Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 47

Thread: spywareguard 2009 removal

  1. #21
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    "He said I had 250 viruses. I asked him why Spybot did not see any of them and he says that he never uses any kind of antispyware programs like that, rather he says to always update the os."

    That sounds pretty "interesting" but we have our own ways to do things

    Please go to Kaspersky website and perform an online antivirus scan.

    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the results. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply along with a fresh HijackThis log.


    If you need a tutorial, see here
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  2. #22
    Member
    Join Date
    Jan 2009
    Posts
    35

    Default

    I did the Kaspersky Online Scan as you directed. It did not find any malware. So I just had a blank report.
    I must ask; what is the difference between Spybot SD and Kaspersky?
    Thanks

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:18:19 PM, on 1/21/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\M-Audio Uno\UnoInst.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Java\jre6\bin\java.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    E:\spy\HiJackThis.exe

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1232580805468
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/downlo...BundleId=26688
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exe

    --
    End of file - 4308 bytes

  3. #23
    Member
    Join Date
    Jan 2009
    Posts
    35

    Default

    I just did a Spybot Scan: It says I have a Win32.Agent.pz and a
    Win32.TDSS.rtk.

  4. #24
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    "I must ask; what is the difference between Spybot SD and Kaspersky?"

    Spybot is antispyware and Kaspersky is antivirus. Please post then spybot report next.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #25
    Member
    Join Date
    Jan 2009
    Posts
    35

    Default

    --- Spybot - Search & Destroy version: 1.6.0 (build: 20080729) ---

    2008-08-14 blindman.exe (1.0.0.8)
    2008-01-28 SDDelFile.exe (1.0.2.4)
    2008-08-14 SDFiles.exe (1.6.0.4)
    2008-08-14 SDMain.exe (1.0.0.6)
    2008-08-14 SDShred.exe (1.0.2.3)
    2008-08-14 SDUpdate.exe (1.6.0.9)
    2008-08-14 SDWinSec.exe (1.0.0.12)
    2008-09-16 TeaTimer.exe (1.6.3.25)
    2008-09-13 unins000.exe (51.49.0.0)
    2008-08-14 Update.exe (1.6.0.7)
    2008-10-22 advcheck.dll (1.6.2.13)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2008-09-15 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2008-10-22 Tools.dll (2.1.6.8)
    2009-01-13 Includes\Adware.sbi
    2009-01-20 Includes\AdwareC.sbi
    2009-01-15 Includes\Cookies.sbi
    2009-01-06 Includes\Dialer.sbi
    2009-01-13 Includes\DialerC.sbi
    2009-01-13 Includes\HeavyDuty.sbi
    2008-11-18 Includes\Hijackers.sbi
    2009-01-13 Includes\HijackersC.sbi
    2008-12-09 Includes\Keyloggers.sbi
    2009-01-20 Includes\KeyloggersC.sbi
    2004-11-29 Includes\LSP.sbi
    2008-11-18 Includes\Malware.sbi
    2009-01-21 Includes\MalwareC.sbi
    2008-12-16 Includes\PUPS.sbi
    2009-01-20 Includes\PUPSC.sbi
    2009-01-13 Includes\Revision.sbi
    2009-01-13 Includes\Security.sbi
    2009-01-20 Includes\SecurityC.sbi
    2008-06-03 Includes\Spybots.sbi
    2008-06-03 Includes\SpybotsC.sbi
    2009-01-20 Includes\Spyware.sbi
    2009-01-13 Includes\SpywareC.sbi
    2008-06-03 Includes\Tracks.uti
    2009-01-21 Includes\Trojans.sbi
    2009-01-21 Includes\TrojansC.sbi
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll


    --- System information ---
    Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
    / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
    / Windows Media Player: Security Update for Windows Media Player (KB952069)
    / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
    / Windows Media Player 9: Security Update for Windows Media Player 9 (KB936782)
    / Windows XP: Security Update for Windows XP (KB941569)
    / Windows XP / SP3: Windows XP Service Pack 3
    / Windows XP / SP4: Security Update for Windows XP (KB938464)
    / Windows XP / SP4: Security Update for Windows XP (KB946648)
    / Windows XP / SP4: Security Update for Windows XP (KB950762)
    / Windows XP / SP4: Security Update for Windows XP (KB950974)
    / Windows XP / SP4: Security Update for Windows XP (KB951066)
    / Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951698)
    / Windows XP / SP4: Security Update for Windows XP (KB951748)
    / Windows XP / SP4: Update for Windows XP (KB951978)
    / Windows XP / SP4: Hotfix for Windows XP (KB952287)
    / Windows XP / SP4: Security Update for Windows XP (KB952954)
    / Windows XP / SP4: Security Update for Windows XP (KB954211)
    / Windows XP / SP4: Security Update for Windows XP (KB954459)
    / Windows XP / SP4: Security Update for Windows XP (KB954600)
    / Windows XP / SP4: Security Update for Windows XP (KB955069)
    / Windows XP / SP4: Update for Windows XP (KB955839)
    / Windows XP / SP4: Security Update for Windows XP (KB956391)
    / Windows XP / SP4: Security Update for Windows XP (KB956802)
    / Windows XP / SP4: Security Update for Windows XP (KB956803)
    / Windows XP / SP4: Security Update for Windows XP (KB956841)
    / Windows XP / SP4: Security Update for Windows XP (KB957097)
    / Windows XP / SP4: Security Update for Windows XP (KB958215)
    / Windows XP / SP4: Security Update for Windows XP (KB958644)
    / Windows XP / SP4: Security Update for Windows XP (KB958687)
    / Windows XP / SP4: Security Update for Windows XP (KB960714)


    --- Startup entries list ---
    Located: HK_LM:Run, AVG7_CC
    command: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    file: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    size: 590848
    MD5: F1B42DE29AF84F24FB59989805B1B62D

    Located: HK_LM:Run, SunJavaUpdateSched
    command: "C:\Program Files\Java\jre6\bin\jusched.exe"
    file: C:\Program Files\Java\jre6\bin\jusched.exe
    size: 136600
    MD5: B98FFA8288EFAABC436C30D198608345

    Located: HK_LM:Run, AVG7_CC (DISABLED)
    command: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    file: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    size: 590848
    MD5: F1B42DE29AF84F24FB59989805B1B62D

    Located: HK_CU:Run, AVG7_Run
    where: .DEFAULT...
    command: C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
    file: C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    size: 219136
    MD5: B331EF4C7437F5093D703340678469EB

    Located: HK_CU:Run, AVG7_Run
    where: S-1-5-19...
    command: C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
    file: C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    size: 219136
    MD5: B331EF4C7437F5093D703340678469EB

    Located: HK_CU:Run, AVG7_Run
    where: S-1-5-20...
    command: C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
    file: C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    size: 219136
    MD5: B331EF4C7437F5093D703340678469EB

    Located: HK_CU:Run, ctfmon.exe
    where: S-1-5-21-602162358-1085031214-839522115-1003...
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3

    Located: HK_CU:Run, AVG7_Run
    where: S-1-5-18...
    command: C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
    file: C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    size: 219136
    MD5: B331EF4C7437F5093D703340678469EB

    Located: WinLogon, crypt32chain
    command: crypt32.dll
    file: crypt32.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cscdll
    command: cscdll.dll
    file: cscdll.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, dimsntfy
    command: %SystemRoot%\System32\dimsntfy.dll
    file: %SystemRoot%\System32\dimsntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, igfxcui
    command: igfxdev.dll
    file: igfxdev.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, Schedule
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, termsrv
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, WgaLogon
    command: WgaLogon.dll
    file: WgaLogon.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

  6. #26
    Member
    Join Date
    Jan 2009
    Posts
    35

    Default

    --- Browser helper object list ---
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Adobe PDF Reader Link Helper
    description: Adobe Acrobat reader
    classification: Legitimate
    known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
    info link: http://www.adobe.com/products/acrobat/readstep2.html
    info source: TonyKlein
    Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
    Long name: AcroIEHelper.dll
    Short name: ACROIE~1.DLL
    Date (created): 10/22/2006 11:08:42 PM
    Date (last access): 1/22/2009 1:32:36 PM
    Date (last write): 10/22/2006 11:08:42 PM
    Filesize: 62080
    Attributes: archive
    MD5: C11F6A1F61481E24BE3FDC06EA6F7D2A
    CRC32: E388508F
    Version: 8.0.0.456

    {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Spybot-S&D IE Protection
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\PROGRA~1\SPYBOT~1\
    Long name: SDHelper.dll
    Short name:
    Date (created): 2/11/2008 5:53:10 PM
    Date (last access): 1/22/2009 1:32:36 PM
    Date (last write): 9/15/2008 1:25:44 PM
    Filesize: 1562960
    Attributes: readonly hidden sysfile archive
    MD5: 35F73F1936BDE91F1B6995510A61E7A8
    CRC32: BE6A5D15
    Version: 1.6.2.14

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Java(tm) Plug-In SSV Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Java(tm) Plug-In SSV Helper
    Path: C:\Program Files\Java\jre6\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 1/21/2009 3:35:34 PM
    Date (last access): 1/22/2009 1:35:18 PM
    Date (last write): 1/21/2009 3:35:34 PM
    Filesize: 320920
    Attributes: archive
    MD5: 35E6FB6E6003BD54A5D69C9C1C762192
    CRC32: 9699660C
    Version: 6.0.110.3

    {DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Java(tm) Plug-In 2 SSV Helper
    Path: C:\Program Files\Java\jre6\bin\
    Long name: jp2ssv.dll
    Short name:
    Date (created): 1/21/2009 3:35:34 PM
    Date (last access): 1/22/2009 1:35:18 PM
    Date (last write): 1/21/2009 3:35:34 PM
    Filesize: 34816
    Attributes: archive
    MD5: 5D57FD3DF32DC69CEC3D1D54B4C43162
    CRC32: D7C13FB2
    Version: 6.0.110.3

    {E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: JQSIEStartDetectorImpl
    CLSID name: JQSIEStartDetectorImpl Class
    Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\
    Long name: jqs_plugin.dll
    Short name: JQS_PL~1.DLL
    Date (created): 1/21/2009 3:35:34 PM
    Date (last access): 1/22/2009 1:35:18 PM
    Date (last write): 1/21/2009 3:35:34 PM
    Filesize: 73728
    Attributes: archive
    MD5: F68EDAFE003F2B3523C0742CD3B8D673
    CRC32: 9C709350
    Version: 6.0.110.3



    --- ActiveX list ---
    {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
    DPF name:
    CLSID name: MUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
    Codebase: http://update.microsoft.com/microsof...?1232580805468
    description:
    classification: Legitimate
    known filename: muweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: muweb.dll
    Short name:
    Date (created): 10/16/2008 2:07:48 PM
    Date (last access): 1/22/2009 1:35:18 PM
    Date (last write): 10/16/2008 2:07:48 PM
    Filesize: 208744
    Attributes: archive
    MD5: 90058C2AD9FC43A3B3D59F82FFC6AEA7
    CRC32: 7D5F90FA
    Version: 7.2.6001.788

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_11
    Installer: C:\WINDOWS\Downloaded Program Files\jinstall-6u11.inf
    Codebase: http://javadl.sun.com/webapps/downlo...BundleId=26688
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_11.dll
    Short name: NPJPI1~1.DLL
    Date (created): 1/21/2009 3:35:34 PM
    Date (last access): 1/22/2009 1:35:18 PM
    Date (last write): 1/21/2009 3:35:34 PM
    Filesize: 132504
    Attributes: archive
    MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
    CRC32: CECB5751
    Version: 6.0.110.3

    {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
    Codebase: http://fpdownload.macromedia.com/get.../ultrashim.cab
    description:
    classification: Open for discussion
    known filename:
    info link:
    info source: Safer Networking Ltd.

    {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_11
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_11.dll
    Short name: NPJPI1~1.DLL
    Date (created): 1/21/2009 3:35:34 PM
    Date (last access): 1/22/2009 1:35:18 PM
    Date (last write): 1/21/2009 3:35:34 PM
    Filesize: 132504
    Attributes: archive
    MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
    CRC32: CECB5751
    Version: 6.0.110.3

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_11
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_11.dll
    Short name: NPJPI1~1.DLL
    Date (created): 1/21/2009 3:35:34 PM
    Date (last access): 1/22/2009 1:35:18 PM
    Date (last write): 1/21/2009 3:35:34 PM
    Filesize: 132504
    Attributes: archive
    MD5: D400116F6776ACB6EDB6B1F5EEB9F92D
    CRC32: CECB5751
    Version: 6.0.110.3



    --- Process list ---
    PID: 0 ( 0) [System]
    PID: 432 ( 4) \SystemRoot\System32\smss.exe
    size: 50688
    PID: 488 ( 432) \??\C:\WINDOWS\system32\csrss.exe
    size: 6144
    PID: 512 ( 432) \??\C:\WINDOWS\system32\winlogon.exe
    size: 507904
    PID: 556 ( 512) C:\WINDOWS\system32\services.exe
    size: 108544
    MD5: 0E776ED5F7CC9F94299E70461B7B8185
    PID: 568 ( 512) C:\WINDOWS\system32\lsass.exe
    size: 13312
    MD5: BF2466B3E18E970D8A976FB95FC1CA85
    PID: 720 ( 556) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 788 ( 556) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 824 ( 556) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 860 ( 556) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1024 ( 556) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1056 ( 556) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1136 ( 556) C:\WINDOWS\system32\spoolsv.exe
    size: 57856
    MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
    PID: 1232 ( 556) C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    size: 418816
    MD5: 3C7B93F947355E374A49564D0D017B7B
    PID: 1256 ( 556) C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    size: 49664
    MD5: 30A14F65DB477DC00A64A5A24E96919C
    PID: 1268 ( 556) C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    size: 406528
    MD5: FC0B2AE890BB0DC8C2306DABEDC8A4BA
    PID: 1352 ( 556) C:\Program Files\Java\jre6\bin\jqs.exe
    size: 152984
    MD5: 32192B4EBE8720ED8D49A455C962CB91
    PID: 1512 (1468) C:\WINDOWS\Explorer.EXE
    size: 1033728
    MD5: 12896823FB95BFB3DC9B46BCAEDC9923
    PID: 1676 (1512) C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    size: 590848
    MD5: F1B42DE29AF84F24FB59989805B1B62D
    PID: 1684 (1512) C:\Program Files\Java\jre6\bin\jusched.exe
    size: 136600
    MD5: B98FFA8288EFAABC436C30D198608345
    PID: 1692 (1512) C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
    PID: 1724 ( 556) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    size: 322120
    MD5: 11F714F85530A2BD134074DC30E99FCA
    PID: 1816 ( 556) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1844 ( 556) C:\Program Files\M-Audio Uno\UnoInst.exe
    size: 106496
    MD5: AD92577D020367F32E0BA77CC85BFFD4
    PID: 416 (1676) C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    size: 219136
    MD5: B331EF4C7437F5093D703340678469EB
    PID: 884 ( 556) C:\WINDOWS\System32\alg.exe
    size: 44544
    MD5: 8C515081584A38AA007909CD02020B3D
    PID: 2780 (1512) C:\Program Files\Spybot - Search & Destroy\bla.scr
    size: 4891984
    MD5: 9C8F0F34F66BB845B42F70E92A972B5F
    PID: 3604 ( 824) C:\WINDOWS\system32\wuauclt.exe
    size: 51224
    MD5: E654B78D2F1D791B30D0ED9A8195EC22
    PID: 4 ( 0) System
    PID: 3592 (1676) C:\PROGRA~1\Grisoft\AVG7\avginet.exe
    size: 514560
    MD5: CA998D11ECD3E3DCFA66329F79243D72


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 1/22/2009 1:41:17 PM

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    http://www.google.com/
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    %SystemRoot%\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

  7. #27
    Member
    Join Date
    Jan 2009
    Posts
    35

    Default

    --- Winsock Layered Service Provider list ---
    Protocol 0: MSAFD Tcpip [TCP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 1: MSAFD Tcpip [UDP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 2: MSAFD Tcpip [RAW/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 3: RSVP UDP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 4: RSVP TCP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CF94444C-8A5F-49CD-95F7-6A8EEA620410}] SEQPACKET 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CF94444C-8A5F-49CD-95F7-6A8EEA620410}] DATAGRAM 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{85665C8B-A8F4-4379-8CD7-6B811D7C569E}] SEQPACKET 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{85665C8B-A8F4-4379-8CD7-6B811D7C569E}] DATAGRAM 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CC302B4D-635D-41EC-9FDB-9F9AF913BF53}] SEQPACKET 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CC302B4D-635D-41EC-9FDB-9F9AF913BF53}] DATAGRAM 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EEAE0537-2BDA-4FD5-996F-25B3C5DB3A09}] SEQPACKET 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EEAE0537-2BDA-4FD5-996F-25B3C5DB3A09}] DATAGRAM 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Namespace Provider 0: Tcpip
    GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: TCP/IP

    Namespace Provider 1: NTDS
    GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\winrnr.dll
    DB protocol: NTDS

    Namespace Provider 2: Network Location Awareness (NLA) Namespace
    GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: NLA-Namespace



    --- Uninstall list ---
    (AddressBook)

    Adobe Flash Player ActiveX 9.0.115.0 (Adobe Flash Player ActiveX)
    uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    publisher: Adobe Systems Incorporated
    help link: http://www.adobe.com/go/flashplayer_support/

    Adobe Flash Player Plugin 9.0.124.0 (Adobe Flash Player Plugin)
    uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    publisher: Adobe Systems Incorporated

    Attansic L2 Fast Ethernet Driver (AtcL2)
    uninstall cmd: rundll32.exe C:\WINDOWS\system32\Attansic\L2\atcInst.dll,AtcUninst C:\WINDOWS\system32\Attansic\L2 x86 1969 2048 L2

    AVG 7.5 (AVG7Uninstall)
    uninstall cmd: C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL

    (Branding)

    Cakewalk Pro Audio 8.0 (Cakewalk Pro Audio 8.0)
    uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Cakewalk\Cakewalk Pro Audio\Uninst.isu"

    (Connection Manager)

    (DirectAnimation)

    (DirectDrawEx)

    (DXM_Runtime)

    (Fontcore)

    Intel(R) Graphics Media Accelerator Driver (HDMI)
    uninstall cmd: C:\WINDOWS\system32\igxpun.exe -uninstall

    HijackThis 2.0.2 2.0.2 (HijackThis)
    uninstall cmd: "E:\HijackThis.exe" /uninstall
    publisher: TrendMicro

    (ICW)

    (IE40)

    (IE4Data)

    (IE5BAKEX)

    (IEData)

    (KB884016)

    (KB884267)

    (KB885353)

    (KB886612)

    (KB887078)

    (KB887626)

    High Definition Audio Driver Package - KB888111 20040219.000000 (KB888111WXPSP2)
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=KB888111

    (KB888656)

    (KB891122)

    (KB893240)

    (KB893241)

    (KB893803)

    (KB895181)

    (KB895316)

    (KB897586)

    (KB898549)

    (KB900399)

    (KB902344)

    Security Update for Windows Media Player (KB911564) (KB911564)
    install date: 20071220
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=911564

    (KB911854)

    Security Update for Windows XP (KB923789) (KB923789)
    uninstall cmd: C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=923789

    Security Update for Windows Media Player 6.4 (KB925398) (KB925398_WMP64)
    install date: 20071220
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=925398

    Hotfix for Windows Media Format 11 SDK (KB929399) (KB929399)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=929399

    Security Update for Windows Media Player 9 (KB936782) (KB936782_WMP9)
    install date: 20071220
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=936782

    Security Update for Windows XP (KB938464) 1 (KB938464)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=938464

    Security Update for Windows XP (KB941569) (KB941569)
    install date: 20071220
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=941569

    Security Update for Windows XP (KB946648) 1 (KB946648)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=946648

    Security Update for Windows XP (KB950762) 1 (KB950762)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=950762

    Security Update for Windows XP (KB950974) 1 (KB950974)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=950974

    Security Update for Windows XP (KB951066) 1 (KB951066)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951066

    Security Update for Windows XP (KB951376-v2) 2 (KB951376-v2)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951376

    Security Update for Windows XP (KB951698) 1 (KB951698)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951698

    Security Update for Windows XP (KB951748) 1 (KB951748)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951748

    Update for Windows XP (KB951978) 1 (KB951978)
    install date: 20090121
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951978

    Security Update for Windows Media Player (KB952069) (KB952069_WM9)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=952069

    Hotfix for Windows XP (KB952287) 1 (KB952287)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=952287

    Security Update for Windows XP (KB952954) 1 (KB952954)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=952954

    Security Update for Windows XP (KB954211) 1 (KB954211)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=954211

    Security Update for Windows XP (KB954459) 1 (KB954459)
    install date: 20090121
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=954459

    Security Update for Windows XP (KB954600) 1 (KB954600)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=954600

    Security Update for Windows XP (KB955069) 1 (KB955069)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=955069

    Update for Windows XP (KB955839) 1 (KB955839)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=955839

    Security Update for Windows XP (KB956391) 1 (KB956391)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956391

    Security Update for Windows XP (KB956802) 1 (KB956802)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956802

    Security Update for Windows XP (KB956803) 1 (KB956803)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956803

    Security Update for Windows XP (KB956841) 1 (KB956841)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956841

    Security Update for Windows XP (KB957097) 1 (KB957097)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=957097

    Security Update for Windows XP (KB958215) 1 (KB958215)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=958215

    Security Update for Windows XP (KB958644) 1 (KB958644)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=958644

    Security Update for Windows XP (KB958687) 1 (KB958687)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=958687

    Security Update for Windows XP (KB960714) 1 (KB960714)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=960714

    (MobileOptionPack)

    Mozilla Firefox (3.0.4) 3.0.4 (en-US) (Mozilla Firefox (3.0.4))
    install location: C:\Program Files\Mozilla Firefox
    uninstall cmd: C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    publisher: Mozilla
    comments: Mozilla Firefox

    (MPlayer2)

    (MSI30-Beta1)

    (MSI30-Beta2)

    (MSI30-KB884016)

    (MSI30-RC1)

    (MSI30-RC2)

    (MSI30a-KB884016)

    (MSI31-Beta)

    (MSI31-RC1)

    Nero 6 Ultra Edition (Nero - Burning Rom!UninstallKey)
    uninstall cmd: C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL

    NeroVision Express 3 (NeroVision!UninstallKey)
    uninstall cmd: C:\WINDOWS\UNNeroVision.exe /UNINSTALL

    (NetMeeting)

    (OutlookExpress)

    (PCHealth)
    uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf

    Picsplorer 3.4 (Picsplorer_is1)
    install date: 20081002
    install location: C:\Documents and Settings\Me\My Documents\readmes\Picsplorer\
    uninstall cmd: "C:\Documents and Settings\Me\My Documents\readmes\Picsplorer\unins000.exe"
    publisher: Picsplorer Software, Inc.
    help link: http://www.picsplorer.com/

    (SchedulingAgent)

    9.0.115.0 (ShockwaveFlash)

    TuneLab 97 (TuneLab 97)
    uninstall cmd: C:\PROGRA~1\TLAB97\UNWISE.EXE C:\PROGRA~1\TLAB97\INSTALL.LOG

    V CAST Music with Rhapsody (V CAST Music with Rhapsody)
    uninstall cmd: C:\PROGRA~1\VCASTM~1\Unwise32.exe /A C:\PROGRA~1\VCASTM~1\install.log

    Windows Genuine Advantage Notifications (KB905474) 1.8.0031.9 (WgaNotify)
    install date: 20090120
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=905474

    (WIC)

    Windows Media Format 11 runtime (Windows Media Format Runtime)
    uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    help link: http://go.microsoft.com/fwlink/?LinkId=62768

    Windows XP Service Pack 3 20080414.031525 (Windows XP Service Pack)
    install date: 20090120
    uninstall cmd: "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=936929

    Windows Media Format 11 runtime (WMFDist11)
    install date: 20081214
    uninstall cmd: "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http:

    Microsoft User-Mode Driver Framework Feature Pack 1.0 (Wudf01000)
    install date: 20081214
    uninstall cmd: "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    comments: Build Number 5716

    Macromedia Dreamweaver MX 2004 7.0 ({05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A})
    version (major): 7
    install location: C:\Program Files\Macromedia\Dreamweaver MX 2004
    install source: C:\Program Files\Macromedia
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}\Setup.exe" -l0x9 mmUninstall
    publisher: Macromedia
    help link: http://www.macromedia.com/go/dreamweaver_support/

    Attansic Giga Ethernet Utility 1.0 ({1F698102-5739-441E-96F0-74F4EA540F06})
    version: 16777216
    install location: C:\Program Files\Attansic\Attansic Giga Ethernet Utility
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F698102-5739-441E-96F0-74F4EA540F06}\setup.exe" -l0x9

    Java(TM) 6 Update 11 6.0.110 ({26A24AE4-039D-4CA4-87B4-2F83216011FF})
    version: 100663406
    version (major): 6
    estimated size: 92660
    install date: 20090121
    install location: C:\Program Files\Java\jre6\
    install source: C:\Documents and Settings\Me\Application Data\Sun\Java\jre1.6.0_11\
    uninstall cmd: MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
    publisher: Sun Microsystems, Inc.
    contact: http://java.com
    help link: http://java.com
    readme: C:\Program Files\Java\jre6\README.txt

    RegAlyzer (OpenSBI Edition) 1.6.0.12 ({296B2D8E-CE82-92AF-B2E8-A646E7CB78A2}_is1)
    install date: 20090106
    install location: C:\Program Files\Safer Networking\RegAlyzer\
    uninstall cmd: "C:\Program Files\Safer Networking\RegAlyzer\unins000.exe"
    publisher: Safer Networking Limited
    help link: http://forums.spybot.info/forumdisplay.php?f=6

    FileAlyzer 1.6.0.4 ({29D3773E-54F4-23C2-D523-236A4453B844}_is1)
    install date: 20090106
    install location: C:\Program Files\Safer Networking\FileAlyzer\
    uninstall cmd: "C:\Program Files\Safer Networking\FileAlyzer\unins000.exe"
    publisher: Safer Networking Limited
    help link: http://forums.spybot.info/forumdisplay.php?f=5

    WebFldrs XP 9.50.7523 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227})
    version: 154279267
    version (major): 9
    version (minor): 50
    estimated size: 2472
    install date: 20071220
    install source: C:\WINDOWS\system32\
    publisher: Microsoft Corporation
    help link: http://www.microsoft.com/windows

    FreeRIP v3.091 3.091 ({501451DE-5808-4599-B544-8BD0915B6B24}_is1)
    install date: 20081121
    install location: C:\Program Files\FreeRIP3\
    uninstall cmd: "C:\Program Files\FreeRIP3\unins000.exe"
    publisher: MGShareware

    PowerDVD ({6811CAA0-BF12-11D4-9EA1-0050BAE317E1})
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall

    Adobe Audition 1.5 1.5 ({86EF9FC4-F209-4520-B7E1-C7FF0EEBDFFF})
    version: 17104896
    version (major): 1
    version (minor): 5
    estimated size: 42440
    install date: 20071219
    install location: C:\Program Files\Adobe\Audition 1.5\
    install source: C:\WINDOWS\Downloaded Installations\{35C2718C-FF5F-493C-BAB7-9366A3D34245}\
    publisher: Adobe Systems
    contact: Customer Support
    help link: http://www.adobe.com/support/main.html
    readme: C:\Program Files\Adobe\Audition 1.5\Readme.htm

    Microsoft Office Professional Edition 2003 11.0.8173.0 ({90110409-6000-11D3-8CFE-0150048383C9})
    version: 184557549
    version (major): 11
    estimated size: 778486
    install date: 20090121
    install source: D:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\
    uninstall cmd: MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
    publisher: Microsoft Corporation
    help link: http://www.microsoft.com/support
    readme: C:\Program Files\Microsoft Office\OFFICE11\1033\OFREADME.HTM

    RunAlyzer 1.6.0.21 ({A5181519-9F3D-4372-ABC6-C333C2F3A816}_is1)
    install date: 20090106
    install location: C:\Program Files\Safer Networking\RunAlyzer\
    uninstall cmd: "C:\Program Files\Safer Networking\RunAlyzer\unins000.exe"
    publisher: Safer Networking Limited
    help link: http://forums.spybot.info/forumdisplay.php?f=8

    Macromedia Extension Manager 1.5 ({A5BA14E0-7384-11D4-BAE7-00409631A2C8})
    version (major): 1
    version (minor): 5
    install location: C:\Program Files\Macromedia\Extension Manager
    install source: C:\Program Files\Macromedia
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5BA14E0-7384-11D4-BAE7-00409631A2C8}\setup.exe" -l0x9 mmUninstall
    publisher: Macromedia
    help link: http://www.macromedia.com/go/exchange/

    Adobe Reader 8.1.2 8.1.2 ({AC76BA86-7AD7-1033-7B44-A81200000003})
    version: 134283266
    version (major): 8
    version (minor): 1
    estimated size: 88543
    install date: 20080301
    install source: C:\Documents and Settings\Me\Local Settings\Application Data\Adobe\Updater5\Install\reader8rdr-en_US\
    uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
    publisher: Adobe Systems Incorporated
    comments:
    contact: Customer Support
    help link: http://www.adobe.com/support/main.html
    readme: [INSTALLDIR]Reader\Readme.htm

    Spybot - Search & Destroy 1.6.0 ({B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1)
    install date: 20080913
    install location: C:\Program Files\Spybot - Search & Destroy\
    uninstall cmd: "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    publisher: Safer Networking Limited
    help link: http://www.safer-networking.org/index.php?page=support

    Realtek High Definition Audio Driver 5.10.0.5345 ({F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC})
    version: 35127296
    install date: 20071219
    install location: C:\Program Files\Realtek\InstallShield\
    install source: D:\Hardware Drivers\MoBo CD\Drivers\Audio\Driver\
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
    publisher: Realtek Semiconductor Corp.

    Uno 5.2.3.016 ({F8E28912-A7B8-488C-B259-33F9014B9D09})
    version: 84017155
    install location: C:\Program Files\M-Audio Uno
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F8E28912-A7B8-488C-B259-33F9014B9D09}\setup.exe" -l0x9

    LG USB Modem Drivers 4.8.1 ({FA02ACAC-9E14-4878-A257-92A22A647C2C})
    version: 67633153
    version (major): 4
    version (minor): 8
    estimated size: 964
    install date: 20081213
    install source: C:\Documents and Settings\Me\Templates\
    uninstall cmd: MsiExec.exe /I{FA02ACAC-9E14-4878-A257-92A22A647C2C}
    publisher: LG Electronics
    contact: LG Electronics

  8. #28
    Member
    Join Date
    Jan 2009
    Posts
    35

    Default

    --- System Services ---
    Service (registry key): Abiosdsk
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 0

    Service (registry key): abp480n5
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ACPI
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft ACPI Driver
    Image path: system32\DRIVERS\ACPI.sys
    Image size: 187776
    Image MD5: 8FD99680A539792A30E97944FDAECF17
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): ACPIEC
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): adpu160m
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): aec
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Kernel Acoustic Echo Canceller
    Image path: system32\drivers\aec.sys
    Image size: 142592
    Image MD5: 8BED39E3C35D6A489438B8141717A557
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): AFD
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AFD
    Description: AFD Networking Support Environment
    Image path: \SystemRoot\System32\drivers\afd.sys
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Aha154x
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): aic78u2
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): aic78xx
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Alerter
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Alerter
    Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: LanmanWorkstation

    Service (registry key): ALG
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Application Layer Gateway Service
    Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\alg.exe
    Image size: 44544
    Image MD5: 8C515081584A38AA007909CD02020B3D
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): AliIde
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): amsint
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): AppMgmt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Application Management
    Description: Provides software installation services such as Assign, Publish, and Remove.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1

    Service (registry key): asc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): asc3350p
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): asc3550
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): AsyncMac
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: RAS Asynchronous Media Driver
    Description: RAS Asynchronous Media Driver
    Image path: system32\DRIVERS\asyncmac.sys
    Image size: 14336
    Image MD5: B153AFFAC761E7F5FCFA822B9C4E97BC
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): atapi
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Standard IDE/ESDI Hard Disk Controller
    Image path: system32\DRIVERS\atapi.sys
    Image size: 96512
    Image MD5: 9F3A2F5AA6875C72BF062C712CFA2674
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): AtcL002
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: NDIS Miniport Driver for Attansic L2 Fast Ethernet Controller
    Image path: system32\DRIVERS\atl02_xp.sys
    Image size: 28416
    Image MD5: 07ED1101F574B93A6312BF5D4241B41A
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Atdisk
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 0

    Service (registry key): Atmarpc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: ATM ARP Client Protocol
    Description: ATM ARP Client Protocol
    Image path: system32\DRIVERS\atmarpc.sys
    Image size: 59904
    Image MD5: 9916C1225104BA14794209CFA8012159
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): AudioSrv
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Audio
    Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: PlugPlay,RpcSs

    Service (registry key): audstub
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Audio Stub Driver
    Image path: system32\DRIVERS\audstub.sys
    Image size: 3072
    Image MD5: D9F724AA26C010A217C97606B160ED68
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Avg7Alrt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AVG7 Alert Manager Server
    Object name: LocalSystem
    Image path: C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    Image size: 418816
    Image MD5: 3C7B93F947355E374A49564D0D017B7B
    Control Set: CurrentControlSet
    Start: 2
    Type: 272
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): Avg7Core
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AVG7 Kernel
    Image path: \SystemRoot\System32\Drivers\avg7core.sys
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Avg7RsW
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AVG7 Wrap Driver
    Image path: \SystemRoot\System32\Drivers\avg7rsw.sys
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Avg7RsXP
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AVG7 Resident Driver XP
    Image path: \SystemRoot\System32\Drivers\avg7rsxp.sys
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Avg7UpdSvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AVG7 Update Service
    Object name: LocalSystem
    Image path: C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    Image size: 49664
    Image MD5: 30A14F65DB477DC00A64A5A24E96919C
    Control Set: CurrentControlSet
    Start: 2
    Type: 16
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): AvgClean
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AVG7 Clean Driver
    Image path: \SystemRoot\System32\Drivers\avgclean.sys
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): AVGEMS
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AVG E-mail Scanner
    Object name: LocalSystem
    Image path: C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    Image size: 406528
    Image MD5: FC0B2AE890BB0DC8C2306DABEDC8A4BA
    Control Set: CurrentControlSet
    Start: 2
    Type: 272
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): AvgTdi
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: AVG Network Redirector
    Image path: \SystemRoot\System32\Drivers\avgtdi.sys
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 2
    Type: 1
    Error Control: 1

    Service (registry key): BattC
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Beep
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): BITS
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Background Intelligent Transfer Service
    Description: Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: Rpcss

    Service (registry key): Browser
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Computer Browser
    Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: LanmanWorkstation,LanmanServer

    Service (registry key): cbidf2k
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): CCDECODE
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Closed Caption Decoder
    Image path: system32\DRIVERS\CCDECODE.sys
    Image size: 17024
    Image MD5: 0BE5AEF125BE881C4F854C554F2B025C
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): cd20xrnt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Cdaudio
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): Cdfs
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 2
    Error Control: 1
    Depends On group: "SCSI CDROM Class"

    Service (registry key): Cdrom
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: CD-ROM Driver
    Image path: system32\DRIVERS\cdrom.sys
    Image size: 62976
    Image MD5: 1F4260CC5B42272D71F79E570A27A4FE
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1
    Depends On group: "SCSI miniport"

    Service (registry key): Changer
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): CiSvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Indexing Service
    Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\cisvc.exe
    Image size: 5632
    Image MD5: 1CFE720EB8D93A7158A4EBC3AB178BDE
    Control Set: CurrentControlSet
    Start: 3
    Type: 288
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): ClipSrv
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: ClipBook
    Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\clipsrv.exe
    Image size: 33280
    Image MD5: 34CBE729F38138217F9C80212A2A0C82
    Control Set: CurrentControlSet
    Start: 4
    Type: 16
    Error Control: 1
    Depends On services: NetDDE

    Service (registry key): CmdIde
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): COMSysApp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: COM+ System Application
    Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    Image size: 5120
    Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: rpcss

    Service (registry key): ContentFilter
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): ContentIndex
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Cpqarray
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): CryptSvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Cryptographic Services
    Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): dac2w2k
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 0

    Service (registry key): dac960nt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): DcomLaunch
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: DCOM Server Process Launcher
    Description: Provides launch functionality for DCOM services.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost -k DcomLaunch
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): Dhcp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: DHCP Client
    Description: Manages network configuration by registering and updating IP addresses and DNS names.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: Tcpip,Afd,NetBT

    Service (registry key): Disk
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Disk Driver
    Image path: system32\DRIVERS\disk.sys
    Image size: 36352
    Image MD5: 044452051F3E02E7963599FC8F4F3E25
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1
    Depends On group: "SCSI miniport"

    Service (registry key): dmadmin
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Logical Disk Manager Administrative Service
    Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\dmadmin.exe /com
    Image size: 224768
    Image MD5: E46050330BD42F33609117F861E32D3C
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs,PlugPlay,DmServer

    Service (registry key): dmboot
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: System32\drivers\dmboot.sys
    Image size: 799744
    Image MD5: D992FE1274BDE0F84AD826ACAE022A41
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): dmio
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Logical Disk Manager Driver
    Image path: System32\drivers\dmio.sys
    Image size: 153344
    Image MD5: 7C824CF7BBDE77D95C08005717A95F6F
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): dmload
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: System32\drivers\dmload.sys
    Image size: 5888
    Image MD5: E9317282A63CA4D188C0DF5E09C6AC5F
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): dmserver
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Logical Disk Manager
    Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs,PlugPlay

    Service (registry key): DMusic
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Kernel DLS Syntheiszer
    Image path: system32\drivers\DMusic.sys
    Image size: 52864
    Image MD5: 8A208DFCF89792A484E76C40E5F50B45
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Dnscache
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: DNS Client
    Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): Dot3svc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Wired AutoConfig
    Description: This service performs IEEE 802.1X authentication on Ethernet interfaces
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k dot3svc
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: Ndisuio,eaphost

    Service (registry key): dpti2o
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): drmkaud
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Kernel DRM Audio Descrambler
    Image path: system32\drivers\drmkaud.sys
    Image size: 2944
    Image MD5: 8F5FCFF8E8848AFAC920905FBD9D33C8
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): EapHost
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Extensible Authentication Protocol Service
    Description: Provides windows clients Extensible Authentication Protocol Service
    Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k eapsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): ERSvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Error Reporting Service
    Description: Allows error reporting for services and applictions running in non-standard environments.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 0
    Depends On services: RpcSs

    Service (registry key): Eventlog
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Event Log
    Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\services.exe
    Image size: 108544
    Image MD5: 0E776ED5F7CC9F94299E70461B7B8185
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): EventSystem
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: COM+ Event System
    Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): EVOLUSB
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: %EVOL_USB_SvcDesc%
    Image path: system32\drivers\evolusb.sys
    Image size: 21984
    Image MD5: A7BC1540D238D2CDBDE238902F7C2AD8
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Fastfat
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 2
    Error Control: 1

    Service (registry key): FastUserSwitchingCompatibility
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Fast User Switching Compatibility
    Description: Provides management for applications that require assistance in a multiple user environment.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: TermService

    Service (registry key): Fdc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Floppy Disk Controller Driver
    Image path: system32\DRIVERS\fdc.sys
    Image size: 27392
    Image MD5: 92CDD60B6730B9F50F6A1A0C1F8CDC81
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Fips
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Flpydisk
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Floppy Disk Driver
    Image path: system32\DRIVERS\flpydisk.sys
    Image size: 20480
    Image MD5: 9D27E7B80BFCDF1CDD9B555862D5E7F0
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): FltMgr
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: FltMgr
    Description: File System Filter Manager Driver
    Image path: system32\drivers\fltmgr.sys
    Image size: 129792
    Image MD5: B2CF4B0786F8212CB92ED2B50C6DB6B0
    Control Set: CurrentControlSet
    Start: 0
    Type: 2
    Error Control: 1

    Service (registry key): Fs_Rec
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 8
    Error Control: 0

    Service (registry key): Ftdisk
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Volume Manager Driver
    Image path: system32\DRIVERS\ftdisk.sys
    Image size: 125056
    Image MD5: 6AC26732762483366C3969C9E4D2259D
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): Gpc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Generic Packet Classifier
    Description: Generic Packet Classifier
    Image path: system32\DRIVERS\msgpc.sys
    Image size: 35072
    Image MD5: 0A02C63C8B144BD8C86B103DEE7C86A2
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): HDAudBus
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft UAA Bus Driver for High Definition Audio
    Image path: system32\DRIVERS\HDAudBus.sys
    Image size: 144384
    Image MD5: 573C7D0A32852B48F3058CFD8026F511
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): helpsvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Help and Support
    Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): HidServ
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Human Interface Device Access
    Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): HidUsb
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft HID Class Driver
    Image path: system32\DRIVERS\hidusb.sys
    Image size: 10368
    Image MD5: CCF82C5EC8A7326C3066DE870C06DAF1
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): hkmsvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Health Key and Certificate Management Service
    Description: Manages health certificates and keys (used by NAP)
    Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): hpn
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): HTTP
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: HTTP
    Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start.
    Image path: System32\Drivers\HTTP.sys
    Image size: 264832
    Image MD5: F6AACF5BCE2893E0C1754AFEB672E5C9
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): HTTPFilter
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: HTTP SSL
    Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: HTTP

    Service (registry key): i2omgmt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): i2omp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): i8042prt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: i8042 Keyboard and PS/2 Mouse Port Driver
    Image path: system32\DRIVERS\i8042prt.sys
    Image size: 52480
    Image MD5: 4A0B06AA8943C1E332520F7440C0AA30
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): ialm
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: system32\DRIVERS\igxpmp32.sys
    Image size: 1181824
    Image MD5: 6FCB904910DA07C9DC2593D66438FA29
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): Imapi
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: CD-Burning Filter Driver
    Image path: system32\DRIVERS\imapi.sys
    Image size: 42112
    Image MD5: 083A052659F5310DD8B6A6CB05EDCF8E
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): ImapiService
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IMAPI CD-Burning COM Service
    Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\imapi.exe
    Image size: 150528
    Image MD5: 30DEAF54A9755BB8546168CFE8A6B5E1
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): inetaccs
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): ini910u
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Inport
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): IntcAzAudAddService
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Service for Realtek HD Audio (WDM)
    Image path: system32\drivers\RtkHDAud.sys
    Image size: 4405248
    Image MD5: 001AACA6ED0E6B00FC5B8FAF74977E81
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): IntelIde
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): intelppm
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Intel Processor Driver
    Image path: system32\DRIVERS\intelppm.sys
    Image size: 36352
    Image MD5: 8C953733D8F36EB2133F5BB58808B66B
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Ip6Fw
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IPv6 Windows Firewall Driver
    Description: Provides intrusion prevention service for a home or small office network.
    Image path: system32\drivers\ip6fw.sys
    Image size: 36608
    Image MD5: 3BB22519A194418D5FEC05D800A19AD0
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): IpFilterDriver
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IP Traffic Filter Driver
    Description: IP Traffic Filter Driver
    Image path: system32\DRIVERS\ipfltdrv.sys
    Image size: 32896
    Image MD5: 731F22BA402EE4B62748ADAF6363C182
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): IpInIp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IP in IP Tunnel Driver
    Description: IP in IP Tunnel Driver
    Image path: system32\DRIVERS\ipinip.sys
    Image size: 20864
    Image MD5: B87AB476DCF76E72010632B5550955F5
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): IpNat
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IP Network Address Translator
    Description: IP Network Address Translator
    Image path: system32\DRIVERS\ipnat.sys
    Image size: 152832
    Image MD5: CC748EA12C6EFFDE940EE98098BF96BB
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): IPSec
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IPSEC driver
    Description: IPSEC driver
    Image path: system32\DRIVERS\ipsec.sys
    Image size: 75264
    Image MD5: 23C74D75E36E7158768DD63D92789A91
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): IRENUM
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IR Enumerator Service
    Image path: system32\DRIVERS\irenum.sys
    Image size: 11264
    Image MD5: C93C9FF7B04D772627A3646D89F7BF89
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): ISAPISearch
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): isapnp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: PnP ISA/EISA Bus Driver
    Image path: system32\DRIVERS\isapnp.sys
    Image size: 37248
    Image MD5: 05A299EC56E52649B1CF2FC52D20F2D7
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 3

    Service (registry key): JavaQuickStarterService
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Java Quick Starter
    Description: Prefetches JRE files for faster startup of Java applets and applications
    Object name: LocalSystem
    Image path: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
    Image size: 152984
    Image MD5: 32192B4EBE8720ED8D49A455C962CB91
    Control Set: CurrentControlSet
    Start: 2
    Type: 16
    Error Control: 1

    Service (registry key): Kbdclass
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Keyboard Class Driver
    Image path: system32\DRIVERS\kbdclass.sys
    Image size: 24576
    Image MD5: 463C1EC80CD17420A542B7F36A36F128
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): kbdhid
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Keyboard HID Driver
    Image path: system32\DRIVERS\kbdhid.sys
    Image size: 14592
    Image MD5: 9EF487A186DEA361AA06913A75B3FA99
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): kmixer
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Kernel Wave Audio Mixer
    Image path: system32\drivers\kmixer.sys
    Image size: 172416
    Image MD5: 692BCF44383D056AED41B045A323D378
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): KSecDD
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): lanmanserver
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Server
    Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): lanmanworkstation
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Workstation
    Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): lbrtfdc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): ldap
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

  9. #29
    Member
    Join Date
    Jan 2009
    Posts
    35

    Default

    Service (registry key): LicenseService
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): LmHosts
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: TCP/IP NetBIOS Helper
    Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: NetBT,Afd

    Service (registry key): Macromedia Licensing Service
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Macromedia Licensing Service
    Description: Provides authentication services for Macromedia applications.
    Object name: LocalSystem
    Image path: "C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"
    Image size: 68096
    Image MD5: B8EAC4507EB4655377B1E094FCE7F12E
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): MADFUUSB
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): MCSTRM
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: MCSTRM
    Control Set: CurrentControlSet
    Start: 2
    Type: 1
    Error Control: 1

    Service (registry key): MDM
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Machine Debug Manager
    Description: Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly.
    Object name: LocalSystem
    Image path: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
    Image size: 322120
    Image MD5: 11F714F85530A2BD134074DC30E99FCA
    Control Set: CurrentControlSet
    Start: 2
    Type: 272
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): Messenger
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Messenger
    Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS

    Service (registry key): mnmdd
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): mnmsrvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: NetMeeting Remote Desktop Sharing
    Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\mnmsrvc.exe
    Image size: 32768
    Image MD5: D18F1F0C101D06A1C1ADF26EED16FCDD
    Control Set: CurrentControlSet
    Start: 3
    Type: 272
    Error Control: 1

    Service (registry key): Modem
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): Mouclass
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Mouse Class Driver
    Image path: system32\DRIVERS\mouclass.sys
    Image size: 23040
    Image MD5: 35C9E97194C8CFB8430125F8DBC34D04
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): MountMgr
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Mount Point Manager
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): mraid35x
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): MRxDAV
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: WebDav Client Redirector
    Description: WebDav Client Redirector
    Image path: system32\DRIVERS\mrxdav.sys
    Image size: 180608
    Image MD5: 11D42BB6206F33FBB3BA0288D3EF81BD
    Control Set: CurrentControlSet
    Start: 3
    Type: 2
    Error Control: 1

    Service (registry key): MRxSmb
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: MRXSMB
    Description: MRXSMB
    Image path: system32\DRIVERS\mrxsmb.sys
    Image size: 455296
    Image MD5: 60AE98742484E7AB80C3C1450E708148
    Control Set: CurrentControlSet
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): MSDTC
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Distributed Transaction Coordinator
    Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\NetworkService
    Image path: C:\WINDOWS\system32\msdtc.exe
    Image size: 6144
    Image MD5: A137F1470499A205ABBB9AAFB3B6F2B1
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RPCSS,SamSS

    Service (registry key): Msfs
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): MSIServer
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Installer
    Description: Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\msiexec.exe /V
    Image size: 78848
    Image MD5: 5879D691E842574A20FE63817CB76DF9
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): MSKSSRV
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Streaming Service Proxy
    Image path: system32\drivers\MSKSSRV.sys
    Image size: 7552
    Image MD5: D1575E71568F4D9E14CA56B7B0453BF1
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): MSPCLOCK
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Streaming Clock Proxy
    Image path: system32\drivers\MSPCLOCK.sys
    Image size: 5376
    Image MD5: 325BB26842FC7CCC1FCCE2C457317F3E
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): MSPQM
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Streaming Quality Manager Proxy
    Image path: system32\drivers\MSPQM.sys
    Image size: 4992
    Image MD5: BAD59648BA099DA4A17680B39730CB3D
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): mssmbios
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft System Management BIOS Driver
    Image path: system32\DRIVERS\mssmbios.sys
    Image size: 15488
    Image MD5: AF5F4F3F14A8EA2C26DE30F7A1E17136
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): MSTEE
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Streaming Tee/Sink-to-Sink Converter
    Image path: system32\drivers\MSTEE.sys
    Image size: 5504
    Image MD5: E53736A9E30C45FA9E7B5EAC55056D1D
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): MTsensor
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: ATK0110 ACPI UTILITY
    Image path: system32\DRIVERS\ASACPI.sys
    Image size: 5810
    Image MD5: D48659BB24C48345D926ECB45C1EBDF5
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Mup
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Mup
    Control Set: CurrentControlSet
    Start: 0
    Type: 2
    Error Control: 1

    Service (registry key): NABTSFEC
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: NABTS/FEC VBI Codec
    Image path: system32\DRIVERS\NABTSFEC.sys
    Image size: 85248
    Image MD5: 5B50F1B2A2ED47D560577B221DA734DB
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): napagent
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Network Access Protection Agent
    Description: Allows windows clients to participate in Network Access Protection
    Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): NDIS
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: NDIS System Driver
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): NdisIP
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft TV/Video Connection
    Image path: system32\DRIVERS\NdisIP.sys
    Image size: 10880
    Image MD5: 7FF1F1FD8609C149AA432F95A8163D97
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NdisTapi
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Access NDIS TAPI Driver
    Description: Remote Access NDIS TAPI Driver
    Image path: system32\DRIVERS\ndistapi.sys
    Image size: 10112
    Image MD5: 1AB3D00C991AB086E69DB84B6C0ED78F
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Ndisuio
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: NDIS Usermode I/O Protocol
    Description: NDIS Usermode I/O Protocol
    Image path: system32\DRIVERS\ndisuio.sys
    Image size: 14592
    Image MD5: F927A4434C5028758A842943EF1A3849
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NdisWan
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Access NDIS WAN Driver
    Description: Remote Access NDIS WAN Driver
    Image path: system32\DRIVERS\ndiswan.sys
    Image size: 91520
    Image MD5: EDC1531A49C80614B2CFDA43CA8659AB
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NDProxy
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NetBIOS
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: NetBIOS Interface
    Description: NetBIOS Interface
    Image path: system32\DRIVERS\netbios.sys
    Image size: 34688
    Image MD5: 5D81CF9A2F1A3A756B66CF684911CDF0
    Control Set: CurrentControlSet
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): NetBT
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: NetBios over Tcpip
    Description: NetBios over Tcpip
    Image path: system32\DRIVERS\netbt.sys
    Image size: 162816
    Image MD5: 74B2B2F5BEA5E9A3DC021D685551BD3D
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): NetDDE
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Network DDE
    Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\netdde.exe
    Image size: 111104
    Image MD5: B857BA82860D7FF85AE29B095645563B
    Control Set: CurrentControlSet
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: NetDDEDSDM

    Service (registry key): NetDDEdsdm
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Network DDE DSDM
    Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\netdde.exe
    Image size: 111104
    Image MD5: B857BA82860D7FF85AE29B095645563B
    Control Set: CurrentControlSet
    Start: 4
    Type: 32
    Error Control: 1

    Service (registry key): Netlogon
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Net Logon
    Description: Supports pass-through authentication of account logon events for computers in a domain.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 13312
    Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: LanmanWorkstation

    Service (registry key): Netman
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Network Connections
    Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 288
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): Nla
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Network Location Awareness (NLA)
    Description: Collects and stores network configuration and location information, and notifies applications when this information changes.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: Tcpip,Afd

    Service (registry key): Npfs
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): Ntfs
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 2
    Error Control: 1

    Service (registry key): NtLmSsp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: NT LM Security Support Provider
    Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 13312
    Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1

    Service (registry key): NtmsSvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Removable Storage
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): Null
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): NwlnkFlt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IPX Traffic Filter Driver
    Description: IPX Traffic Filter Driver
    Image path: system32\DRIVERS\nwlnkflt.sys
    Image size: 12416
    Image MD5: B305F3FAD35083837EF46A0BBCE2FC57
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: NwlnkFwd

    Service (registry key): NwlnkFwd
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IPX Traffic Forwarder Driver
    Description: IPX Traffic Forwarder Driver
    Image path: system32\DRIVERS\nwlnkfwd.sys
    Image size: 32512
    Image MD5: C99B3415198D1AAB7227F2C88FD664B9
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): ose
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Office Source Engine
    Description: Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.
    Object name: LocalSystem
    Image path: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
    Image size: 89136
    Image MD5: 7A56CF3E3F12E8AF599963B16F50FB6A
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): Outlook
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Parport
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Parallel port driver
    Image path: system32\DRIVERS\parport.sys
    Image size: 80128
    Image MD5: 5575FAF8F97CE5E713D108C2A58D7C7C
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): PartMgr
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Partition Manager
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): ParVdm
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 2
    Type: 1
    Error Control: 0
    Depends On services: Parport
    Depends On group: "Parallel arbitrator"

    Service (registry key): PCI
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: PCI Bus Driver
    Image path: system32\DRIVERS\pci.sys
    Image size: 68224
    Image MD5: A219903CCF74233761D92BEF471A07B1
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 3

    Service (registry key): PCIDump
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): PCIIde
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: system32\DRIVERS\pciide.sys
    Image size: 3328
    Image MD5: CCF5F451BB1A5A2A522A76E670000FF0
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): Pcmcia
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): PDCOMP
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): PDFRAME
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): PDRELI
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): PDRFRAME
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): perc2
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): perc2hib
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): PerfDisk
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): PerfNet
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): PerfOS
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): PerfProc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): pfc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Padus ASPI Shell
    Image path: system32\drivers\pfc.sys
    Image size: 10368
    Image MD5: 444F122E68DB44C0589227781F3C8B3F
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): PhilCam8116
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Logitech QuickCam Pro 3000 (08B0)
    Image path: system32\DRIVERS\CamDrO21.sys
    Image size: 314752
    Image MD5: 8754763A924639B9D07D4C8EA9990F1E
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): PlugPlay
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Plug and Play
    Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\services.exe
    Image size: 108544
    Image MD5: 0E776ED5F7CC9F94299E70461B7B8185
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): PolicyAgent
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: IPSEC Services
    Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 13312
    Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RPCSS,Tcpip,IPSec

    Service (registry key): PptpMiniport
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: WAN Miniport (PPTP)
    Description: WAN Miniport (PPTP)
    Image path: system32\DRIVERS\raspptp.sys
    Image size: 48384
    Image MD5: EFEEC01B1D3CF84F16DDD24D9D9D8F99
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): ProtectedStorage
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Protected Storage
    Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 13312
    Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
    Control Set: CurrentControlSet
    Start: 2
    Type: 288
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): PSched
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: QoS Packet Scheduler
    Description: QoS Packet Scheduler
    Image path: system32\DRIVERS\psched.sys
    Image size: 69120
    Image MD5: 09298EC810B07E5D582CB3A3F9255424
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Gpc

    Service (registry key): Ptilink
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Direct Parallel Link Driver
    Description: Direct Parallel Link Driver
    Image path: system32\DRIVERS\ptilink.sys
    Image size: 17792
    Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): ql1080
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Ql10wnt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ql12160
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ql1240
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ql1280
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): RasAcd
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Access Auto Connection Driver
    Description: Remote Access Auto Connection Driver
    Image path: system32\DRIVERS\rasacd.sys
    Image size: 8832
    Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): RasAuto
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Access Auto Connection Manager
    Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RasMan,Tapisrv

    Service (registry key): Rasl2tp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: WAN Miniport (L2TP)
    Description: WAN Miniport (L2TP)
    Image path: system32\DRIVERS\rasl2tp.sys
    Image size: 51328
    Image MD5: 11B4A627BC9614B885C4969BFA5FF8A6
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): RasMan
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Access Connection Manager
    Description: Creates a network connection.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: Tapisrv

    Service (registry key): RasPppoe
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Access PPPOE Driver
    Description: Remote Access PPPOE Driver
    Image path: system32\DRIVERS\raspppoe.sys
    Image size: 41472
    Image MD5: 5BC962F2654137C9909C3D4603587DEE
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Raspti
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Direct Parallel
    Description: Direct Parallel
    Image path: system32\DRIVERS\raspti.sys
    Image size: 16512
    Image MD5: FDBB1D60066FCFBB7452FD8F9829B242
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Rdbss
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Rdbss
    Description: Rdbss
    Image path: system32\DRIVERS\rdbss.sys
    Image size: 175744
    Image MD5: 7AD224AD1A1437FE28D89CF22B17780A
    Control Set: CurrentControlSet
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): RDPCDD
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: System32\DRIVERS\RDPCDD.sys
    Image size: 4224
    Image MD5: 4912D5B403614CE99C28420F75353332
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): RDPDD
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): rdpdr
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Terminal Server Device Redirector Driver
    Image path: system32\DRIVERS\rdpdr.sys
    Image size: 196224
    Image MD5: 15CABD0F7C00C47C70124907916AF3F1
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): RDPNP
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): RDPWD
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): RDSessMgr
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Desktop Help Session Manager
    Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\sessmgr.exe
    Image size: 141312
    Image MD5: 3C37BF86641BDA977C3BF8A840F3B7FA
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): redbook
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Digital CD Audio Playback Filter Driver
    Image path: system32\DRIVERS\redbook.sys
    Image size: 57600
    Image MD5: F828DD7E1419B6653894A8F97A0094C5
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): RemoteAccess
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Routing and Remote Access
    Description: Offers routing services to businesses in local area and wide area network environments.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: RpcSS
    Depends On group: NetBIOSGroup

    Service (registry key): RemoteRegistry
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Registry
    Description: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): RpcLocator
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Procedure Call (RPC) Locator
    Description: Manages the RPC name service database.
    Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\system32\locator.exe
    Image size: 75264
    Image MD5: AAED593F84AFA419BBAE8572AF87CF6A
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: LanmanWorkstation

    Service (registry key): RpcSs
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Procedure Call (RPC)
    Description: Provides the endpoint mapper and other miscellaneous RPC services.
    Object name: NT Authority\NetworkService
    Image path: %SystemRoot%\system32\svchost -k rpcss
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): RSVP
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: QoS RSVP
    Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\rsvp.exe
    Image size: 132608
    Image MD5: 471B3F9741D762ABE75E9DEEA4787E47
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: TcpIp,Afd,RpcSs

    Service (registry key): SamSs
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Security Accounts Manager
    Description: Stores security information for local user accounts.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 13312
    Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): SCardSvr
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Smart Card
    Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\SCardSvr.exe
    Image size: 95744
    Image MD5: 86D007E7A654B9A71D1D7D856B104353
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 0
    Depends On services: PlugPlay

    Service (registry key): Schedule
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Task Scheduler
    Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): ScsiPort
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: %SystemRoot%\system32\drivers\scsiport.sys
    Image size: 96384
    Image MD5: 76C465F570E90C28942D52CCB2580A10
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Secdrv
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Secdrv
    Description: SafeDisc driver
    Image path: system32\DRIVERS\secdrv.sys
    Image size: 20480
    Image MD5: 90A3935D05B494A5A39D37E71F09A677
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

  10. #30
    Member
    Join Date
    Jan 2009
    Posts
    35

    Default

    Service (registry key): seclogon
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Secondary Logon
    Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 288
    Error Control: 0

    Service (registry key): SENS
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: System Event Notification
    Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: EventSystem

    Service (registry key): serenum
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Serenum Filter Driver
    Image path: system32\DRIVERS\serenum.sys
    Image size: 15744
    Image MD5: 0F29512CCD6BEAD730039FB4BD2C85CE
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Serial
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Serial port driver
    Image path: system32\DRIVERS\serial.sys
    Image size: 64512
    Image MD5: CCA207A8896D4C6A0C9CE29A4AE411A7
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): Sfloppy
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0
    Depends On group: "SCSI miniport"

    Service (registry key): SharedAccess
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Firewall/Internet Connection Sharing (ICS)
    Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: Netman,WinMgmt

    Service (registry key): ShellHWDetection
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Shell Hardware Detection
    Description: Provides notifications for AutoPlay hardware events.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 0
    Depends On services: RpcSs

    Service (registry key): Simbad
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): SLIP
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: BDA Slip De-Framer
    Image path: system32\DRIVERS\SLIP.sys
    Image size: 11136
    Image MD5: 866D538EBE33709A5C9F5C62B73B7D14
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Sparrow
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): splitter
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Kernel Audio Splitter
    Image path: system32\drivers\splitter.sys
    Image size: 6272
    Image MD5: AB8B92451ECB048A4D1DE7C3FFCB4A9F
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Spooler
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Print Spooler
    Description: Loads files to memory for later printing.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\spoolsv.exe
    Image size: 57856
    Image MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
    Control Set: CurrentControlSet
    Start: 2
    Type: 272
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): sr
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: System Restore Filter Driver
    Image path: system32\DRIVERS\sr.sys
    Image size: 73472
    Image MD5: 76BB022C2FB6902FD5BDD4F78FC13A5D
    Control Set: CurrentControlSet
    Start: 0
    Type: 2
    Error Control: 1

    Service (registry key): srservice
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: System Restore Service
    Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): Srv
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Srv
    Description: Srv
    Image path: system32\DRIVERS\srv.sys
    Image size: 333952
    Image MD5: 3BB03F2BA89D2BE417206C373D2AF17C
    Control Set: CurrentControlSet
    Start: 3
    Type: 2
    Error Control: 1

    Service (registry key): SSDPSRV
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: SSDP Discovery Service
    Description: Enables discovery of UPnP devices on your home network.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: HTTP

    Service (registry key): stisvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Image Acquisition (WIA)
    Description: Provides image acquisition services for scanners and cameras.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k imgsvc
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): streamip
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: BDA IPSink
    Image path: system32\DRIVERS\StreamIP.sys
    Image size: 15232
    Image MD5: 77813007BA6265C4B6098187E6ED79D2
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): swenum
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Software Bus Driver
    Image path: system32\DRIVERS\swenum.sys
    Image size: 4352
    Image MD5: 3941D127AEF12E93ADDF6FE6EE027E0F
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): swmidi
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Kernel GS Wavetable Synthesizer
    Image path: system32\drivers\swmidi.sys
    Image size: 56576
    Image MD5: 8CE882BCC6CF8A62F2B2323D95CB3D01
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): SwPrv
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: MS Software Shadow Copy Provider
    Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{B5729F3E-860B-4534-A4BA-46D1365FF56F}
    Image size: 5120
    Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 0
    Depends On services: rpcss

    Service (registry key): swwd
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): symc810
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): symc8xx
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): sym_hi
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): sym_u3
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): sysaudio
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft Kernel System Audio Device
    Image path: system32\drivers\sysaudio.sys
    Image size: 60800
    Image MD5: 8B83F3ED0F1688B4958F77CD6D2BF290
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): SysmonLog
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Performance Logs and Alerts
    Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT Authority\NetworkService
    Image path: %SystemRoot%\system32\smlogsvc.exe
    Image size: 89600
    Image MD5: C7ABBC59B43274B1109DF6B24D617051
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): TapiSrv
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Telephony
    Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: PlugPlay,RpcSs

    Service (registry key): Tcpip
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: TCP/IP Protocol Driver
    Description: TCP/IP Protocol Driver
    Image path: system32\DRIVERS\tcpip.sys
    Image size: 361600
    Image MD5: 9AEFA14BD6B182D61E3119FA5F436D3D
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1
    Depends On services: IPSec

    Service (registry key): TDPIPE
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): TDSSserv.sys
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): TDTCP
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): TermDD
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Terminal Device Driver
    Image path: system32\DRIVERS\termdd.sys
    Image size: 40840
    Image MD5: 88155247177638048422893737429D9E
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): TermService
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Terminal Services
    Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost -k DComLaunch
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): Themes
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Themes
    Description: Provides user experience theme management.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): TlntSvr
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Telnet
    Description: Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\tlntsvr.exe
    Image size: 73216
    Image MD5: DB7205804759FF62C34E3EFD8A4CC76A
    Control Set: CurrentControlSet
    Start: 4
    Type: 16
    Error Control: 1
    Depends On services: RPCSS,TCPIP,NTLMSSP

    Service (registry key): TosIde
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): TrkWks
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Distributed Link Tracking Client
    Description: Maintains links between NTFS files within a computer or across computers in a network domain.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): TSDDD
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Udfs
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 2
    Error Control: 1

    Service (registry key): ultra
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): UnoInstallerService
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Uno Installer
    Description: M-Audio driver installer
    Object name: LocalSystem
    Image path: C:\Program Files\M-Audio Uno\UnoInst.exe
    Image size: 106496
    Image MD5: AD92577D020367F32E0BA77CC85BFFD4
    Control Set: CurrentControlSet
    Start: 2
    Type: 272
    Error Control: 1

    Service (registry key): Update
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microcode Update Driver
    Image path: system32\DRIVERS\update.sys
    Image size: 384768
    Image MD5: 402DDC88356B1BAC0EE3DD1580C76A31
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): upnphost
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Universal Plug and Play Device Host
    Description: Provides support to host Universal Plug and Play devices.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: SSDPSRV,HTTP

    Service (registry key): UPS
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Uninterruptible Power Supply
    Description: Manages an uninterruptible power supply (UPS) connected to the computer.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\ups.exe
    Image size: 18432
    Image MD5: 05365FB38FCA1E98F7A566AAAF5D1815
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): usbaudio
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: USB Audio Driver (WDM)
    Image path: system32\drivers\usbaudio.sys
    Image size: 60032
    Image MD5: E919708DB44ED8543A7C017953148330
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbbus
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: LGE CDMA Composite USB Device
    Image path: system32\DRIVERS\lgusbbus.sys
    Image size: 12416
    Image MD5: 5AADC9297C39AA249CD994ACDBA19034
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbccgp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft USB Generic Parent Driver
    Image path: system32\DRIVERS\usbccgp.sys
    Image size: 32128
    Image MD5: 173F317CE0DB8E21322E71B7E60A27E8
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): UsbDiag
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: LGE CDMA USB Serial Port
    Description: LGE CDMA USB Serial Port
    Image path: system32\DRIVERS\lgusbdiag.sys
    Image size: 19840
    Image MD5: 4650FFE04E5922399B0E932319E6B215
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbehci
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
    Image path: system32\DRIVERS\usbehci.sys
    Image size: 30208
    Image MD5: 65DCF09D0E37D4C6B11B5B0B76D470A7
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbhub
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft USB Standard Hub Driver
    Image path: system32\DRIVERS\usbhub.sys
    Image size: 59520
    Image MD5: 1AB3CDDE553B6E064D2E754EFE20285C
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): USBModem
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: LGE CDMA USB Modem
    Description: LGE CDMA Modem Support
    Image path: system32\DRIVERS\lgusbmodem.sys
    Image size: 21632
    Image MD5: 2666FE171E0C2E7085CCD5FE0BAC09E3
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): USBSTOR
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: USB Mass Storage Driver
    Image path: system32\DRIVERS\USBSTOR.SYS
    Image size: 26368
    Image MD5: A32426D9B14A089EAA1D922E0C5801A9
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbuhci
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft USB Universal Host Controller Miniport Driver
    Image path: system32\DRIVERS\usbuhci.sys
    Image size: 20608
    Image MD5: 26496F9DEE2D787FC3E61AD54821FFE6
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): VgaSave
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: VGA Display Controller.
    Description: Controls the VGA display adapter to provide basic display capabilities.
    Image path: \SystemRoot\System32\drivers\vga.sys
    Image size: 0
    Image MD5: D41D8CD98F00B204E9800998ECF8427E
    Control Set: CurrentControlSet
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): ViaIde
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): VolSnap
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): VSS
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Volume Shadow Copy
    Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\vssvc.exe
    Image size: 289792
    Image MD5: 7A9DB3A67C333BF0BD42E42B8596854B
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): W32Time
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Time
    Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): W3SVC
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Wanarp
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Remote Access IP ARP Driver
    Description: Remote Access IP ARP Driver
    Image path: system32\DRIVERS\wanarp.sys
    Image size: 34560
    Image MD5: E20B95BAEDB550F32DD489265C1DA1F6
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): WDICA
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): wdmaud
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Microsoft WINMM WDM Audio Compatibility Driver
    Image path: system32\drivers\wdmaud.sys
    Image size: 83072
    Image MD5: 6768ACF64B18196494413695F0C3A00F
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): WebClient
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: WebClient
    Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: MRxDAV

    Service (registry key): winmgmt
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Management Instrumentation
    Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 0
    Depends On services: RPCSS

    Service (registry key): Winsock
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 3
    Type: 4
    Error Control: 1

    Service (registry key): WinSock2
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): WinTrust
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): WmdmPmSN
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Portable Media Serial Number Service
    Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1

    Service (registry key): Wmi
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Management Instrumentation Driver Extensions
    Description: Provides systems management information to and from drivers.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1

    Service (registry key): WmiApRpl
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): WmiApSrv
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: WMI Performance Adapter
    Description: Provides performance library information from WMI HiPerf providers.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\wbem\wmiapsrv.exe
    Image size: 126464
    Image MD5: E0673F1106E62A68D2257E376079F821
    Control Set: CurrentControlSet
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): WpdUsb
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: WpdUsb
    Image path: System32\Drivers\wpdusb.sys
    Image size: 38528
    Image MD5: CF4DEF1BF66F06964DC0D91844239104
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): WS2IFSL
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 1
    Type: 0
    Error Control: 0

    Service (registry key): wscsvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Security Center
    Description: Monitors system security settings and configurations.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs,winmgmt

    Service (registry key): WSTCODEC
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: World Standard Teletext Codec
    Image path: system32\DRIVERS\WSTCODEC.SYS
    Image size: 19200
    Image MD5: C98B39829C2BBD34E454150633C62C78
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): wuauserv
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Automatic Updates
    Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.
    Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): WudfPf
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver
    Description: Provide communciation services for UMDF components.
    Image path: system32\DRIVERS\WudfPf.sys
    Image size: 77568
    Image MD5: F15FEAFFFBB3644CCC80C5DA584E6311
    Control Set: CurrentControlSet
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): WudfRd
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Driver Foundation - User-mode Driver Framework Reflector
    Description: Reflect device requests to user-mode driver drivers
    Image path: system32\DRIVERS\wudfrd.sys
    Image size: 82944
    Image MD5: 28B524262BCE6DE1F7EF9F510BA3985B
    Control Set: CurrentControlSet
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): WudfSvc
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Windows Driver Foundation - User-mode Driver Framework
    Description: Manages user-mode driver host processes
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: PlugPlay

    Service (registry key): WZCSVC
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Wireless Zero Configuration
    Description: Provides automatic configuration for the 802.11 adapters
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs,Ndisuio

    Service (registry key): xmlprov
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Display name: Network Provisioning Service
    Description: Manages XML configuration files on a domain basis for automatic network provisioning.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    Control Set: CurrentControlSet
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): {85665C8B-A8F4-4379-8CD7-6B811D7C569E}
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): {CF94444C-8A5F-49CD-95F7-6A8EEA620410}
    Registry path: \SYSTEM\CurrentControlSet\Services\
    Control Set: CurrentControlSet
    Start: 0
    Type: 0
    Error Control: 0

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •