--- Search result list --- MyWay.MyWebSearch: [SBI $205CC8F2] Settings (Registry key, nothing done) HKEY_USERS\S-1-5-21-2255801001-2913101256-807077043-1005\Software\FunWebProducts --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --- 2009-01-26 blindman.exe (1.0.0.8) 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-01-26 TeaTimer.exe (1.6.4.26) 2009-02-06 unins000.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll (1.6.2.15) 2007-04-02 aports.dll (2.1.0.0) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2009-01-22 Includes\Adware.sbi (*) 2009-01-22 Includes\AdwareC.sbi (*) 2009-01-22 Includes\Cookies.sbi (*) 2009-01-06 Includes\Dialer.sbi (*) 2009-01-22 Includes\DialerC.sbi (*) 2009-01-22 Includes\HeavyDuty.sbi (*) 2009-02-10 Includes\Hijackers.sbi (*) 2009-02-10 Includes\HijackersC.sbi (*) 2008-12-09 Includes\Keyloggers.sbi (*) 2009-02-17 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2008-11-18 Includes\Malware.sbi (*) 2009-02-17 Includes\MalwareC.sbi (*) 2008-12-16 Includes\PUPS.sbi (*) 2009-02-10 Includes\PUPSC.sbi (*) 2009-01-22 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2009-02-10 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2009-01-28 Includes\Spyware.sbi (*) 2009-01-28 Includes\SpywareC.sbi (*) 2008-06-03 Includes\Tracks.uti 2009-02-18 Includes\Trojans.sbi (*) 2009-02-17 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll --- System information --- Windows XP (Build: 2600) Service Pack 3 (5.1.2600) / .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB887998) / .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB930494) / .NETFramework / 1.0: Microsoft .NET Framework 1.0 Service Pack 3 / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366) / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) / Media Center 2005 / SP4: Update Rollup 2 for Windows XP Media Center Edition 2005 / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2 / MSXML4SP2: Security update for MSXML4 SP2 (KB936181) / MSXML4SP2: Security update for MSXML4 SP2 (KB954430) / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs / Windows / SP1: Microsoft National Language Support Downlevel APIs / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399) / Windows Media Player: Security Update for Windows Media Player (KB952069) / Windows Media Player 10: Update for Windows Media Player 10 (KB913800) / Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734) / Windows Media Player 10: Update for Windows Media Player 10 (KB926251) / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782) / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683) / Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154) / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398) / Windows XP: Security Update for Windows XP (KB923689) / Windows XP: Security Update for Windows XP (KB941569) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB929969) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB931768) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB933566) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB937143) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB939653) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB942615) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533) / Windows XP / SP0: Hotfix for Windows Internet Explorer 7 (KB947864) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB950759) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB953838) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB960714) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260) / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP / Windows XP / SP3: Windows XP Service Pack 3 / Windows XP / SP4: Security Update for Windows XP (KB938464) / Windows XP / SP4: Security Update for Windows XP (KB946648) / Windows XP / SP4: Security Update for Windows XP (KB950760) / Windows XP / SP4: Security Update for Windows XP (KB950762) / Windows XP / SP4: Security Update for Windows XP (KB950974) / Windows XP / SP4: Security Update for Windows XP (KB951066) / Windows XP / SP4: Update for Windows XP (KB951072-v2) / Windows XP / SP4: Security Update for Windows XP (KB951376) / Windows XP / SP4: Security Update for Windows XP (KB951376-v2) / Windows XP / SP4: Security Update for Windows XP (KB951698) / Windows XP / SP4: Security Update for Windows XP (KB951748) / Windows XP / SP4: Update for Windows XP (KB951978) / Windows XP / SP4: Hotfix for Windows XP (KB952287) / Windows XP / SP4: Security Update for Windows XP (KB952954) / Windows XP / SP4: Security Update for Windows XP (KB953839) / Windows XP / SP4: Security Update for Windows XP (KB954211) / Windows XP / SP4: Security Update for Windows XP (KB954459) / Windows XP / SP4: Security Update for Windows XP (KB954600) / Windows XP / SP4: Security Update for Windows XP (KB955069) / Windows XP / SP4: Update for Windows XP (KB955839) / Windows XP / SP4: Security Update for Windows XP (KB956391) / Windows XP / SP4: Security Update for Windows XP (KB956802) / Windows XP / SP4: Security Update for Windows XP (KB956803) / Windows XP / SP4: Security Update for Windows XP (KB956841) / Windows XP / SP4: Security Update for Windows XP (KB957095) / Windows XP / SP4: Security Update for Windows XP (KB957097) / Windows XP / SP4: Security Update for Windows XP (KB958644) / Windows XP / SP4: Security Update for Windows XP (KB958687) / Windows XP / SP4: Security Update for Windows XP (KB960715) / XML Paper Specification Shared Components Pack 1.0: XML Paper Specification Shared Components Pack 1.0 --- Startup entries list --- Located: HK_LM:Run, 4oD command: "C:\Program Files\Kontiki\KHost.exe" -all file: C:\Program Files\Kontiki\KHost.exe size: 1032640 MD5: B5569B12E8FF9A71837C57E7C195169F Located: HK_LM:Run, Auto EPSON Stylus DX4000 Series on ALICE command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S1230.tmp" /EF "HKLM" file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE size: 131072 MD5: 4612D6C9C4B46132E47A6EFD362672D6 Located: HK_LM:Run, SunJavaUpdateSched command: "C:\Program Files\Java\jre6\bin\jusched.exe" file: C:\Program Files\Java\jre6\bin\jusched.exe size: 148888 MD5: 3237A58DC79C051004CD3A67C8FBC781 Located: HK_LM:Run, Symantec PIF AlertEng command: "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" file: C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe size: 583048 MD5: 2D1389E05A807D956829F44BD4B60389 Located: HK_LM:Run, SysMetrix command: C:\Program Files\SysMetrix\SysMetrix.exe file: C:\Program Files\SysMetrix\SysMetrix.exe size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: HK_LM:RunOnce, SpybotSnD command: "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck file: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe size: 5365592 MD5: 0477C2F9171599CA5BC3307FDFBA8D89 Located: HK_CU:Run, CTFMON.EXE where: .DEFAULT... command: C:\WINDOWS\system32\CTFMON.EXE file: C:\WINDOWS\system32\CTFMON.EXE size: 15360 MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3 Located: HK_CU:Run, ctfmon.exe where: S-1-5-21-2255801001-2913101256-807077043-1005... command: C:\WINDOWS\system32\ctfmon.exe file: C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3 Located: HK_CU:Run, kdx where: S-1-5-21-2255801001-2913101256-807077043-1005... command: C:\Program Files\Kontiki\KHost.exe -all file: C:\Program Files\Kontiki\KHost.exe size: 1032640 MD5: B5569B12E8FF9A71837C57E7C195169F Located: HK_CU:Run, msnmsgr where: S-1-5-21-2255801001-2913101256-807077043-1005... command: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background file: C:\Program Files\Windows Live\Messenger\msnmsgr.exe size: 5724184 MD5: A8972A2F9A744DD5EE0BFE429D767F1C Located: HK_CU:Run, RGSC where: S-1-5-21-2255801001-2913101256-807077043-1005... command: C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent file: C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe size: 0 MD5: 5FAC39546E97A2ED6AB9EBB3D3BE906E Located: HK_CU:Run, CTFMON.EXE where: S-1-5-18... command: C:\WINDOWS\system32\CTFMON.EXE file: C:\WINDOWS\system32\CTFMON.EXE size: 15360 MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3 Located: Startup (common), Belkin Wireless USB Utility.lnk where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup... command: C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe file: C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe size: 1404928 MD5: BAB365CB7ED672D5830D77CA9DB1B207 Located: Startup (disabled), BT Broadband Desktop Help (DISABLED) command: C:\PROGRA~1\BTBROA~2\bin\matcli.exe -boot file: C:\PROGRA~1\BTBROA~2\bin\matcli.exe size: 217088 MD5: 9A4B2D4577506BBC8FAE47CBACE4468E Located: Startup (disabled), Norton GoBack (DISABLED) command: file: size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: Startup (disabled), PHOTOfunSTUDIO -viewer- (DISABLED) command: C:\PROGRA~1\PANASO~1\PHOTOF~1\PHAUTO~1.EXE file: C:\PROGRA~1\PANASO~1\PHOTOF~1\PHAUTO~1.EXE size: 40960 MD5: 2240A1A5973B31F9D050C137BD5794EA Located: Startup (disabled), wkcalrem (DISABLED) command: C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\WkCalRem.exe file: C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\WkCalRem.exe size: 15360 MD5: 785BB72FC82FF635136D95247AC07B44 Located: WinLogon, AtiExtEvent command: Ati2evxx.dll file: Ati2evxx.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, crypt32chain command: crypt32.dll file: crypt32.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cryptnet command: cryptnet.dll file: cryptnet.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cscdll command: cscdll.dll file: cscdll.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, dimsntfy command: %SystemRoot%\System32\dimsntfy.dll file: %SystemRoot%\System32\dimsntfy.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, ScCertProp command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, Schedule command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, sclgntfy command: sclgntfy.dll file: sclgntfy.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, SensLogn command: WlNotify.dll file: WlNotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, termsrv command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, WgaLogon command: WgaLogon.dll file: WgaLogon.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, wlballoon command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! --- Browser helper object list --- {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} (StumbleUpon Launcher) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: StumbleUpon Launcher {1E8A6170-7264-4D0F-BEAE-D42A53123C75} () location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Path: C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\ Long name: NppBHO.dll Short name: Date (created): 19/02/2007 03:22:56 Date (last access): 23/02/2009 19:27:44 Date (last write): 19/02/2007 03:22:56 Filesize: 97960 Attributes: readonly archive MD5: FE48BB4C64B6D42EB637732D9D2962E4 CRC32: 9D5C5BBE Version: 2007.1.7.4 {3049C3E9-B461-4BC5-8870-4C09146192CA} (RealPlayer Download and Record Plugin for Internet Explorer) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: RealPlayer Download and Record Plugin for Internet Explorer Path: C:\Program Files\Real\RealPlayer\ Long name: rpbrowserrecordplugin.dll Short name: RPBROW~1.DLL Date (created): 01/08/2007 20:12:42 Date (last access): 23/02/2009 19:27:44 Date (last write): 25/02/2008 00:14:56 Filesize: 370296 Attributes: archive MD5: 6E032715A135D156645D0548B90FEC6D CRC32: 51F09C16 Version: 1.0.1.45 {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} (Yahoo! IE Services Button) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Yahoo! IE Services Button Path: C:\PROGRA~1\Yahoo!\Common\ Long name: yiesrvc.dll Short name: Date (created): 06/12/2006 19:54:00 Date (last access): 23/02/2009 18:32:52 Date (last write): 31/10/2006 15:33:54 Filesize: 198136 Attributes: archive MD5: F8981F09E8DA4FDB7F6B6E2B5361AEAE CRC32: 2CDBBB6C Version: 2006.10.31.3 {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Windows Live Sign-in Helper Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\ Long name: WindowsLiveLogin.dll Short name: WINDOW~1.DLL Date (created): 20/09/2007 10:30:18 Date (last access): 23/02/2009 19:27:44 Date (last write): 20/09/2007 10:30:18 Filesize: 328752 Attributes: archive MD5: 59CF5BF6684AFCF906CADAD39B4214DE CRC32: C363813C Version: 4.200.520.1 {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Windows Live Toolbar Helper Path: C:\Program Files\Windows Live Toolbar\ Long name: msntb.dll Short name: Date (created): 19/10/2007 11:20:48 Date (last access): 23/02/2009 19:27:44 Date (last write): 19/10/2007 11:20:48 Filesize: 546320 Attributes: archive MD5: CEE1BE1DA21300208D07FBEAE9EA2B51 CRC32: 12446524 Version: 3.1.0.146 {DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Java(tm) Plug-In 2 SSV Helper Path: C:\Program Files\Java\jre6\bin\ Long name: jp2ssv.dll Short name: Date (created): 04/12/2008 20:55:26 Date (last access): 23/02/2009 18:32:54 Date (last write): 21/02/2009 21:41:58 Filesize: 35840 Attributes: archive MD5: 2CA866C48BD8781383F63229D4D94349 CRC32: B38362A9 Version: 6.0.120.4 {E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: JQSIEStartDetectorImpl CLSID name: JQSIEStartDetectorImpl Class Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\ Long name: jqs_plugin.dll Short name: JQS_PL~1.DLL Date (created): 04/12/2008 20:55:28 Date (last access): 23/02/2009 18:32:54 Date (last write): 21/02/2009 21:42:02 Filesize: 73728 Attributes: archive MD5: 8F9867CEA366201D7759F930F9F986BB CRC32: A5660ADC Version: 6.0.120.4 {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: EpsonToolBandKicker Class Path: C:\Program Files\EPSON\EPSON Web-To-Page\ Long name: EPSON Web-To-Page.dll Short name: EPSONW~1.DLL Date (created): 02/12/2006 17:44:32 Date (last access): 23/02/2009 19:33:20 Date (last write): 22/02/2005 13:50:34 Filesize: 368640 Attributes: archive MD5: 01319CF4030B3740BA8261E7024ACAD1 CRC32: D484DB79 Version: 1.1.0.0 {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} (SidebarAutoLaunch Class) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: SidebarAutoLaunch Class Path: C:\Program Files\Yahoo!\browser\ Long name: YSidebarIEBHO.dll Short name: YSIDEB~2.DLL Date (created): 06/12/2006 19:51:08 Date (last access): 23/02/2009 18:32:54 Date (last write): 03/02/2005 17:07:08 Filesize: 124032 Attributes: archive MD5: 0645DBCBDB3F4A69AEE13F4B5F9C4291 CRC32: 75CB3FBB Version: 2004.8.3.1 --- ActiveX list --- Microsoft XML Parser for Java (Microsoft XML Parser for Java) DPF name: Microsoft XML Parser for Java CLSID name: Installer: Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab description: classification: Legitimate known filename: %WINDIR%\Java\classes\xmldso.cab info link: info source: Patrick M. Kolla {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) DPF name: CLSID name: Shockwave ActiveX Control Installer: C:\WINDOWS\Downloaded Program Files\erma.inf Codebase: http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab description: Macromedia ShockWave Flash Player 7 classification: Legitimate known filename: SWDIR.DLL info link: info source: Patrick M. Kolla Path: C:\WINDOWS\system32\Adobe\Director\ Long name: SwDir.dll Short name: Date (created): 19/09/2008 23:58:48 Date (last access): 23/02/2009 19:14:30 Date (last write): 06/08/2008 15:30:48 Filesize: 202168 Attributes: archive MD5: B8153BAD2E56C50B147867FA9DAEB095 CRC32: D52113FA Version: 11.0.0.465 {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) DPF name: CLSID name: Checkers Class Installer: Codebase: http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab Path: C:\WINDOWS\Downloaded Program Files\ Long name: msgrchkr.dll Short name: Date (created): 28/02/2007 13:21:04 Date (last access): 23/02/2009 18:48:16 Date (last write): 28/02/2007 13:21:04 Filesize: 131472 Attributes: archive MD5: 1E5CFDF9AEBDD84305A4C8154277A269 CRC32: 73C871D0 Version: 9.5.7087.1 {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) DPF name: CLSID name: Installation Support Installer: C:\Program Files\Yahoo!\common\yinst.inf Codebase: C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll description: Yahoo! Installation helper classification: Legitimate known filename: %SystemRoot%\Downloaded Program Files\yinsthelper.dll info link: info source: Patrick M. Kolla Path: C:\Program Files\Yahoo!\Common\ Long name: Yinsthelper20073151.dll Short name: YINSTH~2.DLL Date (created): 16/03/2007 02:13:06 Date (last access): 23/02/2009 19:14:30 Date (last write): 16/03/2007 02:13:06 Filesize: 209448 Attributes: archive MD5: 4380A4799E826AF03FD975B4A71E9268 CRC32: 423BF1F7 Version: 2007.3.15.1 {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) DPF name: CLSID name: UnoCtrl Class Installer: C:\WINDOWS\Downloaded Program Files\GAME_UNO1.INF Codebase: http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab description: classification: Legitimate known filename: unomsnger.dll info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\Downloaded Program Files\ Long name: GAME_UNO1.dll Short name: GAME_U~1.DLL Date (created): 13/04/2007 01:14:52 Date (last access): 23/02/2009 19:14:30 Date (last write): 13/04/2007 01:14:52 Filesize: 382344 Attributes: archive MD5: A9F8AB66D9D05A13843623EE6B92D259 CRC32: C9DFA641 Version: 1.0.1201.1 {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) DPF name: CLSID name: Facebook Photo Uploader Control Installer: C:\WINDOWS\Downloaded Program Files\FacebookPhotoUploader.inf Codebase: http://upload.facebook.com/controls/FacebookPhotoUploader.cab description: classification: Open for discussion known filename: FacebookPhotoUploader.ocx info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\Downloaded Program Files\ Long name: FacebookPhotoUploader.ocx Short name: FACEBO~1.OCX Date (created): 03/11/2005 19:17:36 Date (last access): 23/02/2009 19:14:30 Date (last write): 03/11/2005 19:17:36 Filesize: 1935120 Attributes: archive MD5: 5A39F109CB87893FD683F49699BCE2B4 CRC32: 729D4EBC Version: 3.5.122.2 {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) DPF name: CLSID name: DivXBrowserPlugin Object Installer: C:\WINDOWS\Downloaded Program Files\DivXPlugin.inf Codebase: http://download.divx.com/player/DivXBrowserPlugin.cab description: classification: Legitimate known filename: npdivx32.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\DivX\DivX Web Player\ Long name: npdivx32.dll Short name: Date (created): 17/10/2008 18:29:52 Date (last access): 23/02/2009 19:14:32 Date (last write): 17/10/2008 18:29:52 Filesize: 1332224 Attributes: archive MD5: D19163C4794227D953AF0F136A59DE85 CRC32: 63D55368 Version: 1.4.2.7 {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) DPF name: CLSID name: Symantec Download Manager Installer: C:\WINDOWS\Downloaded Program Files\symdlmgr.inf Codebase: https://webdl.symantec.com/activex/symdlmgr.cab description: classification: Legitimate known filename: symdlmgr.dll info link: info source: Safer Networking Ltd. {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_12 Installer: Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab description: Sun Java classification: Legitimate known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll info link: info source: Patrick M. Kolla Path: C:\Program Files\Java\jre6\bin\ Long name: npjpi160_12.dll Short name: NPJPI1~2.DLL Date (created): 21/02/2009 21:42:00 Date (last access): 23/02/2009 19:14:32 Date (last write): 21/02/2009 21:42:02 Filesize: 136600 Attributes: archive MD5: BB1F300BABFAAFBC9DAABCBADE3347F0 CRC32: 000509E5 Version: 6.0.120.4 {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () DPF name: CLSID name: Installer: C:\WINDOWS\Downloaded Program Files\erma.inf Codebase: http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab description: classification: Open for discussion known filename: info link: info source: Safer Networking Ltd. {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) DPF name: CLSID name: MessengerStatsClient Class Installer: Codebase: http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab description: classification: Legitimate known filename: MessengerStatsPAClient.dll info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\Downloaded Program Files\ Long name: MessengerStatsPAClient.dll Short name: MESSEN~1.DLL Date (created): 22/02/2007 22:41:12 Date (last access): 23/02/2009 19:14:32 Date (last write): 22/02/2007 22:41:12 Filesize: 304544 Attributes: archive MD5: 8945CCA5FC4F25168E8B6F401EFAF51F CRC32: 0F12FD23 Version: 9.5.6907.1 {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_12 Installer: Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab Path: C:\Program Files\Java\jre6\bin\ Long name: npjpi160_12.dll Short name: NPJPI1~2.DLL Date (created): 21/02/2009 21:42:00 Date (last access): 23/02/2009 19:14:32 Date (last write): 21/02/2009 21:42:02 Filesize: 136600 Attributes: archive MD5: BB1F300BABFAAFBC9DAABCBADE3347F0 CRC32: 000509E5 Version: 6.0.120.4 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_12 Installer: Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab description: classification: Legitimate known filename: npjpi150_06.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\jre6\bin\ Long name: npjpi160_12.dll Short name: NPJPI1~2.DLL Date (created): 21/02/2009 21:42:00 Date (last access): 23/02/2009 19:14:32 Date (last write): 21/02/2009 21:42:02 Filesize: 136600 Attributes: archive MD5: BB1F300BABFAAFBC9DAABCBADE3347F0 CRC32: 000509E5 Version: 6.0.120.4 {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) DPF name: CLSID name: Shockwave Flash Object Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf Codebase: http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab description: Macromedia Shockwave Flash Player classification: Legitimate known filename: info link: info source: Patrick M. Kolla Path: C:\WINDOWS\system32\Macromed\Flash\ Long name: Flash9f.ocx Short name: Date (created): 25/03/2008 02:32:42 Date (last access): 23/02/2009 19:05:34 Date (last write): 25/03/2008 02:32:42 Filesize: 2991488 Attributes: readonly archive MD5: 48FDF435B8595604E54125B321924510 CRC32: 12335E29 Version: 9.0.124.0 {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) DPF name: CLSID name: Minesweeper Flags Class Installer: Codebase: http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab description: classification: Legitimate known filename: MineSweeper.dll info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\Downloaded Program Files\ Long name: MineSweeper.dll Short name: MINESW~1.DLL Date (created): 28/02/2007 13:21:04 Date (last access): 23/02/2009 19:14:32 Date (last write): 28/02/2007 13:21:04 Filesize: 130472 Attributes: archive MD5: E661E91B5929632665683222D509D271 CRC32: 63A9B975 Version: 9.5.6986.1 --- Process list --- PID: 0 ( 0) [System] PID: 624 ( 4) \SystemRoot\System32\smss.exe size: 50688 PID: 700 ( 624) \??\C:\WINDOWS\system32\csrss.exe size: 6144 PID: 1092 ( 624) \??\C:\WINDOWS\system32\winlogon.exe size: 507904 PID: 1136 (1092) C:\WINDOWS\system32\services.exe size: 108544 MD5: 0E776ED5F7CC9F94299E70461B7B8185 PID: 1156 (1092) C:\WINDOWS\system32\lsass.exe size: 13312 MD5: BF2466B3E18E970D8A976FB95FC1CA85 PID: 1332 (1136) C:\WINDOWS\system32\Ati2evxx.exe size: 483328 MD5: 666E4E583A7CF1233C6425DA16ECDC89 PID: 1348 (1136) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1404 (1136) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1448 (1136) C:\WINDOWS\System32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1488 (1136) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1604 (1136) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1744 (1092) C:\WINDOWS\system32\Ati2evxx.exe size: 483328 MD5: 666E4E583A7CF1233C6425DA16ECDC89 PID: 1832 (1136) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe size: 108648 MD5: FE69C498B922CE835E2E2123FBD0A272 PID: 864 ( 796) C:\WINDOWS\Explorer.EXE size: 1033728 MD5: 12896823FB95BFB3DC9B46BCAEDC9923 PID: 896 (1136) C:\Program Files\a-squared Anti-Malware\a2service.exe size: 421496 MD5: 66D2F0F0227E57AADC91D3613D91EC61 PID: 992 (1136) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe size: 102712 MD5: 61A581E5481E22A76A88490C57015105 PID: 1064 (1136) C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe size: 554352 MD5: B5D974C1FD078A68C7536C561B031D39 PID: 1528 (1136) C:\Program Files\Bonjour\mDNSResponder.exe size: 238888 MD5: 9EFE4236F8670846B6E7C5B0EFF6E715 PID: 1660 (1136) C:\WINDOWS\system32\cisvc.exe size: 5632 MD5: 1CFE720EB8D93A7158A4EBC3AB178BDE PID: 1768 (1136) C:\WINDOWS\eHome\ehRecvr.exe size: 237568 MD5: 5D1347AA5AE6E2F77D7F4F8372D95AC9 PID: 1936 (1136) C:\WINDOWS\eHome\ehSched.exe size: 102912 MD5: A53243709439AC2A4C216B817F8D7411 PID: 2000 (1136) C:\Program Files\Java\jre6\bin\jqs.exe size: 152984 MD5: 511AB23A292497F2C527EEE5775B0BFE PID: 2132 (1136) C:\Program Files\Kontiki\KService.exe size: 3068352 MD5: 62CEF3CA80FF1E3AF738DD11E3505DB1 PID: 2224 (1136) C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe size: 2107032 MD5: 048EF3DA03319478E337DD80E69F2B90 PID: 2516 (1136) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 2528 (1136) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 2616 (1136) C:\Program Files\BT Home Hub\Wireless Configuration\WirelessDaemon.exe size: 49152 MD5: 65D0C67A9E038A3F90C7C7D21C76CA14 PID: 2656 ( 864) C:\Program Files\Java\jre6\bin\jusched.exe size: 148888 MD5: 3237A58DC79C051004CD3A67C8FBC781 PID: 2884 (1136) C:\WINDOWS\ehome\mcrdsvc.exe size: 99328 MD5: DF0A511F38F16016BF658FCA0090CB87 PID: 3032 ( 864) C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3 PID: 3116 ( 864) C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe size: 1404928 MD5: BAB365CB7ED672D5830D77CA9DB1B207 PID: 3636 (1136) C:\WINDOWS\system32\dllhost.exe size: 5120 MD5: 0A9BA6AF531AFE7FA5E4FB973852D863 PID: 3192 (1136) C:\WINDOWS\System32\alg.exe size: 44544 MD5: 8C515081584A38AA007909CD02020B3D PID: 3652 (1136) C:\WINDOWS\System32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 3968 (1660) C:\WINDOWS\system32\cidaemon.exe size: 8192 MD5: 582304F6F1946FA5068CF143D729D7ED PID: 2248 (1136) C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe size: 1251720 MD5: FA2F6A8849219B16460BF44F9D1F3AA7 PID: 3224 (1348) C:\WINDOWS\system32\wbem\unsecapp.exe size: 16896 MD5: C7000F2DB2A5515C64C257478769A481 PID: 2912 (1348) C:\WINDOWS\system32\wbem\wmiprvse.exe size: 218112 MD5: 0FFAE66E6D5B1C87CBD22D1F3B6079FD PID: 4036 (1136) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe size: 70144 MD5: 234B1BC2796483E1F5C3F26649FB3388 PID: 2440 (1136) c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe size: 36864 MD5: FACECF3F75BAF3775A879D1168402270 PID: 1112 ( 332) C:\Program Files\Mozilla Firefox\firefox.exe size: 307704 MD5: A4458CA176309C9358E8DF3FE88B33D5 PID: 3940 (1348) C:\WINDOWS\system32\LVComsX.exe size: 221184 MD5: 63BE39ACF8FD8963B01548972D7A06F0 PID: 3324 ( 864) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe size: 5365592 MD5: 0477C2F9171599CA5BC3307FDFBA8D89 PID: 1208 (1136) C:\Program Files\Windows Live\Messenger\usnsvc.exe size: 98328 MD5: 9D19B042A4FD5C02195071EA2FE0C821 PID: 4 ( 0) System PID: 712 (1136) C:\Program Files\iPod\bin\iPodService.exe size: 536872 MD5: 62937A89470AF8FF172F0980CA8AEFC9 PID: 184 (1448) C:\WINDOWS\system32\wuauclt.exe size: 51224 MD5: E654B78D2F1D791B30D0ED9A8195EC22 --- Browser start & search pages list --- Spybot - Search & Destroy browser pages report, 23/02/2009 19:48:16 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/ HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page http://www.msn.com HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@ http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/ HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page http://www.msn.com HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page http://home.bt.yahoo.com HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://home.bt.yahoo.com HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/ HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm --- Winsock Layered Service Provider list --- --- Uninstall list --- 4oD 2.0.23.0 (4oD) install date: 28/01/2008 - 00:56:29 install location: C:\Program Files\Kontiki\ uninstall cmd: MsiExec.exe /I {8B7443F5-E141-42A0-AB61-ED2331AAD606} publisher: Channel 4 Television Corporation and 4 Ventures Limited contact: 4oDHelp@Channel4.com help link: http://help.channel4.com/4od EA SPORTS online 2007 (82A44D22-9452-49FB-00FB-CEC7DCAF7E23) uninstall cmd: C:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe a-squared Anti-Malware 4.0 4.0 (a-squared Anti-Malware_is1) install date: 20090211 install location: C:\Program Files\a-squared Anti-Malware\ uninstall cmd: "C:\Program Files\a-squared Anti-Malware\unins000.exe" publisher: Emsi Software GmbH comments: a-squared help link: http://forum.emsisoft.com Ad-Aware (Ad-Aware) install location: C:\Program Files\Lavasoft\Ad-Aware uninstall cmd: "C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE publisher: Lavasoft comments: All rights reserved help link: http://www.lavasoft.com/support/supportcenter (AddressBook) Adobe Acrobat 4.0 (Adobe Acrobat 4.0) uninstall cmd: C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 4.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 4.0\NT\Uninst.dll" Adobe Flash Player ActiveX 9.0.124.0 (Adobe Flash Player ActiveX) uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe publisher: Adobe Systems Incorporated help link: http://www.adobe.com/go/flashplayer_support/ Adobe Flash Player Plugin 9.0.124.0 (Adobe Flash Player Plugin) uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe publisher: Adobe Systems Incorporated Adobe Shockwave Player 11 (Adobe Shockwave Player) version (major): 11 install location: C:\WINDOWS\system32\Adobe\ uninstall cmd: C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log publisher: Adobe Systems, Inc. help link: http://www.adobe.com/support/shockwave Adobe ExtendScript Toolkit 2 2.0.2 (Adobe_3e054d2218e7aa282c2369d939e58ff) estimated size: 16809 uninstall cmd: C:\Program Files\Common Files\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe publisher: Adobe Systems Incorporated Adobe Fireworks CS3 9.0 (Adobe_bbef028176efa5abf0233d3e1747be8) estimated size: 708743 uninstall cmd: C:\Program Files\Common Files\Adobe\Installers\bbef028176efa5abf0233d3e1747be8\Setup.exe publisher: Adobe Systems Incorporated help link: http://www.adobe.com/support Adobe Stock Photos CS3 1.5 (Adobe_cbb2ea61da9c780bd7e47a5230a9ed7) estimated size: 8034 uninstall cmd: C:\Program Files\Common Files\Adobe\Installers\cbb2ea61da9c780bd7e47a5230a9ed7\Setup.exe publisher: Adobe Systems Incorporated Adobe® Photoshop® Album Starter Edition 3.2 3.2.0 (Adobe® Photoshop® Album Starter Edition 3.2) install location: C:\Program Files\Adobe\Photoshop Album Starter Edition\ uninstall cmd: MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61} publisher: http://www.adobe.com readme: C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\readme.txt Alarm 2.0.4 (Alarm_is1) install date: 20090217 install location: C:\Program Files\Alarm\ uninstall cmd: "C:\Program Files\Alarm\unins000.exe" publisher: Bluefive software help link: http://bluefive.pair.com/faq.htm ATI - Software Uninstall Utility 6.14.10.1016 (All ATI Software) install location: C:\Program Files\ATI Technologies\UninstallAll uninstall cmd: C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe ATI Display Driver 8.421-070928a-053251C-ATI (ATI Display Driver) uninstall cmd: rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean AudibleManager 2089882806.2089882868.2090316064.2089882826 (AudibleManager) uninstall cmd: C:\Program Files\Audible\Bin\Upgrade.exe /Uninstall publisher: Audible, Inc. (Branding) 5.8.22.asst_classic.asst_install (BT Broadband Desktop Help) publisher: Motive Communications, Inc. BT Home Hub (BT Home Hub) uninstall cmd: C:\Program Files\BT Home Hub\Uninstall.exe BT Softphone 1.5.3.6 (BT Softphone 1.5_is1) install location: C:\Program Files\BT Broadband Talk Softphone\ uninstall cmd: "C:\Program Files\BT Broadband Talk Softphone\unins000.exe" publisher: BT help link: www.bt.com BT Yahoo! Applications (BT Yahoo! Applications) uninstall cmd: C:\PROGRA~1\Yahoo!\Common\uninstall.exe BT Broadband Desktop Help (btbb.MCCInstall) uninstall cmd: C:\WINDOWS\Motive\btbb\MCCUninst.exe CCleaner (remove only) (CCleaner) uninstall cmd: "C:\Program Files\CCleaner\uninst.exe" publisher: Piriform ClamWin Free Antivirus 0.94.1 (ClamWin Free Antivirus_is1) install date: 20090211 install location: C:\Program Files\ClamWin\ uninstall cmd: "C:\Program Files\ClamWin\unins000.exe" publisher: alch help link: http://www.clamwin.com/ Combined Community Codec Pack 2007-07-22 2007-07-22 13:55 (Combined Community Codec Pack_is1) install date: 20070801 install location: C:\Program Files\Combined Community Codec Pack\ uninstall cmd: "C:\Program Files\Combined Community Codec Pack\unins000.exe" publisher: CCCP Project help link: http://www.cccp-project.net/ (Connection Manager) (cookingdashtm) (DirectAnimation) (DirectDrawEx) DirectShow WMA converter (remove only) (DShow-WMA) uninstall cmd: "C:\Program Files\DirectShow WMA converter\Uninstall.exe" (DXM_Runtime) EPSON Printer Software (EPSON Printer and Utilities) uninstall cmd: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R EPSON Scan (EPSON Scanner) uninstall cmd: C:\Program Files\epson\escndv\setup\setup.exe /r ESDX4000_4050_CX3900 (ESDX4000_4050_CX3900) install location: C:\Program Files\EPSON\TPMANUAL\ESDX4000_4050_CX3900\USE_G uninstall cmd: C:\Program Files\EPSON\TPMANUAL\ESDX4000_4050_CX3900\USE_G\DOCUNINS.EXE (Fontcore) FoxyTunes for Firefox (FoxyTunesForFirefox) uninstall cmd: "C:\Program Files\Mozilla Firefox\firefox.exe" -chrome chrome://foxytunes/content/extras/uninstallExtension.xul HijackThis 2.0.2 2.0.2 (HijackThis) uninstall cmd: "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall publisher: TrendMicro (ICW) Microsoft Internationalized Domain Names Mitigation APIs (IDNMitigationAPIs) install date: 20061208 publisher: Microsoft Corporation (IE40) (IE4Data) (IE5BAKEX) Windows Internet Explorer 7 20061107.210142 (ie7) install date: 20061208 publisher: Microsoft Corporation help link: http://www.microsoft.com/ie (IEData) (InstallShield Uninstall Information) EPSON Attach To Email 1.01.0000 (InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) version: 16842752 version (major): 1 version (minor): 1 estimated size: 1108 install date: 20061202 install location: C:\Program Files\EPSON\Creativity Suite\Attach To Email\ install source: D:\COMMON\CreativitySuite\AttachToEmail\ uninstall cmd: C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG publisher: SEIKO EPSON comments: Attach To Email - Email support app help link: http://www.epson.com/ Vampire - The Masquerade Bloodlines 1.00.0000 (InstallShield_{C4E2A4A7-B623-40CB-8EEA-72F577E49D56}) version: 16777216 version (major): 1 estimated size: 2912512 install date: 20061203 install location: C:\Program Files\Activision\Vampire - Bloodlines\ install source: D:\ uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{C4E2A4A7-B623-40CB-8EEA-72F577E49D56} /l2057 publisher: Activision help link: http://activision.custhelp.com (KB884267) (KB885353) (KB886612) (KB887078) (KB887626) (KB888656) (KB891122) (KB893240) (KB893241) (KB895181) (KB895316) (KB897586) (KB898549) (KB900399) (KB902344) (KB911854) Security Update for Windows Media Player (KB952069) (KB952069_WM9) install date: 20081212 uninstall cmd: "C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com/?kbid=952069 Security Update for Windows XP (KB954600) 1 (KB954600) install date: 20081211 uninstall cmd: "C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=954600 Update for Windows XP (KB955839) 1 (KB955839) install date: 20081212 uninstall cmd: "C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=955839 Security Update for Windows XP (KB956802) 1 (KB956802) install date: 20081212 uninstall cmd: "C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=956802 Security Update for Windows Internet Explorer 7 (KB958215) 1 (KB958215-IE7) install date: 20081212 uninstall cmd: "C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=958215 Security Update for Windows XP (KB958687) 1 (KB958687) install date: 20090115 uninstall cmd: "C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=958687 Security Update for Windows Internet Explorer 7 (KB960714) 1 (KB960714-IE7) install date: 20081218 uninstall cmd: "C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=960714 Security Update for Windows XP (KB960715) 1 (KB960715) install date: 20090211 uninstall cmd: "C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=960715 Security Update for Windows Internet Explorer 7 (KB961260) 1 (KB961260-IE7) install date: 20090211 uninstall cmd: "C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=961260 (KBKB319740) (KBKB895961) K-Lite Codec Pack 4.0.0 (Full) 4.0.0 (KLiteCodecPack_is1) install date: 20080728 install location: C:\Program Files\K-Lite Codec Pack\ uninstall cmd: "C:\Program Files\K-Lite Codec Pack\unins000.exe" L&H TTS3000 British English (LHTTSENG) uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\LHTTSENG.inf, Uninstall LiveUpdate 3.2 (Symantec Corporation) 3.2.0.68 (LiveUpdate) install location: "C:\Program Files\Symantec\LiveUpdate" uninstall cmd: "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U publisher: Symantec Corporation Microsoft .NET Framework 1.1 Hotfix (KB928366) (M928366) uninstall cmd: "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp" Master of Olympus - Zeus (Master of Olympus - Zeus) uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Sierra\Master of Olympus - Zeus\Uninst.isu" Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033)) uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm Microsoft .NET Framework 3.0 (Microsoft .NET Framework 3.0) install location: c:\WINDOWS\Microsoft.NET\Framework\v3.0\ uninstall cmd: c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe publisher: Microsoft Corporation help link: http://go.microsoft.com/fwlink/?LinkId=51019 (MobileOptionPack) Mozilla Firefox (3.0.6) 3.0.6 (en-GB) (Mozilla Firefox (3.0.6)) install location: C:\Program Files\Mozilla Firefox uninstall cmd: C:\Program Files\Mozilla Firefox\uninstall\helper.exe publisher: Mozilla comments: Mozilla Firefox (MPlayer2) Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1) install date: 20061222 publisher: Microsoft Corporation help link: http://go.microsoft.com/fwlink/?LinkId=74087 (MSI30-Beta1) (MSI30-Beta2) (MSI30-KB884016) (MSI30-RC1) (MSI30-RC2) (MSI30a-KB884016) (MSI31-Beta) (MSI31-RC1) (MsJavaVM) (Nero - Burning Rom!UninstallKey) uninstall cmd: C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL Nero BurnRights (Nero BurnRights!UninstallKey) uninstall cmd: C:\WINDOWS\UNNeroBurnRights.exe /UNINSTALL Nero Suite (NeroMultiInstaller!UninstallKey) uninstall cmd: C:\Program Files\Common Files\Nero\Uninstall\Setupx.exe /uninstall ExtraUninstallID="" (NeroVision!UninstallKey) uninstall cmd: C:\WINDOWS\UNNeroVision.exe /UNINSTALL (NetMeeting) Microsoft National Language Support Downlevel APIs (NLSDownlevelMapping) install date: 20061208 publisher: Microsoft Corporation (NVEContent!UninstallKey) uninstall cmd: C:\WINDOWS\UNNVEContent.exe /UNINSTALL (OutlookExpress) (PCHealth) uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Plato DVD Ripper 7.87 (Plato DVD Ripper_is1) install date: 20080917 install location: C:\Program Files\Plato DVD Ripper\ uninstall cmd: "C:\Program Files\Plato DVD Ripper\unins000.exe" publisher: Plato Global Creativity help link: http://www.dvdtompegx.com/html/dvdripper.html PowerISO (PowerISO) uninstall cmd: "C:\Program Files\PowerISO\uninstall.exe" Microsoft Office Publisher 2007 Trial 12.0.6215.1000 (PUBLISHERR) install location: C:\Program Files\Microsoft Office uninstall cmd: "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PUBLISHERR /dll OSETUP.DLL publisher: Microsoft Corporation Labtec® Camera Driver (QcDrv) install location: C:\Program Files\Common Files\Logitech\QCDRV install source: D:\Drivers\Bin uninstall cmd: "C:\Program Files\Common Files\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT (RealArcade) (RealJukebox 1.0) uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 RealPlayer (RealPlayer 6.0) install location: C:\Program Files\Real\RealPlayer\realplay.exe uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 publisher: RealNetworks comments: Play, Save, and Organize your music and videos, Burn a CD, or simply take your music with you. contact: RealNetworks RegCure 1.5.2.7 1.5.2.7 (RegCure) uninstall cmd: C:\Program Files\RegCure\uninst.exe publisher: RegCure, Inc. Riva FLV Encoder 2.0 2.00.0004 (Riva FLV Encoder 2.0_is1) install location: C:\Program Files\Riva\Riva FLV Encoder 2.0\ uninstall cmd: "C:\Program Files\Riva\Riva FLV Encoder 2.0\unins000.exe" publisher: Rothenberger & Partner help link: http://www.rivavx.de (SchedulingAgent) (Sevinst) Shockwave (Shockwave) uninstall cmd: C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log 9.0.124.0 (ShockwaveFlash) SpellForce SpellForce v1.0 (SpellForce) uninstall cmd: C:\PROGRA~1\JoWooD\SPELLF~1\unwise.exe C:\PROGRA~1\JoWooD\SPELLF~1\install.log publisher: JoWooD Productions Software AG StumbleUpon IE Toolbar (StumbleUponIEToolbar) uninstall cmd: C:\Program Files\StumbleUpon\uninstall.exe Norton 360 (Symantec Corporation) 1.0.0.184 (SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777}) install location: C:\Program Files\Norton 360 uninstall cmd: "C:\Program Files\Common Files\Symantec Shared\SymSetup\{2D617065-1C52-4240-B5BC-C0AE12157777}_1_0_0_184\{2D617065-1C52-4240-B5BC-C0AE12157777}.exe" /X publisher: Symantec Corporation (ViewpointMediaPlayer) Vikki Blows Screen Saver (Vikki Blows ) VideoLAN VLC media player 0.8.6c 0.8.6c (VLC media player) uninstall cmd: C:\Program Files\VideoLAN\VLC\uninstall.exe publisher: VideoLAN Team Windows Genuine Advantage Notifications (KB905474) 1.7.0018.5 (WgaNotify) install date: 20070323 publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=905474 Windows Imaging Component 3.0.0.0 (WIC) install date: 20080302 publisher: Microsoft Corporation Windows Live Toolbar 03.01.0146 (Windows Live Toolbar) uninstall cmd: "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750} publisher: Microsoft Corporation Windows Media Format 11 runtime (Windows Media Format Runtime) uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll help link: http://go.microsoft.com/fwlink/?LinkId=62768 Windows Media Player 11 (Windows Media Player) uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall Windows XP Service Pack 3 20080414.031525 (Windows XP Service Pack) install date: 20080916 uninstall cmd: "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=936929 WinRAR archiver (WinRAR archiver) uninstall cmd: C:\Program Files\WinRAR\uninstall.exe (WMCSetup) Windows Media Format 11 runtime (WMFDist11) install date: 20061222 publisher: Microsoft Corporation help link: http: Windows Media Player 11 (wmp11) install date: 20061222 publisher: Microsoft Corporation help link: http: Microsoft User-Mode Driver Framework Feature Pack 1.0 (Wudf01000) install date: 20061222 publisher: Microsoft Corporation comments: Build Number 5716 XoftSpySE (XoftSpySE) uninstall cmd: C:\Program Files\XoftSpySE\uninstall.exe XP Codec Pack (XP Codec Pack) uninstall cmd: C:\Program Files\XP Codec Pack\Uninstall.exe XML Paper Specification Shared Components Pack 1.0 (XpsEPSC) install date: 20090223 publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=test Yahoo! Toolbar (Yahoo! Toolbar) The Sims 2 University ({01521746-02A6-4A72-00BD-A285DF6B80C6}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 University\EAUninstall.exe SuppSoft 1 ({022DA2C3-81C7-4003-A6BC-1BB147B20097}) version: 16777216 version (major): 1 estimated size: 1105 install date: 20071108 uninstall cmd: MsiExec.exe /I{022DA2C3-81C7-4003-A6BC-1BB147B20097} publisher: Symantec Corporation Adobe Help Viewer CS3 1 ({04AF207D-9A77-465A-8B76-991F6AB66245}) version: 16777216 version (major): 1 estimated size: 4149 install date: 20070914 uninstall cmd: MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245} publisher: Adobe Systems Incorporated Adobe Bridge Start Meeting 1.0 ({08B32819-6EEF-4057-AEDA-5AB681A36A23}) version: 16777216 version (major): 1 estimated size: 477 install date: 20070914 uninstall cmd: MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23} publisher: Adobe Systems Incorporated ArchosLink 2.0.0 ({0B1C719C-3547-4007-86DA-3C214DBE400B}) version: 33554432 version (major): 2 estimated size: 6617 install date: 20070823 install source: C:\Program Files\Archos\ArchosLink\setup\ uninstall cmd: MsiExec.exe /I{0B1C719C-3547-4007-86DA-3C214DBE400B} publisher: Archos contact: Archos Security Update for CAPICOM (KB931906) 2.1.0.2 ({0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}) version: 33619968 version (major): 2 version (minor): 1 estimated size: 770 install date: 20070508 uninstall cmd: MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} publisher: Microsoft Corporation Microsoft .NET Framework 3.0 3.0.04506.30 ({15095BF3-A3D7-4DDF-B193-3A496881E003}) version: 50336154 version (major): 3 estimated size: 16102 install date: 20090223 install location: c:\WINDOWS\Microsoft.NET\Framework\v3.0\ install source: c:\2ad66d8beb088383137c00\ uninstall cmd: MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003} publisher: Microsoft Corporation Windows Live Mail 12.0.1606.1023 ({184E7118-0295-43C4-B72C-1D54AA75AAF7}) version: 201328198 version (major): 12 estimated size: 21931 install date: 20080302 install source: C:\Program Files\Common Files\WindowsLiveInstaller\MsiSources\ uninstall cmd: MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7} publisher: Microsoft Corporation AutoUpdate 1.1 ({18D10072035C4515918F7E37EAFAACFC}) install location: C:\Program Files\DivX\AutoUpdate Norton 360 Help 1.0.0 ({1CA941F1-5006-487E-9FD4-09F812A7D6B8}) version: 16777216 version (major): 1 estimated size: 640 install date: 20071108 uninstall cmd: MsiExec.exe /I{1CA941F1-5006-487E-9FD4-09F812A7D6B8} publisher: Symantec Corporation EPSON Attach To Email 1.01.0000 ({20C45B32-5AB6-46A4-94EF-58950CAF05E5}) version: 16842752 version (major): 1 version (minor): 1 estimated size: 1108 install date: 20061202 install location: C:\Program Files\EPSON\Creativity Suite\Attach To Email\ install source: D:\COMMON\CreativitySuite\AttachToEmail\ publisher: SEIKO EPSON comments: Attach To Email - Email support app help link: http://www.epson.com/ Norton 360 1.0.0.184 ({21829177-4DED-4209-AD08-490B3AC9C01A}) version: 16777216 version (major): 1 estimated size: 1863 install date: 20071108 uninstall cmd: MsiExec.exe /I{21829177-4DED-4209-AD08-490B3AC9C01A} publisher: Symantec Corporation Adobe Setup 1.0 ({2274624C-5B38-41AD-AD27-CEC0924EB628}) version: 16777216 version (major): 1 estimated size: 4344 install date: 20070924 install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Installer6748\ uninstall cmd: MsiExec.exe /I{2274624C-5B38-41AD-AD27-CEC0924EB628} publisher: Adobe Systems Incorporated GearDrvs 1 ({228F6876-A313-40A3-91C0-C3CBE6997D09}) version: 16777216 version (major): 1 estimated size: 104 install date: 20071108 uninstall cmd: MsiExec.exe /I{228F6876-A313-40A3-91C0-C3CBE6997D09} publisher: Symantec Corporation Convert 4.10 ({23970E31-948B-466E-8376-1224D32FDF0C}) version: 67764224 version (major): 4 version (minor): 10 estimated size: 544 install date: 20090223 install location: C:\Program Files\JoshMadison\convert\ install source: C:\DOCUME~1\Esmee\LOCALS~1\Temp\_is153\ uninstall cmd: MsiExec.exe /X{23970E31-948B-466E-8376-1224D32FDF0C} publisher: Joshua F. Madison readme: C:\Program Files\JoshMadison\convert\readme.txt 2.3.0 ({26792CA7-D87A-4DBE-896B-C2F66B344511}) version: 33751040 version (major): 2 version (minor): 3 estimated size: 21271 install date: 20080104 install source: D:\CINEPLAYER_23\ uninstall cmd: MsiExec.exe /I{26792CA7-D87A-4DBE-896B-C2F66B344511} publisher: Roxio help link: http://www.cineplayer.com/default.asp?af=%s&ver=21&sn=%s&lang=ENU ({26A24AE4-039D-4CA4-87B4-2F83216011FF}) Java(TM) 6 Update 12 6.0.120 ({26A24AE4-039D-4CA4-87B4-2F83216012FF}) version: 100663416 version (major): 6 estimated size: 99352 install date: 20090221 install location: C:\Program Files\Java\jre6\ install source: C:\Documents and Settings\Esmee\Application Data\Sun\Java\jre1.6.0_12\ uninstall cmd: MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF} publisher: Sun Microsystems, Inc. contact: http://java.com help link: http://java.com readme: C:\Program Files\Java\jre6\README.txt Adobe Stock Photos CS3 1.5 ({29E5EA97-5F74-4A57-B8B2-D4F169117183}) version: 17104896 version (major): 1 version (minor): 5 estimated size: 10488 install date: 20070924 install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Installer6748\payloads\AdobeStockPhotos1.5All\ uninstall cmd: MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183} publisher: Adobe Systems Incorporated EPSON Scan Assistant 1.10.00 ({2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) version: 17432576 install location: C:\Program Files\EPSON\Creativity Suite\Scan Assistant uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u 3.1.20081127 ({2CCBABCB-6427-4A55-B091-49864623C43F}) version: 20081127 version (major): 3 version (minor): 1 Windows Live Photo Gallery 12.0.1347.0718 ({2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}) version: 201327939 version (major): 12 estimated size: 23127 install date: 20080812 uninstall cmd: MsiExec.exe /X{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C} publisher: Microsoft Corporation help link: http://photogallery.live.com/ Norton 360 1.0.0.184 ({2D617065-1C52-4240-B5BC-C0AE12157777}) version: 16777216 version (major): 1 estimated size: 93029 install date: 20071108 uninstall cmd: MsiExec.exe /I{2D617065-1C52-4240-B5BC-C0AE12157777} publisher: Symantec Corporation SymNet 7.2.0.15 ({2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}) version: 117571584 version (major): 7 version (minor): 2 estimated size: 3118 install date: 20071108 uninstall cmd: MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2} publisher: Symantec Corporation Norton Confidential Web Authentification Component 1.5.1.4 ({3074EB89-1BCA-4AEF-AFF4-EFB4634C1923}) version: 17104897 version (major): 1 version (minor): 5 estimated size: 8141 install date: 20071108 uninstall cmd: MsiExec.exe /I{3074EB89-1BCA-4AEF-AFF4-EFB4634C1923} publisher: Symantec Corporation iTunes 8.0.2.20 ({318AB667-3230-41B5-A617-CB3BF748D371}) version: 134217730 version (major): 8 estimated size: 106344 install date: 20081126 install location: C:\Program Files\iTunes\ install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Apple\Apple Software Update\ uninstall cmd: MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371} publisher: Apple Inc. contact: AppleCare Support help link: http://www.apple.com/support/ help telephone: 1-800-275-2273 Windows Live Toolbar Extension (Windows Live Toolbar) 03.01.0146 ({341201D4-4F61-4ADB-987E-9CCE4D83A58D}) version: 50397330 version (major): 3 version (minor): 1 estimated size: 609 install date: 20080302 uninstall cmd: MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D} publisher: Microsoft Corporation WebFldrs XP 9.50.7523 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}) version: 154279267 version (major): 9 version (minor): 50 estimated size: 628 install date: 20061202 install source: C:\WINDOWS\system32\ publisher: Microsoft Corporation help link: http://www.microsoft.com/windows MSXML 4.0 SP2 (KB927978) 4.20.9841.0 ({37477865-A3F1-4772-AD43-AAFC6BCFF99F}) version: 68429425 version (major): 4 version (minor): 20 estimated size: 2625 install date: 20061206 uninstall cmd: MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F} publisher: Microsoft Corporation help link: http://support.microsoft.com/kb/927978 ccCommon 106.2.0.21 ({3CCAD2EF-CFF2-4637-82AA-AABF370282D3}) version: 1778515968 version (major): 106 version (minor): 2 estimated size: 7022 install date: 20071108 uninstall cmd: MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3} publisher: Symantec Norton 360 1.0.0.184 ({40DA9A54-48CA-4A2C-AEAF-F67715BB046E}) version: 16777216 version (major): 1 estimated size: 341 install date: 20071108 uninstall cmd: MsiExec.exe /I{40DA9A54-48CA-4A2C-AEAF-F67715BB046E} publisher: Symantec Corporation Microsoft Works 08.04.0623 ({416D80BA-6F6D-4672-B7CF-F54DA2F80B44}) version: 134480495 version (major): 8 version (minor): 4 estimated size: 292509 install date: 20061203 install location: INSTALLDIR install source: D:\MSWORKS\ uninstall cmd: MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44} publisher: Microsoft Corporation comments: Microsoft Works 8.0 installation. help link: http://support.microsoft.com/support/works help telephone: The Sims 2 Pets ({4817189D-1785-4627-A33C-39FD90919300}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 Pets\EAUninstall.exe Norton Confidential Browser Component 1.5.1.4 ({4843B611-8FCB-4428-8C23-31D0A5EAE164}) version: 17104897 version (major): 1 version (minor): 5 estimated size: 3397 install date: 20071108 uninstall cmd: MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164} publisher: Symantec Corporation Windows Communication Foundation 3.0.04506.30 ({491DD792-AD81-429C-9EB4-86DD3D22E333}) version: 50336154 version (major): 3 estimated size: 90556 install date: 20090223 install source: C:\DOCUME~1\Esmee\LOCALS~1\Temp\IXP02C1A.tmp\wcu\wcf\ uninstall cmd: MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333} publisher: Microsoft Corporation ArcSoft Software Suite ({497A1721-088F-41EF-8876-B43C9DA5528B}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{497A1721-088F-41EF-8876-B43C9DA5528B}\Setup.exe" -l0x9 publisher: ArcSoft Windows Live Messenger 8.5.1302.1018 ({508CE775-4BA4-4748-82DF-FE28DA9F03B0}) version: 134546710 version (major): 8 version (minor): 5 estimated size: 31981 install date: 20080917 install source: C:\Program Files\Common Files\WindowsLiveInstaller\MsiSources\ uninstall cmd: MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0} publisher: Microsoft Corporation Symantec Real Time Storage Protection Component 10.2.2.6 ({54358FF9-7E78-42EA-8CC8-CDA0A466B7CA}) version: 167903234 version (major): 10 version (minor): 2 estimated size: 1595 install date: 20071207 install location: C:\Program Files\Common Files\Symantec Shared\SRTSP\ publisher: Symantec Corporation Microsoft Games for Windows - LIVE Redistributable 2.0.672.0 ({59E4543A-D49D-4489-B445-473D763C79AF}) version: 33555104 version (major): 2 estimated size: 34808 install date: 20090223 install source: C:\Documents and Settings\Esmee\My Documents\Downloads\gta 4\GTAIV\Redistributable\ uninstall cmd: MsiExec.exe /X{59E4543A-D49D-4489-B445-473D763C79AF} publisher: Microsoft Corporation The Sims™ 2 Teen Style Stuff ({5C648FDB-0138-4619-B66E-230EF53E8E2C}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 Teen Style Stuff\EAUninstall.exe publisher: Electronic Arts Skype™ 3.6 3.6.244 ({5C82DAE5-6EB0-4374-9254-BE3319BA4E82}) version: 50725108 version (major): 3 version (minor): 6 estimated size: 30386 install date: 20080104 install location: C:\Program Files\Skype\ install source: C:\Documents and Settings\All Users\Application Data\Skype\{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}\ uninstall cmd: MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82} publisher: Skype Technologies S.A. help link: http://ui.skype.com/ui/0/3.6.24.244/en/help ({62369F2F77534556AEF4C58152E3BDE5}) Norton 360 1.0.0.184 ({63A6E9A9-A190-46D4-9430-2DB28654AFD8}) version: 16777216 version (major): 1 estimated size: 3486 install date: 20071108 uninstall cmd: MsiExec.exe /I{63A6E9A9-A190-46D4-9430-2DB28654AFD8} publisher: Symantec Corporation EPSON Copy Utility 3 3.2.0.0 ({67EDD823-135A-4D59-87BD-950616D6E857}) version: 50462720 install location: C:\Program Files\EPSON\Creativity Suite uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x9 -UnInstall Apple Software Update 2.1.1.116 ({6956856F-B6B3-4BE0-BA0B-8F495BE32033}) version: 33619969 version (major): 2 version (minor): 1 estimated size: 2208 install date: 20080812 install location: C:\Program Files\Apple Software Update\ install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\ uninstall cmd: MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033} publisher: Apple Inc. contact: AppleCare Support help link: http://www.apple.com/support/ help telephone: 1-800-275-2273 Windows Media Player Firefox Plugin 1.0.0.8 ({69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) version: 16777216 version (major): 1 estimated size: 296 install date: 20081229 uninstall cmd: MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} publisher: Microsoft Corp Norton Spyware Scan 2.0.109.11 ({6D8C8814-00DF-4F4B-BBC7-E817531416CC}) version: 33554541 version (major): 2 estimated size: 15946 install date: 20061216 install location: C:\Program Files\ publisher: Symantec Corporation comments: BT Yahoo! The Sims 2 ({6E7DD182-9FC6-4651-0095-2E666CC6AF35}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2\EAUninstall.exe Adobe Asset Services CS3 3 ({6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}) version: 50331648 version (major): 3 estimated size: 48799 install date: 20070914 uninstall cmd: MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61} publisher: Adobe Systems Incorporated Microsoft Visual C++ 2005 Redistributable 8.0.56336 ({7299052b-02a4-4627-81f2-1818da5d550d}) version: 134274064 version (major): 8 estimated size: 5330 install date: 20090223 install source: C:\DOCUME~1\Esmee\LOCALS~1\Temp\IXP001.TMP\ uninstall cmd: MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} publisher: Microsoft Corporation 6.6.1 ({7585478E9D9B42108671C12F8714CEFE}) install location: C:\Program Files\DivX\DivX Converter uninstall cmd: C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER publisher: DivX, Inc. Map Button (Windows Live Toolbar) 03.01.0146 ({7745B7A9-F323-4BB9-9811-01BF57A028DA}) version: 50397330 version (major): 3 version (minor): 1 estimated size: 543 install date: 20080302 uninstall cmd: MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA} publisher: Microsoft Corporation SPBBC 32bit 3.2.1.3 ({77772678-817F-4401-9301-ED1D01A8DA56}) version: 50462721 version (major): 3 version (minor): 2 estimated size: 3808 install date: 20071108 install location: C:\Program Files\Norton 360\ uninstall cmd: MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56} publisher: Symantec Corporation Adobe ExtendScript Toolkit 2 2.0.2 ({77D2A9D3-5800-43E3-B274-87841BC87DB2}) version: 33554434 version (major): 2 estimated size: 16967 install date: 20080206 install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Installer420\payloads\AdobeExtendScriptToolkit2.0.2All\ uninstall cmd: MsiExec.exe /I{77D2A9D3-5800-43E3-B274-87841BC87DB2} publisher: Adobe Systems Incorporated Windows Live Favorites for Windows Live Toolbar 03.01.0146 ({786C4AD1-DCBA-49A6-B0EF-B317A344BD66}) version: 50397330 version (major): 3 version (minor): 1 estimated size: 1879 install date: 20080302 uninstall cmd: MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66} publisher: Microsoft Corporation contact: Microsoft Corporation The Sims 2 Open For Business ({7B3577F5-1D82-4C9B-008B-69D026FD8BCA}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 Open For Business\EAUninstall.exe DivX Codec 6.8.5 ({7B63B2922B174135AFC0E1377DD81EC2}) install location: C:\Program Files\DivX\DivX Codec uninstall cmd: C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC publisher: DivX, Inc. Software Update for Web Folders 9.60.6715.0 ({7CCEBC24-62DB-4280-A8EC-BFA49F167920}) version: 154933819 version (major): 9 version (minor): 60 estimated size: 2416 install date: 20061021 publisher: Microsoft Corporation help link: http://www.microsoft.com/windows Windows Workflow Foundation 3.0.4203.2 ({7D1B85BD-AA07-48B8-808D-67A4067FC6BD}) version: 50335851 version (major): 3 estimated size: 18672 install date: 20090223 install location: c:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\ install source: c:\2ad66d8beb088383137c00\wcu\wf\ uninstall cmd: MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD} publisher: Microsoft Corporation Adobe Fireworks CS3 9.0 ({7DFC1012-D346-46CE-B03E-FF79125AE029}) version: 150994944 version (major): 9 estimated size: 195107 install date: 20070914 uninstall cmd: MsiExec.exe /I{7DFC1012-D346-46CE-B03E-FF79125AE029} publisher: Adobe Systems Incorporated EPSON Web-To-Page ({7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}) install location: C:\Program Files\EPSON\EPSON Web-To-Page uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x9 -anything Adobe XMP Panels CS3 1.0 ({802771A9-A856-4A41-ACF7-1450E523C923}) version: 16777216 version (major): 1 estimated size: 197 install date: 20070914 uninstall cmd: MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923} publisher: Adobe Systems Incorporated MSXML 4.0 SP2 (KB954430) 4.20.9870.0 ({86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) version: 68429454 version (major): 4 version (minor): 20 estimated size: 2729 install date: 20081112 uninstall cmd: MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} publisher: Microsoft Corporation help link: http://support.microsoft.com/kb/954430 The Sims™ 2 FreeTime ({87F6C83D-F949-4d14-B5CB-DC8C75F8932D}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 FreeTime\EAUninstall.exe publisher: Electronic Arts Microsoft Silverlight 2.0.31005.0 ({89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) version: 33585437 version (major): 2 estimated size: 7268 install date: 20081020 install location: c:\Program Files\Microsoft Silverlight\ uninstall cmd: MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} publisher: Microsoft Corporation help link: http://go.microsoft.com/fwlink/?LinkID=91955 Bonjour 1.0.105 ({8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}) version: 16777321 version (major): 1 estimated size: 497 install date: 20081126 install location: C:\Program Files\Bonjour\ install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Apple\Apple Software Update\ uninstall cmd: MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959} publisher: Apple Inc. contact: AppleCare Support help link: http://www.apple.com/support/ help telephone: 1-800-275-2273 DivX Player 6.8.2 ({8ADFC4160D694100B5B8A22DE9DCABD9}) install location: C:\Program Files\DivX\DivX Player uninstall cmd: C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER publisher: DivXNetworks, Inc. Adobe Setup 1.0 ({8AE03988-8C8C-40EE-BDC7-76781BEF1B1D}) version: 16777216 version (major): 1 estimated size: 6252 install date: 20080206 install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Installer420\ uninstall cmd: MsiExec.exe /I{8AE03988-8C8C-40EE-BDC7-76781BEF1B1D} publisher: Adobe Systems Incorporated 4oD 2.0.23.0 ({8B7443F5-E141-42A0-AB61-ED2331AAD606}) version: 33554455 version (major): 2 estimated size: 7204 install date: 20080128 install location: C:\Program Files\Channel4\4oD\ install source: C:\Documents and Settings\All Users\Application Data\Channel4\4oD\{E967F56C-536A-413E-93BE-001ACD0658C4}\ publisher: Channel 4 Television Corporation and 4 Ventures Limited contact: 4oDHelp@Channel4.com help link: http://help.channel4.com/4od Adobe Type Support 1.0 ({8E6808E2-613D-4FCD-81A2-6C8FA8E03312}) version: 16777216 version (major): 1 estimated size: 5677 install date: 20070914 uninstall cmd: MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312} publisher: Adobe Systems Incorporated Microsoft Software Update for Web Folders (English) 12 12.0.6215.1000 ({90120000-0010-0409-0000-0000000FF1CE}) version: 201332807 version (major): 12 estimated size: 2227 install date: 20080828 install source: C:\MSOCache\All Users\{90120000-0010-0409-0000-0000000FF1CE}-C\ publisher: Microsoft Corporation Microsoft Office Publisher MUI (English) 2007 12.0.6215.1000 ({90120000-0019-0409-0000-0000000FF1CE}) version: 201332807 version (major): 12 estimated size: 45750 install date: 20080828 install location: C:\Program Files\Microsoft Office\ install source: C:\MSOCache\All Users\{90120000-0019-0409-0000-0000000FF1CE}-C\ uninstall cmd: MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE} publisher: Microsoft Corporation 2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-0019-0409-0000-0000000FF1CE}_PUBLISHERR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}) uninstall cmd: msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59} publisher: Microsoft help link: http://support.microsoft.com/kb/936982 Microsoft Office Proof (English) 2007 12.0.6213.1000 ({90120000-001F-0409-0000-0000000FF1CE}) version: 201332805 version (major): 12 estimated size: 47895 install date: 20080828 install location: C:\Program Files\Microsoft Office\ install source: C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.en\ uninstall cmd: MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE} publisher: Microsoft Corporation 2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-001F-0409-0000-0000000FF1CE}_PUBLISHERR_{3EC77D26-799B-4CD8-914F-C1565E796173}) uninstall cmd: msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173} publisher: Microsoft help link: http://support.microsoft.com/kb/936982 Microsoft Office Proof (French) 2007 12.0.6213.1000 ({90120000-001F-040C-0000-0000000FF1CE}) version: 201332805 version (major): 12 estimated size: 23188 install date: 20080828 install location: C:\Program Files\Microsoft Office\ install source: C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\ uninstall cmd: MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE} publisher: Microsoft Corporation 2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-001F-040C-0000-0000000FF1CE}_PUBLISHERR_{430971B1-C31E-45DA-81E0-72C095BAB72C}) uninstall cmd: msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C} publisher: Microsoft help link: http://support.microsoft.com/kb/936982 Microsoft Office Proof (Spanish) 2007 12.0.6213.1000 ({90120000-001F-0C0A-0000-0000000FF1CE}) version: 201332805 version (major): 12 estimated size: 38157 install date: 20080828 install location: C:\Program Files\Microsoft Office\ install source: C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.es\ uninstall cmd: MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE} publisher: Microsoft Corporation 2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-001F-0C0A-0000-0000000FF1CE}_PUBLISHERR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}) uninstall cmd: msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1} publisher: Microsoft help link: http://support.microsoft.com/kb/936982 Microsoft Office Proofing (English) 2007 12.0.4518.1014 ({90120000-002C-0409-0000-0000000FF1CE}) version: 201331110 version (major): 12 estimated size: 506 install date: 20071126 install location: C:\Program Files\Microsoft Office\ install source: C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\ uninstall cmd: MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE} publisher: Microsoft Corporation Microsoft Office Shared MUI (English) 2007 12.0.6215.1000 ({90120000-006E-0409-0000-0000000FF1CE}) version: 201332807 version (major): 12 estimated size: 40806 install date: 20080828 install location: C:\Program Files\Microsoft Office\ install source: C:\MSOCache\All Users\{90120000-0115-0409-0000-0000000FF1CE}-C\ uninstall cmd: MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE} publisher: Microsoft Corporation 2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-006E-0409-0000-0000000FF1CE}_PUBLISHERR_{FAD8A83E-9BAC-4179-9268-A35948034D85}) uninstall cmd: msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85} publisher: Microsoft help link: http://support.microsoft.com/kb/936982 Microsoft Office Shared Setup Metadata MUI (English) 2007 12.0.6215.1000 ({90120000-0115-0409-0000-0000000FF1CE}) version: 201332807 version (major): 12 estimated size: 502 install date: 20080828 install location: C:\Program Files\Microsoft Office\ install source: C:\MSOCache\All Users\{90120000-0115-0409-0000-0000000FF1CE}-C\ uninstall cmd: MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE} publisher: Microsoft Corporation 2007 Microsoft Office Suite Service Pack 1 (SP1) ({90120000-0115-0409-0000-0000000FF1CE}_PUBLISHERR_{FAD8A83E-9BAC-4179-9268-A35948034D85}) uninstall cmd: msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85} publisher: Microsoft help link: http://support.microsoft.com/kb/936982 Adobe Anchor Service CS3 1.0 ({90176341-0A8B-4CCC-A78D-F862228A6B95}) version: 16777216 version (major): 1 estimated size: 1025 install date: 20070914 uninstall cmd: MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95} publisher: Adobe Systems Incorporated Microsoft Office Publisher 2007 12.0.6215.1000 ({91120000-0019-0000-0000-0000000FF1CE}) version: 201332807 version (major): 12 estimated size: 651089 install date: 20081212 install location: C:\Program Files\Microsoft Office\ install source: C:\MSOCache\All Users\{91120000-0019-0000-0000-0000000FF1CE}-C\ uninstall cmd: MsiExec.exe /X{91120000-0019-0000-0000-0000000FF1CE} publisher: Microsoft Corporation Security Update for Microsoft Office system 2007 (KB954326) ({91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{5F7F6FFF-395D-480E-8450-64F385D82C5F}) uninstall cmd: msiexec /package {91120000-0019-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F} publisher: Microsoft help link: http://support.microsoft.com/kb/954326 Security Update for 2007 Microsoft Office System (KB951944) ({91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{797AE457-BA17-4BBC-B501-25FB3A0103C7}) uninstall cmd: msiexec /package {91120000-0019-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7} publisher: Microsoft help link: http://support.microsoft.com/kb/951944 Security Update for Microsoft Office system 2007 (KB956828) ({91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{885E081B-72BD-4E76-8E98-30B4BE468FAC}) uninstall cmd: msiexec /package {91120000-0019-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC} publisher: Microsoft help link: http://support.microsoft.com/kb/956828 Update for Office 2007 (KB946691) ({91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{A420F522-7395-4872-9882-C591B4B92278}) uninstall cmd: msiexec /package {91120000-0019-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278} publisher: Microsoft help link: http://support.microsoft.com/kb/946691 Security Update for 2007 Microsoft Office System (KB951550) ({91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{B243E9A5-ED77-4F1B-B338-2486FD82DC85}) uninstall cmd: msiexec /package {91120000-0019-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85} publisher: Microsoft help link: http://support.microsoft.com/kb/951550 2007 Microsoft Office Suite Service Pack 1 (SP1) ({91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}) uninstall cmd: msiexec /package {91120000-0019-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419} publisher: Microsoft help link: http://support.microsoft.com/kb/936982 Security Update for Microsoft Office Publisher 2007 (KB950114) ({91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}) uninstall cmd: msiexec /package {91120000-0019-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85} publisher: Microsoft help link: http://support.microsoft.com/kb/950114 Windows Live Writer 12.0.1370.0325 ({9176251A-4CC1-4DDB-B343-B487195EB397}) version: 201327962 version (major): 12 estimated size: 15634 install date: 20080409 install source: C:\Program Files\Common Files\WindowsLiveInstaller\MsiSources\ uninstall cmd: MsiExec.exe /X{9176251A-4CC1-4DDB-B343-B487195EB397} publisher: Microsoft Corporation InterVideo WinDVD 5.0-B11.780 ({91810AFC-A4F8-4EBA-A5AA-B198BBC81144}) version (major): 5 install location: C:\Program Files\InterVideo\WinDVD uninstall cmd: "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL publisher: InterVideo Inc. contact: support@intervideo.com help link: http://www.intervideo.com/jsp/Support.jsp MobileMe Control Panel 2.1.2.7 ({924EB80F-C2BB-4B9F-8412-88BBA937393F}) version: 33619970 version (major): 2 version (minor): 1 estimated size: 5263 install date: 20081126 install location: C:\Program Files\Common Files\Apple\Mobile Device Support\ install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Apple\Apple Software Update\ uninstall cmd: MsiExec.exe /I{924EB80F-C2BB-4B9F-8412-88BBA937393F} publisher: Apple Inc. contact: AppleCare Support help link: http://www.apple.com/support/ help telephone: 1-800-275-2273 Symantec Technical Support Controls 1.0.0 ({92B1B3CC-EC78-45B8-96D0-8B3F11495864}) version: 16777216 version (major): 1 estimated size: 4904 install date: 20071108 uninstall cmd: MsiExec.exe /I{92B1B3CC-EC78-45B8-96D0-8B3F11495864} publisher: Symantec Corporation PHOTOfunSTUDIO -viewer- 2.00.000 ({9A9DBEBC-C800-4776-A970-D76D6AA405B1}) version: 33554432 install date: 20090130 install location: C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer- install source: D:\PHOTOFUN\Setup\ uninstall cmd: C:\Program Files\InstallShield Installation Information\{9A9DBEBC-C800-4776-A970-D76D6AA405B1}\setup.exe -runfromtemp -l0x0009 -z"Uninstall" -removeonly publisher: Panasonic FIFA 07 ({9BE8E9B7-A286-44BF-0080-C947C6C1FC21}) uninstall cmd: C:\Program Files\EA SPORTS\FIFA 07\EAUninstall.exe Adobe Bridge CS3 2 ({9C9824D9-9000-4373-A6A5-D0E5D4831394}) version: 33554432 version (major): 2 estimated size: 270278 install date: 20070914 uninstall cmd: MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394} publisher: Adobe Systems Incorporated Adobe CMaps 1.0 ({A2B242BD-FF8D-4840-9DAA-9170EABEC59C}) version: 16777216 version (major): 1 estimated size: 6493 install date: 20070914 uninstall cmd: MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C} publisher: Adobe Systems Incorporated Highlight Viewer (Windows Live Toolbar) 03.01.0146 ({A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}) version: 50397330 version (major): 3 version (minor): 1 estimated size: 1303 install date: 20080302 uninstall cmd: MsiExec.exe /X{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF} publisher: Microsoft Corporation Belkin Wireless USB Utility 6.3.2.16 ({A6359CCF-215D-43D9-8366-479D231F2A72}) version: 100859906 version (major): 6 version (minor): 3 estimated size: 5016 install date: 20061206 install location: C:\Program Files\Belkin\USB F5D7050\Wireless Utility\ publisher: Belkin help link: http://www.belkin.com Adobe® Photoshop® Album Starter Edition 3.2 3.2.0 ({A654A805-41D9-40C7-AA46-4AF04F044D61}) version: 50462720 version (major): 3 version (minor): 2 estimated size: 19336 install date: 20070622 install location: C:\Program Files\Adobe\Photoshop Album Starter Edition\ install source: C:\WINDOWS\Downloaded Installations\{3E547985-AA94-4B1B-8ADD-21E060E5E31F}\ publisher: Adobe Systems, Inc. readme: C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\readme.txt Windows Live installer 12.0.1471.1025 ({A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}) version: 201328063 version (major): 12 estimated size: 2204 install date: 20080302 uninstall cmd: MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320} publisher: Microsoft Corporation help link: http://get.live.com Adobe Reader 8.1.3 8.1.3 ({AC76BA86-7AD7-1033-7B44-A81300000003}) version: 134283267 version (major): 8 version (minor): 1 estimated size: 88778 install date: 20081119 install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Adobe\Updater5\Install\reader8rdr-en_US\ uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003} publisher: Adobe Systems Incorporated comments: contact: Customer Support help link: http://www.adobe.com/support/main.html readme: C:\Program Files\Adobe\Reader 8.0\Reader\Readme.htm Spelling Dictionaries Support For Adobe Reader 8 8.0.0 ({AC76BA86-7AD7-5464-3428-800000000003}) version: 134217728 version (major): 8 estimated size: 33322 install date: 20080904 install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Adobe\Updater5\Install\reader8rdr-en_US\ uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003} publisher: Adobe Systems comments: This is a placeholder for ARP comments for Spelling Dictionaries for Adobe Reader 8.0 contact: Customer Support help link: http://www.adobe.com/support/main.html help telephone: 1-800-833-6687 ABBYY FineReader 6.0 Sprint 6.00.1395.4512 ({ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) version: 100664691 version (major): 6 estimated size: 122009 install date: 20061202 install location: C:\Program Files\ABBYY FineReader 6.0 Sprint\ install source: D:\COMMON\ABBYY\ uninstall cmd: MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07} publisher: ABBYY Software House contact: support@abbyy.com help link: http://www.abbyy.com/support Windows Live Sign-in Assistant 4.200.520.1 ({AFA4E5FD-ED70-4D92-99D0-162FD56DC986}) version: 80216584 version (major): 4 version (minor): 200 estimated size: 1333 install date: 20080302 install source: C:\Program Files\Common Files\WindowsLiveInstaller\MsiSources\ uninstall cmd: MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986} publisher: Microsoft Corporation Norton Save and Restore 11.0.0.11492 ({B0255743-165B-4BD5-8DA8-37DFB993B101}) version: 184549376 version (major): 11 estimated size: 95256 install date: 20061202 install location: C:\Program Files\Norton Save and Restore\ install source: D:\ uninstall cmd: MsiExec.exe /X{B0255743-165B-4BD5-8DA8-37DFB993B101} publisher: Symantec comments: Symantec Inc. contact: Customer Support Department help link: http://www.symantec.com/support help telephone: readme: "C:\Program Files\Norton Save and Restore\SHARED\Readme.txt" DivX Converter 6.6.1 ({B13A7C41581B411290FBC0395694E2A9}) install location: C:\Program Files\DivX\DivX Converter uninstall cmd: C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER publisher: DivX, Inc. Adobe Camera Raw 4.0 4.0 ({B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}) version: 67108864 version (major): 4 estimated size: 9969 install date: 20070914 uninstall cmd: MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C} publisher: Adobe Systems Incorporated Spybot - Search & Destroy 1.6.2 ({B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) install date: 20090206 install location: C:\Program Files\Spybot - Search & Destroy\ uninstall cmd: "C:\Program Files\Spybot - Search & Destroy\unins000.exe" publisher: Safer Networking Limited help link: http://www.safer-networking.org/index.php?page=support Microsoft .NET Framework 2.0 Service Pack 1 2.1.21022 ({B508B3F1-A24A-32C0-B310-85786919EF28}) version: 33640990 version (major): 2 version (minor): 1 estimated size: 190114 install date: 20080411 uninstall cmd: MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28} publisher: Microsoft Corporation help link: http://go.microsoft.com/fwlink/?LinkId=98073 The Sims™ 2 Apartment Life ({B6F5B704-06D3-4687-90F3-6195304AD755}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 Apartment Life\EAUninstall.exe publisher: Electronic Arts DivX Web Player 1.4.2 ({B7050CBDB2504B34BC2A9CA0A692CC29}) install location: C:\Program Files\DivX\DivX Web Player uninstall cmd: C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN publisher: DivX,Inc. ATI Catalyst Control Center 1.2.2545.38916 ({B7777E08-1344-42E8-975B-6F541F9ADBD8}) version: 16910833 version (major): 1 version (minor): 2 estimated size: 67692 install date: 20070209 install source: C:\ATI\SUPPORT\7-1_xp_dd_ccc_wdm_enu_40211\ACE\ uninstall cmd: MsiExec.exe /I{B7777E08-1344-42E8-975B-6F541F9ADBD8} comments: Free technical support for ATI products, available 24 hours a day through our customer care webform. contact: Customer Support Department help link: http://www.ati.com/support/ help telephone: 1-877-284-1564 PIF DESIGNER ({B90450DF-E781-46FD-B1F1-0C86DA40E443}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x9 anything Adobe Default Language CS3 1.0 ({B9B35331-B7E4-4E5C-BF4C-7BC87856124D}) version: 16777216 version (major): 1 estimated size: 1730 install date: 20070914 uninstall cmd: MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D} publisher: Adobe Systems Incorporated Windows Presentation Foundation 3.0.6920.0 ({BAF78226-3200-4DB4-BE33-4D922A799840}) version: 50338568 version (major): 3 estimated size: 117877 install date: 20090223 install source: c:\2ad66d8beb088383137c00\wcu\wpf\ uninstall cmd: MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840} publisher: Microsoft Corporation EPSON Easy Photo Print 1.2.3.0 ({BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}) version: 16908291 install location: C:\Program Files\EPSON\Creativity Suite\Easy Photo Print uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}\SETUP.EXE" -l0x9 UNINST Packard Bell DSC3 Installer Shield ({BDC4AC60-96F3-11D5-AE1E-0000210292ED}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BDC4AC60-96F3-11D5-AE1E-0000210292ED}\setup.exe" MSXML 4.0 SP2 (KB936181) 4.20.9848.0 ({C04E32E0-0416-434D-AFB9-6969D703A9EF}) version: 68429432 version (major): 4 version (minor): 20 estimated size: 2680 install date: 20070815 uninstall cmd: MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} publisher: Microsoft Corporation help link: http://support.microsoft.com/kb/936181 Labtec WebCam Software 8.42.0000 ({C43048A9-742C-4DAD-90D2-E3B53C9DB825}) version: 136970240 install location: C:\Program Files\Logitech\Video install source: D:\WebCam\ uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x9 publisher: Labtec, Inc. contact: Labtec Customer Support help link: http://www.labtec.com/support help telephone: USA: (702) 269-3457 UK: +44 (0) 1344-894301 readme: C:\Program Files\Logitech\Video\Readme.txt Vampire - The Masquerade Bloodlines 1.00.0000 ({C4E2A4A7-B623-40CB-8EEA-72F577E49D56}) version: 16777216 version (major): 1 estimated size: 2912512 install date: 20061203 install location: C:\Program Files\Activision\Vampire - Bloodlines\ install source: D:\ publisher: Activision help link: http://activision.custhelp.com Adobe Setup 1.0 ({C92A5A89-B218-46F7-8898-77C52113FFE0}) version: 16777216 version (major): 1 estimated size: 16068 install date: 20070914 uninstall cmd: MsiExec.exe /I{C92A5A89-B218-46F7-8898-77C52113FFE0} publisher: Adobe Systems Incorporated Microsoft .NET Framework 1.1 1.1.4322 ({CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) version: 16847074 version (major): 1 version (minor): 1 estimated size: 75259 install date: 20070712 uninstall cmd: MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} publisher: Microsoft readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm GearDrvs 1.00.0000 ({CB84F0F2-927B-458D-9DC5-87832E3DC653}) version: 16777216 version (major): 1 estimated size: 1324 install date: 20081006 install source: C:\WINDOWS\system32\ uninstall cmd: MsiExec.exe /I{CB84F0F2-927B-458D-9DC5-87832E3DC653} publisher: GEAR Software Roxio Easy DVD Copy 2 2.1.020 ({CDD55C1D-FC16-41F7-9E8D-884466E622EC}) version: 33619988 version (major): 2 version (minor): 1 estimated size: 147497 install date: 20080104 install location: C:\Program Files\Roxio\Easy Media Creator 8\ install source: D:\ uninstall cmd: MsiExec.exe /I{CDD55C1D-FC16-41F7-9E8D-884466E622EC} publisher: Roxio, Inc. comments: Master installer for The Digital Media Suite contact: http://support.roxio.com help link: http://support.roxio.com readme: C:\Program Files\Roxio\Easy Media Creator 8\EasyDVDCopy2ReadMe.html Adobe Version Cue CS3 Client 3 ({D0DFF92A-492E-4C40-B862-A74A173C25C5}) version: 50331648 version (major): 3 estimated size: 22415 install date: 20070914 uninstall cmd: MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5} publisher: Adobe Systems Incorporated Adobe PDF Library Files 8.0 ({D2559B88-CC9D-4B48-81BB-F492BAA9C48C}) version: 134217728 version (major): 8 estimated size: 59001 install date: 20070914 uninstall cmd: MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C} publisher: Adobe Systems Incorporated Norton Confidential Web Protection Component 1.5.1.4 ({D353CC51-430D-4C6F-9B7E-52003DA1E05A}) version: 17104897 version (major): 1 version (minor): 5 estimated size: 965 install date: 20071108 uninstall cmd: MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A} publisher: Symantec Corporation GTA San Andreas 1.00.00001 ({D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) version: 16777217 install date: 20061227 install location: C:\Program Files\Rockstar Games\GTA San Andreas install source: D:\ uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly publisher: Rockstar Games contact: Rockstar Games help link: http://www.Rockstargames.com readme: C:\Program Files\Rockstar Games\GTA San Andreas\ReadMe\Readme.txt Windows Live Toolbar 03.01.0146 ({D5A145FC-D00C-4F1A-9119-EB4D9D659750}) version: 50397330 version (major): 3 version (minor): 1 estimated size: 9486 install date: 20080302 install source: C:\Program Files\Common Files\WindowsLiveInstaller\MsiSources\ uninstall cmd: MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750} publisher: Microsoft Corporation Adobe Extension Manager CS3 1.8 ({D7A53E41-3F32-4A44-989C-53DDEBB2130C}) version: 17301504 version (major): 1 version (minor): 8 estimated size: 50381 install date: 20070914 uninstall cmd: MsiExec.exe /I{D7A53E41-3F32-4A44-989C-53DDEBB2130C} publisher: Adobe Systems Incorporated LiveUpdate Notice (Symantec Corporation) 1.4.5 ({DBA4DB9D-EE51-4944-A419-98AB1F1249C8}) version: 17039365 version (major): 1 version (minor): 4 estimated size: 8760 install date: 20080226 uninstall cmd: MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8} publisher: Symantec Corporation Ad-Aware 8.0.0 ({DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}) version: 134217728 version (major): 8 estimated size: 57384 install date: 20090207 install location: C:\Program Files\Lavasoft\Ad-Aware uninstall cmd: C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe publisher: Lavasoft The Sims™ 2 Seasons ({DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 Seasons\EAUninstall.exe Poker Masters 1.00.0000 ({E0A192C7-2C4A-4F7D-99A6-F7347E0FEAC9}) version: 16777216 uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E0A192C7-2C4A-4F7D-99A6-F7347E0FEAC9}\Setup.exe" -l0x9 Adobe Update Manager CS3 5.1.0 ({E69AE897-9E0B-485C-8552-7841F48D42D8}) version: 83951616 version (major): 5 version (minor): 1 estimated size: 6232 install date: 20070914 uninstall cmd: MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8} publisher: Adobe Systems Incorporated EPSON File Manager 1.1.0.0 ({E86BC406-944E-41F6-ADE6-2C136734C96B}) version: 16842752 install location: C:\Program Files\EPSON\Creativity Suite\File Manager uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x9 UNINST AppCore 1 ({EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}) version: 16777216 version (major): 1 estimated size: 412 install date: 20071108 uninstall cmd: MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B} publisher: Symantec Corporation Smart Menus (Windows Live Toolbar) 03.01.0146 ({F084395C-40FB-4DB3-981C-B51E74E1E83D}) version: 50397330 version (major): 3 version (minor): 1 estimated size: 679 install date: 20080302 uninstall cmd: MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D} publisher: Microsoft Corporation Microsoft SQL Server 2005 Compact Edition [ENU] 3.1.0000 ({F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) version: 50397184 version (major): 3 version (minor): 1 estimated size: 1783 install date: 20080302 install location: C:\Program Files\Microsoft SQL Server Compact Edition\ uninstall cmd: MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8} publisher: Microsoft Corporation help link: http://www.microsoft.com/sql/everywhere Realtek High Definition Audio Driver ({F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) uninstall cmd: RtlUpd.exe -r -m The Sims™ 2 Bon Voyage ({F248ADFA-64E0-4b03-8A83-059078BED6A0}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 Bon Voyage\EAUninstall.exe publisher: Electronic Arts Visual C++ 2008 x86 Runtime - (v9.0.30729) 9.0.30729 ({F333A33D-125C-32A2-8DCE-5C5D14231E27}) version: 151025673 version (major): 9 estimated size: 23963 install date: 20090207 uninstall cmd: MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27} publisher: Microsoft Corporation Visual C++ 2008 x86 Runtime - v9.0.30729.01 9.0.30729.01 ({F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) uninstall cmd: C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT="" publisher: Microsoft Corporation AV 1 ({F4DB525F-A986-4249-B98B-42A8066251CA}) version: 16777216 version (major): 1 estimated size: 5063 install date: 20071108 uninstall cmd: MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA} publisher: Symantec Corporation The Sims 2 Nightlife ({F7529650-B9DB-481B-0089-A2AC3C2821C1}) uninstall cmd: C:\Program Files\EA GAMES\The Sims 2 Nightlife\EAUninstall.exe The Simpsons Hit & Run(TM) 1.00.000 ({F79AAB3A-B8B4-4AC7-94AB-1C4C076C6A89}) version: 16777216 install location: C:\Program Files\Vivendi Universal Games\The Simpsons Hit & Run\ uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79AAB3A-B8B4-4AC7-94AB-1C4C076C6A89}\setup.exe" -l0x9 QuickTime 7.55.90.70 ({F958CA02-BB40-4007-894B-258729456EE4}) version: 121045082 version (major): 7 version (minor): 55 estimated size: 75933 install date: 20081126 install location: C:\Program Files\QuickTime\ install source: C:\Documents and Settings\Esmee\Local Settings\Application Data\Apple\Apple Software Update\ uninstall cmd: MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4} publisher: Apple Inc. contact: AppleCare Support help link: http://www.apple.com/support/ help telephone: 1-800-275-2273 MSXML 6.0 Parser (KB925673) 6.00.3888.0 ({FE9126DB-5F84-495A-BB46-3C724F1C2D08}) version: 100667184 version (major): 6 estimated size: 1496 install date: 20090223 install source: c:\2ad66d8beb088383137c00\wcu\msxml\ uninstall cmd: MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08} publisher: Microsoft Corporation help link: http://support.microsoft.com/kb/925673 --- System Services --- Service (registry key): .NET CLR Data Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NET CLR Networking Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NET Data Provider for Oracle Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NET Data Provider for SqlServer Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NETFramework Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): a2AntiMalware Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: a-squared Anti-Malware Service Description: Scans the PC for unwanted software and provides protection from malicious code Object name: LocalSystem Image path: "C:\Program Files\a-squared Anti-Malware\a2service.exe" Image size: 421496 Image MD5: 66D2F0F0227E57AADC91D3613D91EC61 Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Service (registry key): Abiosdsk Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 0 Service (registry key): abp480n5 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ACDaemon Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ArcSoft Connect Daemon Object name: LocalSystem Image path: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe Image size: 102712 Image MD5: 61A581E5481E22A76A88490C57015105 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Service (registry key): ACPI Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft ACPI Driver Image path: system32\DRIVERS\ACPI.sys Image size: 187776 Image MD5: 8FD99680A539792A30E97944FDAECF17 Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): ACPIEC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): adpu160m Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): adxapie Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: adxapie Image path: \??\C:\DOCUME~1\Esmee\LOCALS~1\Temp\adxapie.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): aec Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel Acoustic Echo Canceller Image path: system32\drivers\aec.sys Image size: 142592 Image MD5: 8BED39E3C35D6A489438B8141717A557 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Afc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PPdus ASPI Shell Image path: system32\drivers\Afc.sys Image size: 11776 Image MD5: A7B8A3A79D35215D798A300DF49ED23F Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): AFD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: AFD Description: AFD Networking Support Environment Image path: \SystemRoot\System32\drivers\afd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): Aha154x Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): aic78u2 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): aic78xx Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Alerter Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Alerter Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): ALG Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Application Layer Gateway Service Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\alg.exe Image size: 44544 Image MD5: 8C515081584A38AA007909CD02020B3D Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): AliIde Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): amsint Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): AppMgmt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Application Management Description: Provides software installation services such as Assign, Publish, and Remove. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): Arp1394 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: 1394 ARP Client Protocol Description: 1394 ARP Client Protocol Image path: system32\DRIVERS\arp1394.sys Image size: 60800 Image MD5: B5B8A80875C1DEDEDA8B02765642C32F Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): asc Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): asc3350p Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): asc3550 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ASP.NET Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ASP.NET_1.1.4322 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ASP.NET_2.0.50727 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): aspnet_state Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ASP.NET State Service Description: Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe Image size: 33800 Image MD5: 4EABF511B1AF176A971C3271E48FA3A8 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): AsyncMac Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: RAS Asynchronous Media Driver Description: RAS Asynchronous Media Driver Image path: system32\DRIVERS\asyncmac.sys Image size: 14336 Image MD5: B153AFFAC761E7F5FCFA822B9C4E97BC Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): atapi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Standard IDE/ESDI Hard Disk Controller Image path: system32\DRIVERS\atapi.sys Image size: 96512 Image MD5: 9F3A2F5AA6875C72BF062C712CFA2674 Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): Atdisk Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 0 Service (registry key): Ati HotKey Poller Registry path: \SYSTEM\CurrentControlSet\Services\ Object name: LocalSystem Image path: %SystemRoot%\system32\Ati2evxx.exe Image size: 483328 Image MD5: 666E4E583A7CF1233C6425DA16ECDC89 Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Service (registry key): ATI Smart Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ATI Smart Object name: LocalSystem Image path: C:\WINDOWS\system32\ati2sgag.exe Image size: 520192 Image MD5: BFBE2F559EBA2AAFF58235760FC1ECBA Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Service (registry key): ati2mtag Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\ati2mtag.sys Image size: 2456064 Image MD5: 0C2CA1C294938139829B1983A0C38B31 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): Atierecord Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Atmarpc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ATM ARP Client Protocol Description: ATM ARP Client Protocol Image path: system32\DRIVERS\atmarpc.sys Image size: 59904 Image MD5: 9916C1225104BA14794209CFA8012159 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): AudioSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Audio Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: PlugPlay,RpcSs Service (registry key): audstub Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Audio Stub Driver Image path: system32\DRIVERS\audstub.sys Image size: 3072 Image MD5: D9F724AA26C010A217C97606B160ED68 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Automatic LiveUpdate Scheduler Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Automatic LiveUpdate Scheduler Description: Manages the scheduling of Automatic LiveUpdate sessions Object name: LocalSystem Image path: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" Image size: 554352 Image MD5: B5D974C1FD078A68C7536C561B031D39 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): BattC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Beep Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): BITS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Background Intelligent Transfer Service Description: Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: Rpcss Service (registry key): BLKWGU(Belkin) Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Belkin Wireless G USB Network Adapter(Belkin) Image path: system32\DRIVERS\BLKWGU.sys Image size: 402944 Image MD5: ED910B63A75863A89AAB65F2763D5B71 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Bonjour Service Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Bonjour Service Description: Bonjour allows applications like iTunes and Safari to advertise and discover services on the local network. Having Bonjour running enables you to connect to hardware devices like Apple TV and software services like iTunes sharing and AirTunes. If you disable Bonjour, any network service that explicitly depends on it will fail to start. Object name: LocalSystem Image path: "C:\Program Files\Bonjour\mDNSResponder.exe" Image size: 238888 Image MD5: 9EFE4236F8670846B6E7C5B0EFF6E715 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: Tcpip Service (registry key): Browser Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Computer Browser Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation,LanmanServer Service (registry key): cbidf2k Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): CCDECODE Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Closed Caption Decoder Image path: system32\DRIVERS\CCDECODE.sys Image size: 17024 Image MD5: 0BE5AEF125BE881C4F854C554F2B025C Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ccEvtMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Event Manager Description: Event propagation and logging service Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon Image size: 108648 Image MD5: FE69C498B922CE835E2E2123FBD0A272 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RPCSS,ccSetMgr Service (registry key): ccSetMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Settings Manager Description: Settings storage and management service Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon Image size: 108648 Image MD5: FE69C498B922CE835E2E2123FBD0A272 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RPCSS Service (registry key): cd20xrnt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Cdaudio Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): Cdfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Depends On group: "SCSI CDROM Class" Service (registry key): Cdrom Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: CD-ROM Driver Image path: system32\DRIVERS\cdrom.sys Image size: 62976 Image MD5: 1F4260CC5B42272D71F79E570A27A4FE Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On group: "SCSI miniport" Service (registry key): Changer Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): CiSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Indexing Service Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language. Object name: LocalSystem Image path: %SystemRoot%\system32\cisvc.exe Image size: 5632 Image MD5: 1CFE720EB8D93A7158A4EBC3AB178BDE Control Set: CurrentControlSet Start: 2 Type: 288 Error Control: 1 Depends On services: RPCSS Service (registry key): ClipSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ClipBook Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\clipsrv.exe Image size: 33280 Image MD5: 34CBE729F38138217F9C80212A2A0C82 Control Set: CurrentControlSet Start: 4 Type: 16 Error Control: 1 Depends On services: NetDDE Service (registry key): clr_optimization_v2.0.50727_32 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: .NET Runtime Optimization Service v2.0.50727_X86 Description: Microsoft .NET Framework NGEN Object name: LocalSystem Image path: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe Image size: 70144 Image MD5: 234B1BC2796483E1F5C3F26649FB3388 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Service (registry key): CLTNetCnService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Lic NetConnect service Description: Symantec Lic NetConnect Service Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon Image size: 108648 Image MD5: FE69C498B922CE835E2E2123FBD0A272 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Service (registry key): CmdIde Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): comHost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: COM Host Description: COM aggregation host service Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe" Image size: 49248 Image MD5: 3B38F3DEFD61DB294421993F969BC88F Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Depends On services: RpcSs Service (registry key): COMSysApp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: COM+ System Application Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} Image size: 5120 Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: rpcss Service (registry key): ContentFilter Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ContentIndex Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Cpqarray Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): CryptSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Cryptographic Services Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): dac2w2k Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 0 Service (registry key): dac960nt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): DcomLaunch Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: DCOM Server Process Launcher Description: Provides launch functionality for DCOM services. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost -k DcomLaunch Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): Dhcp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: DHCP Client Description: Manages network configuration by registering and updating IP addresses and DNS names. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: Tcpip,Afd,NetBT Service (registry key): Disk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Disk Driver Image path: system32\DRIVERS\disk.sys Image size: 36352 Image MD5: 044452051F3E02E7963599FC8F4F3E25 Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Depends On group: "SCSI miniport" Service (registry key): dmadmin Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Logical Disk Manager Administrative Service Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops. Object name: LocalSystem Image path: %SystemRoot%\System32\dmadmin.exe /com Image size: 224768 Image MD5: E46050330BD42F33609117F861E32D3C Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,PlugPlay,DmServer Service (registry key): dmboot Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\drivers\dmboot.sys Image size: 799744 Image MD5: D992FE1274BDE0F84AD826ACAE022A41 Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): dmio Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Logical Disk Manager Driver Image path: System32\drivers\dmio.sys Image size: 153344 Image MD5: 7C824CF7BBDE77D95C08005717A95F6F Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): dmload Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\drivers\dmload.sys Image size: 5888 Image MD5: E9317282A63CA4D188C0DF5E09C6AC5F Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): dmserver Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Logical Disk Manager Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,PlugPlay Service (registry key): DMusic Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel DLS Syntheiszer Image path: system32\drivers\DMusic.sys Image size: 52864 Image MD5: 8A208DFCF89792A484E76C40E5F50B45 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Dnscache Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: DNS Client Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k NetworkService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: Tcpip Service (registry key): Dot3svc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Wired AutoConfig Description: This service performs IEEE 802.1X authentication on Ethernet interfaces Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k dot3svc Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Ndisuio,eaphost Service (registry key): dpti2o Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): drmkaud Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel DRM Audio Descrambler Image path: system32\drivers\drmkaud.sys Image size: 2944 Image MD5: 8F5FCFF8E8848AFAC920905FBD9D33C8 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): EapHost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Extensible Authentication Protocol Service Description: Provides windows clients Extensible Authentication Protocol Service Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k eapsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): eeCtrl Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Eraser Control driver Image path: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys Image size: 371248 Image MD5: 47CE4E650D91DC095A2FDDB15631A78A Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: FltMgr Service (registry key): ehRecvr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Media Center Receiver Service Description: Media Center Service for TV and FM broadcast reception Object name: LocalSystem Image path: C:\WINDOWS\eHome\ehRecvr.exe Image size: 237568 Image MD5: 5D1347AA5AE6E2F77D7F4F8372D95AC9 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Depends On services: RPCSS Service (registry key): ehSched Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Media Center Scheduler Service Object name: LocalSystem Image path: C:\WINDOWS\eHome\ehSched.exe Image size: 102912 Image MD5: A53243709439AC2A4C216B817F8D7411 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): EraserSvc10824 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Eraser Service Description: Eraser Service, version 108.2.4 in use. Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon Image size: 108648 Image MD5: FE69C498B922CE835E2E2123FBD0A272 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): EraserUtilDrvI4 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: EraserUtilDrvI4 Image path: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI4.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): EraserUtilRebootDrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: EraserUtilRebootDrv Image path: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys Image size: 99376 Image MD5: CE3EF5C79CB0BFA036E844F74C52D759 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ERSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Error Reporting Service Description: Allows error reporting for services and applictions running in non-standard environments. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RpcSs Service (registry key): Eventlog Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Event Log Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Object name: LocalSystem Image path: %SystemRoot%\system32\services.exe Image size: 108544 Image MD5: 0E776ED5F7CC9F94299E70461B7B8185 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): EventSystem Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: COM+ Event System Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): Fastfat Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Service (registry key): FastUserSwitchingCompatibility Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Fast User Switching Compatibility Description: Provides management for applications that require assistance in a multiple user environment. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: TermService Service (registry key): Fax Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Fax Description: Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network. Object name: LocalSystem Image path: %systemroot%\system32\fxssvc.exe Image size: 267776 Image MD5: E97D6A8684466DF94FF3BC24FB787A07 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: TapiSrv,RpcSs,PlugPlay,Spooler Service (registry key): Fdc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Floppy Disk Controller Driver Image path: system32\DRIVERS\fdc.sys Image size: 27392 Image MD5: 92CDD60B6730B9F50F6A1A0C1F8CDC81 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Fips Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): FLEXnet Licensing Service Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: FLEXnet Licensing Service Description: This service performs licensing functions on behalf of FLEXnet enabled products. Object name: LocalSystem Image path: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" Image size: 654848 Image MD5: 227846995AFEEFA70D328BF5334A86A5 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): Flpydisk Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): FltMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: FltMgr Description: File System Filter Manager Driver Image path: system32\drivers\fltmgr.sys Image size: 129792 Image MD5: B2CF4B0786F8212CB92ED2B50C6DB6B0 Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Service (registry key): FontCache3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Presentation Foundation Font Cache 3.0.0.0 Description: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications. Object name: NT AUTHORITY\LocalService Image path: c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe Image size: 36864 Image MD5: FACECF3F75BAF3775A879D1168402270 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): Fs_Rec Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 8 Error Control: 0 Service (registry key): Ftdisk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Volume Manager Driver Image path: system32\DRIVERS\ftdisk.sys Image size: 125056 Image MD5: 6AC26732762483366C3969C9E4D2259D Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): GEARAspiWDM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: GEAR ASPI Filter Driver Image path: System32\Drivers\GEARAspiWDM.sys Image size: 15464 Image MD5: AB8A6A87D9D7255C3884D5B9541A6E80 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Gpc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Generic Packet Classifier Description: Generic Packet Classifier Image path: system32\DRIVERS\msgpc.sys Image size: 35072 Image MD5: 0A02C63C8B144BD8C86B103DEE7C86A2 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HdAudAddService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft UAA Function Driver for High Definition Audio Service Image path: system32\drivers\HdAudio.sys Image size: 145920 Image MD5: 2A013E7530BEAB6E569FAA83F517E836 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HDAudBus Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft UAA Bus Driver for High Definition Audio Image path: system32\DRIVERS\HDAudBus.sys Image size: 144384 Image MD5: 573C7D0A32852B48F3058CFD8026F511 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): helpsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Help and Support Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): HidServ Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HID Input Service Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): hidusb Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft HID Class Driver Image path: system32\DRIVERS\hidusb.sys Image size: 10368 Image MD5: CCF82C5EC8A7326C3066DE870C06DAF1 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): hkmsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Health Key and Certificate Management Service Description: Manages health certificates and keys (used by NAP) Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): hpn Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): HTTP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HTTP Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start. Image path: System32\Drivers\HTTP.sys Image size: 264832 Image MD5: F6AACF5BCE2893E0C1754AFEB672E5C9 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HTTPFilter Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HTTP SSL Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: HTTP Service (registry key): i2omgmt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): i2omp Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): i8042prt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): IDriverT Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: InstallDriver Table Manager Description: Provides support for the Running Object Table for InstallShield Drivers Object name: LocalSystem Image path: "C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe" Image size: 73728 Image MD5: 6F95324909B502E2651442C1548AB12F Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Service (registry key): idsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows CardSpace Description: Securely enables the creation, management, and disclosure of digital identities. Object name: LocalSystem Image path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" Image size: 741376 Image MD5: EA7267505149B3A10DF32506A4E4E412 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): Imapi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: CD-Burning Filter Driver Image path: system32\DRIVERS\imapi.sys Image size: 42112 Image MD5: 083A052659F5310DD8B6A6CB05EDCF8E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): ImapiService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IMAPI CD-Burning COM Service Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\imapi.exe Image size: 150528 Image MD5: 30DEAF54A9755BB8546168CFE8A6B5E1 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): inetaccs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ini910u Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Inport Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): IntcAzAudAddService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Service for Realtek HD Audio (WDM) Image path: system32\drivers\RtkHDAud.sys Image size: 4374016 Image MD5: 7385944D4F025BD8C498BFD97981E336 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): IntelIde Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): intelppm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel Processor Driver Image path: system32\DRIVERS\intelppm.sys Image size: 36352 Image MD5: 8C953733D8F36EB2133F5BB58808B66B Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): Ip6Fw Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPv6 Windows Firewall Driver Description: Provides intrusion prevention service for a home or small office network. Image path: system32\drivers\ip6fw.sys Image size: 36608 Image MD5: 3BB22519A194418D5FEC05D800A19AD0 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): IpFilterDriver Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IP Traffic Filter Driver Description: IP Traffic Filter Driver Image path: System32\DRIVERS\ipfltdrv.sys Image size: 32896 Image MD5: 731F22BA402EE4B62748ADAF6363C182 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): IpInIp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IP in IP Tunnel Driver Description: IP in IP Tunnel Driver Image path: system32\DRIVERS\ipinip.sys Image size: 20864 Image MD5: B87AB476DCF76E72010632B5550955F5 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): IpNat Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IP Network Address Translator Description: IP Network Address Translator Image path: system32\DRIVERS\ipnat.sys Image size: 152832 Image MD5: CC748EA12C6EFFDE940EE98098BF96BB Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): iPod Service Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: iPod Service Description: iPod hardware management services Object name: LocalSystem Image path: "C:\Program Files\iPod\bin\iPodService.exe" Image size: 536872 Image MD5: 62937A89470AF8FF172F0980CA8AEFC9 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RpcSs Service (registry key): IPSec Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPSEC driver Description: IPSEC driver Image path: system32\DRIVERS\ipsec.sys Image size: 75264 Image MD5: 23C74D75E36E7158768DD63D92789A91 Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): IRENUM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IR Enumerator Service Image path: system32\DRIVERS\irenum.sys Image size: 11264 Image MD5: C93C9FF7B04D772627A3646D89F7BF89 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ISAPISearch Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): isapnp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PnP ISA/EISA Bus Driver Image path: system32\DRIVERS\isapnp.sys Image size: 37248 Image MD5: 05A299EC56E52649B1CF2FC52D20F2D7 Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): JavaQuickStarterService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Java Quick Starter Description: Prefetches JRE files for faster startup of Java applets and applications Object name: LocalSystem Image path: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" Image size: 152984 Image MD5: 511AB23A292497F2C527EEE5775B0BFE Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Service (registry key): Kbdclass Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Keyboard Class Driver Image path: system32\DRIVERS\kbdclass.sys Image size: 24576 Image MD5: 463C1EC80CD17420A542B7F36A36F128 Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): kbdhid Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Keyboard HID Driver Image path: system32\DRIVERS\kbdhid.sys Image size: 14592 Image MD5: 9EF487A186DEA361AA06913A75B3FA99 Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): kmixer Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel Wave Audio Mixer Image path: system32\drivers\kmixer.sys Image size: 172416 Image MD5: 692BCF44383D056AED41B045A323D378 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): KSecDD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): KService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: KService Description: Delivery Manager Service Object name: LocalSystem Image path: "C:\Program Files\Kontiki\KService.exe" Image size: 3068352 Image MD5: 62CEF3CA80FF1E3AF738DD11E3505DB1 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): lanmanserver Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Server Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): lanmanworkstation Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Workstation Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): Lavasoft Ad-Aware Service Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Lavasoft Ad-Aware Service Description: Ad-Aware Service Object name: LocalSystem Image path: "C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe" Image size: 950096 Image MD5: 034CC619BBA67D0B87B7617BD5C6676E Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Depends On services: RpcSS Service (registry key): Lbd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Lbd Description: Ad-Aware mini-filter driver Image path: system32\DRIVERS\Lbd.sys Image size: 64160 Image MD5: 53B670772D98B459A5AF35598AB5815E Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Depends On services: FltMgr Service (registry key): lbrtfdc Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): ldap Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): LicenseService Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): LiveUpdate Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: LiveUpdate Description: LiveUpdate Core Engine Object name: LocalSystem Image path: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" Image size: 2999664 Image MD5: A97EEB81F05BCE3D7AA6C81F04EF39A4 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): LiveUpdate Notice Ex Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: LiveUpdate Notice Service Ex Description: Manages Norton product notices. Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon Image size: 108648 Image MD5: FE69C498B922CE835E2E2123FBD0A272 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Service (registry key): LiveUpdate Notice Service Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: LiveUpdate Notice Service Description: Manages Norton product notices Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll" Image size: 583048 Image MD5: 2D1389E05A807D956829F44BD4B60389 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Service (registry key): LmHosts Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: TCP/IP NetBIOS Helper Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: NetBT,Afd Service (registry key): LVUSBSta Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Logitech USB Monitor Filter Image path: system32\drivers\lvusbsta.sys Image size: 22016 Image MD5: 0BE8E67A2639E6F663225E485CC1B2FB Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): McrdSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Media Center Extender Service Object name: NT AUTHORITY\LocalService Image path: C:\WINDOWS\ehome\mcrdsvc.exe Image size: 99328 Image MD5: DF0A511F38F16016BF658FCA0090CB87 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RPCSS,SSDPSRV Service (registry key): Messenger Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Messenger Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS Service (registry key): MHN Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: MHN Description: Multimedia Home Networking (MHN) is a networking platform for Audio Video (AV) streaming applications on IP home networks. MHN enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications by providing mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: TcpIp,Afd,RpcSs,mhndrv Service (registry key): MHNDRV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: MHN driver Description: Multimedia Home Network component driver Image path: system32\DRIVERS\mhndrv.sys Image size: 11008 Image MD5: 7F2F1D2815A6449D346FCCCBC569FBD6 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): mnmdd Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): mnmsrvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NetMeeting Remote Desktop Sharing Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\mnmsrvc.exe Image size: 32768 Image MD5: D18F1F0C101D06A1C1ADF26EED16FCDD Control Set: CurrentControlSet Start: 3 Type: 272 Error Control: 1 Service (registry key): Modem Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): Mouclass Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mouse Class Driver Image path: system32\DRIVERS\mouclass.sys Image size: 23040 Image MD5: 35C9E97194C8CFB8430125F8DBC34D04 Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): mouhid Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mouse HID Driver Image path: system32\DRIVERS\mouhid.sys Image size: 12160 Image MD5: B1C303E17FB9D46E87A98E4BA6769685 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): MountMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mount Point Manager Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): mraid35x Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): MREMPR5 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: MREMPR5 NDIS Protocol Driver Image path: \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS Image size: 19345 Image MD5: 2BC9E43F55DE8C30FC817ED56D0EE907 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MRENDIS5 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: MRENDIS5 NDIS Protocol Driver Image path: \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS Image size: 18003 Image MD5: 594B9D8194E3F4ECBF0325BD10BBEB05 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MRxDAV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WebDav Client Redirector Description: WebDav Client Redirector Image path: system32\DRIVERS\mrxdav.sys Image size: 180608 Image MD5: 11D42BB6206F33FBB3BA0288D3EF81BD Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): MRxSmb Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: MRXSMB Description: MRXSMB Image path: system32\DRIVERS\mrxsmb.sys Image size: 455296 Image MD5: 60AE98742484E7AB80C3C1450E708148 Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): MSDTC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Distributed Transaction Coordinator Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\NetworkService Image path: C:\WINDOWS\system32\msdtc.exe Image size: 6144 Image MD5: A137F1470499A205ABBB9AAFB3B6F2B1 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS,SamSS Service (registry key): MSDTC Bridge 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Msfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): MSIServer Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Installer Object name: LocalSystem Image path: C:\WINDOWS\system32\msiexec.exe /V Image size: 78848 Image MD5: 5879D691E842574A20FE63817CB76DF9 Control Set: CurrentControlSet Start: 3 Type: 288 Error Control: 1 Service (registry key): MSKSSRV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Service Proxy Image path: system32\drivers\MSKSSRV.sys Image size: 7552 Image MD5: D1575E71568F4D9E14CA56B7B0453BF1 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MSPCLOCK Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Clock Proxy Image path: system32\drivers\MSPCLOCK.sys Image size: 5376 Image MD5: 325BB26842FC7CCC1FCCE2C457317F3E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MSPQM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Quality Manager Proxy Image path: system32\drivers\MSPQM.sys Image size: 4992 Image MD5: BAD59648BA099DA4A17680B39730CB3D Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): mssmbios Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft System Management BIOS Driver Image path: system32\DRIVERS\mssmbios.sys Image size: 15488 Image MD5: AF5F4F3F14A8EA2C26DE30F7A1E17136 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MSTEE Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Tee/Sink-to-Sink Converter Image path: system32\drivers\MSTEE.sys Image size: 5504 Image MD5: E53736A9E30C45FA9E7B5EAC55056D1D Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Mup Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mup Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Service (registry key): NABTSFEC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NABTS/FEC VBI Codec Image path: system32\DRIVERS\NABTSFEC.sys Image size: 85248 Image MD5: 5B50F1B2A2ED47D560577B221DA734DB Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): napagent Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Access Protection Agent Description: Allows windows clients to participate in Network Access Protection Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): NAVENG Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NAVENG Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090223.002\NAVENG.SYS Image size: 89104 Image MD5: 494C4EBFEE40BAAFF49492B97ABAF18C Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NAVEX15 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NAVEX15 Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090223.002\NAVEX15.SYS Image size: 876144 Image MD5: F4A95D6D20767A5F1F2B2FED261A1B23 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NDIS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NDIS System Driver Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): NdisIP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft TV/Video Connection Image path: system32\DRIVERS\NdisIP.sys Image size: 10880 Image MD5: 7FF1F1FD8609C149AA432F95A8163D97 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NdisTapi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access NDIS TAPI Driver Description: Remote Access NDIS TAPI Driver Image path: system32\DRIVERS\ndistapi.sys Image size: 10112 Image MD5: 1AB3D00C991AB086E69DB84B6C0ED78F Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Ndisuio Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NDIS Usermode I/O Protocol Description: NDIS Usermode I/O Protocol Image path: system32\DRIVERS\ndisuio.sys Image size: 14592 Image MD5: F927A4434C5028758A842943EF1A3849 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NdisWan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access NDIS WAN Driver Description: Remote Access NDIS WAN Driver Image path: system32\DRIVERS\ndiswan.sys Image size: 91520 Image MD5: EDC1531A49C80614B2CFDA43CA8659AB Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NDProxy Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NetBIOS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NetBIOS Interface Description: NetBIOS Interface Image path: system32\DRIVERS\netbios.sys Image size: 34688 Image MD5: 5D81CF9A2F1A3A756B66CF684911CDF0 Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): NetBT Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NetBios over Tcpip Description: NetBios over Tcpip Image path: system32\DRIVERS\netbt.sys Image size: 162816 Image MD5: 74B2B2F5BEA5E9A3DC021D685551BD3D Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): NetDDE Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network DDE Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\netdde.exe Image size: 111104 Image MD5: B857BA82860D7FF85AE29B095645563B Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: NetDDEDSDM Service (registry key): NetDDEdsdm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network DDE DSDM Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\netdde.exe Image size: 111104 Image MD5: B857BA82860D7FF85AE29B095645563B Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Service (registry key): Netlogon Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Net Logon Description: Supports pass-through authentication of account logon events for computers in a domain. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): Netman Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Connections Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 288 Error Control: 1 Depends On services: RpcSs Service (registry key): NetTcpPortSharing Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Net.Tcp Port Sharing Service Description: Provides ability to share TCP ports over the net.tcp protocol. Object name: NT AUTHORITY\LocalService Image path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" Image size: 122880 Image MD5: 8070BB07FE06DE8B9ACB29B07016A273 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Service (registry key): NIC1394 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: 1394 Net Driver Image path: system32\DRIVERS\nic1394.sys Image size: 61824 Image MD5: E9E47CFB2D461FA0FC75B7A74C6383EA Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Nla Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Location Awareness (NLA) Description: Collects and stores network configuration and location information, and notifies applications when this information changes. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Tcpip,Afd Service (registry key): nm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Monitor Driver Image path: system32\DRIVERS\NMnt.sys Image size: 40320 Image MD5: 1E421A6BCF2203CC61B821ADA9DE878B Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Norton Save and Restore Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Norton Save and Restore Description: Administrative service for scheduling and disk imaging. Object name: LocalSystem Image path: C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe Image size: 2107032 Image MD5: 048EF3DA03319478E337DD80E69F2B90 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RPCSS,EventLog,PlugPlay Service (registry key): Npfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): NSCService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Norton Protection Center Service Description: Norton Console Service Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE" Image size: 750720 Image MD5: BDFD869422054A90372BF26FF4442C27 Control Set: CurrentControlSet Start: 4 Type: 16 Error Control: 0 Service (registry key): Ntfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Service (registry key): NtLmSsp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NT LM Security Support Provider Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): NtmsSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Removable Storage Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): Null Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): NwlnkFlt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPX Traffic Filter Driver Description: IPX Traffic Filter Driver Image path: system32\DRIVERS\nwlnkflt.sys Image size: 12416 Image MD5: B305F3FAD35083837EF46A0BBCE2FC57 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: NwlnkFwd Service (registry key): NwlnkFwd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPX Traffic Forwarder Driver Description: IPX Traffic Forwarder Driver Image path: system32\DRIVERS\nwlnkfwd.sys Image size: 32512 Image MD5: C99B3415198D1AAB7227F2C88FD664B9 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): odserv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Office Diagnostics Service Description: Run portions of Microsoft Office Diagnostics. Object name: LocalSystem Image path: "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE" Image size: 443776 Image MD5: E54AA592A65F317390EEE386A8821692 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): ohci1394 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: VIA OHCI Compliant IEEE 1394 Host Controller Image path: system32\DRIVERS\ohci1394.sys Image size: 61696 Image MD5: CA33832DF41AFB202EE7AEB05145922F Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): ose Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Office Source Engine Description: Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports. Object name: LocalSystem Image path: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" Image size: 145184 Image MD5: 5A432A042DAE460ABE7199B758E8606C Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): Parport Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): PartMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Partition Manager Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): ParVdm Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 0 Depends On services: Parport Depends On group: "Parallel arbitrator" Service (registry key): PCI Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PCI Bus Driver Image path: system32\DRIVERS\pci.sys Image size: 68224 Image MD5: A219903CCF74233761D92BEF471A07B1 Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): PCIDump Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): PCIIde Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\pciide.sys Image size: 3328 Image MD5: CCF5F451BB1A5A2A522A76E670000FF0 Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): Pcmcia Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): PDCOMP Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): PDFRAME Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): PDRELI Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): PDRFRAME Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): perc2 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): perc2hib Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): PerfDisk Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfNet Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfOS Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfProc Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PID_0928 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Labtec WebCam(PID_0928) Image path: system32\DRIVERS\LV561AV.SYS Image size: 211712 Image MD5: A2B25662FB5FAF875CCEAD2166B5F9AD Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): PlugPlay Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Plug and Play Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Object name: LocalSystem Image path: %SystemRoot%\system32\services.exe Image size: 108544 Image MD5: 0E776ED5F7CC9F94299E70461B7B8185 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): PolicyAgent Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPSEC Services Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS,Tcpip,IPSec Service (registry key): PptpMiniport Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WAN Miniport (PPTP) Description: WAN Miniport (PPTP) Image path: system32\DRIVERS\raspptp.sys Image size: 48384 Image MD5: EFEEC01B1D3CF84F16DDD24D9D9D8F99 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ProtectedStorage Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Protected Storage Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 2 Type: 288 Error Control: 1 Depends On services: RpcSs Service (registry key): PSched Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: QoS Packet Scheduler Description: QoS Packet Scheduler Image path: system32\DRIVERS\psched.sys Image size: 69120 Image MD5: 09298EC810B07E5D582CB3A3F9255424 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Gpc Service (registry key): Ptilink Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Direct Parallel Link Driver Description: Direct Parallel Link Driver Image path: system32\DRIVERS\ptilink.sys Image size: 17792 Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): PxHelp20 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PxHelp20 Image path: System32\Drivers\PxHelp20.sys Image size: 43528 Image MD5: D86B4A68565E444D76457F14172C875A Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): ql1080 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Ql10wnt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ql12160 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ql1240 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ql1280 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): RasAcd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access Auto Connection Driver Description: Remote Access Auto Connection Driver Image path: system32\DRIVERS\rasacd.sys Image size: 8832 Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): RasAuto Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access Auto Connection Manager Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RasMan,Tapisrv Service (registry key): Rasl2tp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WAN Miniport (L2TP) Description: WAN Miniport (L2TP) Image path: system32\DRIVERS\rasl2tp.sys Image size: 51328 Image MD5: 11B4A627BC9614B885C4969BFA5FF8A6 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): RasMan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access Connection Manager Description: Creates a network connection. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Tapisrv Service (registry key): RasPppoe Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access PPPOE Driver Description: Remote Access PPPOE Driver Image path: system32\DRIVERS\raspppoe.sys Image size: 41472 Image MD5: 5BC962F2654137C9909C3D4603587DEE Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Raspti Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Direct Parallel Description: Direct Parallel Image path: system32\DRIVERS\raspti.sys Image size: 16512 Image MD5: FDBB1D60066FCFBB7452FD8F9829B242 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Rdbss Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Rdbss Description: Rdbss Image path: system32\DRIVERS\rdbss.sys Image size: 175744 Image MD5: 7AD224AD1A1437FE28D89CF22B17780A Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): RDPCDD Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\DRIVERS\RDPCDD.sys Image size: 4224 Image MD5: 4912D5B403614CE99C28420F75353332 Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): RDPDD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): rdpdr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Terminal Server Device Redirector Driver Image path: system32\DRIVERS\rdpdr.sys Image size: 196224 Image MD5: 15CABD0F7C00C47C70124907916AF3F1 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): RDPNP Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): RDPWD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): RDSessMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Desktop Help Session Manager Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box. Object name: LocalSystem Image path: C:\WINDOWS\system32\sessmgr.exe Image size: 141312 Image MD5: 3C37BF86641BDA977C3BF8A840F3B7FA Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): redbook Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Digital CD Audio Playback Filter Driver Image path: system32\DRIVERS\redbook.sys Image size: 57600 Image MD5: F828DD7E1419B6653894A8F97A0094C5 Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): RemoteAccess Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Routing and Remote Access Description: Offers routing services to businesses in local area and wide area network environments. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: RpcSS Depends On group: NetBIOSGroup Service (registry key): RemoteRegistry Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Registry Description: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): RpcLocator Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Procedure Call (RPC) Locator Description: Manages the RPC name service database. Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\system32\locator.exe Image size: 75264 Image MD5: AAED593F84AFA419BBAE8572AF87CF6A Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): RpcSs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Procedure Call (RPC) Description: Provides the endpoint mapper and other miscellaneous RPC services. Object name: NT Authority\NetworkService Image path: %SystemRoot%\system32\svchost -k rpcss Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): RSVP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: QoS RSVP Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets. Object name: LocalSystem Image path: %SystemRoot%\system32\rsvp.exe Image size: 132608 Image MD5: 471B3F9741D762ABE75E9DEEA4787E47 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: TcpIp,Afd,RpcSs Service (registry key): RT73 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Belkin USB Network Adapter Image path: system32\DRIVERS\rt73.sys Image size: 232192 Image MD5: BF4709C002D632170DC15A282813D6B3 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SamSs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Security Accounts Manager Description: Stores security information for local user accounts. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): SCardSvr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Smart Card Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\SCardSvr.exe Image size: 95744 Image MD5: 86D007E7A654B9A71D1D7D856B104353 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 0 Depends On services: PlugPlay Service (registry key): SCDEmu Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): Schedule Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Task Scheduler Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): ScsiPort Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: %SystemRoot%\system32\drivers\scsiport.sys Image size: 96384 Image MD5: 76C465F570E90C28942D52CCB2580A10 Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Secdrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Secdrv Description: SafeDisc driver Image path: system32\DRIVERS\secdrv.sys Image size: 20480 Image MD5: 90A3935D05B494A5A39D37E71F09A677 Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Service (registry key): seclogon Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Secondary Logon Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 288 Error Control: 0 Service (registry key): SENS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: System Event Notification Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: EventSystem Service (registry key): serenum Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Serenum Filter Driver Image path: system32\DRIVERS\serenum.sys Image size: 15744 Image MD5: 0F29512CCD6BEAD730039FB4BD2C85CE Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Serial Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Serial port driver Image path: system32\DRIVERS\serial.sys Image size: 64512 Image MD5: CCA207A8896D4C6A0C9CE29A4AE411A7 Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): ServiceModelEndpoint 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ServiceModelOperation 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ServiceModelService 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): sfdrv01 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: StarForce Protection Environment Driver (version 1.x) Image path: System32\drivers\sfdrv01.sys Image size: 51200 Image MD5: 9E7DEE11FD5A4355941A45F13C0ED59A Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): sfhlp02 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: StarForce Protection Helper Driver (version 2.x) Image path: System32\drivers\sfhlp02.sys Image size: 6656 Image MD5: ECEFB59D2206D281E6D317AF0EA0D8BD Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): Sfloppy Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Depends On group: "SCSI miniport" Service (registry key): sfvfs02 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: StarForce Protection VFS Driver (version 2.x) Image path: System32\drivers\sfvfs02.sys Image size: 63488 Image MD5: D5A7E09D2C6A702809E49190D52ADC9F Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): SharedAccess Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Firewall/Internet Connection Sharing (ICS) Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: Netman,WinMgmt Service (registry key): ShellHWDetection Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Shell Hardware Detection Description: Provides notifications for AutoPlay hardware events. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RpcSs Service (registry key): Simbad Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): SiSGbeXP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SiS191/SiS190 Ethernet Device NDIS 5.1 Driver Image path: system32\DRIVERS\SiSGbeXP.sys Image size: 40960 Image MD5: DDC15479FCDD243B087EB1CEE1B591C9 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SLIP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: BDA Slip De-Framer Image path: system32\DRIVERS\SLIP.sys Image size: 11136 Image MD5: 866D538EBE33709A5C9F5C62B73B7D14 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SMSvcHost 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Sparrow Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): SPBBCDrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SPBBCDrv Image path: \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys Image size: 418104 Image MD5: CDEA9A0A0E547FEF4C44CCAE35A9B09C Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): splitter Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel Audio Splitter Image path: system32\drivers\splitter.sys Image size: 6272 Image MD5: AB8B92451ECB048A4D1DE7C3FFCB4A9F Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Spooler Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Print Spooler Description: Loads files to memory for later printing. Object name: LocalSystem Image path: %SystemRoot%\system32\spoolsv.exe Image size: 57856 Image MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Depends On services: RPCSS Service (registry key): spupdsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Service Pack Installer update service Description: Enables Installer to complete its scheduled post-reboot tasks Object name: LocalSystem Image path: C:\WINDOWS\system32\spupdsvc.exe Image size: 26488 Image MD5: 5329079D8726DE34A58C2EF0BD2AC8B9 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: SamSs Service (registry key): sr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: System Restore Filter Driver Image path: system32\DRIVERS\sr.sys Image size: 73472 Image MD5: 76BB022C2FB6902FD5BDD4F78FC13A5D Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Service (registry key): srservice Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: System Restore Service Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): SRTSP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SRTSP Image path: System32\Drivers\SRTSP.SYS Image size: 279088 Image MD5: 655773F2F1A3730C6CF20280A49F4EE1 Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Depends On services: SRTSPX,FltMgr Service (registry key): SRTSPL Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SRTSPL Image path: System32\Drivers\SRTSPL.SYS Image size: 317616 Image MD5: 2A0AAF370D4C6574A34AE2F4A0709CAE Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: SRTSPX Service (registry key): SRTSPX Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SRTSPX Image path: System32\Drivers\SRTSPX.SYS Image size: 43696 Image MD5: 3104BDCEACE2D5710776DD05E6A286C1 Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): Srv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Srv Description: Srv Image path: system32\DRIVERS\srv.sys Image size: 333952 Image MD5: 3BB03F2BA89D2BE417206C373D2AF17C Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): SSDPSRV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SSDP Discovery Service Description: Enables discovery of UPnP devices on your home network. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: HTTP Service (registry key): stisvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Image Acquisition (WIA) Description: Provides image acquisition services for scanners and cameras. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k imgsvc Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): streamip Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: BDA IPSink Image path: system32\DRIVERS\StreamIP.sys Image size: 15232 Image MD5: 77813007BA6265C4B6098187E6ED79D2 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): swenum Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Software Bus Driver Image path: system32\DRIVERS\swenum.sys Image size: 4352 Image MD5: 3941D127AEF12E93ADDF6FE6EE027E0F Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): swmidi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel GS Wavetable Synthesizer Image path: system32\drivers\swmidi.sys Image size: 56576 Image MD5: 8CE882BCC6CF8A62F2B2323D95CB3D01 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SwPrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: MS Software Shadow Copy Provider Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{831F5E37-93AA-4A42-B454-EF375812FF90} Image size: 5120 Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Depends On services: rpcss Service (registry key): swwd Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Symantec Core LC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Core LC Description: Symantec Core LC Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" Image size: 1251720 Image MD5: FA2F6A8849219B16460BF44F9D1F3AA7 Control Set: CurrentControlSet Start: 3 Type: 272 Error Control: 1 Depends On services: RPCSS Service (registry key): symc810 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): symc8xx Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): SYMDNS Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMDNS.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SymEvent Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS Image size: 124464 Image MD5: 06B95820DF51502099A8A15C93E87986 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SYMFW Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMFW.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SYMIDS Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMIDS.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SYMIDSCO Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20090217.002\SymIDSCo.sys Image size: 250224 Image MD5: C87748B4A7541B81C9564ED5B3CF8697 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SYMNDIS Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMNDIS.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Depends On services: SymTDI,SYMFW,SYMIDS Service (registry key): SYMREDRV Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMREDRV.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SymSnap Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 0 Service (registry key): SYMTDI Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SYMTDI Image path: \SystemRoot\System32\Drivers\SYMTDI.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): sym_hi Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): sym_u3 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): sysaudio Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel System Audio Device Image path: system32\drivers\sysaudio.sys Image size: 60800 Image MD5: 8B83F3ED0F1688B4958F77CD6D2BF290 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SysmonLog Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Performance Logs and Alerts Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT Authority\NetworkService Image path: %SystemRoot%\system32\smlogsvc.exe Image size: 89600 Image MD5: C7ABBC59B43274B1109DF6B24D617051 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): TapiSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Telephony Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: PlugPlay,RpcSs Service (registry key): Tcpip Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: TCP/IP Protocol Driver Description: TCP/IP Protocol Driver Image path: system32\DRIVERS\tcpip.sys Image size: 361600 Image MD5: 9AEFA14BD6B182D61E3119FA5F436D3D Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: IPSec Service (registry key): TDPIPE Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): TDTCP Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): TermDD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Terminal Device Driver Image path: system32\DRIVERS\termdd.sys Image size: 40840 Image MD5: 88155247177638048422893737429D9E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): TermService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Terminal Services Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost -k DComLaunch Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): Themes Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Themes Description: Provides user experience theme management. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): TlntSvr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Telnet Description: Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\tlntsvr.exe Image size: 73216 Image MD5: DB7205804759FF62C34E3EFD8A4CC76A Control Set: CurrentControlSet Start: 4 Type: 16 Error Control: 1 Depends On services: RPCSS,TCPIP,NTLMSSP Service (registry key): TosIde Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): TrkWks Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Distributed Link Tracking Client Description: Maintains links between NTFS files within a computer or across computers in a network domain. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): TSDDD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Udfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Service (registry key): ultra Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Update Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microcode Update Driver Image path: system32\DRIVERS\update.sys Image size: 384768 Image MD5: 402DDC88356B1BAC0EE3DD1580C76A31 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): upnphost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Universal Plug and Play Device Host Description: Provides support to host Universal Plug and Play devices. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: SSDPSRV,HTTP Service (registry key): UPS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Uninterruptible Power Supply Description: Manages an uninterruptible power supply (UPS) connected to the computer. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\ups.exe Image size: 18432 Image MD5: 05365FB38FCA1E98F7A566AAAF5D1815 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): usb Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): usbccgp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB Generic Parent Driver Image path: system32\DRIVERS\usbccgp.sys Image size: 32128 Image MD5: 173F317CE0DB8E21322E71B7E60A27E8 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbehci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver Image path: system32\DRIVERS\usbehci.sys Image size: 30208 Image MD5: 65DCF09D0E37D4C6B11B5B0B76D470A7 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbhub Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB2 Enabled Hub Image path: system32\DRIVERS\usbhub.sys Image size: 59520 Image MD5: 1AB3CDDE553B6E064D2E754EFE20285C Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbohci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB Open Host Controller Miniport Driver Image path: system32\DRIVERS\usbohci.sys Image size: 17152 Image MD5: 0DAECCE65366EA32B162F85F07C6753B Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbprint Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB PRINTER Class Image path: system32\DRIVERS\usbprint.sys Image size: 25856 Image MD5: A717C8721046828520C9EDF31288FC00 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbscan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB Scanner Driver Image path: system32\DRIVERS\usbscan.sys Image size: 15104 Image MD5: A0B8CF9DEB1184FBDD20784A58FA75D4 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbstor Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB Mass Storage Driver Image path: system32\DRIVERS\USBSTOR.SYS Image size: 26368 Image MD5: A32426D9B14A089EAA1D922E0C5801A9 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usnjsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Messenger Sharing Folders USN Journal Reader service Description: Service installed by Messenger to enable sharing scenarios Object name: LocalSystem Image path: "C:\Program Files\Windows Live\Messenger\usnsvc.exe" Image size: 98328 Image MD5: 9D19B042A4FD5C02195071EA2FE0C821 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: rpcss,eventlog Service (registry key): V2IMount Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): VgaSave Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: VGA Display Controller. Description: Controls the VGA display adapter to provide basic display capabilities. Image path: \SystemRoot\System32\drivers\vga.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): ViaIde Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): VolSnap Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): VSS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Volume Shadow Copy Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\vssvc.exe Image size: 289792 Image MD5: 7A9DB3A67C333BF0BD42E42B8596854B Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): VXD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): W32Time Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Time Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): W3SVC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Wanarp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access IP ARP Driver Description: Remote Access IP ARP Driver Image path: system32\DRIVERS\wanarp.sys Image size: 34560 Image MD5: E20B95BAEDB550F32DD489265C1DA1F6 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WDICA Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): wdmaud Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft WINMM WDM Audio Compatibility Driver Image path: system32\drivers\wdmaud.sys Image size: 83072 Image MD5: 6768ACF64B18196494413695F0C3A00F Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WebClient Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WebClient Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: MRxDAV Service (registry key): Windows Workflow Foundation 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): winmgmt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Management Instrumentation Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RPCSS Service (registry key): Winsock Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 4 Error Control: 1 Service (registry key): WinSock2 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): WinTrust Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Wireless Adapter Configurator Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Wireless Adapter Configurator Object name: LocalSystem Image path: C:\Program Files\BT Home Hub\Wireless Configuration\WirelessDaemon.exe Image size: 49152 Image MD5: 65D0C67A9E038A3F90C7C7D21C76CA14 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Service (registry key): WLSetupSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Live Setup Service Description: Windows Live Setup Service Object name: LocalSystem Image path: "C:\Program Files\Windows Live\installer\WLSetupSvc.exe" Image size: 266240 Image MD5: 94A85E956A065E23E0010A6A7826243B Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): WmdmPmSN Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Portable Media Serial Number Service Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): Wmi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Management Instrumentation Driver Extensions Description: Provides systems management information to and from drivers. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): WmiApRpl Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): WmiApSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WMI Performance Adapter Description: Provides performance library information from WMI HiPerf providers. Object name: LocalSystem Image path: C:\WINDOWS\system32\wbem\wmiapsrv.exe Image size: 126464 Image MD5: E0673F1106E62A68D2257E376079F821 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): WMPNetworkSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Media Player Network Sharing Service Description: Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play Object name: NT AUTHORITY\NetworkService Image path: "C:\Program Files\Windows Media Player\WMPNetwk.exe" Image size: 913408 Image MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: upnphost,http,HTTPFilter Service (registry key): WpdUsb Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WpdUsb Image path: system32\DRIVERS\wpdusb.sys Image size: 38528 Image MD5: CF4DEF1BF66F06964DC0D91844239104 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WS2IFSL Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Socket 2.0 Non-IFS Service Provider Support Environment Image path: \SystemRoot\System32\drivers\ws2ifsl.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): wscsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Security Center Description: Monitors system security settings and configurations. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,winmgmt Service (registry key): WSTCODEC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: World Standard Teletext Codec Image path: system32\DRIVERS\WSTCODEC.SYS Image size: 19200 Image MD5: C98B39829C2BBD34E454150633C62C78 Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): wuauserv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Automatic Updates Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): WudfPf Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver Description: Provide communciation services for UMDF components. Image path: system32\DRIVERS\WudfPf.sys Image size: 77568 Image MD5: F15FEAFFFBB3644CCC80C5DA584E6311 Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): WudfRd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Driver Foundation - User-mode Driver Framework Reflector Description: Reflect device requests to user-mode driver drivers Image path: system32\DRIVERS\wudfrd.sys Image size: 82944 Image MD5: 28B524262BCE6DE1F7EF9F510BA3985B Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WudfSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Driver Foundation - User-mode Driver Framework Description: Manages user-mode driver host processes Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: PlugPlay Service (registry key): WZCSVC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Wireless Zero Configuration Description: Provides automatic configuration for the 802.11 adapters Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,Ndisuio Service (registry key): xmlprov Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Provisioning Service Description: Manages XML configuration files on a domain basis for automatic network provisioning. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): YPCService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: YPCService Object name: LocalSystem Image path: C:\WINDOWS\system32\YPCSER~1.EXE Image size: 86016 Image MD5: D46403EF02C003DE80B4BE8A31549FB4 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): ZDPSp50 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ZDPSp50 NDIS Protocol Driver Image path: System32\Drivers\ZDPSp50.sys Image size: 17664 Image MD5: 00AE175B903D45ED4A62384D3315DC2A Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): {21F8FBEF-134B-4A13-8E3F-1DE1AB0921A2} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {2C7B89FC-F8A2-49E0-8CA5-2AB559954B25} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {2ED721BD-2BFC-4687-994E-3B1F0E371496} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {77C9CE34-6531-4A8B-A9CD-593618D60DE5} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {8463DD02-D273-47A7-BF19-E1F9D9BAFEA6} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {C6026FC0-C803-439B-A971-C1A284FF87F8} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {DB7979C1-F893-4E98-8A60-1161BABEFD11} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0