K\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEF3EFE7-5159-436D-9BF0-CCC633179EB4}\Setup.exe" -l0x9 -removeonly
publisher: EVGA
help link: www.evga.com/support/default.asp

MSXML 4.0 SP2 (KB936181) 4.20.9848.0 ({C04E32E0-0416-434D-AFB9-6969D703A9EF})
version: 68429432
version (major): 4
version (minor): 20
estimated size: 2680
install date: 20070928
install source: c:\8e96ed17dd24251b8ad6ebd5044905\
uninstall cmd: MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/936181

Ulead COOL 3D Production Studio Trial 1.0 ({C4F6BA7F-EE0C-45F8-AE33-F5C71E3F6AA3})
version: 16777216
version (major): 1
install location: C:\Program Files\Ulead Systems\Ulead COOL 3D Production Studio Trial
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4F6BA7F-EE0C-45F8-AE33-F5C71E3F6AA3}\setup.exe" -l0x9
publisher: Ulead Systems

({C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x9

Norton AntiVirus 2005 11.0.1 ({C6F5B6CF-609C-428E-876F-CA83176C021B})
version: 184549377
version (major): 11
estimated size: 58628
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\NAV\
uninstall cmd: MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B}
publisher: Symantec Corporation

VBA 6.2 ({C94E45B0-6AA6-4FB9-9AAE-22085F631880})
version: 100794368
version (major): 6
version (minor): 2
estimated size: 18139
install date: 20071216
install location: C:\Program Files\Corel\CorelDRAW Graphics Suite 13\
install source: C:\Program Files\Corel\CorelDRAW Graphics Suite X3 Setup Files\CGS13\
uninstall cmd: MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}
publisher: Corel Corporation
comments:
contact: Corel Customer Service
help link: http://www.corel.com
help telephone: U.S. 1-800-772-6735 Outside U.S. +441628 581601, UK: 0870 774 0202
readme: file:///C:\INSTALLDIRRES\Languages\EN\Readme.html

Symantec Network Drivers Update 5.5.6.604 ({CA0A1E54-CE0F-4366-B09C-A87B61DC5633})
version: 84213766
version (major): 5
version (minor): 5
estimated size: 2750
install date: 20070927
install source: C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\Updt999\
publisher: Symantec Corporation

Microsoft .NET Framework 1.1 1.1.4322 ({CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1})
version: 16847074
version (major): 1
version (minor): 1
estimated size: 51215
install date: 20070928
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\miaE9.tmp\data\Microsoft .NET Framework 1.1 with Service Pack 1\mDotNet.dll\
uninstall cmd: MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
publisher: Microsoft
readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm

SUPERAntiSpyware Free Edition 3.9.0.1008 ({CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA})
version: 50921472
version (major): 3
version (minor): 9
estimated size: 12617
install date: 20071202
install source: C:\Program Files\Common Files\Wise Installation Wizard\
uninstall cmd: MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
publisher: SUPERAntiSpyware.com
help link: http://www.superantispyware.com/support.html

Norton AntiVirus SYMLT MSI 11.0.1 ({D1FF75E7-DD42-4CFD-B052-20B3FFF4EDB8})
version: 184549377
version (major): 11
estimated size: 1159
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\NAV\
uninstall cmd: MsiExec.exe /I{D1FF75E7-DD42-4CFD-B052-20B3FFF4EDB8}
publisher: Symantec Corp.

Symantec Script Blocking Installer 11.0.1 ({D327AFC9-7BAA-473A-8319-6EB7A0D40138})
version: 184549377
version (major): 11
estimated size: 477
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\Support\ScrBlock\
uninstall cmd: MsiExec.exe /I{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
publisher: Symantec

Windows Live Toolbar 03.01.0146 ({D5A145FC-D00C-4F1A-9119-EB4D9D659750})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 9486
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\c9b6705345e53bd29f6fdc752500ef99\img\
uninstall cmd: MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750}
publisher: Microsoft Corporation

Google Toolbar for Internet Explorer 4.0.0.002 ({DBEA1034-5882-4A88-8033-81C4EF0CFA29})
version: 67108864
version (major): 4
estimated size: 1068
install date: 20080416
install source: C:\Program Files\Google\Installers\
uninstall cmd: MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
publisher: Google Inc.

ccCommon 103.0.1.26 ({DC367608-64A7-4BF7-92F4-8BAA25BA02DB})
version: 1728053249
version (major): 103
estimated size: 5682
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\Support\ccCommon\
uninstall cmd: MsiExec.exe /I{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}
publisher: Symantec

Microsoft .NET Framework 3.0 Service Pack 1 3.1.20706 ({DD02FB0E-0255-3174-A4C4-AADD23486DCC})
version: 50417890
version (major): 3
version (minor): 1
estimated size: 171276
install date: 20071005
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\dotnetfx3520706.01\1033\dotnetfx30\
uninstall cmd: MsiExec.exe /I{DD02FB0E-0255-3174-A4C4-AADD23486DCC}
publisher: Microsoft

({DEBD7BF3-5856-11D6-A285-00A0CC51B2FE})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9

AI Nap 1.00.17 ({E2216699-EA02-4B85-BAB1-1DF34C4BDF9D})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E2216699-EA02-4B85-BAB1-1DF34C4BDF9D}\setup.exe" -l0x9

Norton AntiVirus Parent MSI 11.0.1 ({E5EE9939-259F-4DE2-8023-5C49E16A4F43})
version: 184549377
version (major): 11
estimated size: 661
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\NAV\
uninstall cmd: MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
publisher: Symantec Corp.

({EE6699B3-E5AD-4E59-8F2B-207DF630670C})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\setup.exe" -l0x9

Smart Menus (Windows Live Toolbar) 03.01.0146 ({F084395C-40FB-4DB3-981C-B51E74E1E83D})
version: 50397330
version (major): 3
version (minor): 1
estimated size: 679
install date: 20071129
install source: C:\WINDOWS\SoftwareDistribution\Download\5e9319890eb24b78ffaf0887019a0742\img\
uninstall cmd: MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
publisher: Microsoft Corporation

5.10.01.6110 ({F0A37341-D692-11D4-A984-009027EC0A9C})
version: 50331648
install date: 20070922
install location: C:\Program Files\Analog Devices\SoundMAX
install source: L:\Drivers\Audio\32bit\2K_XP\
publisher: Analog Devices

2.5-B33.45 ({F366D0C4-18F2-44A6-A4E7-7ED2DD37F3D3})
version (major): 2
version (minor): 5
install location: C:\Program Files\InterVideo\Disc Master 2.5
uninstall cmd: "C:\Program Files\InstallShield Installation Information\{F366D0C4-18F2-44A6-A4E7-7ED2DD37F3D3}\setup.exe" --u:{F366D0C4-18F2-44A6-A4E7-7ED2DD37F3D3}
publisher: InterVideo Inc.
contact: support@intervideo.com
help link: http://www.intervideo.com/jsp/Support.jsp

({F37167DD-4436-4641-90B6-329D60632DDA})
install location: C:\Program Files\InterVideo Information Service
uninstall cmd: "C:\Program Files\InstallShield Installation Information\{F37167DD-4436-4641-90B6-329D60632DDA}\Setup.exe" REMOVEALL --u:{F37167DD-4436-4641-90B6-329D60632DDA}

Update Manager 4.60 ({F428D0FB-765D-40EB-BDD8-A1E7F5C597FA})
version: 71041024
version (major): 4
version (minor): 60
estimated size: 710
install date: 20071216
install source: C:\Program Files\Corel\CorelDRAW Graphics Suite X3 Setup Files\CGS13\
uninstall cmd: MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}
publisher: Corel Corporation

MP3+G Toolz 4.0 ({F50A4470-7A45-4A5A-97F8-806990B736C2})
version: 67108864
version (major): 4
estimated size: 6565
install date: 20070922
install source: C:\Documents and Settings\BURNING ADDICTION\Desktop\
uninstall cmd: MsiExec.exe /I{F50A4470-7A45-4A5A-97F8-806990B736C2}
publisher: ActiveASP Software
contact: support@activeaspsoftware.net
help link: http://www.activeaspsoftware.net/

Norton WMI Update 2005.1.0.111 ({F64306A5-4C32-41bb-B153-53986527FAB4})
version (major): 2005
version (minor): 1
estimated size: 613
install date: 20071202
install source: C:\unzipped\Norton Antivirus 2005 + Keygen\Norton Antivirus 2005\Support\SymSC\
uninstall cmd: MsiExec.exe /X{F64306A5-4C32-41bb-B153-53986527FAB4}
publisher: Symantec Corporation

PC Probe II 1.04.05 ({F7338FA3-DAB5-49B2-900D-0AFB5760C166})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}\setup.exe" -l0x9

VideoStudio 11.0.0.0000 ({F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9})
version: 184549376
version (major): 11
estimated size: 197393
install date: 20071216
install location: C:\Program Files\Ulead Systems\Ulead VideoStudio 11\
install source: C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\pft3B.tmp\
publisher: InterVideo Digital Technology Corporation

2.4 ({FA7621DC-7144-4A24-973C-B9BC0E945628})
version: 33816576
install location: c:\program files\intervideo\mediaone gallery
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FA7621DC-7144-4A24-973C-B9BC0E945628}\setup.exe" -l0x9

({FB2292C6-1F0A-11D7-AB2D-0090271A23A2})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9

({FD549B7B-3532-4160-80D4-3E3DD39A9AE5})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD549B7B-3532-4160-80D4-3E3DD39A9AE5}\setup.exe" -l0x9

({FD851F7E-F887-405D-9E1C-488811113EF3})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD851F7E-F887-405D-9E1C-488811113EF3}\setup.exe" -l0x9



--- System Services ---
Service (registry key): .NET CLR Data
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET CLR Networking
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET Data Provider for Oracle
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET Data Provider for SqlServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NETFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Abiosdsk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): abp480n5
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ACPI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft ACPI Driver
Image path: system32\DRIVERS\ACPI.sys
Image size: 187776
Image MD5: A10C7534F7223F4A73A948967D00E69B
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ACPIEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ADIHdAudAddService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ADI UAA Function Driver for High Definition Audio Service
Image path: system32\drivers\ADIHdAud.sys
Image size: 293888
Image MD5: 0158F4027C0808FF65ED3B3D683339C9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): adpu160m
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): AEAudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AE Audio Service
Image path: system32\drivers\AEAudio.sys
Image size: 93952
Image MD5: 358063AB6C1C4173B735525CDFA65F94
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): aec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Acoustic Echo Canceller
Image path: system32\drivers\aec.sys
Image size: 142464
Image MD5: 1EE7B434BA961EF845DE136224C30FEC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): AFD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AFD
Description: AFD Networking Support Environment
Image path: \SystemRoot\System32\drivers\afd.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): Aha154x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): aic78u2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): aic78xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Alerter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Alerter
Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): ALG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Layer Gateway Service
Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\alg.exe
Image size: 44544
Image MD5: F1958FBF86D5C004CF19A5951A9514B7
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): AliIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): AmdK8
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AMD Processor Driver
Image path: system32\DRIVERS\AmdK8.sys
Image size: 36864
Image MD5: 0A4D13B388C814560BD69C3A496ECFA8
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): amsint
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): AppMgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Management
Description: Provides software installation services such as Assign, Publish, and Remove.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): Arp1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 ARP Client Protocol
Description: 1394 ARP Client Protocol
Image path: system32\DRIVERS\arp1394.sys
Image size: 60800
Image MD5: F0D692B0BFFB46E30EB3CEA168BBC49F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): asc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): asc3350p
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): asc3550
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): AsIO
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AsIO
Image path: system32\drivers\AsIO.sys
Image size: 12664
Image MD5: 663F2FB92608073824EE3106886120F3
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): ASP.NET
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ASP.NET_1.1.4322
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ASP.NET_2.0.50727
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Aspi32
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\aspi32.sys
Image size: 16512
Image MD5: 54AB078660E536DA72B21A27F56B035B
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1

Service (registry key): AspiXNT
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): aspnet_state
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ASP.NET State Service
Description: Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
Image size: 34144
Image MD5: F8DFB3152BD61A7E40A603601AB6DD8F
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): AsyncMac
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: RAS Asynchronous Media Driver
Description: RAS Asynchronous Media Driver
Image path: system32\DRIVERS\asyncmac.sys
Image size: 14336
Image MD5: 02000ABF34AF4C218C35D257024807D6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): atapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Standard IDE/ESDI Hard Disk Controller
Image path: system32\DRIVERS\atapi.sys
Image size: 95360
Image MD5: CDFE4411A69C224BD1D11B2DA92DAC51
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Atdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): Atmarpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ATM ARP Client Protocol
Description: ATM ARP Client Protocol
Image path: system32\DRIVERS\atmarpc.sys
Image size: 59904
Image MD5: EC88DA854AB7D7752EC8BE11A741BB7F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): AudioSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Audio
Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs

Service (registry key): audstub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Audio Stub Driver
Image path: system32\DRIVERS\audstub.sys
Image size: 3072
Image MD5: D9F724AA26C010A217C97606B160ED68
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Automatic LiveUpdate Scheduler
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Automatic LiveUpdate Scheduler
Description: Manages the scheduling of Automatic LiveUpdate sessions
Object name: LocalSystem
Image path: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
Image size: 100032
Image MD5: 7768CE75C5CBF0D8F441CE2BBD806B7F
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): BANTExt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Belarc SMBios Access
Image path: \SystemRoot\System32\Drivers\BANTExt.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): BattC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): BCM43XX
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wireless-G PCI Adapter Driver
Image path: system32\DRIVERS\bcmwl5.sys
Image size: 369024
Image MD5: 38CA1443660D0F5F06887C6A2E692AEB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Beep
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): BITS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Background Intelligent Transfer Service
Description: Transfers data between clients and servers in the background. If BITS is disabled, features such as Windows Update will not work correctly.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): Browser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Computer Browser
Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,LanmanServer

Service (registry key): Capture Device Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Capture Device Service
Description: Manages device arrival and removal event. This service is provided by InterVideo.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe"
Image size: 198168
Image MD5: 1778EBA872274C1226D869CD9486847E
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): catchme
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \??\C:\DOCUME~1\BURNIN~1\LOCALS~1\Temp\catchme.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): cbidf2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): CCDECODE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Closed Caption Decoder
Image path: system32\DRIVERS\CCDECODE.sys
Image size: 17024
Image MD5: 6163ED60B684BAB19D3352AB22FC48B2
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ccEvtMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Event Manager
Description: Symantec Event Manager
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
Image size: 197992
Image MD5: CF1A0433BB97C839484DD359691DD521
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0
Depends On services: RPCSS,ccSetMgr

Service (registry key): ccPwdSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Password Validation
Description: Symantec Password Validation Service
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
Image size: 79208
Image MD5: F6394A17866C8E553874DE5EFF3F3679
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0

Service (registry key): ccSetMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Settings Manager
Description: Symantec Settings Manager
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
Image size: 181608
Image MD5: 76C495A19F694E18BCE9713B3587948E
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0
Depends On services: RPCSS

Service (registry key): cd20xrnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Cdaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): Cdfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Depends On group: "SCSI CDROM Class"

Service (registry key): Cdrom
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-ROM Driver
Image path: system32\DRIVERS\cdrom.sys
Image size: 49536
Image MD5: AF9C19B3100FE010496B1A27181FBF72
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"

Service (registry key): cdudf_xp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): Changer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): Cinemsup
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Cinemsup
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): CiSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Indexing Service
Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
Object name: LocalSystem
Image path: %SystemRoot%\system32\cisvc.exe
Image size: 5632
Image MD5: 3192BD04D032A9C4A85A3278C268A13A
Control Set: CurrentControlSet
Start: 3
Type: 288
Error Control: 1
Depends On services: RPCSS

Service (registry key): ClipSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ClipBook
Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\clipsrv.exe
Image size: 33280
Image MD5: C8DEC22C4137D7A90F8BDF41CA4B82AE
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: NetDDE

Service (registry key): clr_optimization_v2.0.50727_32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: .NET Runtime Optimization Service v2.0.50727_X86
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
Image size: 69976
Image MD5: FD5A44DF0F3EF91F54697CDA5548686C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0

Service (registry key): CmdIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): COMMONFX.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\COMMONFX.DLL
Image size: 87552
Image MD5: C87684620CD1AE8B833C1B97F5506931
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): COMSysApp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ System Application
Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Image size: 5120
Image MD5: DD87DB7387B9EB441C5674888A0D840C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: rpcss

Service (registry key): ContentFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ContentIndex
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Cpqarray
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Creative Service for CDROM Access
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative Service for CDROM Access
Object name: LocalSystem
Image path: C:\WINDOWS\system32\CTsvcCDA.exe
Image size: 44032
Image MD5: 3C8B6609712F4FF78E521F6DCFC4032B
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): CryptSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Cryptographic Services
Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): CT20XUT.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CT20XUT.DLL
Image size: 158720
Image MD5: 71C8899FC61309E4233D66F33C8B07B0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ctac32k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative AC3 Software Decoder
Image path: System32\drivers\ctac32k.sys
Image size: 502272
Image MD5: FB06BB39860340C6FA84867F0288D1DD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ctaud2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative Audio Driver (WDM)
Image path: system32\drivers\ctaud2k.sys
Image size: 499584
Image MD5: B810FA12CF726B200E057834EAEBB1AC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTAUDFX.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTAUDFX.DLL
Image size: 536576
Image MD5: EB9B1F0EB965C6F4E10DC3A4F4B32A6B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ctdvda2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative DVD-Audio Device Driver
Image path: System32\drivers\ctdvda2k.sys
Image size: 340704
Image MD5: C4333325D325EFA668888D0D3177C6FF
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTEAPSFX.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTEAPSFX.DLL
Image size: 160768
Image MD5: 6D463E3473A09EB9772D9512FFEA7E8A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTEDSPFX.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTEDSPFX.DLL
Image size: 280320
Image MD5: C8AC1FFAEADD655193D7B1811A572D8D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTEDSPIO.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTEDSPIO.DLL
Image size: 128768
Image MD5: 44495D9DAF675257D00B25B041EE6667
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTEDSPSY.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTEDSPSY.DLL
Image size: 323328
Image MD5: 8E90B1762CB42E2FC76DAC9210C83C66
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTERFXFX.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTERFXFX.DLL
Image size: 94976
Image MD5: D3FBD9983325435B06795F29CB57ED3D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTEXFIFX.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTEXFIFX.DLL
Image size: 1170432
Image MD5: 053E9C1CF766A57EFFA6C6240D8F8479
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTHWIUT.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTHWIUT.DLL
Image size: 61952
Image MD5: 14C514F2A0A9C339D84BBD82042D9A7A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ctprxy2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative Proxy Driver
Image path: System32\drivers\ctprxy2k.sys
Image size: 7168
Image MD5: 1FA95C8CF34B9911E352A07EA7A200FC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CTSBLFX.DLL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\CTSBLFX.DLL
Image size: 548352
Image MD5: 3EB698774A5817034B50D99C60CED637
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ctsfm2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative SoundFont Management Device Driver
Image path: System32\drivers\ctsfm2k.sys
Image size: 143872
Image MD5: 400CB754B91F73BEE2655686A57269D2
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): dac2w2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): dac960nt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): DcomLaunch
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DCOM Server Process Launcher
Description: Provides launch functionality for DCOM services.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost -k DcomLaunch
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): Dhcp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DHCP Client
Description: Manages network configuration by registering and updating IP addresses and DNS names.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd,NetBT

Service (registry key): Disk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Disk Driver
Image path: system32\DRIVERS\disk.sys
Image size: 36352
Image MD5: 00CA44E4534865F8A3B64F7C0984BFF0
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"

Service (registry key): dmadmin
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager Administrative Service
Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops.
Object name: LocalSystem
Image path: %SystemRoot%\System32\dmadmin.exe /com
Image size: 224768
Image MD5: 554C7CB178FE3BD12450B81AD63ADBC3
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay,DmServer

Service (registry key): dmboot
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmboot.sys
Image size: 799744
Image MD5: C0FBB516E06E243F0CF31F597E7EBF7D
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): dmio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager Driver
Image path: System32\drivers\dmio.sys
Image size: 153344
Image MD5: F5E7B358A732D09F4BCF2824B88B9E28
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): dmload
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmload.sys
Image size: 5888
Image MD5: E9317282A63CA4D188C0DF5E09C6AC5F
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): dmserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager
Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay

Service (registry key): DMusic
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DLS Syntheiszer
Image path: system32\drivers\DMusic.sys
Image size: 52864
Image MD5: A6F881284AC1150E37D9AE47FF601267
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

TheOnlyBigDog
2008-08-25, 09:28
Service (registry key): Dnscache
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DNS Client
Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip

Service (registry key): dpti2o
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): drmkaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DRM Audio Descrambler
Image path: system32\drivers\drmkaud.sys
Image size: 2944
Image MD5: 1ED4DBBAE9F5D558DBBA4CC450E3EB2E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): DVDVRRdr_xp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): dvd_2K
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): emupia
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: E-mu Plug-in Architecture Driver
Image path: System32\drivers\emupia2k.sys
Image size: 78336
Image MD5: 7BB488EC082D40645936D9E583F560DC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ERSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Error Reporting Service
Description: Allows error reporting for services and applictions running in non-standard environments.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs

Service (registry key): EuMusDesignVirtualAudioCableWdm_lcs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Breakaway Pipeline (WDM)
Image path: system32\DRIVERS\vaclcskd.sys
Image size: 40448
Image MD5: E0DA71254F4A1B86F6776442A100AC01
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Eventlog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Event Log
Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 108032
Image MD5: C6CE6EEC82F187615D1002BB3BB50ED4
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): EventSystem
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ Event System
Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): Fastfat
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): FastUserSwitchingCompatibility
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Fast User Switching Compatibility
Description: Provides management for applications that require assistance in a multiple user environment.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: TermService

Service (registry key): Fdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Floppy Disk Controller Driver
Image path: system32\DRIVERS\fdc.sys
Image size: 27392
Image MD5: CED2E8396A8838E59D8FD529C680E02C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Fips
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): FLEXnet Licensing Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: FLEXnet Licensing Service
Description: This service performs licensing functions on behalf of FLEXnet enabled products.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
Image size: 654848
Image MD5: 227846995AFEEFA70D328BF5334A86A5
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): Flpydisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Floppy Disk Driver
Image path: system32\DRIVERS\flpydisk.sys
Image size: 20480
Image MD5: 0DD1DE43115B93F4D85E889D7A86F548
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): FltMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: FltMgr
Description: File System Filter Manager Driver
Image path: system32\DRIVERS\fltMgr.sys
Image size: 128896
Image MD5: 3D234FB6D6EE875EB009864A299BEA29
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): ForceWare Intelligent Application Manager (IAM)
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ForceWare Intelligent Application Manager (IAM)
Object name: LocalSystem
Image path: C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
Image size: 172032
Image MD5: AF65875403A3BC39F299390387651C4F
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS,WINMGMT

Service (registry key): ForcewareWebInterface
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Forceware Web Interface
Description: Apache
Object name: LocalSystem
Image path: "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice
Image size: 20543
Image MD5: B81F8778F5BB485F3B75114F0C99A49F
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: Tcpip,Afd

Service (registry key): Fs_Rec
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 8
Error Control: 0

Service (registry key): Ftdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Manager Driver
Image path: system32\DRIVERS\ftdisk.sys
Image size: 125056
Image MD5: 6AC26732762483366C3969C9E4D2259D
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): gameenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Game Port Enumerator
Image path: system32\DRIVERS\gameenum.sys
Image size: 10624
Image MD5: 5F92FD09E5610A5995DA7D775EADCD12
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): GMSIPCI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: GMSIPCI
Image path: \??\M:\INSTALL\GMSIPCI.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): GoogleDesktopManager-061008-081103
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Google Desktop Manager 5.7.806.10245
Object name: LocalSystem
Image path: "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe"
Image size: 29744
Image MD5: 6542DC2E93BCE4D4289FA70A4D367DC2
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): Gpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Generic Packet Classifier
Description: Generic Packet Classifier
Image path: system32\DRIVERS\msgpc.sys
Image size: 35072
Image MD5: C0F1D4A21DE5A415DF8170616703DEBF
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): gusvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Google Updater Service
Object name: LocalSystem
Image path: "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
Image size: 138680
Image MD5: D213C2B1CE0FAEAB59EC0C55B4493F94
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0
Depends On services: RPCSS

Service (registry key): ha10kx2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative Hardware Abstract Layer Driver
Image path: System32\drivers\ha10kx2k.sys
Image size: 766976
Image MD5: 9BB84B1DFF8BCE7FDDDEA746F6819FCF
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): hap16v2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative P16V HAL Driver
Image path: System32\drivers\hap16v2k.sys
Image size: 154112
Image MD5: 1418833169B29780FBDAB127623B8767
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): hap17v2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative P17V HAL Driver
Image path: system32\drivers\hap17v2k.sys
Image size: 180224
Image MD5: 8B3148391DC121D96D513785D588E75B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): HDAudBus
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft UAA Bus Driver for High Definition Audio
Image path: system32\DRIVERS\HDAudBus.sys
Image size: 138240
Image MD5: CBC3DEF409549672B915FB9403D63F74
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): helpsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Help and Support
Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): HidServ
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Human Interface Device Access
Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): hpn
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): HTTP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP
Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start.
Image path: System32\Drivers\HTTP.sys
Image size: 262784
Image MD5: CB77BB47E67E84DEB17BA29632501730
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): HTTPFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP SSL
Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP

Service (registry key): i2omgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): i2omp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): i8042prt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: i8042 Keyboard and PS/2 Mouse Port Driver
Image path: system32\DRIVERS\i8042prt.sys
Image size: 52736
Image MD5: 5502B58EEF7486EE6F93F3F164DCB808
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): idsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows CardSpace
Description: Securely enables the creation, management, and disclosure of digital identities.
Object name: LocalSystem
Image path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
Image size: 843776
Image MD5: 9B776D49274F7D1CD7BD6AB7D2310D25
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): Imapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-Burning Filter Driver
Image path: system32\DRIVERS\imapi.sys
Image size: 41856
Image MD5: F8AA320C6A0409C0380E5D8A99D76EC6
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): ImapiService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IMAPI CD-Burning COM Service
Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\imapi.exe
Image size: 150016
Image MD5: FA788520BCAC0F5D9D5CDE5615C0D931
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): inetaccs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ini910u
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Inport
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): IntelIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Ip6Fw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPv6 Windows Firewall Driver
Description: Provides intrusion prevention service for a home or small office network.
Image path: system32\DRIVERS\Ip6Fw.sys
Image size: 29056
Image MD5: 4448006B6BC60E6C027932CFC38D6855
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): IpFilterDriver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Traffic Filter Driver
Description: IP Traffic Filter Driver
Image path: system32\DRIVERS\ipfltdrv.sys
Image size: 32896
Image MD5: 731F22BA402EE4B62748ADAF6363C182
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): IpInIp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP in IP Tunnel Driver
Description: IP in IP Tunnel Driver
Image path: system32\DRIVERS\ipinip.sys
Image size: 20992
Image MD5: E1EC7F5DA720B640CD8FB8424F1B14BB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): IpNat
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Network Address Translator
Description: IP Network Address Translator
Image path: system32\DRIVERS\ipnat.sys
Image size: 134912
Image MD5: E2168CBC7098FFE963C6F23F472A3593
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): IPSec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC driver
Description: IPSEC driver
Image path: system32\DRIVERS\ipsec.sys
Image size: 74752
Image MD5: 64537AA5C003A6AFEEE1DF819062D0D1
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): IRENUM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IR Enumerator Service
Image path: system32\DRIVERS\irenum.sys
Image size: 11264
Image MD5: 50708DAA1B1CBB7D6AC1CF8F56A24410
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ISAPISearch
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): isapnp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PnP ISA/EISA Bus Driver
Image path: system32\DRIVERS\isapnp.sys
Image size: 35840
Image MD5: E504F706CCB699C2596E9A3DA1596E87
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3

Service (registry key): Iviaspi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IVI ASPI Shell
Image path: system32\drivers\iviaspi.sys
Image size: 21060
Image MD5: F59C3569A2F2C464BB78CB1BDCDCA55E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ivicd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Ivi CDVD Filter Driver
Image path: system32\drivers\ivicd.sys
Image size: 38784
Image MD5: 6681D4A5DD4967A4DDC8DEB3E4BD491E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): IviRegMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IviRegMgr
Object name: LocalSystem
Image path: C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
Image size: 112152
Image MD5: 213822072085B5BBAD9AF30AB577D817
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): iviudf
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\drivers\IviUdf.sys
Image size: 126592
Image MD5: 492FE21332922B6B19DEFD0C17C70CEE
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1

Service (registry key): JGOGO
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: JMicron Hot-Plug Driver
Image path: system32\DRIVERS\JGOGO.sys
Image size: 6912
Image MD5: C995C0E8B4503FAC38793BB0236AD246
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 0

Service (registry key): JRAID
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\jraid.sys
Image size: 44416
Image MD5: C341318BEAE24FA4042C5F8C64CB38B6
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Kbdclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Keyboard Class Driver
Image path: system32\DRIVERS\kbdclass.sys
Image size: 24576
Image MD5: EBDEE8A2EE5393890A1ACEE971C4C246
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): kmixer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Wave Audio Mixer
Image path: system32\drivers\kmixer.sys
Image size: 172416
Image MD5: BA5DEDA4D934E6288C2F66CAF58D2562
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): KSecDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): L8042Kbd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logitech SetPoint Keyboard Driver
Image path: system32\DRIVERS\L8042Kbd.sys
Image size: 20496
Image MD5: D88846F9F4F27AE9BE584A6E5B6B8753
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): L8042mou
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SetPoint PS/2 Mouse Filter Driver
Image path: system32\DRIVERS\L8042mou.Sys
Image size: 63248
Image MD5: BEA61FDA2103F6F51B14EB0872E8A050
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): lanmanserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Server
Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): lanmanworkstation
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Workstation
Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): lbrtfdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): ldap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): LHidKe
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): LicenseService
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): LiveUpdate
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: LiveUpdate
Description: LiveUpdate Core Engine
Object name: LocalSystem
Image path: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"
Image size: 2119360
Image MD5: FB466FAA799EACE5075FC1DE269F0066
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): LmHosts
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP NetBIOS Helper
Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: NetBT,Afd

Service (registry key): LMouKE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SetPoint Mouse Filter Driver
Image path: system32\DRIVERS\LMouKE.Sys
Image size: 79376
Image MD5: CAB504E38FCED9A56D87D838E9BA13E9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MDM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Machine Debug Manager
Description: Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
Image size: 322120
Image MD5: 11F714F85530A2BD134074DC30E99FCA
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS

Service (registry key): Messenger
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Messenger
Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS

Service (registry key): mmc_2K
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): mnmdd
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): mnmsrvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetMeeting Remote Desktop Sharing
Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\mnmsrvc.exe
Image size: 32768
Image MD5: F6415361201915B9FE3896B0E4E724FF
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1

Service (registry key): Modem
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): Mouclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mouse Class Driver
Image path: system32\DRIVERS\mouclass.sys
Image size: 23040
Image MD5: 34E1F0031153E491910E12551400192C
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): MountMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): mraid35x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): MRENDIS5
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MRENDIS5 NDIS Protocol Driver
Image path: \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS
Image size: 18003
Image MD5: 594B9D8194E3F4ECBF0325BD10BBEB05
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MRxDAV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebDav Client Redirector
Description: WebDav Client Redirector
Image path: system32\DRIVERS\mrxdav.sys
Image size: 179584
Image MD5: 29414447EB5BDE2F8397DC965DBB3156
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1

Service (registry key): MRxSmb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MRXSMB
Description: MRXSMB
Image path: system32\DRIVERS\mrxsmb.sys
Image size: 453120
Image MD5: 025AF03CE51645C62F3B6907A7E2BE5E
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): MSDTC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Transaction Coordinator
Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: C:\WINDOWS\system32\msdtc.exe
Image size: 6144
Image MD5: C7C3D89EB0A6F3DBA622EA737FA335B1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS,SamSS

Service (registry key): MSDTC Bridge 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Msfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): MSIServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Installer
Object name: LocalSystem
Image path: C:\WINDOWS\system32\msiexec.exe /V
Image size: 78848
Image MD5: F5F0146580E7023ADB963879840777F8
Control Set: CurrentControlSet
Start: 3
Type: 288
Error Control: 1

Service (registry key): MSKSSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Service Proxy
Image path: system32\drivers\MSKSSRV.sys
Image size: 7552
Image MD5: AE431A8DD3C1D0D0610CDBAC16057AD0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSPCLOCK
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Clock Proxy
Image path: system32\drivers\MSPCLOCK.sys
Image size: 5376
Image MD5: 13E75FEF9DFEB08EEDED9D0246E1F448
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSPQM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Quality Manager Proxy
Image path: system32\drivers\MSPQM.sys
Image size: 4992
Image MD5: 1988A33FF19242576C3D0EF9CE785DA7
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): mssmbios
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft System Management BIOS Driver
Image path: system32\DRIVERS\mssmbios.sys
Image size: 15488
Image MD5: 469541F8BFD2B32659D5D463A6714BCE
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSSQL$SQLEXPRESS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SQL Server (SQLEXPRESS)
Description: Provides storage, processing and controlled access of data and rapid transaction processing.
Object name: NT AUTHORITY\NetworkService
Image path: "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
Image size: 29178224
Image MD5: D07C9575726797B0E9069E1108A1C483
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): MSSQLServerADHelper
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SQL Server Active Directory Helper
Description: Enables integration with Active Directories.
Object name: NT AUTHORITY\NetworkService
Image path: "C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe"
Image size: 45272
Image MD5: ADAF062116B4E6D96E44D26486A87AF6
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1

Service (registry key): MSTEE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Tee/Sink-to-Sink Converter
Image path: system32\drivers\MSTEE.sys
Image size: 5504
Image MD5: BF13612142995096AB084F2DB7F40F77
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MTsensor
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ATK0110 ACPI UTILITY
Image path: system32\DRIVERS\ASACPI.sys
Image size: 5810
Image MD5: D48659BB24C48345D926ECB45C1EBDF5
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Mup
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mup
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): NABTSFEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NABTS/FEC VBI Codec
Image path: system32\DRIVERS\NABTSFEC.sys
Image size: 85376
Image MD5: 5C8DC6429C43DC6177C1FA5B76290D1A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): navapsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Norton AntiVirus Auto-Protect Service
Description: Handles Norton AntiVirus Auto-Protect events.
Object name: LocalSystem
Image path: "C:\Program Files\Norton AntiVirus\navapsvc.exe"
Image size: 177264
Image MD5: 8FC8458BCB585617AAC9E17A558D9155
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): NAVENG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NAVENG
Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080820.016\NAVENG.Sys
Image size: 89104
Image MD5: D8F9E712479F2F8DC8C3524A62365F95
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NAVEX15
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NAVEX15
Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080820.016\NavEx15.Sys
Image size: 873552
Image MD5: 0B127BBE41300DEDE016E86E47329CDD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NBService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NBService
Description: Nero BackItUp Service is responsible to control all jobs created using Nero BackItUp. These jobs can create backups of selected files/folders/partitions or complete hard disk to hard disk, network drive, disc or FTP.
Object name: LocalSystem
Image path: C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
Image size: 800040
Image MD5: 5836B9E91863A00EC1B8E785EFD86ECB
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): NDIS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS System Driver
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): NdisIP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft TV/Video Connection
Image path: system32\DRIVERS\NdisIP.sys
Image size: 10880
Image MD5: 520CE427A8B298F54112857BCF6BDE15
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NdisTapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS TAPI Driver
Description: Remote Access NDIS TAPI Driver
Image path: system32\DRIVERS\ndistapi.sys
Image size: 9600
Image MD5: 08D43BBDACDF23F34D79E44ED35C1B4C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Ndisuio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS Usermode I/O Protocol
Description: NDIS Usermode I/O Protocol
Image path: system32\DRIVERS\ndisuio.sys
Image size: 12928
Image MD5: 34D6CD56409DA9A7ED573E1C90A308BF
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NdisWan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS WAN Driver
Description: Remote Access NDIS WAN Driver
Image path: system32\DRIVERS\ndiswan.sys
Image size: 91776
Image MD5: 0B90E255A9490166AB368CD55A529893
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NDProxy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NetBIOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBIOS Interface
Description: NetBIOS Interface
Image path: system32\DRIVERS\netbios.sys
Image size: 34560
Image MD5: 3A2ACA8FC1D7786902CA434998D7CEB4
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): NetBT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBios over Tcpip
Description: NetBios over Tcpip
Image path: system32\DRIVERS\netbt.sys
Image size: 162816
Image MD5: 0C80E410CD2F47134407EE7DD19CC86B
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): NetDDE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE
Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: 05AFB5AD06462257BEA7495283C86D50
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: NetDDEDSDM

Service (registry key): NetDDEdsdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE DSDM
Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: 05AFB5AD06462257BEA7495283C86D50
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1

Service (registry key): Netlogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Net Logon
Description: Supports pass-through authentication of account logon events for computers in a domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): Netman
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Connections
Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 288
Error Control: 1
Depends On services: RpcSs

Service (registry key): NetTcpPortSharing
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Net.Tcp Port Sharing Service
Description: Provides ability to share TCP ports over the net.tcp protocol.
Object name: NT AUTHORITY\LocalService
Image path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
Image size: 122880
Image MD5: EC0A95D9FD9C78E6C4B2B63CE82748BC
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1

Service (registry key): NIC1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 Net Driver
Image path: system32\DRIVERS\nic1394.sys
Image size: 61824
Image MD5: 5C5C53DB4FEF16CF87B9911C7E8C6FBC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Nla
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Location Awareness (NLA)
Description: Collects and stores network configuration and location information, and notifies applications when this information changes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd

Service (registry key): NMIndexingService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NMIndexingService
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe"
Image size: 279848
Image MD5: A328A46D87BB92CE4D8A4528E9D84787
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): NPFMntor
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Norton AntiVirus Firewall Monitor Service
Description: Detects installation of Symantec Firewall clients
Object name: LocalSystem
Image path: "C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe"
Image size: 46704
Image MD5: 96DB6F2D69F787C61A46CC86D6CFE69F
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0

Service (registry key): Npfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): nSvcIp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ForceWare IP service
Object name: LocalSystem
Image path: C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
Image size: 135227
Image MD5: 4D864C3526C573E54FBDA663A7855FE2
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: WINMGMT

Service (registry key): nSvcLog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ForceWare user log service
Object name: LocalSystem
Image path: C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
Image size: 65599
Image MD5: 68C060CE0BD72DD66313356BA698BFF2
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): Ntfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): NtLmSsp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NT LM Security Support Provider
Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): NtmsSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Removable Storage
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): Null
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): nv
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\nv4_mini.sys
Image size: 6807328
Image MD5: F8BE83F0C686533170F7537E94BF411A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): nvata
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\nvata.sys
Image size: 105344
Image MD5: 4D6C6B46B3EDF6F2E219A86B61D104AE
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3

Service (registry key): NVENETFD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NVIDIA nForce Networking Controller Driver
Image path: system32\DRIVERS\NVENETFD.sys
Image size: 57856
Image MD5: 1B83B60541BE1B6DB81641C448007F21
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): nvnetbus
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NVIDIA Network Bus Enumerator
Image path: system32\DRIVERS\nvnetbus.sys
Image size: 19968
Image MD5: 57B669F9234604A350174B86764444B0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NVSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NVIDIA Display Driver Service
Description: Provides system and desktop level support to the NVIDIA display driver
Object name: LocalSystem
Image path: %SystemRoot%\system32\nvsvc32.exe
Image size: 155716
Image MD5: E9E110CDF6A063A5F9B841C36FB5CC95
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): NVTCP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NVIDIA TCP/IP Protocol Driver
Image path: System32\DRIVERS\NVTcp.sys
Image size: 110592
Image MD5: C0E7437765A694328579C4674EF3AB20
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: Tcpip,nvnetbus

Service (registry key): NwlnkFlt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Filter Driver
Description: IPX Traffic Filter Driver
Image path: system32\DRIVERS\nwlnkflt.sys
Image size: 12416
Image MD5: B305F3FAD35083837EF46A0BBCE2FC57
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: NwlnkFwd

Service (registry key): NwlnkFwd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Forwarder Driver
Description: IPX Traffic Forwarder Driver
Image path: system32\DRIVERS\nwlnkfwd.sys
Image size: 32512
Image MD5: C99B3415198D1AAB7227F2C88FD664B9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ohci1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OHCI Compliant IEEE 1394 Host Controller
Image path: system32\DRIVERS\ohci1394.sys
Image size: 61056
Image MD5: 0951DB8E5823EA366B0E408D71E1BA2A
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ossrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Creative OS Services Driver
Image path: system32\drivers\ctoss2k.sys
Image size: 116224
Image MD5: 01E1AB8249F9DDE5978C6B4AF18EDA7C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Parport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Parallel port driver
Image path: system32\DRIVERS\parport.sys
Image size: 80128
Image MD5: 29744EB4CE659DFE3B4122DEB45BC478
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): PartMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ParVdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0
Depends On services: Parport
Depends On group: "Parallel arbitrator"

Service (registry key): PCI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PCI Bus Driver
Image path: system32\DRIVERS\pci.sys
Image size: 68224
Image MD5: 8086D9979234B603AD5BC2F5D890B234
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3

Service (registry key): PCIDump
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): PCIIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\pciide.sys
Image size: 3328
Image MD5: CCF5F451BB1A5A2A522A76E670000FF0
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Pcmcia
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Pcouffin
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: VSO Software pcouffin
Image path: System32\Drivers\Pcouffin.sys
Image size: 47360
Image MD5: 02AAAFB7BA137CE5DDABCDF8090954D9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): PDCOMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDRELI
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDRFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): perc2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): perc2hib
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): PerfDisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfNet
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfProc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Pfc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Padus ASPI Shell
Image path: system32\drivers\pfc.sys
Image size: 10368
Image MD5: 444F122E68DB44C0589227781F3C8B3F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): PfModNT
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \??\C:\WINDOWS\system32\drivers\PfModNT.sys
Image size: 8192
Image MD5: FDA352035C58A5C0CA6DE13E66C0BF80
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1

Service (registry key): PhilCam8116
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logitech QuickCam Pro 3000 (08B0)
Image path: system32\DRIVERS\CamDrO21.sys
Image size: 314752
Image MD5: 8754763A924639B9D07D4C8EA9990F1E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): PlugPlay
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Plug and Play
Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 108032
Image MD5: C6CE6EEC82F187615D1002BB3BB50ED4
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): PolicyAgent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC Services
Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS,Tcpip,IPSec

Service (registry key): PptpMiniport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (PPTP)
Description: WAN Miniport (PPTP)
Image path: system32\DRIVERS\raspptp.sys
Image size: 48384
Image MD5: 1C5CC65AAC0783C344F16353E60B72AC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Processor
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Processor Driver
Image path: system32\DRIVERS\processr.sys
Image size: 35328
Image MD5: 0D97D88720A4087EC93AF7DBB303B30A
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): ProtectedStorage
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Protected Storage
Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 1
Depends On services: RpcSs

Service (registry key): ProtexisLicensing
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ProtexisLicensing
Description: Protexis Licensing Service
Object name: LocalSystem
Image path: C:\WINDOWS\system32\PSIService.exe
Image size: 174656
Image MD5: 64E413BA0C529AA40C3924BBCC4153DB
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

TheOnlyBigDog
2008-08-25, 09:30
Service (registry key): PSched
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: QoS Packet Scheduler
Description: QoS Packet Scheduler
Image path: system32\DRIVERS\psched.sys
Image size: 69120
Image MD5: 48671F327553DCF1D27F6197F622A668
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Gpc

Service (registry key): Ptilink
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel Link Driver
Description: Direct Parallel Link Driver
Image path: system32\DRIVERS\ptilink.sys
Image size: 17792
Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): pwd_2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): PxHelp20
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PxHelp20
Image path: System32\Drivers\PxHelp20.sys
Image size: 43528
Image MD5: D86B4A68565E444D76457F14172C875A
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ql1080
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Ql10wnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql12160
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql1240
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql1280
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): RasAcd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Driver
Description: Remote Access Auto Connection Driver
Image path: system32\DRIVERS\rasacd.sys
Image size: 8832
Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): RasAuto
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Manager
Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RasMan,Tapisrv

Service (registry key): Rasl2tp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (L2TP)
Description: WAN Miniport (L2TP)
Image path: system32\DRIVERS\rasl2tp.sys
Image size: 51328
Image MD5: 98FAEB4A4DCF812BA1C6FCA4AA3E115C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): RasMan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Connection Manager
Description: Creates a network connection.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tapisrv

Service (registry key): RasPppoe
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access PPPOE Driver
Description: Remote Access PPPOE Driver
Image path: system32\DRIVERS\raspppoe.sys
Image size: 41472
Image MD5: 7306EEED8895454CBED4669BE9F79FAA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Raspti
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel
Description: Direct Parallel
Image path: system32\DRIVERS\raspti.sys
Image size: 16512
Image MD5: FDBB1D60066FCFBB7452FD8F9829B242
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Rdbss
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Rdbss
Description: Rdbss
Image path: system32\DRIVERS\rdbss.sys
Image size: 174592
Image MD5: 03B965B1CA47F6EF60EB5E51CB50E0AF
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): RDPCDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\DRIVERS\RDPCDD.sys
Image size: 4224
Image MD5: 4912D5B403614CE99C28420F75353332
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): RDPDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): rdpdr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Server Device Redirector Driver
Image path: system32\DRIVERS\rdpdr.sys
Image size: 196864
Image MD5: A2CAE2C60BC37E0751EF9DDA7CEAF4AD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): RDPNP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): RDPWD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): RDSessMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Desktop Help Session Manager
Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\sessmgr.exe
Image size: 140800
Image MD5: 729798E0933076B8FCFCD9934698F164
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): redbook
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Digital CD Audio Playback Filter Driver
Image path: system32\DRIVERS\redbook.sys
Image size: 57472
Image MD5: B31B4588E4086D8D84ADBF9845C2402B
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): RemoteAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Routing and Remote Access
Description: Offers routing services to businesses in local area and wide area network environments.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RpcSS
Depends On group: NetBIOSGroup

Service (registry key): RemoteRegistry
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Registry
Description: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): RpcLocator
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC) Locator
Description: Manages the RPC name service database.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\locator.exe
Image size: 75264
Image MD5: 793F04A09B15E7C6C11DBDFFAF06C0AB
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): RpcSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC)
Description: Provides the endpoint mapper and other miscellaneous RPC services.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\svchost -k rpcss
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): RSVP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: QoS RSVP
Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
Object name: LocalSystem
Image path: %SystemRoot%\system32\rsvp.exe
Image size: 132608
Image MD5: 471B3F9741D762ABE75E9DEEA4787E47
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: TcpIp,Afd,RpcSs

Service (registry key): SABProcEnum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SABProcEnum
Image path: \??\C:\Program Files\Internet Explorer\SABProcEnum.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SamSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Accounts Manager
Description: Stores security information for local user accounts.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): SASDIFSV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SASDIFSV
Image path: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Image size: 8944
Image MD5: C030C9A39E85B6F04A8DD25D1A50258A
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): SASENUM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SASENUM
Image path: \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Image size: 4096
Image MD5: 7F1085895E499907F68DF7731924122B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SASKUTIL
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SASKUTIL
Image path: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Image size: 55024
Image MD5: 64C100DBF57C6CB6E7D5D24153F5E444
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): SAVRT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SAVRT
Image path: \??\C:\Program Files\Norton AntiVirus\SAVRT.SYS
Image size: 338056
Image MD5: 3D2EB85B0A130CBA0CD08BCDD2B2E485
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: SAVRTPEL

Service (registry key): SAVRTPEL
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SAVRTPEL
Image path: \??\C:\Program Files\Norton AntiVirus\SAVRTPEL.SYS
Image size: 50312
Image MD5: A5D09F85B8717BBF67520B1CC71D641F
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): SAVScan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SAVScan
Description: Handles Norton AntiVirus Auto-Protect Archive Scanning
Object name: LocalSystem
Image path: "C:\Program Files\Norton AntiVirus\SAVScan.exe"
Image size: 198368
Image MD5: 63EE66B5229A14809E5D89A9275325AD
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: SAVRT

Service (registry key): sbp2port
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SBP-2 Transport/Protocol Bus Driver
Image path: system32\DRIVERS\sbp2port.sys
Image size: 43136
Image MD5: 3E2C3B180872BE4120F246D85560B734
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): SBService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ScriptBlocking Service
Object name: LocalSystem
Image path: C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
Image size: 67184
Image MD5: 2B4730E2E359FA0CDA5B1B1D362380EC
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): SCardSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Smart Card
Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\SCardSvr.exe
Image size: 95744
Image MD5: 25D8DE134DF108E3DBC8D7D23B1AA58E
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 0
Depends On services: PlugPlay

Service (registry key): Schedule
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Task Scheduler
Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): Secdrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secdrv
Description: SafeDisc driver
Image path: system32\DRIVERS\secdrv.sys
Image size: 20480
Image MD5: 90A3935D05B494A5A39D37E71F09A677
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): seclogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secondary Logon
Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 0

Service (registry key): SenFiltService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SenFilt Service
Image path: system32\drivers\Senfilt.sys
Image size: 392960
Image MD5: B6A6B409FDA9D9EBD3AADB838D3D7173
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SENS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Event Notification
Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: EventSystem

Service (registry key): serenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Serenum Filter Driver
Image path: system32\DRIVERS\serenum.sys
Image size: 15488
Image MD5: A2D868AEEFF612E70E213C451A70CAFB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Serial
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Serial port driver
Image path: system32\DRIVERS\serial.sys
Image size: 64896
Image MD5: CD9404D115A00D249F70A371B46D5A26
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): ServiceModelEndpoint 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelOperation 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelService 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Sfloppy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Depends On group: "SCSI miniport"

Service (registry key): SharedAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Firewall/Internet Connection Sharing (ICS)
Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Netman,WinMgmt

Service (registry key): ShellHWDetection
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Shell Hardware Detection
Description: Provides notifications for AutoPlay hardware events.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs

Service (registry key): Simbad
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): SLIP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: BDA Slip De-Framer
Image path: system32\DRIVERS\SLIP.sys
Image size: 11136
Image MD5: 5CAEED86821FA2C6139E32E9E05CCDC9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SMSvcHost 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): SNDSrvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Network Drivers Service
Description: Symantec Network Drivers Service
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"
Image size: 206552
Image MD5: 5815052B868B96CAE6CE3D4C53E971EB
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0

Service (registry key): Sparrow
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): SPBBCDrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SPBBCDrv
Image path: \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
Image size: 341096
Image MD5: 924E82D6DEC26F82036E69B8D3F04216
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): SPBBCSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec SPBBCSvc
Description: Symantec SPBBC
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"
Image size: 173160
Image MD5: 08FA56B7C13B4CBF0E5D351AECAD92B1
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): splitter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Audio Splitter
Image path: system32\drivers\splitter.sys
Image size: 6400
Image MD5: 0CE218578FFF5F4F7E4201539C45C78F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Spooler
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Print Spooler
Description: Loads files to memory for later printing.
Object name: LocalSystem
Image path: %SystemRoot%\system32\spoolsv.exe
Image size: 57856
Image MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS

Service (registry key): SQLBrowser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SQL Server Browser
Description: Provides SQL Server connection information to client computers.
Object name: NT AUTHORITY\NetworkService
Image path: "C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
Image size: 242544
Image MD5: D2B096CD2F56FAC6EEEED9A77DDF6DC8
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): sr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Filter Driver
Image path: system32\DRIVERS\sr.sys
Image size: 73472
Image MD5: E41B6D037D6CD08461470AF04500DC24
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): srservice
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Service
Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): Srv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Srv
Description: Srv
Image path: system32\DRIVERS\srv.sys
Image size: 332928
Image MD5: EA554A3FFC3F536FE8320EB38F5E4843
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1

Service (registry key): SSDPSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SSDP Discovery Service
Description: Enables discovery of UPnP devices on your home network.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP

Service (registry key): stisvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Image Acquisition (WIA)
Description: Provides image acquisition services for scanners and cameras.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k imgsvc
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): streamip
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: BDA IPSink
Image path: system32\DRIVERS\StreamIP.sys
Image size: 15360
Image MD5: 284C57DF5DC7ABCA656BC2B96A667AFB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): swenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Software Bus Driver
Image path: system32\DRIVERS\swenum.sys
Image size: 4352
Image MD5: 03C1BAE4766E2450219D20B993D6E046
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): swmidi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel GS Wavetable Synthesizer
Image path: system32\drivers\swmidi.sys
Image size: 54272
Image MD5: 94ABC808FC4B6D7D2BBF42B85E25BB4D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SwPrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MS Software Shadow Copy Provider
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{02AFC6E5-7F1D-422D-83D0-D59779EE18E9}
Image size: 5120
Image MD5: DD87DB7387B9EB441C5674888A0D840C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Depends On services: rpcss

Service (registry key): Symantec Core LC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Core LC
Description: Symantec Core LC
Object name: LocalSystem
Image path: C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Image size: 817304
Image MD5: 287136B3EA7D2FAB893B5CAE47E75EFD
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS

Service (registry key): symc810
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): symc8xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): SYMDNS
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMDNS.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SymEvent
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \??\C:\Program Files\Symantec\SYMEVENT.SYS
Image size: 124016
Image MD5: C9B8F325B2A22CDA1BDA7B25181B1389
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SYMFW
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMFW.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SYMIDS
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMIDS.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SYMIDSCO
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20080813.001\symidsco.sys
Image size: 240496
Image MD5: 1DB45C243188F7B4C51DD7305D7E5CBB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): symlcbrd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: symlcbrd
Image path: \??\C:\WINDOWS\system32\drivers\symlcbrd.sys
Image size: 4608
Image MD5: 6E65FE9EB2406D17FE560711060B08DC
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0

Service (registry key): SYMNDIS
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMNDIS.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SYMREDRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMREDRV.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SYMTDI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SYMTDI
Image path: \SystemRoot\System32\Drivers\SYMTDI.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): sym_hi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): sym_u3
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): sysaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel System Audio Device
Image path: system32\drivers\sysaudio.sys
Image size: 60800
Image MD5: 650AD082D46BAC0E64C9C0E0928492FD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SysmonLog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Performance Logs and Alerts
Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT Authority\NetworkService
Image path: %SystemRoot%\system32\smlogsvc.exe
Image size: 89600
Image MD5: 8B54AA346D1B1B113FFAA75501B8B1B2
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): TapiSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telephony
Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs

Service (registry key): Tcpip
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP Protocol Driver
Description: TCP/IP Protocol Driver
Image path: system32\DRIVERS\tcpip.sys
Image size: 360320
Image MD5: 2A5554FC5B1E04E131230E3CE035C3F9
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: IPSec

Service (registry key): TDPIPE
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): TDTCP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): TermDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Device Driver
Image path: system32\DRIVERS\termdd.sys
Image size: 40840
Image MD5: A540A99C281D933F3D69D55E48727F47
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): TermService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Services
Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost -k DComLaunch
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): Themes
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Themes
Description: Provides user experience theme management.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): TlntSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telnet
Description: Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\tlntsvr.exe
Image size: 73216
Image MD5: 37DB0A7D097310E8B4DE803FC3119C78
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: RPCSS,TCPIP,NTLMSSP

Service (registry key): TosIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): TPkd
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): TrkWks
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Link Tracking Client
Description: Maintains links between NTFS files within a computer or across computers in a network domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): TSDDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): udffsrec
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\drivers\udffsrec.sys
Image size: 5376
Image MD5: F1B6099213D7449B8156E38A296E9D9F
Control Set: CurrentControlSet
Start: 1
Type: 8
Error Control: 0

Service (registry key): UDFReadr
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): Udfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): UleadBurningHelper
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Ulead Burning Helper
Object name: LocalSystem
Image path: C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Image size: 67056
Image MD5: 4BD2C322118A2470B450492A0C3302F9
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): ultra
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Update
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microcode Update Driver
Image path: system32\DRIVERS\update.sys
Image size: 209408
Image MD5: AFF2E5045961BBC0A602BB6F95EB1345
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): upnphost
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Universal Plug and Play Device Host
Description: Provides support to host Universal Plug and Play devices.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: SSDPSRV,HTTP

Service (registry key): UPS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Uninterruptible Power Supply
Description: Manages an uninterruptible power supply (UPS) connected to the computer.
Object name: LocalSystem
Image path: %SystemRoot%\System32\ups.exe
Image size: 18432
Image MD5: 3F5DF65B0758675F95A2D43918A740A3
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): usbaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Audio Driver (WDM)
Image path: system32\drivers\usbaudio.sys
Image size: 59264
Image MD5: 45A0D14B26C35497AD93BCE7E15C9941
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbccgp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Generic Parent Driver
Image path: system32\DRIVERS\usbccgp.sys
Image size: 31616
Image MD5: BFFD9F120CC63BCBAA3D840F3EEF9F79
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbehci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
Image path: system32\DRIVERS\usbehci.sys
Image size: 26624
Image MD5: 15E993BA2F6946B2BFBBFCD30398621E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbhub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB2 Enabled Hub
Image path: system32\DRIVERS\usbhub.sys
Image size: 57600
Image MD5: C72F40947F92CEA56A8FB532EDF025F1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbohci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Open Host Controller Miniport Driver
Image path: system32\DRIVERS\usbohci.sys
Image size: 17024
Image MD5: BDFE799A8531BAD8A5A985821FE78760
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbprint
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB PRINTER Class
Image path: system32\DRIVERS\usbprint.sys
Image size: 25856
Image MD5: A42369B7CD8886CD7C70F33DA6FCBCF5
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): USBSTOR
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Mass Storage Driver
Image path: system32\DRIVERS\USBSTOR.SYS
Image size: 26496
Image MD5: 6CD7B22193718F1D17A47A1CD6D37E75
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usnjsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Messenger Sharing Folders USN Journal Reader service
Description: Service installed by Messenger to enable sharing scenarios
Object name: LocalSystem
Image path: "C:\Program Files\MSN Messenger\usnsvc.exe"
Image size: 97136
Image MD5: C5B70A6AA947667CE0E5FC84A05EC8B6
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: rpcss,eventlog

Service (registry key): VgaSave
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\drivers\vga.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): ViaIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): VolSnap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): VSS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Shadow Copy
Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\vssvc.exe
Image size: 289792
Image MD5: 3EE00364AE0FD8D604F46CBAF512838A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): VxD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): W32Time
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Time
Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): W3SVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Wanarp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access IP ARP Driver
Description: Remote Access IP ARP Driver
Image path: system32\DRIVERS\wanarp.sys
Image size: 34560
Image MD5: 984EF0B9788ABF89974CFED4BFBAACBC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WDICA
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): wdmaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft WINMM WDM Audio Compatibility Driver
Image path: system32\drivers\wdmaud.sys
Image size: 82944
Image MD5: EFD235CA22B57C81118C1AEB4798F1C1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WebClient
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebClient
Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: MRxDAV

Service (registry key): winmgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation
Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RPCSS

Service (registry key): Winsock
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 4
Error Control: 1

Service (registry key): WinSock2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WinTrust
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WMDM PMSP Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WMDM PMSP Service
Object name: LocalSystem
Image path: C:\WINDOWS\system32\MsPMSPSv.exe
Image size: 53248
Image MD5: 668056D5C3C11AB7D266819A96B964E8
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): WmdmPmSN
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Portable Media Serial Number Service
Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): Wmi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation Driver Extensions
Description: Provides systems management information to and from drivers.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): WmiApRpl
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WmiApSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WMI Performance Adapter
Description: Provides performance library information from WMI HiPerf providers.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\wbem\wmiapsrv.exe
Image size: 126464
Image MD5: BA8CECC3E813E1F7C441B20393D4F86C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): WMPNetworkSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Media Player Network Sharing Service
Description: Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
Object name: NT AUTHORITY\NetworkService
Image path: "C:\Program Files\Windows Media Player\WMPNetwk.exe"
Image size: 913408
Image MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: upnphost,http,HTTPFilter

Service (registry key): WS2IFSL
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Socket 2.0 Non-IFS Service Provider Support Environment
Image path: \SystemRoot\System32\drivers\ws2ifsl.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): wscsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Center
Description: Monitors system security settings and configurations.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,winmgmt

Service (registry key): WSTCODEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: World Standard Teletext Codec
Image path: system32\DRIVERS\WSTCODEC.SYS
Image size: 19328
Image MD5: D5842484F05E12121C511AA93F6439EC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): wuauserv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Automatic Updates
Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): WudfPf
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver
Description: Provide communciation services for UMDF components.
Image path: system32\DRIVERS\WudfPf.sys
Image size: 77568
Image MD5: F15FEAFFFBB3644CCC80C5DA584E6311
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WudfRd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Reflector
Description: Reflect device requests to user-mode driver drivers
Image path: system32\DRIVERS\wudfrd.sys
Image size: 82944
Image MD5: 28B524262BCE6DE1F7EF9F510BA3985B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WudfSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework
Description: Manages user-mode driver host processes
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: PlugPlay

Service (registry key): WZCSVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wireless Zero Configuration
Description: Provides automatic configuration for the 802.11 adapters
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,Ndisuio

Service (registry key): xmlprov
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Provisioning Service
Description: Manages XML configuration files on a domain basis for automatic network provisioning.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): {01D01C09-CBA1-4338-A515-F5DA731CACAE}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): {1C6E08EC-4177-4C5A-B695-249B7DDD1F9A}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): {2F4B6600-CD64-47D7-8E66-2739C5C5E4C1}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): {406908A1-9718-4063-BEF7-E5A3B1D2D742}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): {86238EB8-86CA-494A-B6F0-DE7137A0F2FD}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): {A2473715-6EB6-411A-B262-9BCC01B222F8}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Shaba
2008-08-25, 10:27
Go to Start > Run
Type regedit and click OK.

On the leftside, click to highlight My Computer at the top.
Go up to "File > Export"
Make sure in that window there is a tick next to "All" under Export Branch.
Leave the "Save As Type" as "Registration Files".
Under "Filename" put backup
Choose to save it to C:\ or in somewhere else safe location so that you will remember where you put it (don't put it on the Desktop!)
Click Save and then go to File > Exit.

Open Notepad and copy the contents of the following box to a new file.


Windows Registry Editor Version 5.00

[-HKEY_USERS\S-1-5-21-1343024091-1123561945-839522115-1003\Software\XTTB00001]

Save it as fix.reg (save type: "All files" (*.*)) to your desktop.

It should look like this -> http://users.telenet.be/bluepatchy/miekiemoes/images/reg.gif

Go to Desktop, double-click fix.reg and merge the infomation with the registry.

(In case you are unsure how to create a reg file, take a look here (http://www.nellie2.co.uk/file.htm#How_to_Make_a_.Reg_File_) with screenshots.)

Reboot.

Re-scan with spybot and let me know if it's gone.

TheOnlyBigDog
2008-08-25, 11:32
No. I rebooted and re-ran SpyBot and it shows that it is still there.:sad:

Shaba
2008-08-25, 11:41
Did you copy everything from code box?

TheOnlyBigDog
2008-08-25, 11:51
Yes. I did everything you said to do in your post.:sad:

Shaba
2008-08-25, 11:58
No problems then it is likely permission issue.

We will check it next :)

Download RegDACL (http://www.heysoft.de/nt/reg/ep-regd.htm) and extract it to C: root (C:\).

Launch Notepad, and copy/paste the box below into a new text file. Save it as FixReg.bat and save it in the same folder as where you extracted RegDACL.


RegDACL HKEY_USERS\S-1-5-21-1343024091-1123561945-839522115-1003\Software\XTTB00001 /GGE:F

Locate FixReg.bat in that folder and double-click on it.

Try to merge again that fix.reg.

Reboot

Re-scan with spybot and let me know if it's gone.

TheOnlyBigDog
2008-08-25, 19:01
Nope. Once again, it remains.:sad:

Shaba
2008-08-25, 19:06
OK, then put this to FixReg.bat and try again, please:


RegDACL HKEY_USERS\S-1-5-21-1343024091-1123561945-839522115-1003\Software\XTTB00001 /SGE:F


Remember to save FixReg.bat and fix.reg both as all files (*.*) and include .bat and .reg

TheOnlyBigDog
2008-08-25, 19:48
Once again, it has decided to keep gracing us with it's presence. :sad:

Shaba
2008-08-25, 19:48
Are you doing everything from admin account?

TheOnlyBigDog
2008-08-25, 19:55
Yes. My acct is the only acct on this puter.

Shaba
2008-08-25, 20:00
Go to start - run - regedit - ok

Go to HKEY_USERS\S-1-5-21-1343024091-1123561945-839522115-1003\Software

Find XTTB00001

Take ownership of that key as described here (http://technet.microsoft.com/en-us/library/cc786173.aspx)

Right-click and choose Delete.

Let me know if it is now gone.

TheOnlyBigDog
2008-08-25, 20:44
Well... I' tried taking ownership and deleting the file two times and everytime I reboot, it seems to come right back.:sad:

TheOnlyBigDog
2008-08-25, 20:45
Wouldn't it just be easier to reformat the hdd and reinstall windows?

Shaba
2008-08-25, 21:14
No.

That is nothing but a registry key.

That looks like to be related to ICQ toolbar so it might be a false positive as well.

You may want to try to uninstall ICQ toolbar and let me know if it still is there after that.

TheOnlyBigDog
2008-08-25, 21:22
Yes I do have a iCQ toolbar that magically appeared a few days ago, but how do I uninstall it. I can't find it in my proggies or in the add/remove in the control panel.:sad:

Shaba
2008-08-25, 21:30
Go to start - run

Type C:\PROGRA~1\ICQTOO~1 and click ok.

Tell me if there is an uninstaller.

TheOnlyBigDog
2008-08-25, 21:45
This is the list that opened up in that folder:

Cache
about: HTML Document
basis: XML Document
Dig_Res: XML Document
download: HTML Document
Games: XML Document
games_button: XML Document
icons 432x16 Paint Shop Pro Photo X2
loading: HTML Document
logo_small 132x22 GIF Image
newversion: Text Document
tb_buttons: XML Document
tb_games: XML Document
tb_options: XML Document
toolbaru.crc: CRC File
toolbaru.dll 2.0.20.11: IE Toolbar
version: Text Document

This is all there is!

Shaba
2008-08-26, 10:09
I see.

We try this:

Open HijackThis, click do a system scan only and checkmark these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Close all windows including browser and press fix checked.

Reboot.

Go to start - run

Type C:\PROGRA~1\ICQTOO~1 and click ok.

Delete all files inside it as well as folder itself.

Go to start - run - regedit - ok

Go to HKEY_USERS\S-1-5-21-1343024091-1123561945-839522115-1003\Software

Find XTTB00001

Take ownership of that key as described earlier

Right-click and choose Delete.

Let me know if it is now gone.

TheOnlyBigDog
2008-08-26, 19:03
Thank you so much. It is finally gone and my puter is now running just like it should. :):):)

Shaba
2008-08-26, 19:06
Great :)

Still some issues left?

TheOnlyBigDog
2008-08-26, 19:53
Oh No. What issues?

Shaba
2008-08-26, 19:59
I mean malware issues? :)

TheOnlyBigDog
2008-08-26, 20:11
Oh no! That friggin' toolbar was the only issue. I've run SpyBot, SuperAnitSpyware and Norton's and all is beautiful.:)

Shaba
2008-08-26, 20:32
Great :)

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

You can fix these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Please download JavaRa (http://sourceforge.net/project/downloading.php?groupname=javara&filename=JavaRa.zip&use_mirror=osdn) and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

Double-click on JavaRa.exe to start the program.
From the drop-down menu, choose English and click on Select.
JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
A logfile will pop up. Please save it to a convenient location.

Then download and install Java Runtime Environment (JRE) 6 Update 7 (http://java.sun.com/javase/downloads/index.jsp).


Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

Malwarebytes' Anti-Malware Setup Guide (http://www.bfccomputers.com/forum/index.php?showtopic=1644)

Malwarebytes' Anti-Malware Scanning Guide (http://www.bfccomputers.com/forum/index.php?showtopic=1645)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://castlecops.com/postlite7736-.html)

Happy surfing and stay clean! :bigthumb:

Shaba
2008-08-28, 10:48
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.