PDA

View Full Version : Another Adrevolver/ victim



Fredo_P
2008-10-20, 01:37
Hello all,
THis is my first post and I am at my last string of sanity. Only goig to give the basics to keep it short.
Started last night. Attempting to fix since 5am PST.
Used S&D, Norton 360, Spy sweeper, windows defender. No good.

Symtptoms:
-WIndows Auto update will not start, unkown program preventing it from starting as per windows alert warning.
-IE8 privacy settings locked and set to allow all cookies. Nothing will force it back to any other setting.
-Way to many pop-ups.
-Adrevolver/ cookie and other cookies will not delete at all
-Trojas appear after starting IE8

Cookies I want gone:
@media.adrevolver.com/adrevolver/
@www7.addfreestats.com/cgi-bin


Post search results as next reply it was to long...

Fredo_P
2008-10-20, 01:41
--- Search result list ---
Hint of the Day: Click the bar at the right of this to see more information! ()


AdRevolver: Tracking cookie (Internet Explorer: Fredo) (Cookie, nothing done)



--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---

2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-09-16 TeaTimer.exe (1.6.3.25)
2008-10-18 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-07-07 advcheck.dll (1.6.1.12)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-07-07 Tools.dll (2.1.5.7)
2008-09-02 Includes\Adware.sbi (*)
2008-10-14 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-09-02 Includes\Dialer.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-22 Includes\HeavyDuty.sbi (*)
2008-09-02 Includes\Hijackers.sbi (*)
2008-10-07 Includes\HijackersC.sbi (*)
2008-09-09 Includes\Keyloggers.sbi (*)
2008-10-14 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-10-08 Includes\Malware.sbi (*)
2008-10-14 Includes\MalwareC.sbi (*)
2008-09-02 Includes\PUPS.sbi (*)
2008-10-14 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-09-30 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-09-09 Includes\Spyware.sbi (*)
2008-10-14 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-10-15 Includes\Trojans.sbi (*)
2008-10-14 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



--- System information ---
Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
/ Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
/ Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP3: Windows XP Service Pack 3
/ Windows XP / SP4: Security Update for Windows XP (KB938464)
/ Windows XP / SP4: Security Update for Windows XP (KB946648)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Update for Windows XP (KB951072-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951698)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Update for Windows XP (KB951978)
/ Windows XP / SP4: Hotfix for Windows XP (KB952287)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB953839)
/ Windows XP / SP4: Security Update for Windows XP (KB954211)
/ Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
/ Windows XP / SP4: Security Update for Windows XP (KB956391)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB956841)
/ Windows XP / SP4: Security Update for Windows XP (KB957095)


--- Startup entries list ---
Located: HK_LM:Run, Adobe Reader Speed Launcher
command: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
file: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
size: 34672
MD5: 69B16C7B7746BA5C642FC05B3561FC73

Located: HK_LM:Run, Alcmtr
command: "C:\WINDOWS\ALCMTR.EXE"
file: C:\WINDOWS\ALCMTR.EXE
size: 69632
MD5: 8B4CBBA1EA526830C7F97E7822E2493A

Located: HK_LM:Run, BDRegion
command: "C:\Program Files\Cyberlink\Shared Files\brs.exe"
file: C:\Program Files\Cyberlink\Shared Files\brs.exe
size: 91432
MD5: 7C1B1828E36061CD58F9AC80D045113D

Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 51048
MD5: B1A2A8870DF52238AE256D692F443EDB

Located: HK_LM:Run, LGODDFU
command: "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
file: C:\Program Files\lg_fwupdate\fwupdate.exe
size: 249856
MD5: 60D19376DD59F9239EC0BC1F14C34E4D

Located: HK_LM:Run, NeroFilterCheck
command: "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
file: C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
size: 570664
MD5: F0DEB8D82B31BD7F8EB552F1FC421D65

Located: HK_LM:Run, NvCplDaemon
command: "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: 037B1E7798960E0420003D05BB577EE6

Located: HK_LM:Run, NvMediaCenter
command: "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: 037B1E7798960E0420003D05BB577EE6

Located: HK_LM:Run, nwiz
command: "C:\WINDOWS\system32\nwiz.exe" /install
file: C:\WINDOWS\system32\nwiz.exe
size: 1630208
MD5: D76B1D340C6C8F5A676DC717919B319A

Located: HK_LM:Run, osCheck
command: "C:\Program Files\Norton 360 Premier Edition\osCheck.exe"
file: C:\Program Files\Norton 360 Premier Edition\osCheck.exe
size: 988512
MD5: 956740878FF68E493C1D9923C65C9A20

Located: HK_LM:Run, PDVD8LanguageShortcut
command: "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
file: C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe
size: 50472
MD5: AA62A9A6CE962107761775C66F49AD53

Located: HK_LM:Run, RemoteControl8
command: "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
file: C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
size: 83240
MD5: 0A80BED61A1729DAB9499BC5A9B515A9

Located: HK_LM:Run, RivaTuner
command: "C:\Program Files\RivaTuner v2.11\RivaTuner.exe" /T
file: C:\Program Files\RivaTuner v2.11\RivaTuner.exe
size: 2715648
MD5: 939B05833F6526F557086C2E3D2AB685

Located: HK_LM:Run, RivaTunerStartupDaemon
command: "C:\Program Files\RivaTuner v2.11\RivaTuner.exe" /S
file: C:\Program Files\RivaTuner v2.11\RivaTuner.exe
size: 2715648
MD5: 939B05833F6526F557086C2E3D2AB685

Located: HK_LM:Run, RTHDCPL
command: "C:\WINDOWS\RTHDCPL.EXE"
file: C:\WINDOWS\RTHDCPL.EXE
size: 16871936
MD5: 7315846D5D2BC82C37E27E82767F7DB5

Located: HK_LM:Run, SpySweeper
command: C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe /startintray
file: C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
size: 6272888
MD5: 7952DB7EFEF99DA0BB92767E0D5A548B

Located: HK_LM:Run, Start WingMan Profiler
command: "C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
file: C:\Program Files\Logitech\Gaming Software\LWEMon.exe
size: 88584
MD5: F4646F979737586F4107BBF284A556E7

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
file: C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
size: 144784
MD5: 6AB4C021FBD36DC6764924C312428D97

Located: HK_LM:Run, Windows Defender
command: "C:\Program Files\Windows Defender\MSASCui.exe" -hide
file: C:\Program Files\Windows Defender\MSASCui.exe
size: 866584
MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC

Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-789336058-1767777339-839522115-1004...
command: "C:\WINDOWS\system32\ctfmon.exe"
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3

Located: HK_CU:Run, NVIDIA nTune
where: S-1-5-21-789336058-1767777339-839522115-1004...
command: "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
file: C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
size: 81920
MD5: DA32F8864EFF0B437A7F4BD75FA9A7BA

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!



--- Browser helper object list ---
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} (NCO 2.0 IE BHO)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: NCO 2.0 IE BHO
CLSID name:
Path: C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\
Long name: CoIEPlg.dll
Short name:
Date (created): 2/23/2008 7:08:26 PM
Date (last access): 10/19/2008 4:18:42 PM
Date (last write): 6/30/2008 1:44:04 PM
Filesize: 349552
Attributes: archive
MD5: 3063C05D9CA51D9BB47830BD04A19766
CRC32: CBCA0ED1
Version: 2008.2.7.7

{62b81646-1e65-4dc1-9865-0f618a4403fb} ({bf3044a8-16f0-5689-1cd4-56e164618b26})
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: {bf3044a8-16f0-5689-1cd4-56e164618b26}
CLSID name:
Path: C:\WINDOWS\system32\
Long name: notvxz.dll
Short name:
Date (created): 10/18/2008 10:54:46 PM
Date (last access): 10/19/2008 4:18:42 PM
Date (last write): 10/18/2008 10:54:46 PM
Filesize: 101888
Attributes: archive
MD5: 669BE84DB4C83F4BF7A9E9F32841F32B
CRC32: 4D3CFEF3

{6D53EC84-6AAE-4787-AEEE-F4628F01010C} (Symantec Intrusion Prevention)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: Symantec Intrusion Prevention
CLSID name: Symantec Intrusion Prevention
Path: C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\
Long name: IPSBHO.dll
Short name:
Date (created): 9/5/2008 12:09:52 AM
Date (last access): 10/19/2008 4:26:42 PM
Date (last write): 9/5/2008 12:09:52 AM
Filesize: 116088
Attributes: archive
MD5: 317FC88BDD45DD92A4A8A6C1F7963EF3
CRC32: 00F465C4
Version: 8.2.0.81

{9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Windows Live Sign-in Helper
Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
Long name: WindowsLiveLogin.dll
Short name: WINDOW~1.DLL
Date (created): 2/22/2008 3:24:38 PM
Date (last access): 10/19/2008 4:24:42 PM
Date (last write): 2/22/2008 3:24:38 PM
Filesize: 401968
Attributes: archive
MD5: E393F5B7D090DF8370452916FFE92F9A
CRC32: 684A21B5
Version: 5.0.744.4

{9BAA11B2-3370-4157-97CD-6FB2B380B437} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\WINDOWS\system32\
Long name: qoMecbbC.dll
Short name:
Date (created): 10/18/2008 11:46:28 AM
Date (last access): 10/19/2008 4:26:06 PM
Date (last write): 10/18/2008 11:46:36 AM
Filesize: 243712
Attributes: archive
MD5: D682682F2643F9F23A97F5D2711304EC
CRC32: 5B49823A



--- ActiveX list ---
{1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab)
DPF name: System Requirements Lab
CLSID name: System Requirements Lab Class
Installer:
Codebase: http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: sysreqlab3.dll
Short name: SYSREQ~1.DLL
Date (created): 5/20/2008 8:32:40 PM
Date (last access): 10/19/2008 3:57:28 PM
Date (last write): 5/20/2008 8:32:40 PM
Filesize: 267568
Attributes: archive
MD5: B7AE21C49E0D2F48B6D63BC0BC408AD2
CRC32: E4218836
Version: 3.0.0.0

{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
Codebase: http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1220595184765
description:
classification: Legitimate
known filename: wuweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: wuweb.dll
Short name:
Date (created): 9/4/2008 8:55:00 PM
Date (last access): 10/19/2008 3:56:06 PM
Date (last write): 7/18/2008 10:09:44 PM
Filesize: 205000
Attributes: archive
MD5: 4889720E56E85E1FE4659039BB5F6E3F
CRC32: EE278BD5
Version: 7.2.6001.784

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
DPF name:
CLSID name: MUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
Codebase: http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1221893404887
description:
classification: Legitimate
known filename: muweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: muweb.dll
Short name:
Date (created): 7/30/2007 7:18:34 PM
Date (last access): 10/19/2008 3:58:46 PM
Date (last write): 7/18/2008 10:07:54 PM
Filesize: 210976
Attributes: archive
MD5: 5D5DE96F10C6ACDFBEF06125D0EC5890
CRC32: 8B6B8748
Version: 7.2.6001.784

{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_07
Installer: C:\WINDOWS\Downloaded Program Files\jinstall-6u7.inf
Codebase: http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1221880676289&h=3476fbec759228ed1dd0794fcd8ff0c1/&filename=jinstall-6u7-windows-i586-jc.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre1.6.0_07\bin\
Long name: npjpi160_07.dll
Short name: NPJPI1~1.DLL
Date (created): 6/10/2008 2:32:34 AM
Date (last access): 10/19/2008 4:33:58 PM
Date (last write): 6/10/2008 4:27:02 AM
Filesize: 132496
Attributes: archive
MD5: 7C83A2809E13950359189767AC9D5DB8
CRC32: 925C2A88
Version: 6.0.70.6

{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_07
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Path: C:\Program Files\Java\jre1.6.0_07\bin\
Long name: npjpi160_07.dll
Short name: NPJPI1~1.DLL
Date (created): 6/10/2008 2:32:34 AM
Date (last access): 10/19/2008 4:33:58 PM
Date (last write): 6/10/2008 4:27:02 AM
Filesize: 132496
Attributes: archive
MD5: 7C83A2809E13950359189767AC9D5DB8
CRC32: 925C2A88
Version: 6.0.70.6

Fredo_P
2008-10-20, 01:42
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_07
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre1.6.0_07\bin\
Long name: npjpi160_07.dll
Short name: NPJPI1~1.DLL
Date (created): 6/10/2008 2:32:34 AM
Date (last access): 10/19/2008 4:33:58 PM
Date (last write): 6/10/2008 4:27:02 AM
Filesize: 132496
Attributes: archive
MD5: 7C83A2809E13950359189767AC9D5DB8
CRC32: 925C2A88
Version: 6.0.70.6

{D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.12)
DPF name:
CLSID name: Measurement Services Client v.3.12
Installer: C:\WINDOWS\Downloaded Program Files\MSC3.inf
Codebase: http://service.futuremark.com/virtualmark/tc/MSC3.cab
description:
classification: Legitimate
known filename: MSC3.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\FUTURE~1\MSC\
Long name: MSC3.ocx
Short name:
Date (created): 12/14/2006 12:34:08 PM
Date (last access): 10/19/2008 4:33:58 PM
Date (last write): 12/14/2006 12:34:08 PM
Filesize: 1085440
Attributes: archive
MD5: 82165E21E225C1F5FA1135EB6F4C3E44
CRC32: 97BC49CC
Version: 3.12.0.1



--- Process list ---
PID: 0 ( 0) [System]
PID: 1088 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 1156 (1088) \??\C:\WINDOWS\system32\csrss.exe
size: 6144
PID: 1180 (1088) \??\C:\WINDOWS\system32\winlogon.exe
size: 507904
PID: 1224 (1180) C:\WINDOWS\system32\services.exe
size: 108544
MD5: 0E776ED5F7CC9F94299E70461B7B8185
PID: 1236 (1180) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: BF2466B3E18E970D8A976FB95FC1CA85
PID: 1420 (1224) C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
size: 1066360
MD5: F8F9FC4D8F3D0A3950723F32AF95B3E8
PID: 1452 (1224) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1524 (1224) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1648 (1224) C:\Program Files\Windows Defender\MsMpEng.exe
size: 13592
MD5: F45DD1E1365D857DD08BC23563370D0E
PID: 1688 (1224) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1944 (1224) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 336 (1224) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
size: 149352
MD5: 0981902E0C29655FA8FA161247064907
PID: 276 ( 140) C:\WINDOWS\Explorer.EXE
size: 1033728
MD5: 12896823FB95BFB3DC9B46BCAEDC9923
PID: 608 (1224) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 708 (1224) C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
size: 238968
MD5: AE9560C298D847AEF346BDD5FAD3B0E3
PID: 828 (1224) C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
size: 1553704
MD5: 40F8DC71CD638C40DB38A0C08AF2A6ED
PID: 992 (1224) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
size: 335872
MD5: 7CF1B716372B89568AE4C0FE769F5869
PID: 1084 (1224) C:\Program Files\nHancer\nHancerService.exe
size: 49152
MD5: 73FC16D1263C59D921BE809CD8264038
PID: 1660 (1596) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
size: 149352
MD5: 0981902E0C29655FA8FA161247064907
PID: 1892 ( 276) C:\WINDOWS\RTHDCPL.EXE
size: 16871936
MD5: 7315846D5D2BC82C37E27E82767F7DB5
PID: 304 ( 276) C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
size: 144784
MD5: 6AB4C021FBD36DC6764924C312428D97
PID: 1484 ( 276) C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: 037B1E7798960E0420003D05BB577EE6
PID: 1568 ( 276) C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
size: 83240
MD5: 0A80BED61A1729DAB9499BC5A9B515A9
PID: 232 ( 276) C:\Program Files\Cyberlink\Shared Files\brs.exe
size: 91432
MD5: 7C1B1828E36061CD58F9AC80D045113D
PID: 1868 ( 276) C:\Program Files\Windows Defender\MSASCui.exe
size: 866584
MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC
PID: 1896 ( 276) C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
size: 6272888
MD5: 7952DB7EFEF99DA0BB92767E0D5A548B
PID: 2060 ( 276) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
PID: 2180 (1224) C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
size: 131072
MD5: C4305F070481199D102F20DAC23E554B
PID: 2328 (1224) C:\WINDOWS\system32\nvsvc32.exe
size: 163908
MD5: 42321AC5448078131903B272E6C49024
PID: 2524 (1224) C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
size: 3667304
MD5: BC3AE476BA1C88831C7CE0DCCFD1943C
PID: 4016 (1892) C:\WINDOWS\ALCFDRTM.EXE
size: 73728
MD5: 7F23EBB4AF738149CC0EBE9DA10F9145
PID: 2224 (1688) C:\WINDOWS\system32\wscntfy.exe
size: 13824
MD5: F92E1076C42FCD6DB3D72D8CFE9816D5
PID: 2680 (1224) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: 8C515081584A38AA007909CD02020B3D
PID: 2716 (1452) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
size: 120384
MD5: 83B8590810DCBF60C1A6342165268A22
PID: 3896 ( 276) C:\Program Files\Internet Explorer\iexplore.exe
size: 637984
MD5: 903D3FDCBA34DAD82966E761635A663B
PID: 3296 (2524) C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
size: 181608
MD5: D46CA5672138175E4246AA7317B78E86
PID: 2784 ( 276) C:\WINDOWS\system32\notepad.exe
size: 69120
MD5: 5E28284F9B5F9097640D58A73D38AD4C
PID: 1360 (3896) C:\Program Files\Internet Explorer\iexplore.exe
size: 637984
MD5: 903D3FDCBA34DAD82966E761635A663B
PID: 1144 (3896) C:\Program Files\Internet Explorer\iexplore.exe
size: 637984
MD5: 903D3FDCBA34DAD82966E761635A663B
PID: 5772 (3896) C:\Program Files\Internet Explorer\iexplore.exe
size: 637984
MD5: 903D3FDCBA34DAD82966E761635A663B
PID: 2648 ( 276) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 4891472
MD5: 3B1B5D09D3C9C4CD39D4DB06ED7A0855
PID: 4 ( 0) System
PID: 1984 ( 276) C:\WINDOWS\system32\notepad.exe
size: 69120
MD5: 5E28284F9B5F9097640D58A73D38AD4C


--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 10/19/2008 4:40:44 PM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://google.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


--- Winsock Layered Service Provider list ---


--- Uninstall list ---
Windows Driver Package - ABIT (UGURU) System (3.0.2005.531 ) 3.0.2005.531 (347F83755F38F1570B602823E659DC5335F5A948)
uninstall cmd: C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst.exe /u C:\WINDOWS\system32\DRVSTORE\uguru_347F83755F38F1570B602823E659DC5335F5A948\uguru.inf
publisher: ABIT

Level-D Simulations 767-300 (763v2)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\Microsoft Games\Flight Simulator 9\763v2.ini"

Level-D Simulations 767-300 Update (763v21)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\Microsoft Games\Flight Simulator 9\763v21.ini"

'757-300 Captain' Expansion Model 2.0.00 (A753CAPTAIN)
version (major): 2
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\csA753_uninstall.exe
publisher: © 1999-2008 Captain Sim
help link: www.captainsim.info/support/

'757 Freighter Captain' Expansion Model 2.0.00 (A754CAPTAIN)
version (major): 2
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\csA754_uninstall.exe
publisher: © 1999-2008 Captain Sim
help link: www.captainsim.info/support/

Active Camera 2004 2.1 for FS 2004 (updated to 9.1) (Active Camera 2004 2.1 for FS 2004 (updated to 9.1))
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\Active Camera 2004 2_1_for_FS9_1 uninstal.exe

Active Camera 2004 fix version 2.1 (FS9.1) (Active Camera 2004 fix version 2.1 (FS9.1))
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\Active Camera 2004 v 2.1 fix for FS 9_1 uninstal.exe

(AddressBook)

Adobe Acrobat 5.0 5.0 (Adobe Acrobat 5.0)
version (major): 5
install location: C:\Program Files\Adobe\Acrobat 5.0
install source: C:\Documents and Settings\Fredo\Local Settings\Temp\pft71~tmp\
uninstall cmd: C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
publisher: Adobe Systems, Inc.
help link: http://www.adobe.com/prodindex/acrobat/main.html

Adobe AIR 1.0.4990 (Adobe AIR)
install location: C:\
uninstall cmd: C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
publisher: Adobe Systems Inc.

Adobe Flash Player 10 ActiveX 10.0.12.36 (Adobe Flash Player ActiveX)
uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
publisher: Adobe Systems Incorporated
help link: http://www.adobe.com/go/flashplayer_support/

Flight One ATR 72-500 (ATR_72500)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\Microsoft Games\Flight Simulator 9\ATR_72500.ini"

'757-200 Captain' Block F Upgrade 2.0.00 (B752BF_UPGR_FS9)
version (major): 2
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\csU752_uninstall.exe
publisher: © 1999-2008 Captain Sim
help link: www.captainsim.info/support/

Boeing 737 Fuel Planner 1.5 (Boeing 737 Fuel Planner 1.5)
uninstall cmd: C:\Program Files\Boeing737FPL\Uninstal.exe

(Branding)

Block C - ACE 757 2.0.00 (C757CAPTAIN)
version (major): 2
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\csC757_uninstall.exe
publisher: © 1999-2008 Captain Sim
help link: www.captainsim.info/support/

CH Control Manager (CHControlManager_is1)
install location: C:\Program Files\CH Products\Control Manager\
uninstall cmd: "C:\Program Files\CH Products\Control Manager\unins000.exe"

Acrobat.com 1.1.377 (com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1)
install location: C:\Program Files\Adobe\Acrobat.com\
uninstall cmd: C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
publisher: Adobe Systems Incorporated

(Connection Manager)

(DirectAnimation)

(DirectDrawEx)

DriverAgent by TouchStone Software (DriverAgent.exe)
uninstall cmd: RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove

(DXM_Runtime)

'757 Captain' Soundset 1.4 1.4.00 (E757CAPTAIN)
version (major): 1
version (minor): 4
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\csE757_uninstall.exe
publisher: © 1999-2007 Captain Sim
help link: www.captainsim.info/support/

Microsoft Flight Simulator 2004 A Century of Flight 9.0 (Flight Simulator 9.0)
version (major): 9
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
uninstall cmd: "C:\Program Files\Microsoft Games\Flight Simulator 9\UNINSTAL.EXE" /runtemp /addremove
publisher: Microsoft
help link: http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Games\Flight Simulator 9\Readme.rtf

(Fontcore)

FS2Crew: 737 Pro Edition (FS2Crew: 737 Pro Edition)
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\Uninstal.exe

FS2Crew: PMDG 747 Edition (FS9/Non F1) (FS2Crew: PMDG 747 Edition (FS9/Non F1))
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\UnFS2CREW747.exe

FS2Crew: PMDG 747 Edition Update 1.2 (FS2Crew: PMDG 747 Edition Update 1.2)
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\UnFS2CREW747.exe

FSGenesis Appalachians & Northeast 38m Terrain (FSGenesis Appalachians & Northeast 38m Terrain)
uninstall cmd: C:\WINDOWS\unvise32.exe C:\Program Files\Microsoft Games\Flight Simulator 9\scenery\world\FSGDocs\uninstal_apdem38v2.log

FSGenesis Western Hemisphere - North 153m Terrain (FSGenesis Western Hemisphere - North 153m Terrain)
uninstall cmd: C:\WINDOWS\unvise32.exe C:\Program Files\Microsoft Games\Flight Simulator 9\scenery\world\FSGDocs\uninstal_153dem-wn.log

Flight Environment (FSWater_10)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\Microsoft Games\Flight Simulator 9\FSWater_10.ini"

Ground Environment Professional (Ground Environment Professional)
uninstall cmd: C:\Program Files\Flight One Software\GEProUninstal.exe

(ICW)

(IDNMitigationAPIs)

(IE40)

(IE4Data)

(IE5BAKEX)

(ie7)

Windows Internet Explorer 8 Beta 2 20080822.031232 (ie8)
install date: 20080905
uninstall cmd: "C:\WINDOWS\ie8\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://www.microsoft.com/ie

(IEData)

(InCD!UninstallKey)
uninstall cmd: C:\WINDOWS\NuNInst.exe /UNINSTALL

(InstallShield Uninstall Information)

CyberLink PowerDVD 8 8.0.1730 (InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47})
version: 134217728
version (major): 8
estimated size: 142612
install date: 20081018
install location: C:\Program Files\CyberLink\PowerDVD8\
install source: C:\Documents and Settings\Fredo\My Documents\My Received Files\Torrents\CyberLink PowerDVD Ultra v8.0.2021.50+Keys-HeartBug\Setup 8.0.1730\
uninstall cmd: "C:\Program Files\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\setup.exe" /z-uninstall
publisher: CyberLink Corp.
help link: http://support.gocyberlink.com/
help telephone: +886-2-86671298

NVIDIA nTune 1.00.0000 (InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF})
version: 16777216
version (major): 1
estimated size: 37599
install date: 20080924
install location: C:\Program Files\NVIDIA Corporation\
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\_is39\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} /l1033
publisher: NVIDIA Corporation
comments: Your Comments
contact: Customer Support Department
help link: http://www.yourcompany.com/help
help telephone: 1-408-486-0000

Microsoft Flight Simulator X 10.0.61355.0 (InstallShield_{9527A496-5DF9-412A-ADC7-168BA5379CA6})
version: 167833065
version (major): 10
estimated size: 13616545
install date: 20080910
install location: C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\
install source: E:\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{9527A496-5DF9-412A-ADC7-168BA5379CA6}
publisher: Microsoft Game Studios
comments: Copyright © 2006 Microsoft Corporation

KATL Atlanta (KATL Atlanta)
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\Uninstall KATL.exe

(KB884267)

(KB885353)

(KB886612)

(KB887078)

(KB887626)

High Definition Audio Driver Package - KB888111 20040219.000000 (KB888111WXPSP2)
uninstall cmd: "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=KB888111

(KB888656)

(KB889858)

(KB891122)

Windows Genuine Advantage Validation Tool (KB892130) (KB892130)
install date: 20080905
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=892130

(KB892313)

(KB893240)

(KB893241)

(KB895181)

(KB895316)

(KB895572)

(KB897586)

(KB898549)

(KB900399)

(KB902344)

(KB907658)

(KB911565)

(KB911854)

Hotfix for Windows Media Format 11 SDK (KB929399) (KB929399)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=929399

Security Update for Windows Media Player 11 (KB936782) (KB936782_WMP11)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=936782

Security Update for Windows XP (KB938464) 1 (KB938464)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938464

Hotfix for Windows Media Player 11 (KB939683) (KB939683)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=939683

Security Update for Windows XP (KB941569) (KB941569)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941569

Security Update for Windows XP (KB946648) 1 (KB946648)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=946648

Security Update for Windows XP (KB950762) 1 (KB950762)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950762

Security Update for Windows XP (KB950974) 1 (KB950974)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950974

Fredo_P
2008-10-20, 01:44
Security Update for Windows XP (KB951066) 1 (KB951066)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951066

Update for Windows XP (KB951072-v2) 2 (KB951072-v2)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951072

Security Update for Windows XP (KB951376-v2) 2 (KB951376-v2)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951376

Security Update for Windows XP (KB951698) 1 (KB951698)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951698

Security Update for Windows XP (KB951748) 1 (KB951748)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951748

Update for Windows XP (KB951978) 1 (KB951978)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951978

Hotfix for Windows XP (KB952287) 1 (KB952287)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952287

Security Update for Windows XP (KB952954) 1 (KB952954)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952954

Security Update for Windows XP (KB953839) 1 (KB953839)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=953839

Security Update for Windows Media Player 11 (KB954154) (KB954154_WM11)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=954154

Security Update for Windows XP (KB954211) 1 (KB954211)
install date: 20081017
uninstall cmd: "C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=954211

Hotfix for Windows XP (KB954550-v5) 5 (KB954550-v5)
install date: 20080905
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=954550

Security Update for Windows XP (KB956391) 1 (KB956391)
install date: 20081017
uninstall cmd: "C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956391

Security Update for Windows XP (KB956803) 1 (KB956803)
install date: 20081017
uninstall cmd: "C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956803

Security Update for Windows XP (KB956841) 1 (KB956841)
install date: 20081017
uninstall cmd: "C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956841

Security Update for Windows XP (KB957095) 1 (KB957095)
install date: 20081017
uninstall cmd: "C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=957095

KEWR Newark (KEWR Newark)
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\Uninstall KEWR.exe

Legendary C-130 1.0.00 (LEGENDARYC130)
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\csC130_uninstall.exe
publisher: © 1999-2005 Captain Sim

3.3.0.45 (LiveUpdate)
install location: "C:\Program Files\Symantec\LiveUpdate"
uninstall cmd: "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
publisher: Symantec Corporation

Microsoft .NET Framework 1.1 Hotfix (KB928366) (M928366)
uninstall cmd: "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"

Futuremark Measurement Services Client (Measurement Services Client)
uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msc3.inf,DefaultUninstall,5

Phoenix 1 (MegaCity - Phoenix_is1)
install location: C:\Program Files\Microsoft Games\Flight Simulator 9\megaCityPhoenix\
uninstall cmd: "C:\Program Files\Microsoft Games\Flight Simulator 9\megaCityPhoenix\unins000.exe"
publisher: PC Aviator Inc.

New York Scenery 1.0 (MegaScenery - New York Scenery_is1)
uninstall cmd: "C:\Program Files\Microsoft Games\Flight Simulator 9\megaSceneryNY\unins000.exe"
publisher: PC Aviator Inc.

Northern California Scenery 1.0 (MegaScenery - Northern California_is1)
install location: C:\Program Files\Microsoft Games\Flight Simulator 9\megaSceneryNC\
uninstall cmd: "C:\Program Files\Microsoft Games\Flight Simulator 9\megaSceneryNC\unins000.exe"
publisher: PC Aviator Inc.

Pacific Northwest Scenery 1.0 (MegaScenery - Pacific Northwest_is1)
install location: C:\megaScenery\megaSceneryPNW\
uninstall cmd: C:\megaScenery\megaSceneryPNW\unins000.exe
publisher: PC Aviator Inc.

Southern California 2 (MegaScenery - Southern California_is1)
install location: C:\Program Files\Microsoft Games\Flight Simulator 9\megaScenerySOCAL\
uninstall cmd: "C:\Program Files\Microsoft Games\Flight Simulator 9\megaScenerySOCAL\unins000.exe"
publisher: PC Aviator Inc.

Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033))
uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm

Microsoft .NET Framework 3.0 (Microsoft .NET Framework 3.0)
install location: C:\WINDOWS\Microsoft.NET\Framework\v3.0\
uninstall cmd: C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=51019

Microsoft .NET Framework 3.5 SP1 (Microsoft .NET Framework 3.5 SP1)
install location: C:\WINDOWS\Microsoft.NET\Framework\v3.5\
uninstall cmd: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=120337

(MobileOptionPack)

(MPlayer2)

Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1)
install date: 20080905
uninstall cmd: "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=74087

(Nero - Burning Rom!UninstallKey)
uninstall cmd: C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL

(NeroBackItUp!UninstallKey)
uninstall cmd: C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL

(NetMeeting)

(NLSDownlevelMapping)

NVIDIA Drivers (NVIDIA Drivers)
uninstall cmd: C:\WINDOWS\system32\nvuninst.exe UninstallGUI

(OutlookExpress)

(PCHealth)
uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf

V1.3 BUILD 01 (PMDG 737: 600/700 Model Update)
publisher: Precision Manuals Development Group
contact: Technical Support
help telephone: N/A

V1.3 BUILD 74 (PMDG 737: 600/700 Release Version)
publisher: Precision Manuals Development Group
contact: Technical Support
help telephone: N/A

V1.3 BUILD 01 (PMDG 737: 800/900)
publisher: Precision Manuals Development Group
contact: Technical Support
help telephone: N/A

Version 1.0 (PMDG B1900 EXPRESS)
publisher: Precision Manuals Development Group
contact: Technical Support

V1.3 BUILD 01 (PMDG EXPRESS B1900 Service Update 1.1)
publisher: Precision Manuals Development Group
contact: Technical Support
help telephone: N/A

Version 1.0 (PMDG Express B1900C v1.0)
publisher: Precision Manuals Development Group
contact: Technical Support

Version 1.0 (PMDG Express B1900C v1.02)
publisher: Precision Manuals Development Group
contact: Technical Support

LiveUpdate (Symantec Corporation) 3.4.1.234 (PsuedoLiveUpdate)
version: 50593792
version (major): 3
version (minor): 4
estimated size: 13395
install date: 9/5/2008
install location: C:\Program Files\Symantec\LiveUpdate
uninstall cmd: MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate"
publisher: Symantec Corporation

RivaTuner v2.11 (RivaTuner)
uninstall cmd: "C:\Program Files\RivaTuner v2.11\uninstall.exe"

(SchedulingAgent)

(Sevinst)

Microsoft Flight Simulator X Service Pack 1 10.0.61355.0 (SP1_9527A496-5DF9-412A-ADC7-168BA5379CA6)
uninstall cmd: c:\WINDOWS\system32\msiexec.exe /qb /l*vx "%TEMP%\FlightSimPatchUninstall.log" /uninstall {92635E02-4C29-4A8F-AA82-7B8B95C823D3} /package {9527A496-5DF9-412A-ADC7-168BA5379CA6}
publisher: Microsoft Game Studios

SquawkBox (SquawkBox)
uninstall cmd: C:\Program Files\SquawkBox\sbuninstall.exe SquawkBox

Microsoft Office Standard 2007 12.0.6215.1000 (STANDARDR)
install location: C:\Program Files\Microsoft Office
uninstall cmd: "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARDR /dll OSETUP.DLL
publisher: Microsoft Corporation

(SymcData-idsdefs)

Norton 360 Premier Edition (Symantec Corporation) 2.2.0.2 (SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777})
install location: C:\Program Files\Norton 360 Premier Edition
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226
uninstall cmd: "C:\Program Files\Common Files\Symantec Shared\SymSetup\{2D617065-1C52-4240-B5BC-C0AE12157777}_2_2_0_2\Setup.exe" /X
publisher: Symantec Corporation
help link: http://www.symantec.com/techsupp/globalsupport.html

System Requirements Lab (SystemRequirementsLab)
uninstall cmd: C:\Program Files\SystemRequirementsLab\Uninstall.exe

TJSJ San Juan (TJSJ San Juan)
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\Uninstall TJSJ.exe

Vuze (Vuze)
uninstall cmd: C:\Program Files\Vuze\uninstall.exe
publisher: Vuze Inc.

(Wdf01000)

(Wdf01001)

Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 (Wdf01005)
install date: 20080920
uninstall cmd: "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
publisher: Microsoft Corporation

Windows Genuine Advantage Validation Tool (KB892130) 1.7.0069.2 (WGA)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=892130

(WIC)

Winamp 5.541 (Winamp)
uninstall cmd: "C:\Program Files\Winamp\UninstWA.exe"
publisher: Nullsoft, Inc
help link: http://forums.winamp.com

Windows Media Format 11 runtime (Windows Media Format Runtime)
uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
help link: http://go.microsoft.com/fwlink/?LinkId=62768

Windows Media Player 11 (Windows Media Player)
uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall

Windows XP Service Pack 3 20080414.031525 (Windows XP Service Pack)
install date: 20080905
uninstall cmd: "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=936929

Windows Live Beta (all programs) 14.0.5025.0904 (WinLiveSuite_Wave3)
install location: C:\Program Files\Windows Live\
uninstall cmd: C:\Program Files\Windows Live\Installer\wlarp.exe
publisher: Microsoft Corporation
help link: http://support.live.com/

(WMCSetup)

Windows Media Format 11 runtime (WMFDist11)
install date: 20080905
uninstall cmd: "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:

Windows Media Player 11 (wmp11)
install date: 20080905
uninstall cmd: "C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:

Microsoft User-Mode Driver Framework Feature Pack 1.0 (Wudf01000)
install date: 20080905
uninstall cmd: "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
comments: Build Number 5716

Adobe AIR 1.0.8.4990 ({00203668-8170-44A0-BE44-B632FA4D780F})
version: 16777224
version (major): 1
estimated size: 24847
install date: 20080919
install source: C:\Documents and Settings\Fredo\Local Settings\Application Data\nos\Adobe AIR Installer\
uninstall cmd: MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
publisher: Adobe Systems Inc.

nHancer 2.4.0202 ({096EEB94-71B8-4C5B-A4E4-F785031B3F37})
version: 33816778
version (major): 2
version (minor): 4
estimated size: 2880
install date: 20081013
install location: C:\Program Files\nHancer\
install source: C:\Documents and Settings\Fredo\Application Data\KSE\nHancer\install\
uninstall cmd: MsiExec.exe /X{096EEB94-71B8-4C5B-A4E4-F785031B3F37}
publisher: KSE
comments: Advanced nVidia Control Utility
help link: http://www.nhancer.com/?dat=contact

Norton 360 HTMLHelp 2.0.0.175 ({0BDD3FAD-61CD-4BF3-B9C4-4CEFD43F53F8})
version: 33554432
version (major): 2
estimated size: 440
install date: 20080905
install location: C:\Program Files\Common Files\Symantec Shared\NHelp\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\Help\
uninstall cmd: MsiExec.exe /I{0BDD3FAD-61CD-4BF3-B9C4-4CEFD43F53F8}
publisher: Symantec Corporation

HP USB Disk Storage Format Tool ({0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}\Setup.exe" -l0x9 anything

PMDG747_400F 1.01.0000 ({164360E5-0AAD-48AD-8A36-3F8A859FAB6F})
version: 16842752
install date: 20080910
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\bye10.tmp\Disk1\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{164360E5-0AAD-48AD-8A36-3F8A859FAB6F}\setup.exe" -l0x9 -removeonly
publisher: Precision Manuals Development Group
contact: support@precisionmanuals.com
help link: http://www.precisionmanuals.com
help telephone: Telephone Support Not Available

DVD Suite 5.0.1319 ({1FBF6C24-C1FD-4101-A42B-0C564F9E8E79})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
publisher: CyberLink Corporation

GearDrvs 5.0.0.2 ({206FD69B-F9FE-4164-81BD-D52552BC9C23})
version: 83886080
version (major): 5
estimated size: 120
install date: 20080905
install location: C:\WINDOWS\system32\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\GearDrvs\
uninstall cmd: MsiExec.exe /I{206FD69B-F9FE-4164-81BD-D52552BC9C23}
publisher: Symantec Corporation

aerosoft's - AES-Base&&AirportPack - FS2004 ({20A96613-3802-436C-842E-653C62FABA0D})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{20A96613-3802-436C-842E-653C62FABA0D}\Setup.exe" -uninst

Norton 360 2.0.0.242 ({21829177-4DED-4209-AD08-490B3AC9C01A})
version: 33554432
version (major): 2
estimated size: 9919
install date: 20080905
install location: C:\Program Files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\N360\
uninstall cmd: MsiExec.exe /I{21829177-4DED-4209-AD08-490B3AC9C01A}
publisher: Symantec Corporation

MSVCRT 14.0.1468.721 ({22B775E7-6C42-4FC5-8E10-9A5E3257BD94})
version: 234882492
version (major): 14
estimated size: 1641
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\fb17294a1c91ab7\
uninstall cmd: MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
publisher: Microsoft

Backup 1.0.0.382 ({24DF7221-644B-4C3A-A478-459502D40522})
version: 16777216
version (major): 1
estimated size: 11081
install date: 20080905
install location: C:\Program Files\Common Files\\Symantec Shared\Backup
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\Backup\
uninstall cmd: MsiExec.exe /I{24DF7221-644B-4C3A-A478-459502D40522}
publisher: Symantec Corporation

PMDG_747-400_Sound_Update 1.00.000 ({2758F387-D016-4725-9D03-AB039364DF3D})
version: 16777216
install date: 20080910
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\bye16.tmp\Disk1\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2758F387-D016-4725-9D03-AB039364DF3D}\setup.exe" -l0x9 -removeonly
publisher: Precision Manuals Development Group
contact: support@precisionmanuals.com
help link: http://www.precisionmanuals.com
help telephone: No Telephone Support Available

CyberLink PowerDVD 8 8.0.1730 ({2BF2E31F-B8BB-40A7-B650-98D28E0F7D47})
version: 134217728
version (major): 8
estimated size: 142612
install date: 20081018
install location: C:\Program Files\CyberLink\PowerDVD8\
install source: C:\Documents and Settings\Fredo\My Documents\My Received Files\Torrents\CyberLink PowerDVD Ultra v8.0.2021.50+Keys-HeartBug\Setup 8.0.1730\
publisher: CyberLink Corp.
help link: http://support.gocyberlink.com/
help telephone: +886-2-86671298

Norton 360 2.2.0.2 ({2D617065-1C52-4240-B5BC-C0AE12157777})
version: 33685504
version (major): 2
version (minor): 2
estimated size: 127996
install date: 20080905
install location: C:\Program Files\Norton 360 Premier Edition\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\N360\
uninstall cmd: MsiExec.exe /I{2D617065-1C52-4240-B5BC-C0AE12157777}
publisher: Symantec Corporation

FSNavigator 4.7 ({2F76FF6D-B992-4FD9-8686-F09F868B2C58})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F76FF6D-B992-4FD9-8686-F09F868B2C58}\Setup.exe" -l0x9
publisher: FSNavigator team
contact: support@fsnavigator.com

MSXML 4.0 SP2 and SOAP Toolkit 3.0 1.0.0.0 ({32343DB6-9A52-40C9-87E4-5E7C79791C87})
version: 16777216
version (major): 1
estimated size: 676
install date: 20081019
install location: C:\Program Files\
install source: C:\Program Files\Webroot\WebrootSecurity\
uninstall cmd: MsiExec.exe /I{32343DB6-9A52-40C9-87E4-5E7C79791C87}
publisher: Webroot Software, Inc.

Java(TM) 6 Update 7 1.6.0.70 ({3248F0A8-6813-11D6-A77B-00B0D0160070})
version: 17170432
version (major): 1
version (minor): 6
estimated size: 117050
install date: 20080919
install source: http://javadl.sun.com/webapps/download/GetFile/1.6.0_07-b06/windows-i586/
uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
publisher: Sun Microsystems, Inc.
contact: http://java.com
help link: http://java.com
readme: C:\Program Files\Java\jre1.6.0_07\README.txt

NVIDIA CUDA SDK 0.81 ({340F4261-6F01-4A25-BC9D-13FEE3C3AC56})
version: 5308416
install location: C:\Program Files\NVIDIA Corporation\NVIDIA CUDA SDK
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{340F4261-6F01-4A25-BC9D-13FEE3C3AC56}\setup.exe" -l0x9

WebFldrs XP 9.50.7523 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227})
version: 154279267
version (major): 9
version (minor): 50
estimated size: 2472
install date: 20080904
install source: C:\WINDOWS\system32\
publisher: Microsoft Corporation
help link: http://www.microsoft.com/windows

Oblivion 1.00.0000 ({35CB6715-41F8-4F99-8881-6FC75BF054B0})
version: 16777216
install date: 20080921
install location: C:\Program Files\Bethesda Softworks\Oblivion
install source: E:\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe" -l0x9 -removeonly
publisher: Bethesda Softworks
comments: The Elder Scrolls IV: Oblivion
help link: http://support.bethsoft.com
readme: C:\Program Files\Bethesda Softworks\Oblivion\readme.txt

JMB36X Raid Configurer 1.00.0000 ({3A1B5D40-41E9-43FA-8C7B-A8667F5586EF})
version: 16777216
install date: 20080904
install location: C:\Program Files\JMICRON Technology Corp.\JMB36X Raid Configurer
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\abit\Drivers\JMB36X\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}\setup.exe" -l0x9 -removeonly
publisher: JMICRON Technology Corp.

Spy Sweeper Core 4.2.0.125 ({3F5B6210-0903-4DC6-8034-8F488AA3A782})
version: 67239936
version (major): 4
version (minor): 2
estimated size: 7252
install date: 20081019
install location: C:\Program Files\Webroot\WebrootSecurity\
install source: C:\Program Files\Webroot\WebrootSecurity\
uninstall cmd: MsiExec.exe /I{3F5B6210-0903-4DC6-8034-8F488AA3A782}
publisher: Webroot Software

Symantec Technical Support Controls 3.5.3 ({45690715-80A6-4445-B61D-ADEC5888E8CD})
version: 50659331
version (major): 3
version (minor): 5
estimated size: 9558
install date: 20080905
install location: C:\Program Files\Norton 360 Premier Edition\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\SuppSoft\
uninstall cmd: MsiExec.exe /I{45690715-80A6-4445-B61D-ADEC5888E8CD}
publisher: Symantec Corporation

Microsoft Flight Simulator X Service Pack 2 10.0.61472.0 ({4847BBB9-EADD-4C92-90BF-4223B0892FF6})
version: 167833632
version (major): 10
estimated size: 632042
install date: 20080920
install location: C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\
install source: C:\Documents and Settings\Fredo\Local Settings\Temporary Internet Files\Content.IE5\JI0ZX0BZ\
uninstall cmd: MsiExec.exe /X{4847BBB9-EADD-4C92-90BF-4223B0892FF6}
publisher: Microsoft Game Studios
help link: http://www.fsinsider.com/Pages/default.aspx
readme: C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\readme.htm

O&O Defrag Professional Edition 10.0.1634 ({53480330-E1D1-41CA-B8F8-7F78644F7F50})
version: 167773794
version (major): 10
estimated size: 21483
install date: 20080910
install location: C:\Program Files\OO Software\Defrag Professional\
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\O&O Defrag Professional\
uninstall cmd: MsiExec.exe /I{53480330-E1D1-41CA-B8F8-7F78644F7F50}
publisher: O&O Software GmbH
comments: Windows 2000/XP/2003/Vista Defragmentation Software
contact: support@oo-software.com
help link: http://www.oo-software.com
help telephone: +49 - (030) 4303 4300
readme: C:\Program Files\OO Software\Defrag Professional\Readme.txt

Norton Confidential Core 2.6.0.3 ({55A6283C-638A-4EE0-B491-51118554BDA2})
version: 33947648
version (major): 2
version (minor): 6
estimated size: 14954
install date: 20080905
install location: C:\Program Files\Norton 360 Premier Edition\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\NCO\
uninstall cmd: MsiExec.exe /I{55A6283C-638A-4EE0-B491-51118554BDA2}
publisher: Symantec Corporation

neroxml 1.0.0 ({56C049BE-79E9-4502-BEA7-9754A3E60F9B})
version: 16777216
version (major): 1
estimated size: 3795
install date: 20080908
install source: D:\CDS\Nero\Installation\Redist\
uninstall cmd: MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
publisher: Nero AG
contact: Nero AG

({582876EC-A178-44D4-9823-C10D6C62EAFF})
uninstall cmd: MsiExec /X{A7E07C2B-2220-4415-87E3-784D5814BC93}

Windows Live Beta (all programs) 14.0.5025.904 ({5D4A033A-A286-44BE-A0F0-B05FAC25D07F})
version: 234886049
version (major): 14
estimated size: 1074
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\4b141c01c91ab8\
uninstall cmd: MsiExec.exe /I{5D4A033A-A286-44BE-A0F0-B05FAC25D07F}
publisher: Microsoft Corporation
help link: http://support.live.com/

LG ODD Auto Firmware Update 6.01.0723.01 ({6179550A-3E7C-499E-BCC9-9E8113E0A285})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6179550A-3E7C-499E-BCC9-9E8113E0A285}\setup.exe"

Logitech Gaming Software 5.02 5.02.116 ({64B20B36-AEE7-4DD4-897C-C5DA5C218F60})
version: 84017268
version (major): 5
version (minor): 2
estimated size: 12683
install date: 20081017
install location: C:\Program Files\Logitech\Gaming Software\
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\pft4B.tmp\
uninstall cmd: MsiExec.exe /X{64B20B36-AEE7-4DD4-897C-C5DA5C218F60}
publisher: Logitech
contact: Customer Support
help link: http://www.logitech.com/support
help telephone: +1 702-269-3457

Microsoft XML Parser 8.0.8308.1 ({68E1BAC6-F79F-43C4-AF03-A89F53F748D3})
version: 134226036
version (major): 8
estimated size: 788
install date: 20080916
install source: C:\Program Files\U-ABIT\uGuru\
publisher: Microsoft Corporation

MSXML 4.0 SP2 Parser and SDK 4.20.9818.0 ({716E0306-8318-4364-8B8F-0CC4E9376BAC})
version: 68429402
version (major): 4
version (minor): 20
estimated size: 1258
install date: 20080910
install source: E:\
uninstall cmd: MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
publisher: Microsoft Corporation
help link: http://www.msdn.microsoft.com/xml

Microsoft Visual C++ 2005 Redistributable 8.0.56336 ({7299052b-02a4-4627-81f2-1818da5d550d})
version: 134274064
version (major): 8
estimated size: 5330
install date: 20080905
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
publisher: Microsoft Corporation

Solstice 1.24.00 ({7447292F-C0D3-431C-9B6B-DD1B82CF5261})
version: 18350080
version (major): 1
version (minor): 24
estimated size: 2567762
install date: 20080920
install location: c:\Program Files\Outspark\Solstice\
install source: c:\Documents and Settings\Fredo\Local Settings\Application Data\Downloaded Installations\{73FA3F2A-287F-4C68-95D8-DB712369CFC1}\
uninstall cmd: MsiExec.exe /X{7447292F-C0D3-431C-9B6B-DD1B82CF5261}
publisher: Outspark
contact: support@outspark.com
help link: http://support.outspark.com

Spy Sweeper 6.0 ({76F8CB2B-6516-4E1E-B6F1-AED4ABDB4B0A}_is1)
install date: 20081019
install location: C:\Program Files\Webroot\WebrootSecurity\
uninstall cmd: "C:\Program Files\Webroot\WebrootSecurity\unins000.exe"
publisher: Webroot Software, Inc.

SPBBC 32bit 4.1.0.15 ({77772678-817F-4401-9301-ED1D01A8DA56})
version: 67174400
version (major): 4
version (minor): 1
estimated size: 4417
install date: 20080905
install location: C:\Program Files\Norton 360 Premier Edition\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\SPBBC\
uninstall cmd: MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
publisher: Symantec Corporation

Acrobat.com 0.0.0 ({77DCDCE3-2DED-62F3-8154-05E745472D07})
estimated size: 1623
install date: 20080919
install source: C:\Documents and Settings\Fredo\Local Settings\Temp\fla188.tmp\
uninstall cmd: MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
publisher: Adobe Systems Incorporated

Windows Live Call 14.0.5023.0902 ({78AC782A-C708-4B21-A3A0-ECD4A3284588})
version: 234886047
version (major): 14
estimated size: 1718
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\e21ff61c91ab8\
uninstall cmd: MsiExec.exe /I{78AC782A-C708-4B21-A3A0-ECD4A3284588}
publisher: Microsoft Corporation

NVIDIA nTune 1.00.0000 ({7C7F30F4-94E7-4AA8-8941-90C4A80C68BF})
version: 16777216
version (major): 1
estimated size: 37599
install date: 20080924
install location: C:\Program Files\NVIDIA Corporation\
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\_is39\
publisher: NVIDIA Corporation
comments: Your Comments
contact: Customer Support Department
help link: http://www.yourcompany.com/help
help telephone: 1-408-486-0000

3DMark06 1.1.0 ({7F3AD00A-1819-4B15-BB7D-08B3586336D7})
version: 16842752
install date: 20080921
install location: C:\Program Files\Futuremark\3DMark06
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\bye1.tmp\Disk1\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F3AD00A-1819-4B15-BB7D-08B3586336D7}\setup.exe" -l0x9 -removeonly
publisher: Futuremark
help link: http://www.futuremark.com

Windows Live Sign-in Assistant 5.000.744.4 ({8984E374-6C93-427C-A3B9-AD92472FDCA0})
version: 83886824
version (major): 5
estimated size: 1945
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\2cfa6bc1c91ab8\
uninstall cmd: MsiExec.exe /I{8984E374-6C93-427C-A3B9-AD92472FDCA0}
publisher: Microsoft Corporation

Microsoft Silverlight 1.0.30716.0 ({89F4137D-6C26-4A84-BDB8-2E5A4BB71E00})
version: 16807932
version (major): 1
estimated size: 1328
install date: 20080919
install source: c:\7bea3e042c78aa69ac0335f2\
uninstall cmd: MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkID=91955

Microsoft Software Update for Web Folders (English) 12 12.0.6215.1000 ({90120000-0010-0409-0000-0000000FF1CE})
version: 201332807
version (major): 12
estimated size: 14675
install date: 20080905
install source: C:\MSOCache\All Users\{90120000-0010-0409-0000-0000000FF1CE}-C\
publisher: Microsoft Corporation

Microsoft Office Excel MUI (English) 2007 12.0.6215.1000 ({90120000-0016-0409-0000-0000000FF1CE})
version: 201332807
version (major): 12
estimated size: 37740
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-0016-0409-0000-0000000FF1CE}-C\
uninstall cmd: MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59})
uninstall cmd: msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office PowerPoint MUI (English) 2007 12.0.6215.1000 ({90120000-0018-0409-0000-0000000FF1CE})
version: 201332807
version (major): 12
estimated size: 15521
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-0018-0409-0000-0000000FF1CE}-C\
uninstall cmd: MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59})
uninstall cmd: msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office Outlook MUI (English) 2007 12.0.6215.1000 ({90120000-001A-0409-0000-0000000FF1CE})
version: 201332807
version (major): 12
estimated size: 22840
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-001A-0409-0000-0000000FF1CE}-C\
uninstall cmd: MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59})
uninstall cmd: msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office Word MUI (English) 2007 12.0.6215.1000 ({90120000-001B-0409-0000-0000000FF1CE})
version: 201332807
version (major): 12
estimated size: 18657
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-001B-0409-0000-0000000FF1CE}-C\
uninstall cmd: MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59})
uninstall cmd: msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office Proof (English) 2007 12.0.6213.1000 ({90120000-001F-0409-0000-0000000FF1CE})
version: 201332805
version (major): 12
estimated size: 56807
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.en\
uninstall cmd: MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{3EC77D26-799B-4CD8-914F-C1565E796173})
uninstall cmd: msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office Proof (French) 2007 12.0.6213.1000 ({90120000-001F-040C-0000-0000000FF1CE})
version: 201332805
version (major): 12
estimated size: 23736
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\
uninstall cmd: MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{430971B1-C31E-45DA-81E0-72C095BAB72C})
uninstall cmd: msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office Proof (Spanish) 2007 12.0.6213.1000 ({90120000-001F-0C0A-0000-0000000FF1CE})
version: 201332805
version (major): 12
estimated size: 38517
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.es\
uninstall cmd: MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1})
uninstall cmd: msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office Proofing (English) 2007 12.0.4518.1014 ({90120000-002C-0409-0000-0000000FF1CE})
version: 201331110
version (major): 12
estimated size: 506
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\
uninstall cmd: MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

Microsoft Office Shared MUI (English) 2007 12.0.6215.1000 ({90120000-006E-0409-0000-0000000FF1CE})
version: 201332807
version (major): 12
estimated size: 37082
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-0115-0409-0000-0000000FF1CE}-C\
uninstall cmd: MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{FAD8A83E-9BAC-4179-9268-A35948034D85})
uninstall cmd: msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office Shared Setup Metadata MUI (English) 2007 12.0.6215.1000 ({90120000-0115-0409-0000-0000000FF1CE})
version: 201332807
version (major): 12
estimated size: 502
install date: 20080905
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{90120000-0115-0409-0000-0000000FF1CE}-C\
uninstall cmd: MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{FAD8A83E-9BAC-4179-9268-A35948034D85})
uninstall cmd: msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Microsoft Office Standard 2007 12.0.6215.1000 ({91120000-0012-0000-0000-0000000FF1CE})
version: 201332807
version (major): 12
estimated size: 742311
install date: 20081016
install location: C:\Program Files\Microsoft Office\
install source: C:\MSOCache\All Users\{91120000-0012-0000-0000-0000000FF1CE}-C\
uninstall cmd: MsiExec.exe /X{91120000-0012-0000-0000-0000000FF1CE}
publisher: Microsoft Corporation

Security Update for 2007 Microsoft Office System (KB955936) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{1D94099C-2BBA-440E-BD5E-093BBDF8F028})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {1D94099C-2BBA-440E-BD5E-093BBDF8F028}
publisher: Microsoft
help link: http://support.microsoft.com/kb/955936

Update for Microsoft Office Outlook 2007 (KB952142) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{4AD3A076-427C-491F-A5B7-7D1DE788A756})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
publisher: Microsoft
help link: http://support.microsoft.com/kb/952142

Security Update for Microsoft Office PowerPoint 2007 (KB951338) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{558B709B-821B-4FC5-90FC-9A8890641E77})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
publisher: Microsoft
help link: http://support.microsoft.com/kb/951338

Security Update for Microsoft Office system 2007 (KB954326) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{5F7F6FFF-395D-480E-8450-64F385D82C5F})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
publisher: Microsoft
help link: http://support.microsoft.com/kb/954326

Security Update for Microsoft Office Excel 2007 (KB955470) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E8637D8-10D6-4568-AA06-E2706F31685E})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {6E8637D8-10D6-4568-AA06-E2706F31685E}
publisher: Microsoft
help link: http://support.microsoft.com/kb/955470

Security Update for 2007 Microsoft Office System (KB951944) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{797AE457-BA17-4BBC-B501-25FB3A0103C7})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
publisher: Microsoft
help link: http://support.microsoft.com/kb/951944

Security Update for Microsoft Office system 2007 (KB951808) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{8F375E11-4FD6-4B89-9E2B-A76D48B51E00})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
publisher: Microsoft
help link: http://support.microsoft.com/kb/951808

Update for Office 2007 (KB946691) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{A420F522-7395-4872-9882-C591B4B92278})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
publisher: Microsoft
help link: http://support.microsoft.com/kb/946691

Security Update for Microsoft Office Word 2007 (KB950113) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{AD72BABE-C733-4FCF-9674-4314466191B9})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
publisher: Microsoft
help link: http://support.microsoft.com/kb/950113

2007 Microsoft Office Suite Service Pack 1 (SP1) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
publisher: Microsoft
help link: http://support.microsoft.com/kb/936982

Update for Outlook 2007 Junk Email Filter (kb957258) ({91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{E070CDA4-A8DD-47FA-89A0-F5DA5D5DDFF9})
uninstall cmd: msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {E070CDA4-A8DD-47FA-89A0-F5DA5D5DDFF9}
publisher: Microsoft
help link: http://support.microsoft.com/kb/957258

Microsoft Application Error Reporting 12.0.6012.5000 ({95120000-00B9-0409-0000-0000000FF1CE})
version: 201332604
version (major): 12
estimated size: 7271
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\f8910c041c91ab7\
publisher: Microsoft Corporation
help link: http://support.microsoft.com

Microsoft Flight Simulator X 10.0.61355.0 ({9527A496-5DF9-412A-ADC7-168BA5379CA6})
version: 167833515
version (major): 10
estimated size: 13616545
install date: 20080920
install source: E:\
uninstall cmd: MsiExec.exe /X{9527A496-5DF9-412A-ADC7-168BA5379CA6}
publisher: Microsoft Game Studios
comments: Copyright © 2006 Microsoft Corporation

Fredo_P
2008-10-20, 01:45
PMDG747_400 Queen of the Skies 1.10.0000 ({97679567-0095-464E-B5F2-E218A1CF3421})
version: 17432576
install date: 20080910
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\bye1.tmp\Disk1\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{97679567-0095-464E-B5F2-E218A1CF3421}\setup.exe" -l0x9 -removeonly
publisher: Precision Manuals Development Group
contact: support@precisionmanuals.com
help link: http://www.precisionmanuals.com
help telephone: Telephone Support Not Available

KMSP v1.1.1 for FS2004 1.1.1 ({98297A57-368B-4FC3-A236-5BDEBB0C3702})
version: 16842753
version (major): 1
version (minor): 1
estimated size: 208441
install date: 20080908
install location: C:\Program Files\Microsoft Games\Flight Simulator 9\BluePrint Simulations\KMSP\
install source: D:\BluePrint Simulations - KMSP v1.1.1 (FS9)\
uninstall cmd: MsiExec.exe /I{98297A57-368B-4FC3-A236-5BDEBB0C3702}
publisher: BluePrint Simulations
comments: This installer database contains the logic and data required to install KMSP v1.1.1 for FS2004.
contact: support@blueprintsimulations.com
help link: http://www.blueprintsimulations.com

Microsoft .NET Framework 3.0 3.0.04506.30 ({9DE9E293-5D7B-4312-88C2-BDFAEC5310AE})
version: 50336154
version (major): 3
estimated size: 16302
install date: 20080920
install location: C:\WINDOWS\Microsoft.NET\Framework\v3.0\
install source: C:\Documents and Settings\Fredo\Local Settings\Temp\SIT34769.tmp\
publisher: Microsoft Corporation

Windows Defender 1.1.1593.21 ({A06275F4-324B-4E85-95E6-87B2CD729401})
version: 16844345
version (major): 1
version (minor): 1
estimated size: 8982
install date: 20081019
install source: C:\Documents and Settings\Fredo\Local Settings\Temporary Internet Files\Content.IE5\7DPKOSH9\
uninstall cmd: MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=55273

Segoe UI 14.0.4327.805 ({A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7})
version: 234885351
version (major): 14
estimated size: 1060
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\fed338441c91ab7\
uninstall cmd: MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
publisher: Microsoft Corp

Microsoft .NET Framework 3.0 Service Pack 2 3.2.30729 ({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7})
version: 50493449
version (major): 3
version (minor): 2
estimated size: 199849
install date: 20080905
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\dotnetfx3530729.01\1033\dotnetfx30\
uninstall cmd: MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=98075

Microsoft Visual C++ 2005 Redistributable 8.0.50727.42 ({A49F249F-0C91-497F-86DF-B2585E8E76B7})
version: 134268455
version (major): 8
estimated size: 4584
install date: 20080910
install source: C:\FSXTMP\
uninstall cmd: MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
publisher: Microsoft Corporation

NVIDIA PhysX v8.09.04 8.09.04 ({A7E07C2B-2220-4415-87E3-784D5814BC93})
version: 134807556
version (major): 8
version (minor): 9
estimated size: 135249
install date: 20081010
install location: C:\DOCUME~1\Fredo\LOCALS~1\Temp\
install source: C:\Program Files\Common Files\Wise Installation Wizard\
uninstall cmd: MsiExec.exe /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
publisher: NVIDIA Corporation
comments: PhysX Driver & Engines: 2.3.1/2/3; 2.4.0/1/4; 2.5.0/1/2/3/4; 2.6.0/1/2/3/4; 2.7.0/1/2/3/4/5/6; 2.8.0/1
help link: www.NVIDIA.com

Intel(R) Processor ID Utility 3.9.0000 ({A92A4DB0-CD37-42D1-BE1D-603D53C24328})
version: 50921472
version (major): 3
version (minor): 9
estimated size: 3852
install date: 20080917
install location: C:\Program Files\Intel Corporation\Intel Processor ID Utility\
install source: D:\
uninstall cmd: MsiExec.exe /X{A92A4DB0-CD37-42D1-BE1D-603D53C24328}
publisher: Intel(R) Corporation

Windows Live Writer 14.0.5025.0904 ({AC5568AB-C3E3-490E-BE40-50977C12288D})
version: 234886049
version (major): 14
estimated size: 14069
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\2111def61c91ab8\
uninstall cmd: MsiExec.exe /X{AC5568AB-C3E3-490E-BE40-50977C12288D}
publisher: Microsoft Corporation

Adobe Reader 9 9.0.0 ({AC76BA86-7AD7-1033-7B44-A90000000001})
version: 150994944
version (major): 9
estimated size: 209258
install date: 20080919
install location: C:\Program Files\Adobe\Reader 9.0\Reader\
install source: C:\Documents and Settings\Fredo\Local Settings\Application Data\Adobe\Reader 9.0\Setup Files\READER9\
uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
publisher: Adobe Systems Incorporated
comments:
contact: Customer Support
help link: http://www.adobe.com/support/main.html
readme: C:\Program Files\Adobe\Reader 9.0\Readme.htm

REALTEK GbE & FE Ethernet PCI NIC Driver 1.17.0001 ({ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730})
version: 17891329
install date: 20080922
install location: C:\WINDOWS\OPTIONS\CABS\
install source: C:\Documents and Settings\Fredo\Desktop\Extracted\PCI_Install_5699_0828\
uninstall cmd: C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe -runfromtemp -l0x0009 -removeonly
publisher: Realtek

NVIDIA CUDA Toolkit 0.80.0000 ({AF68235B-7FA7-4B91-AD10-C22867154174})
version: 5242880
install location: C:\CUDA
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AF68235B-7FA7-4B91-AD10-C22867154174}\setup.exe" -l0x9

Windows Live Messenger 14.0.5027.0908 ({B1403D7D-C725-4858-AACC-7E5FA2D72859})
version: 234886051
version (major): 14
estimated size: 41856
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\133633d61c91ab8\
uninstall cmd: MsiExec.exe /X{B1403D7D-C725-4858-AACC-7E5FA2D72859}
publisher: Microsoft Corporation

ccCommon 107.0.5.5 ({B24E05CC-46FF-4787-BBB8-5CD516AFB118})
version: 1795162117
version (major): 107
estimated size: 9326
install date: 20080905
install location: C:\Program Files\Common Files\Symantec Shared\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\ccCommon\
uninstall cmd: MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
publisher: Symantec

Spybot - Search & Destroy 1.6.0 ({B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1)
install date: 20081018
install location: C:\Program Files\Spybot - Search & Destroy\
uninstall cmd: "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
publisher: Safer Networking Limited
help link: http://www.safer-networking.org/index.php?page=support

Outspark Sharp Launcher 1.69.00 ({B5560986-7A6A-4CCA-A808-853D2CED3796})
version: 21299200
version (major): 1
version (minor): 69
estimated size: 3218
install date: 20081018
install location: C:\Program Files\Outspark\SharpLauncher\
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\{837647DF-A372-4056-AF3D-F6F4703CBB90}\{C66519E7-2769-48FF-BC0D-50553EA8A0CB}\
uninstall cmd: MsiExec.exe /X{B5560986-7A6A-4CCA-A808-853D2CED3796}
publisher: Outspark

PowerProducer ({B7A0CE06-068E-11D6-97FD-0050BACBF861})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall

({BB8B979E-E336-47E7-96BC-1031C1B94561})

Netflix Movie Viewer 1.2.211 ({BCE72AED-3332-4863-9567-C5DCB9052CA2})
version: 16908499
version (major): 1
version (minor): 2
estimated size: 1564
install date: 20080919
install location: C:\Program Files\Netflix\Netflix Movie Viewer\
install source: C:\Documents and Settings\Fredo\Local Settings\Temporary Internet Files\Content.IE5\JI0ZX0BZ\
uninstall cmd: MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}
publisher: Netflix
comments: Netflix Movie Viewer
contact: Netflix Customer Service
help link: www.netflix.com/Help

SecurDisc Viewer 7.03.0749 ({BE90CE58-41DE-4708-9291-A9D1D49B1033})
version: 117637869
version (major): 7
version (minor): 3
estimated size: 12963
install date: 20080908
install location: C:\Program Files\Nero\Nero 7\
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\NERO14225\
uninstall cmd: MsiExec.exe /X{BE90CE58-41DE-4708-9291-A9D1D49B1033}
publisher: Nero AG
comments: Nero AG
contact: techsupport@nero.com retail-support@nero.com chinese-techsupport@nero.com
help link: techsupport@nero.com retail-support@nero.com chinese-techsupport@nero.com
help telephone: xxxxxxxxxxxxxx

MSXML 4.0 SP2 (KB936181) 4.20.9848.0 ({C04E32E0-0416-434D-AFB9-6969D703A9EF})
version: 68429432
version (major): 4
version (minor): 20
estimated size: 2680
install date: 20080919
install source: c:\f1c6fc250b7cd6ddd53a\
uninstall cmd: MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/936181

Microsoft .NET Framework 2.0 Service Pack 2 2.2.30729 ({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F})
version: 33716233
version (major): 2
version (minor): 2
estimated size: 309193
install date: 20080905
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\dotnetfx3530729.01\1033\dotnetfx20\
uninstall cmd: MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=98073

Contacts 14.0.5027.908 ({C6BDA6E5-B391-4CE5-8D86-B53AC96FFE03})
version: 234886051
version (major): 14
estimated size: 1940
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\fcde8a701c91ab7\
uninstall cmd: MsiExec.exe /I{C6BDA6E5-B391-4CE5-8D86-B53AC96FFE03}
publisher: Microsoft Corporation

ActiveSky v6.5 6.05.0001 ({C6CE0096-B666-43ED-9428-022A209C7EF0})
version: 100990977
version (major): 6
version (minor): 5
estimated size: 263554
install date: 20080920
install location: C:\Program Files\Microsoft Games\Flight Simulator 9\
install source: C:\WINDOWS\Downloaded Installations\{CB3D505F-A138-418A-AB61-710EF43EF22B}\
uninstall cmd: MsiExec.exe /I{C6CE0096-B666-43ED-9428-022A209C7EF0}
publisher: HiFi
comments: Contact: www.hifisim.com
contact: Customer Support Department
help link: http://www.yourcompany.com/help
help telephone: 1-555-555-4505

Microsoft .NET Framework 1.1 1.1.4322 ({CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1})
version: 16847074
version (major): 1
version (minor): 1
estimated size: 68956
install date: 20080920
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
publisher: Microsoft
readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm

GearDrvs 1.00.0000 ({CB84F0F2-927B-458D-9DC5-87832E3DC653})
version: 16777216
version (major): 1
estimated size: 1324
install date: 20081016
install location: C:\Program Files\GEAR Software\My Product Name\
install source: C:\WINDOWS\system32\
uninstall cmd: MsiExec.exe /I{CB84F0F2-927B-458D-9DC5-87832E3DC653}
publisher: GEAR Software

WinZip 11.2 11.2.8094 ({CD95F661-A5C4-44F5-A6AA-ECDD91C240B6})
version: 184688542
version (major): 11
version (minor): 2
estimated size: 12082
install date: 20080905
install location: C:\Program Files\WinZip\
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\WZSE0.TMP\
uninstall cmd: MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}
publisher: WinZip Computing, S.L.
help link: http://www.winzip.com/wzgate.cgi?lang=EN&url=www.winzip.com/contact.htm

Microsoft .NET Framework 3.5 SP1 3.5.30729 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9})
version: 50690057
version (major): 3
version (minor): 5
estimated size: 66544
install date: 20080905
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\IXP0210D.tmp\dotnetfx35\x86\
uninstall cmd: MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
publisher: Microsoft Corporation

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) 1 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595)
uninstall cmd: C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
publisher: Microsoft Corporation
comments: This hotfix is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this hotfix will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/953595.
help link: http://support.microsoft.com/kb/953595

Symantec Real Time Storage Protection Component 10.2.3.9 ({D6E6FA4A-5445-4850-8365-CF216C1CBB7A})
version: 167903235
version (major): 10
version (minor): 2
estimated size: 1595
install date: 20080905
install location: C:\Program Files\Common Files\Symantec Shared\SRTSP\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\SRTSP\
uninstall cmd: MsiExec.exe /I{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}
publisher: Symantec Corporation

Windows Live Mail 14.0.5027.0908 ({DFD6935E-D94A-4DBE-AD8F-E37CBC6B577F})
version: 234886051
version (major): 14
estimated size: 32859
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\1cb14dba1c91ab8\
uninstall cmd: MsiExec.exe /I{DFD6935E-D94A-4DBE-AD8F-E37CBC6B577F}
publisher: Microsoft Corporation

LiveUpdate (Symantec Corporation) 3.4.1.238 ({E80F62FF-5D3C-4A19-8409-9721F2928206})
version: 50593793
version (major): 3
version (minor): 4
estimated size: 10410
install date: 20080905
install location: C:\Program Files\Symantec\LiveUpdate
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\LUpdate\
uninstall cmd: MsiExec.exe /X{E80F62FF-5D3C-4A19-8409-9721F2928206}
publisher: Symantec Corporation

Choice Guard 1.1.69.0 ({EBD5E7A9-DBB8-4E24-AE3A-CF9390AF1CCB})
version: 16842821
version (major): 1
version (minor): 1
estimated size: 186
install date: 20080919
install source: C:\Program Files\Common Files\Windows Live\.cache\65c06ae1c91ab8\
uninstall cmd: MsiExec.exe /I{EBD5E7A9-DBB8-4E24-AE3A-CF9390AF1CCB}
publisher: Microsoft Corporation

Nero 7 Essentials 7.03.1055 ({EF3E420F-2DCF-4C24-8E37-896801901033})
version: 117638175
version (major): 7
version (minor): 3
estimated size: 295248
install date: 20080908
install location: C:\Program Files\Nero\Nero 7\
install source: D:\CDS\Nero\Installation\
uninstall cmd: MsiExec.exe /X{EF3E420F-2DCF-4C24-8E37-896801901033}
publisher: Nero AG
comments: Nero AG
contact: techsupport@nero.com retail-support@nero.com chinese-techsupport@nero.com
help link: techsupport@nero.com retail-support@nero.com chinese-techsupport@nero.com
help telephone: xxxxxxxxxxxxxx

AppCore 2.0.0.79 ({EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B})
version: 33554432
version (major): 2
estimated size: 708
install date: 20080905
install location: C:\Program Files\Common Files\Symantec Shared\AppCore\
install source: C:\Documents and Settings\Fredo\Application Data\Symantec\Layouts\Norton 360\2.0\English\BB8C1A11EC10591CC4684E3F2F19E6A3BBA29869\20080226\Support\AppCore\
uninstall cmd: MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
publisher: Symantec Corporation

Realtek High Definition Audio Driver 5.10.0.5643 ({F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC})
version: 37486592
install date: 20080916
install location: C:\Program Files\Realtek\Audio\InstallShield\
install source: C:\Documents and Settings\Fredo\Desktop\Extracted\WDM_R196\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
publisher: Realtek Semiconductor Corp.

SymNet 8.0.2.6 ({FAF3E37C-F15A-4B9E-8262-748091069E9D})
version: 134217730
version (major): 8
estimated size: 1651
install date: 20080905
install location: C:\Program Files\Common Files\Symantec Shared\SymNetDrv\
install source: C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\Updt91\
publisher: Symantec Corporation

MSXML 6.0 Parser (KB925673) 6.00.3888.0 ({FE9126DB-5F84-495A-BB46-3C724F1C2D08})
version: 100667184
version (major): 6
estimated size: 1496
install date: 20080920
install source: C:\DOCUME~1\Fredo\LOCALS~1\Temp\dotnetfx304506.30\1033\wcu\msxml\
uninstall cmd: MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/925673

abti uGuru 3.1.0.5 ({FF8500E6-EA0D-11D7-8755-0080C8F92A32})
version: 50397184
install date: 20080916
install location: C:\Program Files\U-ABIT
install source: C:\Documents and Settings\Fredo\Desktop\Extracted\3.109\
uninstall cmd: C:\Program Files\InstallShield Installation Information\{FF8500E6-EA0D-11D7-8755-0080C8F92A32}\setup.exe -runfromtemp -l0x0009 -removeonly
publisher: U-ABIT

FSacars 4.0 ({FFC78FC9-2FE6-4648-BFEB-446C61C2D61E})
version: 67108864
version (major): 4
estimated size: 4128
install date: 20080919
install source: C:\Documents and Settings\Fredo\Local Settings\Temp\wz0b33\
uninstall cmd: MsiExec.exe /I{FFC78FC9-2FE6-4648-BFEB-446C61C2D61E}
publisher: Jose Oliveira/FSacars team
comments: ACARS and Log System
contact: Jose Oliveira/FSacars team
help link: Fsacars@satavirtual.org



--- System Services ---
Service (registry key): .NET CLR Data
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET CLR Networking
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET Data Provider for Oracle
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET Data Provider for SqlServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NETFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Abiosdsk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): abp480n5
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ACPI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft ACPI Driver
Image path: system32\DRIVERS\ACPI.sys
Image size: 187776
Image MD5: 8FD99680A539792A30E97944FDAECF17
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ACPIEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): adpu160m
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): aec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Acoustic Echo Canceller
Image path: system32\drivers\aec.sys
Image size: 142592
Image MD5: 8BED39E3C35D6A489438B8141717A557
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): AFD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AFD
Description: AFD Networking Support Environment
Image path: \SystemRoot\System32\drivers\afd.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): Aha154x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): aic78u2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): aic78xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Alerter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Alerter
Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): ALG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Layer Gateway Service
Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\alg.exe
Image size: 44544
Image MD5: 8C515081584A38AA007909CD02020B3D
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): AliIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): amsint
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): AppMgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Management
Description: Provides software installation services such as Assign, Publish, and Remove.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): Arp1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 ARP Client Protocol
Description: 1394 ARP Client Protocol
Image path: system32\DRIVERS\arp1394.sys
Image size: 60800
Image MD5: B5B8A80875C1DEDEDA8B02765642C32F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): asc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): asc3350p
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): asc3550
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ASP.NET
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ASP.NET_1.1.4322
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ASP.NET_2.0.50727
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): aspnet_state
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ASP.NET State Service
Description: Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
Image size: 34312
Image MD5: 0E5E4957549056E2BF2C49F4F6B601AD
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): AsyncMac
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: RAS Asynchronous Media Driver
Description: RAS Asynchronous Media Driver
Image path: system32\DRIVERS\asyncmac.sys
Image size: 14336
Image MD5: B153AFFAC761E7F5FCFA822B9C4E97BC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): atapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Standard IDE/ESDI Hard Disk Controller
Image path: system32\DRIVERS\atapi.sys
Image size: 96512
Image MD5: 9F3A2F5AA6875C72BF062C712CFA2674
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Atdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): Atmarpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ATM ARP Client Protocol
Description: ATM ARP Client Protocol
Image path: system32\DRIVERS\atmarpc.sys
Image size: 59904
Image MD5: 9916C1225104BA14794209CFA8012159
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): AudioSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Audio
Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs

Service (registry key): audstub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Audio Stub Driver
Image path: system32\DRIVERS\audstub.sys
Image size: 3072
Image MD5: D9F724AA26C010A217C97606B160ED68
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Automatic LiveUpdate Scheduler
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Automatic LiveUpdate Scheduler
Description: Manages the scheduling of Automatic LiveUpdate sessions
Object name: LocalSystem
Image path: "C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe"
Image size: 238968
Image MD5: AE9560C298D847AEF346BDD5FAD3B0E3
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0

Service (registry key): BattC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Beep
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): BITS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Background Intelligent Transfer Service
Description: Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Rpcss

Service (registry key): Bridge
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MAC Bridge
Image path: system32\DRIVERS\bridge.sys
Image size: 71552
Image MD5: F934D1B230F84E1D19DD00AC5A7A83ED
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): BridgeMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MAC Bridge Miniport
Image path: system32\DRIVERS\bridge.sys
Image size: 71552
Image MD5: F934D1B230F84E1D19DD00AC5A7A83ED
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Browser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Computer Browser
Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,LanmanServer

Service (registry key): cbidf2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ccEvtMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Event Manager
Description: Event propagation and logging service
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
Image size: 149352
Image MD5: 0981902E0C29655FA8FA161247064907
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RPCSS,ccSetMgr

Service (registry key): ccSetMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Settings Manager
Description: Settings storage and management service
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
Image size: 149352
Image MD5: 0981902E0C29655FA8FA161247064907
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RPCSS

Service (registry key): cd20xrnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Cdaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): Cdfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Depends On group: "SCSI CDROM Class"

Service (registry key): Cdrom
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-ROM Driver
Image path: system32\DRIVERS\cdrom.sys
Image size: 62976
Image MD5: 1F4260CC5B42272D71F79E570A27A4FE
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"

Service (registry key): Changer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Fredo_P
2008-10-20, 01:48
Service (registry key): chdrvr01
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CH Control Manager Driver 1
Image path: system32\DRIVERS\chdrvr01.sys
Image size: 215104
Image MD5: AABFFD787AB272FC903AFEEB336C6899
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): chdrvr02
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CH Control Manager Driver 2
Image path: system32\DRIVERS\chdrvr02.sys
Image size: 3744
Image MD5: 7536FB70BCBF5D10B810E67E72F68137
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): chdrvr03
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CH Control Manager Driver 3
Image path: system32\DRIVERS\chdrvr03.sys
Image size: 9024
Image MD5: 07E3319E5BAE758CEB83C80419681B6A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): CiSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Indexing Service
Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
Object name: LocalSystem
Image path: %SystemRoot%\system32\cisvc.exe
Image size: 5632
Image MD5: 1CFE720EB8D93A7158A4EBC3AB178BDE
Control Set: CurrentControlSet
Start: 4
Type: 288
Error Control: 1
Depends On services: RPCSS

Service (registry key): ClipSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ClipBook
Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\clipsrv.exe
Image size: 33280
Image MD5: 34CBE729F38138217F9C80212A2A0C82
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: NetDDE

Service (registry key): clr_optimization_v2.0.50727_32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: .NET Runtime Optimization Service v2.0.50727_X86
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
Image size: 69632
Image MD5: D87ACAED61E417BBA546CED5E7E36D9C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0

Service (registry key): CLTNetCnService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Lic NetConnect service
Description: Symantec Lic NetConnect Service
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
Image size: 149352
Image MD5: 0981902E0C29655FA8FA161247064907
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0

Service (registry key): CmdIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): COH_Mon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COH_Mon
Image path: \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys
Image size: 23888
Image MD5: 6186B6B953BDC884F0F379B84B3E3A98
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): comHost
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM Host
Description: COM aggregation host service
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe"
Image size: 55640
Image MD5: 75A69CA9998577F8B2BE8695040E5DF4
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Depends On services: RpcSs

Service (registry key): COMSysApp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ System Application
Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Image size: 5120
Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: rpcss

Service (registry key): ContentFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ContentIndex
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): CO_Mon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CO_Mon
Image path: \??\C:\WINDOWS\system32\drivers\CO_Mon.sys
Image size: 36056
Image MD5: 73F5D6835BFA66019C03E316D99649DA
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1

Service (registry key): Cpqarray
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): CryptSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Cryptographic Services
Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): dac2w2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): dac960nt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): DcomLaunch
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DCOM Server Process Launcher
Description: Provides launch functionality for DCOM services.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost -k DcomLaunch
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): Dhcp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DHCP Client
Description: Manages network configuration by registering and updating IP addresses and DNS names.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd,NetBT

Service (registry key): Disk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Disk Driver
Image path: system32\DRIVERS\disk.sys
Image size: 36352
Image MD5: 044452051F3E02E7963599FC8F4F3E25
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"

Service (registry key): dmadmin
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager Administrative Service
Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops.
Object name: LocalSystem
Image path: %SystemRoot%\System32\dmadmin.exe /com
Image size: 224768
Image MD5: E46050330BD42F33609117F861E32D3C
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay,DmServer

Service (registry key): dmboot
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmboot.sys
Image size: 799744
Image MD5: D992FE1274BDE0F84AD826ACAE022A41
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): dmio
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmio.sys
Image size: 153344
Image MD5: 7C824CF7BBDE77D95C08005717A95F6F
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): dmload
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmload.sys
Image size: 5888
Image MD5: E9317282A63CA4D188C0DF5E09C6AC5F
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): dmserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager
Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay

Service (registry key): DMusic
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DLS Syntheiszer
Image path: system32\drivers\DMusic.sys
Image size: 52864
Image MD5: 8A208DFCF89792A484E76C40E5F50B45
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Dnscache
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DNS Client
Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip

Service (registry key): Dot3svc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wired AutoConfig
Description: This service performs IEEE 802.1X authentication on Ethernet interfaces
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k dot3svc
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Ndisuio,eaphost

Service (registry key): dpti2o
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): drmkaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DRM Audio Descrambler
Image path: system32\drivers\drmkaud.sys
Image size: 2944
Image MD5: 8F5FCFF8E8848AFAC920905FBD9D33C8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): EapHost
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Extensible Authentication Protocol Service
Description: Provides windows clients Extensible Authentication Protocol Service
Object name: localSystem
Image path: %SystemRoot%\System32\svchost.exe -k eapsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): eeCtrl
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Eraser Control driver
Image path: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
Image size: 371248
Image MD5: 47CE4E650D91DC095A2FDDB15631A78A
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: FltMgr

Service (registry key): ENTECH
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ENTECH
Image path: \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys
Image size: 21664
Image MD5: FD9FC82F134B1C91004FFC76A5AE494B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): EraserUtilRebootDrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: EraserUtilRebootDrv
Image path: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
Image size: 99376
Image MD5: CE3EF5C79CB0BFA036E844F74C52D759
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ERSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Error Reporting Service
Description: Allows error reporting for services and applictions running in non-standard environments.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 0
Depends On services: RpcSs

Service (registry key): Eventlog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Event Log
Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 108544
Image MD5: 0E776ED5F7CC9F94299E70461B7B8185
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): EventSystem
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ Event System
Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): Fastfat
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): FastUserSwitchingCompatibility
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Fast User Switching Compatibility
Description: Provides management for applications that require assistance in a multiple user environment.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: TermService

Service (registry key): Fdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Floppy Disk Controller Driver
Image path: system32\DRIVERS\fdc.sys
Image size: 27392
Image MD5: 92CDD60B6730B9F50F6A1A0C1F8CDC81
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Fips
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): Flpydisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Floppy Disk Driver
Image path: system32\DRIVERS\flpydisk.sys
Image size: 20480
Image MD5: 9D27E7B80BFCDF1CDD9B555862D5E7F0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): FltMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: FltMgr
Description: File System Filter Manager Driver
Image path: system32\drivers\fltmgr.sys
Image size: 129792
Image MD5: B2CF4B0786F8212CB92ED2B50C6DB6B0
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): FontCache3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Presentation Foundation Font Cache 3.0.0.0
Description: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
Object name: NT AUTHORITY\LocalService
Image path: C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
Image size: 46104
Image MD5: 8BA7C024070F2B7FDD98ED8A4BA41789
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): Fs_Rec
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 8
Error Control: 0

Service (registry key): Ftdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Manager Driver
Image path: system32\DRIVERS\ftdisk.sys
Image size: 125056
Image MD5: 6AC26732762483366C3969C9E4D2259D
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): GEARAspiWDM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: GEAR ASPI Filter Driver
Image path: System32\Drivers\GEARAspiWDM.sys
Image size: 15464
Image MD5: AB8A6A87D9D7255C3884D5B9541A6E80
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Gpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Generic Packet Classifier
Description: Generic Packet Classifier
Image path: system32\DRIVERS\msgpc.sys
Image size: 35072
Image MD5: 0A02C63C8B144BD8C86B103DEE7C86A2
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): HDAudBus
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft UAA Bus Driver for High Definition Audio
Image path: system32\DRIVERS\HDAudBus.sys
Image size: 144384
Image MD5: 573C7D0A32852B48F3058CFD8026F511
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): helpsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Help and Support
Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): HidServ
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HID Input Service
Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): hidusb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft HID Class Driver
Image path: system32\DRIVERS\hidusb.sys
Image size: 10368
Image MD5: CCF82C5EC8A7326C3066DE870C06DAF1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): hkmsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Health Key and Certificate Management Service
Description: Manages health certificates and keys (used by NAP)
Object name: localSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): hpn
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): HTTP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP
Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start.
Image path: System32\Drivers\HTTP.sys
Image size: 264832
Image MD5: F6AACF5BCE2893E0C1754AFEB672E5C9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): HTTPFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP SSL
Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP

Service (registry key): i2omgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): i2omp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): i8042prt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: i8042 Keyboard and PS/2 Mouse Port Driver
Image path: system32\DRIVERS\i8042prt.sys
Image size: 52480
Image MD5: 4A0B06AA8943C1E332520F7440C0AA30
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): IDriverT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: InstallDriver Table Manager
Description: Provides support for the Running Object Table for InstallShield Drivers
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
Image size: 69632
Image MD5: 1CF03C69B49ACB70C722DF92755C0C8C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0

Service (registry key): idsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows CardSpace
Description: Securely enables the creation, management, and disclosure of digital identities.
Object name: LocalSystem
Image path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
Image size: 881664
Image MD5: C01AC32DC5C03076CFB852CB5DA5229C
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): Imapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-Burning Filter Driver
Image path: system32\DRIVERS\imapi.sys
Image size: 42112
Image MD5: 083A052659F5310DD8B6A6CB05EDCF8E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): ImapiService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IMAPI CD-Burning COM Service
Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\imapi.exe
Image size: 150528
Image MD5: 30DEAF54A9755BB8546168CFE8A6B5E1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): InCDfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nero InCD File System
Image path: system32\drivers\InCDFs.sys
Image size: 118952
Image MD5: 98E96B6F095E6289C3293B99D0F926B2
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): InCDPass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nero InCDPass
Image path: system32\drivers\InCDPass.sys
Image size: 36648
Image MD5: 0B3E2517CF826020688650D46ADF5B05
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): InCDrec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nero InCD File System Recognizer
Image path: system32\drivers\InCDRec.sys
Image size: 16040
Image MD5: 00EE363EA793A9D8DAB5254ACBD7D8E6
Control Set: CurrentControlSet
Start: 1
Type: 8
Error Control: 1

Service (registry key): incdrm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nero InCD MRW Remapper
Image path: system32\drivers\InCDRm.sys
Image size: 38312
Image MD5: D41AB5BE8861AFF53851594DE58DDDFA
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): InCDsrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: InCD Helper
Description: Helper service for the InCD filesystem driver
Object name: LocalSystem
Image path: C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
Image size: 1553704
Image MD5: 40F8DC71CD638C40DB38A0C08AF2A6ED
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): inetaccs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ini910u
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Inport
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): IntcAzAudAddService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Service for Realtek HD Audio (WDM)
Image path: system32\drivers\RtkHDAud.sys
Image size: 4754944
Image MD5: 74B482F8B2A9EBE8473381A7A58F801D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): IntelIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): intelppm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Intel Processor Driver
Image path: system32\DRIVERS\intelppm.sys
Image size: 36352
Image MD5: 8C953733D8F36EB2133F5BB58808B66B
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): Ip6Fw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPv6 Windows Firewall Driver
Description: Provides intrusion prevention service for a home or small office network.
Image path: system32\drivers\ip6fw.sys
Image size: 36608
Image MD5: 3BB22519A194418D5FEC05D800A19AD0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): IpFilterDriver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Traffic Filter Driver
Description: IP Traffic Filter Driver
Image path: system32\DRIVERS\ipfltdrv.sys
Image size: 32896
Image MD5: 731F22BA402EE4B62748ADAF6363C182
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): IpInIp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP in IP Tunnel Driver
Description: IP in IP Tunnel Driver
Image path: system32\DRIVERS\ipinip.sys
Image size: 20864
Image MD5: B87AB476DCF76E72010632B5550955F5
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): IpNat
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Network Address Translator
Description: IP Network Address Translator
Image path: system32\DRIVERS\ipnat.sys
Image size: 152832
Image MD5: CC748EA12C6EFFDE940EE98098BF96BB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): IPSec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC driver
Description: IPSEC driver
Image path: system32\DRIVERS\ipsec.sys
Image size: 75264
Image MD5: 23C74D75E36E7158768DD63D92789A91
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): IRENUM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IR Enumerator Service
Image path: system32\DRIVERS\irenum.sys
Image size: 11264
Image MD5: C93C9FF7B04D772627A3646D89F7BF89
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ISAPISearch
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): isapnp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PnP ISA/EISA Bus Driver
Image path: system32\DRIVERS\isapnp.sys
Image size: 37248
Image MD5: 05A299EC56E52649B1CF2FC52D20F2D7
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3

Service (registry key): JRAID
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\jraid.sys
Image size: 49920
Image MD5: 6E4E3C0B27116B14D1150BE7EECEAAC6
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Kbdclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Keyboard Class Driver
Image path: system32\DRIVERS\kbdclass.sys
Image size: 24576
Image MD5: 463C1EC80CD17420A542B7F36A36F128
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): kbdhid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Keyboard HID Driver
Image path: system32\DRIVERS\kbdhid.sys
Image size: 14592
Image MD5: 9EF487A186DEA361AA06913A75B3FA99
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): kmixer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Wave Audio Mixer
Image path: system32\drivers\kmixer.sys
Image size: 172416
Image MD5: 692BCF44383D056AED41B045A323D378
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): KSecDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): lanmanserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Server
Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): lanmanworkstation
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Workstation
Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): lbrtfdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): ldap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): LicenseService
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): LiveUpdate
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: LiveUpdate
Description: LiveUpdate Core Engine
Object name: LocalSystem
Image path: "C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE"
Image size: 3220856
Image MD5: 36375738DC0B3CD1F764268008E74FDF
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 0

Service (registry key): LiveUpdate Notice
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: LiveUpdate Notice
Description: Manages Norton product notices
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
Image size: 149352
Image MD5: 0981902E0C29655FA8FA161247064907
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0

Service (registry key): LmHosts
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP NetBIOS Helper
Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: NetBT,Afd

Service (registry key): MDM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Machine Debug Manager
Description: Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
Image size: 335872
Image MD5: 7CF1B716372B89568AE4C0FE769F5869
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS

Service (registry key): Memctl
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Memctl
Image path: \??\C:\Program Files\U-ABIT\FlashMenu\Memctl.sys
Image size: 4047
Image MD5: 6DC926C53624755B07CFE254F3845AFA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Messenger
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Messenger
Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS

Service (registry key): mnmdd
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): mnmsrvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetMeeting Remote Desktop Sharing
Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\mnmsrvc.exe
Image size: 32768
Image MD5: D18F1F0C101D06A1C1ADF26EED16FCDD
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1

Service (registry key): Modem
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): Mouclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mouse Class Driver
Image path: system32\DRIVERS\mouclass.sys
Image size: 23040
Image MD5: 35C9E97194C8CFB8430125F8DBC34D04
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): mouhid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mouse HID Driver
Image path: system32\DRIVERS\mouhid.sys
Image size: 12160
Image MD5: B1C303E17FB9D46E87A98E4BA6769685
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): MountMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mount Point Manager
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): mraid35x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): MRxDAV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebDav Client Redirector
Description: WebDav Client Redirector
Image path: system32\DRIVERS\mrxdav.sys
Image size: 180608
Image MD5: 11D42BB6206F33FBB3BA0288D3EF81BD
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1

Service (registry key): MRxSmb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MRXSMB
Description: MRXSMB
Image path: system32\DRIVERS\mrxsmb.sys
Image size: 456576
Image MD5: 68755F0FF16070178B54674FE5B847B0
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): MSDTC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Transaction Coordinator
Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: C:\WINDOWS\system32\msdtc.exe
Image size: 6144
Image MD5: A137F1470499A205ABBB9AAFB3B6F2B1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS,SamSS

Service (registry key): MSDTC Bridge 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Msfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): MSIServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Installer
Description: Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\msiexec.exe /V
Image size: 78848
Image MD5: 5879D691E842574A20FE63817CB76DF9
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): MSKSSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Service Proxy
Image path: system32\drivers\MSKSSRV.sys
Image size: 7552
Image MD5: D1575E71568F4D9E14CA56B7B0453BF1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSPCLOCK
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Clock Proxy
Image path: system32\drivers\MSPCLOCK.sys
Image size: 5376
Image MD5: 325BB26842FC7CCC1FCCE2C457317F3E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSPQM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Quality Manager Proxy
Image path: system32\drivers\MSPQM.sys
Image size: 4992
Image MD5: BAD59648BA099DA4A17680B39730CB3D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): mssmbios
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft System Management BIOS Driver
Image path: system32\DRIVERS\mssmbios.sys
Image size: 15488
Image MD5: AF5F4F3F14A8EA2C26DE30F7A1E17136
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Mup
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mup
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): napagent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Access Protection Agent
Description: Allows windows clients to participate in Network Access Protection
Object name: localSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): NAVENG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NAVENG
Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081019.003\NAVENG.SYS
Image size: 89104
Image MD5: D8F9E712479F2F8DC8C3524A62365F95
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NAVEX15
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NAVEX15
Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081019.003\NAVEX15.SYS
Image size: 873552
Image MD5: 0B127BBE41300DEDE016E86E47329CDD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NBService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NBService
Description: Nero BackItUp Service is responsible to control all jobs created using Nero BackItUp. These jobs can create backups of selected files/folders/partitions or complete hard disk to hard disk, network drive, disc or FTP.
Object name: LocalSystem
Image path: C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
Image size: 800040
Image MD5: 5836B9E91863A00EC1B8E785EFD86ECB
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): NDIS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS System Driver
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): NdisTapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS TAPI Driver
Description: Remote Access NDIS TAPI Driver
Image path: system32\DRIVERS\ndistapi.sys
Image size: 10112
Image MD5: 1AB3D00C991AB086E69DB84B6C0ED78F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Ndisuio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS Usermode I/O Protocol
Description: NDIS Usermode I/O Protocol
Image path: system32\DRIVERS\ndisuio.sys
Image size: 14592
Image MD5: F927A4434C5028758A842943EF1A3849
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NdisWan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS WAN Driver
Description: Remote Access NDIS WAN Driver
Image path: system32\DRIVERS\ndiswan.sys
Image size: 91520
Image MD5: EDC1531A49C80614B2CFDA43CA8659AB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NDProxy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NeroRegInCDSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nero Registry InCD Service
Object name: LocalSystem
Image path: C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): NetBIOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBIOS Interface
Description: NetBIOS Interface
Image path: system32\DRIVERS\netbios.sys
Image size: 34688
Image MD5: 5D81CF9A2F1A3A756B66CF684911CDF0
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): NetBT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBios over Tcpip
Description: NetBios over Tcpip
Image path: system32\DRIVERS\netbt.sys
Image size: 162816
Image MD5: 74B2B2F5BEA5E9A3DC021D685551BD3D
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): NetDDE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE
Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: B857BA82860D7FF85AE29B095645563B
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: NetDDEDSDM

Service (registry key): NetDDEdsdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE DSDM
Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: B857BA82860D7FF85AE29B095645563B
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1

Service (registry key): Netlogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Net Logon
Description: Supports pass-through authentication of account logon events for computers in a domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): Netman
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Connections
Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 288
Error Control: 1
Depends On services: RpcSs

Service (registry key): NetTcpPortSharing
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Net.Tcp Port Sharing Service
Description: Provides ability to share TCP ports over the net.tcp protocol.
Object name: NT AUTHORITY\LocalService
Image path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
Image size: 132096
Image MD5: D34612C5D02D026535B3095D620626AE
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): nHancer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: nHancer Support
Description: Support service for nHancer to change nVidia's registry entries and the file windows\system32\nvapps.xml. Those changes require administration privileges, because of that, the nHancer UI can't change them directly.
Object name: LocalSystem
Image path: "C:\Program Files\nHancer\nHancerService.exe"
Image size: 49152
Image MD5: 73FC16D1263C59D921BE809CD8264038
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): NIC1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 Net Driver
Image path: system32\DRIVERS\nic1394.sys
Image size: 61824
Image MD5: E9E47CFB2D461FA0FC75B7A74C6383EA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Nla
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Location Awareness (NLA)
Description: Collects and stores network configuration and location information, and notifies applications when this information changes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd

Service (registry key): nm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Monitor Driver
Image path: system32\DRIVERS\NMnt.sys
Image size: 40320
Image MD5: 1E421A6BCF2203CC61B821ADA9DE878B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NMIndexingService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NMIndexingService
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe"
Image size: 279848
Image MD5: A328A46D87BB92CE4D8A4528E9D84787
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): Npfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): Ntfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): NtLmSsp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NT LM Security Support Provider
Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): NtmsSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Removable Storage
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): nTuneService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: nTune Service
Description: Service to allow a remote administrator to access this machine for gathering information, and performing performance updates
Object name: LocalSystem
Image path: C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe /StartService
Image size: 131072
Image MD5: C4305F070481199D102F20DAC23E554B
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0

Service (registry key): NuidFltr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NUID filter driver
Image path: system32\DRIVERS\NuidFltr.sys
Image size: 9728
Image MD5: 20623A75F3C6C1076EBBA64DD8C4BC02
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Fredo_P
2008-10-20, 01:49
Service (registry key): Null
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): nv
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\nv4_mini.sys
Image size: 6133856
Image MD5: 83780F3A86D2804912F22F6E37CD2254
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): NVR0Dev
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NVR0Dev
Image path: \??\C:\WINDOWS\nvoclock.sys
Image size: 29696
Image MD5: 61D6B1C71AD94F8485E966BEBC36D092
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NVStrap
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NVStrap
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): NVSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NVIDIA Display Driver Service
Description: Provides system and desktop level support to the NVIDIA display driver
Object name: LocalSystem
Image path: %SystemRoot%\system32\nvsvc32.exe
Image size: 163908
Image MD5: 42321AC5448078131903B272E6C49024
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): NwlnkFlt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Filter Driver
Description: IPX Traffic Filter Driver
Image path: system32\DRIVERS\nwlnkflt.sys
Image size: 12416
Image MD5: B305F3FAD35083837EF46A0BBCE2FC57
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: NwlnkFwd

Service (registry key): NwlnkFwd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Forwarder Driver
Description: IPX Traffic Forwarder Driver
Image path: system32\DRIVERS\nwlnkfwd.sys
Image size: 32512
Image MD5: C99B3415198D1AAB7227F2C88FD664B9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NwlnkIpx
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NWLink IPX/SPX/NetBIOS Compatible Transport Protocol
Description: NWLink IPX/SPX/NetBIOS Compatible Transport Protocol
Image path: system32\DRIVERS\nwlnkipx.sys
Image size: 88320
Image MD5: 8B8B1BE2DBA4025DA6786C645F77F123
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1

Service (registry key): NwlnkNb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NWLink NetBIOS
Description: NWLink NetBIOS
Image path: system32\DRIVERS\nwlnknb.sys
Image size: 63232
Image MD5: 56D34A67C05E94E16377C60609741FF8
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1

Service (registry key): NwlnkSpx
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NWLink SPX/SPXII Protocol
Description: NWLink SPX/SPXII Protocol
Image path: system32\DRIVERS\nwlnkspx.sys
Image size: 55936
Image MD5: C0BB7D1615E1ACBDC99757F6CEAF8CF0
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1

Service (registry key): NwSapAgent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SAP Agent
Description: Service Advertising Protocol
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: NwlnkIpx

Service (registry key): O&O Defrag
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: O&O Defrag
Description: O&O Defragmentation Service
Object name: LocalSystem
Image path: C:\WINDOWS\system32\oodag.exe
Image size: 1050120
Image MD5: AE404E89E2A936CE62A27A104894D6B4
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1

Service (registry key): odserv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Office Diagnostics Service
Description: Run portions of Microsoft Office Diagnostics.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
Image size: 443776
Image MD5: E54AA592A65F317390EEE386A8821692
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): ohci1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Texas Instruments OHCI Compliant IEEE 1394 Host Controller
Image path: system32\DRIVERS\ohci1394.sys
Image size: 61696
Image MD5: CA33832DF41AFB202EE7AEB05145922F
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): OODBS
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ose
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Office Source Engine
Description: Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Image size: 145184
Image MD5: 5A432A042DAE460ABE7199B758E8606C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): Outlook
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Parport
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PartMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Partition Manager
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ParVdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0
Depends On services: Parport
Depends On group: "Parallel arbitrator"

Service (registry key): PCI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PCI Bus Driver
Image path: system32\DRIVERS\pci.sys
Image size: 68224
Image MD5: A219903CCF74233761D92BEF471A07B1
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3

Service (registry key): PCIDump
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): PCIIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\pciide.sys
Image size: 3328
Image MD5: CCF5F451BB1A5A2A522A76E670000FF0
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Pcmcia
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): PDCOMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDRELI
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDRFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): perc2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): perc2hib
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): PerfDisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfNet
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfProc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PlugPlay
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Plug and Play
Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 108544
Image MD5: 0E776ED5F7CC9F94299E70461B7B8185
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): PolicyAgent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC Services
Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS,Tcpip,IPSec

Service (registry key): PptpMiniport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (PPTP)
Description: WAN Miniport (PPTP)
Image path: system32\DRIVERS\raspptp.sys
Image size: 48384
Image MD5: EFEEC01B1D3CF84F16DDD24D9D9D8F99
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ProtectedStorage
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Protected Storage
Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 1
Depends On services: RpcSs

Service (registry key): PSched
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: QoS Packet Scheduler
Description: QoS Packet Scheduler
Image path: system32\DRIVERS\psched.sys
Image size: 69120
Image MD5: 09298EC810B07E5D582CB3A3F9255424
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Gpc

Service (registry key): Ptilink
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel Link Driver
Description: Direct Parallel Link Driver
Image path: system32\DRIVERS\ptilink.sys
Image size: 17792
Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): PxHelp20
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PxHelp20
Image path: System32\Drivers\PxHelp20.sys
Image size: 43528
Image MD5: D86B4A68565E444D76457F14172C875A
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ql1080
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Ql10wnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql12160
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql1240
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql1280
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): RasAcd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Driver
Description: Remote Access Auto Connection Driver
Image path: system32\DRIVERS\rasacd.sys
Image size: 8832
Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): RasAuto
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Manager
Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RasMan,Tapisrv

Service (registry key): Rasl2tp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (L2TP)
Description: WAN Miniport (L2TP)
Image path: system32\DRIVERS\rasl2tp.sys
Image size: 51328
Image MD5: 11B4A627BC9614B885C4969BFA5FF8A6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): RasMan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Connection Manager
Description: Creates a network connection.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tapisrv

Service (registry key): RasPppoe
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access PPPOE Driver
Description: Remote Access PPPOE Driver
Image path: system32\DRIVERS\raspppoe.sys
Image size: 41472
Image MD5: 5BC962F2654137C9909C3D4603587DEE
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Raspti
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel
Description: Direct Parallel
Image path: system32\DRIVERS\raspti.sys
Image size: 16512
Image MD5: FDBB1D60066FCFBB7452FD8F9829B242
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Rdbss
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Rdbss
Description: Rdbss
Image path: system32\DRIVERS\rdbss.sys
Image size: 175744
Image MD5: 7AD224AD1A1437FE28D89CF22B17780A
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): RDPCDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\DRIVERS\RDPCDD.sys
Image size: 4224
Image MD5: 4912D5B403614CE99C28420F75353332
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): RDPDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): RDPNP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): RDPWD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): RDSessMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Desktop Help Session Manager
Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\sessmgr.exe
Image size: 141312
Image MD5: 3C37BF86641BDA977C3BF8A840F3B7FA
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): redbook
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Digital CD Audio Playback Filter Driver
Image path: system32\DRIVERS\redbook.sys
Image size: 57600
Image MD5: F828DD7E1419B6653894A8F97A0094C5
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): RemoteAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Routing and Remote Access
Description: Offers routing services to businesses in local area and wide area network environments.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RpcSS
Depends On group: NetBIOSGroup

Service (registry key): RivaTuner32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: RivaTuner32
Image path: \??\C:\Program Files\RivaTuner v2.11\RivaTuner32.sys
Image size: 9088
Image MD5: C0C8909BE3ECC9DF8089112BF9BE954E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): RpcLocator
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC) Locator
Description: Manages the RPC name service database.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\locator.exe
Image size: 75264
Image MD5: AAED593F84AFA419BBAE8572AF87CF6A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): RpcSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC)
Description: Provides the endpoint mapper and other miscellaneous RPC services.
Object name: NT Authority\NetworkService
Image path: %SystemRoot%\system32\svchost -k rpcss
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): RSVP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: QoS RSVP
Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
Object name: LocalSystem
Image path: %SystemRoot%\system32\rsvp.exe
Image size: 132608
Image MD5: 471B3F9741D762ABE75E9DEEA4787E47
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: TcpIp,Afd,RpcSs

Service (registry key): RTL8023xp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Realtek 10/100/1000 PCI NIC Family NDIS XP Driver
Image path: system32\DRIVERS\Rtnicxp.sys
Image size: 109952
Image MD5: 432F94857DC866A6D3D06931EED85434
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SamSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Accounts Manager
Description: Stores security information for local user accounts.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): SCardSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Smart Card
Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\SCardSvr.exe
Image size: 95744
Image MD5: 86D007E7A654B9A71D1D7D856B104353
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 0
Depends On services: PlugPlay

Service (registry key): Schedule
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Task Scheduler
Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): ScsiPort
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: %SystemRoot%\system32\drivers\scsiport.sys
Image size: 96384
Image MD5: 76C465F570E90C28942D52CCB2580A10
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Secdrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secdrv
Description: SafeDisc driver
Image path: system32\DRIVERS\secdrv.sys
Image size: 20480
Image MD5: 90A3935D05B494A5A39D37E71F09A677
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): seclogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secondary Logon
Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 0

Service (registry key): SENS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Event Notification
Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: EventSystem

Service (registry key): Serial
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0

Service (registry key): ServiceModelEndpoint 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelOperation 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelService 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Sfloppy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Depends On group: "SCSI miniport"

Service (registry key): SharedAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Firewall/Internet Connection Sharing (ICS)
Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Netman,WinMgmt

Service (registry key): ShellHWDetection
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Shell Hardware Detection
Description: Provides notifications for AutoPlay hardware events.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs

Service (registry key): Simbad
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): SMSvcHost 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Sparrow
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): SPBBCDrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SPBBCDrv
Image path: \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
Image size: 447024
Image MD5: 72C6D9494CFB97CC799B12DFD01920F3
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): splitter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Audio Splitter
Image path: system32\drivers\splitter.sys
Image size: 6272
Image MD5: AB8B92451ECB048A4D1DE7C3FFCB4A9F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Spooler
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Print Spooler
Description: Loads files to memory for later printing.
Object name: LocalSystem
Image path: %SystemRoot%\system32\spoolsv.exe
Image size: 57856
Image MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
Control Set: CurrentControlSet
Start: 4
Type: 272
Error Control: 1
Depends On services: RPCSS

Service (registry key): sr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Filter Driver
Image path: system32\DRIVERS\sr.sys
Image size: 73472
Image MD5: 76BB022C2FB6902FD5BDD4F78FC13A5D
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): srservice
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Service
Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): SRTSP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SRTSP
Image path: System32\Drivers\SRTSP.SYS
Image size: 279088
Image MD5: E0E54A571D4323567E95E11FE76A5FF3
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1
Depends On services: SRTSPX,FltMgr

Service (registry key): SRTSPL
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SRTSPL
Image path: System32\Drivers\SRTSPL.SYS
Image size: 317616
Image MD5: 4E44F0E22DF824D318988CAA6F321C30
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: SRTSPX

Service (registry key): SRTSPX
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SRTSPX
Image path: System32\Drivers\SRTSPX.SYS
Image size: 43696
Image MD5: D3BB40427CF3D02E56BBA97FEDA0A3AA
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): Srv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Srv
Description: Srv
Image path: system32\DRIVERS\srv.sys
Image size: 333824
Image MD5: 4F8A43ADEF66F135564085A9DCA96A26
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1

Service (registry key): SSDPSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SSDP Discovery Service
Description: Enables discovery of UPnP devices on your home network.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP

Service (registry key): ssfs0bbc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ssfs0bbc
Description: Spy Sweeper File System Filter Driver
Image path: system32\DRIVERS\ssfs0bbc.sys
Image size: 29808
Image MD5: 05F1EB5DB0A3857B2AEF1D4A24F0FD83
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 0

Service (registry key): sshrmd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Sshrmd
Description: Spy Sweeper Hookrack MiniDriver
Image path: system32\DRIVERS\sshrmd.sys
Image size: 23152
Image MD5: 46F4F3BA5F31ABF524790AB730E5B7AC
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 0

Service (registry key): ssidrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Ssidrv
Description: Spy Sweeper Interdiction Driver
Image path: system32\DRIVERS\ssidrv.sys
Image size: 170608
Image MD5: 15DADA35802460973BCEF9F2E300E39B
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 0

Service (registry key): stisvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Image Acquisition (WIA)
Description: Provides image acquisition services for scanners and cameras.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k imgsvc
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): swenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Software Bus Driver
Image path: system32\DRIVERS\swenum.sys
Image size: 4352
Image MD5: 3941D127AEF12E93ADDF6FE6EE027E0F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): swmidi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel GS Wavetable Synthesizer
Image path: system32\drivers\swmidi.sys
Image size: 56576
Image MD5: 8CE882BCC6CF8A62F2B2323D95CB3D01
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SwPrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MS Software Shadow Copy Provider
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{00B0AB27-CCEF-42C4-B3CE-5704AA31C861}
Image size: 5120
Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Depends On services: rpcss

Service (registry key): swwd
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Symantec Core LC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Core LC
Description: Symantec Core LC
Object name: LocalSystem
Image path: C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
Image size: 1245064
Image MD5: 438FAFE708C93B2236FC26B6F2BD5FD0
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): symc810
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): symc8xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): SYMDNS
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMDNS.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SymEvent
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Image size: 123952
Image MD5: C5EAFB6A8C73FB26B73EE613C1A5AEF6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SYMFW
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMFW.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SYMIDS
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMIDS.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SYMIDSCO
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20081014.001\SymIDSCo.sys
Image size: 250224
Image MD5: C87748B4A7541B81C9564ED5B3CF8697
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SymIM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Symantec Network Security Intermediate Filter Service
Image path: system32\DRIVERS\SymIM.sys
Image size: 31280
Image MD5: 54BDA52E4B8EE68E9C01D4B9CD75CD95
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SymIMMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\SymIM.sys
Image size: 31280
Image MD5: 54BDA52E4B8EE68E9C01D4B9CD75CD95
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SYMNDIS
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMNDIS.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SYMREDRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\Drivers\SYMREDRV.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): SYMTDI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SYMTDI
Image path: \SystemRoot\System32\Drivers\SYMTDI.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): sym_hi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): sym_u3
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): sysaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel System Audio Device
Image path: system32\drivers\sysaudio.sys
Image size: 60800
Image MD5: 8B83F3ED0F1688B4958F77CD6D2BF290
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SysmonLog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Performance Logs and Alerts
Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT Authority\NetworkService
Image path: %SystemRoot%\system32\smlogsvc.exe
Image size: 89600
Image MD5: C7ABBC59B43274B1109DF6B24D617051
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): TapiSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telephony
Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs

Service (registry key): Tcpip
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP Protocol Driver
Description: TCP/IP Protocol Driver
Image path: system32\DRIVERS\tcpip.sys
Image size: 361600
Image MD5: 9AEFA14BD6B182D61E3119FA5F436D3D
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: IPSec

Service (registry key): TDPIPE
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): TDTCP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): TermDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Device Driver
Image path: system32\DRIVERS\termdd.sys
Image size: 40840
Image MD5: 88155247177638048422893737429D9E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): TermService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Services
Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost -k DComLaunch
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): Themes
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Themes
Description: Provides user experience theme management.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): TosIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): TrkWks
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Link Tracking Client
Description: Maintains links between NTFS files within a computer or across computers in a network domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): TSDDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): TVICHW32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TVICHW32
Image path: \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS
Image size: 23600
Image MD5: E266683FC95ABDEC17CD378564E1B54B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Udfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): UGURU
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\drivers\uGuru.sys
Image size: 14592
Image MD5: C3CD138762AAB1797805C26BF5DEFCBE
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): ultra
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Update
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microcode Update Driver
Image path: system32\DRIVERS\update.sys
Image size: 384768
Image MD5: 402DDC88356B1BAC0EE3DD1580C76A31
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): upnphost
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Universal Plug and Play Device Host
Description: Provides support to host Universal Plug and Play devices.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: SSDPSRV,HTTP

Service (registry key): UPS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Uninterruptible Power Supply
Description: Manages an uninterruptible power supply (UPS) connected to the computer.
Object name: LocalSystem
Image path: %SystemRoot%\System32\ups.exe
Image size: 18432
Image MD5: 05365FB38FCA1E98F7A566AAAF5D1815
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1

Service (registry key): usbaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Audio Driver (WDM)
Image path: system32\drivers\usbaudio.sys
Image size: 60032
Image MD5: E919708DB44ED8543A7C017953148330
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbccgp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Generic Parent Driver
Image path: system32\DRIVERS\usbccgp.sys
Image size: 32128
Image MD5: 173F317CE0DB8E21322E71B7E60A27E8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbehci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
Image path: system32\DRIVERS\usbehci.sys
Image size: 30208
Image MD5: 65DCF09D0E37D4C6B11B5B0B76D470A7
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbhub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB2 Enabled Hub
Image path: system32\DRIVERS\usbhub.sys
Image size: 59520
Image MD5: 1AB3CDDE553B6E064D2E754EFE20285C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): USBSTOR
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Mass Storage Driver
Image path: system32\DRIVERS\USBSTOR.SYS
Image size: 26368
Image MD5: A32426D9B14A089EAA1D922E0C5801A9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbuhci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Universal Host Controller Miniport Driver
Image path: system32\DRIVERS\usbuhci.sys
Image size: 20608
Image MD5: 26496F9DEE2D787FC3E61AD54821FFE6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): VgaSave
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: VGA Display Controller.
Description: Controls the VGA display adapter to provide basic display capabilities.
Image path: \SystemRoot\System32\drivers\vga.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): ViaIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): VolSnap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): VSS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Shadow Copy
Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\vssvc.exe
Image size: 289792
Image MD5: 7A9DB3A67C333BF0BD42E42B8596854B
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): W32Time
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Time
Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): W3SVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Wanarp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access IP ARP Driver
Description: Remote Access IP ARP Driver
Image path: system32\DRIVERS\wanarp.sys
Image size: 34560
Image MD5: E20B95BAEDB550F32DD489265C1DA1F6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Wdf01000
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wdf01000
Image path: system32\DRIVERS\Wdf01000.sys
Image size: 492000
Image MD5: FD47474BD21794508AF449D9D91AF6E6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WDICA
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): wdmaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft WINMM WDM Audio Compatibility Driver
Image path: system32\drivers\wdmaud.sys
Image size: 83072
Image MD5: 6768ACF64B18196494413695F0C3A00F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WebClient
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebClient
Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: MRxDAV

Service (registry key): WebrootSpySweeperService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Webroot Spy Sweeper Engine
Description: Provides core functionality to Webroot Spy Sweeper. This service must be enabled and started for Spy Sweeper to function.
Object name: LocalSystem
Image path: "C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe"
Image size: 3667304
Image MD5: BC3AE476BA1C88831C7CE0DCCFD1943C
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): WinDefend
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Defender
Description: Helps protect users from malicious software, spyware, and other potentially unwanted software
Object name: LocalSystem
Image path: "C:\Program Files\Windows Defender\MsMpEng.exe"
Image size: 13592
Image MD5: F45DD1E1365D857DD08BC23563370D0E
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RpcSs

Service (registry key): Windows Workflow Foundation 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Winflash
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WINFLASH
Image path: \??\C:\Program Files\U-ABIT\FlashMenu\WinFlash.sys
Image size: 3548
Image MD5: FD5B87CD55134BF3545116DBBD45BE88
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): winmgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation
Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RPCSS

Service (registry key): Winsock
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 4
Error Control: 1

Service (registry key): WinSock2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WinTrust
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WmBEnum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logitech Virtual Bus Enumerator Driver
Image path: system32\drivers\WmBEnum.sys
Image size: 19336
Image MD5: 38932C4649F8BAAD6CE1000AC6503D5B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WmdmPmSN
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Portable Media Serial Number Service
Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): WmFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logitech Gaming HID Filter Driver
Image path: system32\drivers\WmFilter.sys
Image size: 28168
Image MD5: 58B3ADAB903FA1A78C86E6A42B80FE76
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): Wmi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WmiApRpl
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WmiApSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WMI Performance Adapter
Description: Provides performance library information from WMI HiPerf providers.
Object name: LocalSystem
Image path: C:\WINDOWS\system32\wbem\wmiapsrv.exe
Image size: 126464
Image MD5: E0673F1106E62A68D2257E376079F821
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): WMPNetworkSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Media Player Network Sharing Service
Description: Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
Object name: NT AUTHORITY\NetworkService
Image path: "C:\Program Files\Windows Media Player\WMPNetwk.exe"
Image size: 913408
Image MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: upnphost,http,HTTPFilter

Service (registry key): WmVirHid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logitech Virtual Hid Device Driver
Image path: system32\drivers\WmVirHid.sys
Image size: 14728
Image MD5: E45F01F4014D7AB13B8A0C41EBF48A3D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WmXlCore
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logitech Translation Layer Driver
Image path: system32\drivers\WmXlCore.sys
Image size: 48904
Image MD5: 0398265DD65AAE2ECE180FA9D1E7B5BB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): WRConsumerService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Webroot Client Service
Description: This service provides system level operations for the Webroot Client.
Object name: LocalSystem
Image path: "C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe"
Image size: 1066360
Image MD5: F8F9FC4D8F3D0A3950723F32AF95B3E8
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): WS2IFSL
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 0
Error Control: 0

Service (registry key): wscsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Center
Description: Monitors system security settings and configurations.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,winmgmt

Service (registry key): wuauserv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Automatic Updates
Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1

Service (registry key): WudfPf
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver
Description: Provide communciation services for UMDF components.
Image path: system32\DRIVERS\WudfPf.sys
Image size: 77568
Image MD5: F15FEAFFFBB3644CCC80C5DA584E6311
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WudfRd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Reflector
Description: Reflect device requests to user-mode driver drivers
Image path: system32\DRIVERS\wudfrd.sys
Image size: 82944
Image MD5: 28B524262BCE6DE1F7EF9F510BA3985B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WudfSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework
Description: Manages user-mode driver host processes
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: PlugPlay

Service (registry key): WZCSVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wireless Zero Configuration
Description: Provides automatic configuration for the 802.11 adapters
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,Ndisuio

Service (registry key): xmlprov
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Provisioning Service
Description: Manages XML configuration files on a domain basis for automatic network provisioning.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): {11FA55F6-A1AD-4069-9A7E-B5ECD8622F2D}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): {2B7797BA-D91F-4E01-A61F-EA411DE4E2A9}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): {74101FCC-93D8-44E1-A304-7D27881DFED2}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Fredo_P
2008-10-20, 01:50
Service (registry key): {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}
Image path: \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl
Image size: 41456
Image MD5: 5867CE254625645345C833510D24F124
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1

tashi
2008-10-20, 05:24
Hello Fredo_P,

Because of the volume of posts to your own topic, it will appear you are already being assisted. Volunteer analysts look for topics with no response.

Please see the stickied procedure for this forum: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Start a new topic providing the HJT log and a link to this thread which I will then close.

Best regards.