This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Think I have a virus (PUP.Optional)

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Last week I wanted to download yahoo messenger. But, I couldn't get it to download from yahoo site. It kept telling me I had to clear at least 100mb of disk space. So, I uninstalled a couple programs I didn't use. It still gave me the same message when I tried to download y messenger. I did a Cleaned up and did a disk defragment. And, I erased all but the current restore points. It still wouldn' t let me download y messenger and kept telling me I had to clear at least 100mb of disk space. So, I tried another site for yahoo messenger. After I downloaded it I scanned it with my virus scan(F-Secure) and it said no harmful files were found. So, I installed it. I didn't really like it(it had other messengers on it too) so I uninstalled it. After wards, all my icons changed to the same thing and I couldn't get into any programs or I couldn't do a system restore. I wrote in here and they helped me so I could do a system restore. My F-Secure software has been giving me some problems lately, not being able to do the virus scans. Its a beta version. I wrote to F-Secure beta team for help but haven't received a reply yet. I wrote in a couple times a couple weeks before any of this other started happening. And, I'm still waiting for a reply from them.
Any way, now that I restored, I did a Malwarebytes scan and it came up with 4 things on it. I will include a copy of the log. I was going to try to do an F-Secure scan but now when I try to do a F-Secure scan the boxes come up but there's nothing in them, they're blank. But, when I use the F-Secure online scan, it isn't picking up anything, nothing at all, not even what the Malwarebytes scan did. The F-Secure online scan tells me there no harmful files were found. But, that might be because its not a deep enough scan, not sure. Any way, my computer has been a little slow and keeps wanting to go to sleep mode. When I try to reboot, before it gets to my desktop it goes into sleep mode and it won't come out of it. Not sure how I got back to my desktop but thankfully I did. I tried to do a DDS scan but it only scanned a little then stopped and never started again. I waited a few hours. I also tried to do an OTL scan but pretty much the same happened, it scanned until it got to the firefox settings and stopped, never started again. I wasn't even online. Again, I waited several hours. I was able to to a Hijack this scan and will post the log.
In the Malwarebytes scan there were 4 PUP.Optional.(something or other written here). You should be able to see them on the scan log.
This is the log from the Hijack this scan …………..

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:25:07 AM, on 8/13/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.21342)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\F-Secure\fshoster32.exe
G:\WINDOWS\system32\inetsrv\inetinfo.exe
G:\WINDOWS\system32\lxctcoms.exe
G:\Program Files\CDBurnerXP\NMSAccessU.exe
G:\Program Files\Macrium\Reflect\ReflectService.exe
G:\WINDOWS\System32\snmp.exe
G:\Program Files\System Protect\SysProtect_srv.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\ctfmon.exe
G:\WINDOWS\system32\igfxtray.exe
G:\WINDOWS\system32\hkcmd.exe
G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
G:\Program Files\System Protect\SysProtect_Tray.exe
G:\Program Files\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE
G:\Program Files\F-Secure\fshoster32.exe
G:\Program Files\Online Vault\OnlineVault.exe
G:\Program Files\Messenger\msmsgs.exe
G:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
G:\Program Files\OpenOffice.org 3\program\soffice.exe
G:\Program Files\OpenOffice.org 3\program\soffice.bin
G:\Program Files\Mozilla Firefox\firefox.exe
G:\Program Files\Mozilla Firefox\plugin-container.exe
G:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
G:\Program Files\F-Secure\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE
G:\Program Files\F-Secure\apps\ComputerSecurity\Anti-Virus\fssm32.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3247201
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - G:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
O2 - BHO: F-Secure Online Safety - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - G:\Program Files\F-Secure\apps\OnlineSafety\browser\install\fs_ie_https\fs_ie_https.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - G:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - G:\PROGRA~1\Microsoft Office\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - G:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [IgfxTray] G:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] G:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Lexmark 5400 Series Fax Server] "G:\Program Files\Lexmark 5400 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [LXCTCATS] rundll32 G:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SystemProtect] G:\Program Files\System Protect\SysProtect_Tray.exe
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "G:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "G:\Program Files\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure Hoster (678)] "G:\Program Files\F-Secure\fshoster32.exe" -app -hosterid:1
O4 - HKCU\..\Run: [OnlineVault] "G:\Program Files\Online Vault\OnlineVault.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "G:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [InstallIQUpdater] "G:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
O4 - HKCU\..\Run: [RoboForm] "G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: OpenOffice.org 3.3.lnk = G:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: ZooskMessenger.lnk = G:\Program Files\ZooskMessenger\ZooskMessenger.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://tbedits.myscrapnook.com/one-toolbar…mp;n=2012061923
O8 - Extra context menu item: Customize Menu - file://G:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://G:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm TaskBar Icon - file://G:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html
O8 - Extra context menu item: Save Forms - file://G:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Se&nd to OneNote - res://G:\PROGRA~1\Microsoft Office\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Show RoboForm Toolbar - file://G:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: TaskBar - {320AF880-6646-11D3-ABEE-C5DBF3571F51} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: RoboForm TaskBar Icon - {320AF880-6646-11D3-ABEE-C5DBF3571F51} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: Show RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - G:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - G:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Online Vault - {FA32182A-EA44-4583-803B-AA827F0D4E06} - G:\PROGRA~1\ONLINE~2\ONLINE~1.EXE
O9 - Extra 'Tools' menuitem: Online Vault - {FA32182A-EA44-4583-803B-AA827F0D4E06} - G:\PROGRA~1\ONLINE~2\ONLINE~1.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - G:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: g:\fs_ccf_ni_umh32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - G:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - G:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - G:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Bonjour Service - Apple Inc. - G:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - G:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe
O23 - Service: F-Secure Dll Hoster (fshoster) - F-Secure Corporation - G:\Program Files\F-Secure\fshoster32.exe
O23 - Service: FSMA - F-Secure Corporation - G:\Program Files\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - G:\Program Files\F-Secure\apps\CCF_Reputation\fsorsp.exe
O23 - Service: iPod Service - Apple Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxct_device - - G:\WINDOWS\system32\lxctcoms.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - G:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NMSAccess - Unknown owner - G:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - G:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: System Protect Deletion Prevention Service (SP_Service) - Xacti Corporation - G:\Program Files\System Protect\SysProtect_srv.exe
O23 - Service: UMVPFSrv - Logitech Inc. - G:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

–
End of file - 11966 bytes

And, this is the log from the Malwarebytes scan ………………..

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.08.11.01

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Administrator :: P-071A7C4D21704 [administrator]

8/12/2013 3:18:15 AM
MBAM-log-2013-08-12 (10-51-21).txt

Scan type: Full scan (G:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 289838
Time elapsed: 1 hour(s), 1 minute(s), 38 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.0.0 (PUP.Optional.Surf) -> No action taken.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit) -> Bad: (http://search.conduit.com?SearchSource=10&ctid=CT3247201) Good: (http://www.google.com) -> No action taken.

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
G:\Documents and Settings\Administrator\My Documents\Downloads\setup snow.exe (PUP.Optional.AirInstaller) -> No action taken.
G:\Program Files\Coupons\uninstall.exe (PUP.Optional.Surf) -> No action taken.

(end)

If you could please help me to remove this virus and get my computer working right again, I would really appreciate it.

Thank you very much,

Mare'

ps. I also attached a screen shot of when I click on the F-Secure virus scan software, first the small box down at the bottom comes up. There is writing there but no icons. Then when I click on Computer scan, the next pic is a screen shot of the blank box that comes of after clicking Computer scan. So, I'm not able to even try to do a scan now.
Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.



Scan with DDS

Download DDS and save it to your desktop from here or here or
here.

Disable any script blocker, and then double click dds.scr to run the tool.

When done, DDS will open two (2) logs

DDS.txt: save to your desktop then post its contents in your topic
Attach.txt: save to your desktop then attach it to your next reply



Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hello Marius, Thanks for getting back to me so quickly. I tried to do the DDS scan before I wrote my post, I tried a couple times but it kept stopping. I also tried the OTL scan and the same thing happened. That's why I did the Hijack this scan, because it was the only one I could get to work. I will try the DDS scan again(although I'm not sure if going to work again) and I will try Gmer scan, too. I just wanted to let you know real quick about already trying the DDS scan. Ya, I tried to do the DDS scan again, and again it stops after a few seconds of scanning and doesn't start again. Ive let it sit for several hours but it never starts again or never finishes the scan. I also tried to do the Gmer scan but I got a message about rootkit activity, so I clicked no for the scan(as per the instructions). My computer is running slow and when I try to run the scans then it freezes everything else on my computer. When I try to reboot, most of the time it doesn't come all the way up(won't go to desktop) and it goes in to sleep mode and it won't come out. So, I have to keep trying to reboot and hope I get lucky to be able to get back to my desktop. I'm just afraid one of these times its not going to come back up at all. Please help asap. Thank you very much!
Combofix

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications


====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
I cannot access my F-Secure Security software, whenever I try to open it all the boxes are blank. And there isn't directions on how to disable it on the list from the link provided. But, I just got a reply back from F-Secure about this(blank boxes) and they said to uninstall the F-Secure security software and then reinstall it. Do you think I should do this before trying the Combofix? Do you think it will be alright to uninstall and reinstall the F-Secure security software while having this virus?
I uninstalled the F-Secure security software and I keep trying to run the ComboFix but it keeps stopping. And won't start again. I even waited over-night(about 8 or so hours) and it never starts again. I can hear the scan running for about a minute or two when it first starts to scan but then it stops and doesn't start again. There is the first box that opens(black background with green writing) then 2 more boxes open and scan real quick(there are 2 bars in the box that fill up). Then it opens a box (with blue background with white writing) that says it shouldn't take more than 10 mins to scan your computer, possibly double for a really infected computer. This is the box where I can hear it start scanning but a minute or two later (I hear it stop scanning) and it just sits there and doesn't start scanning again. I'm not sure what to do now. I'm a little nervous not having any security software running. Please help! Thanks! ps. Combofix said there was a newer version and asked if I wanted to use that, a couple times I said no but then when that didn't work, I decided to try clicking yes, but still none of the scans will scan all the way through.
I tried booting into safe mode and I tried the Combofix again but the same thing happened. The scan went to the blue box with white writing and seemed like it started to scan, although nothing else came up on the screen except it saying the scan shouldn't take any more than 10 minutes possibly double for a badly infected machine. The reason I tried it in safe mode is because it seems as though now that I uninstalled the F-Secure security my computer keeps going into sleep mode more often. I couldn't get my computer to boot up to my desktop so I went into safe mode. I figured while I was there I'd try the Combofix again but again it did the same thing as before. I tried several times too. I let it sit for several hours but you can hear when it is scanning and when it stops. The scan seems to stop after a minute or two and never starts again. I'm really sorry this isn't working.
P.S. I almost forgot that I have Spybot Search & Destroy so I ran a scan, I'm not sure if this will help or not but here are the results ……

— Search result list —
W3i.IQ5.fraud: [SBI $467B1F92] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Freeze.com

W3i.IQ5.fraud: [SBI $678078F9] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\W3i

W3i.IQ5.fraud: [SBI $7E2D9563] Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\Installer\Features\1F0BC1E8FB762504AA32AF229E84401C

W3i.IQ5.fraud: [SBI $08003FE2] Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\Installer\Products\1F0BC1E8FB762504AA32AF229E84401C

W3i.IQ5.fraud: [SBI $CE6C1679] Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}

W3i.IQ5.fraud: [SBI $CE6C1679] Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}

W3i.IQ5.fraud: [SBI $CF7AAB03] Autorun settings (InstallIQUpdater) (Registry value, nothing done)
HKEY_USERS\S-1-5-21-789336058-308236825-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\InstallIQUpdater

W3i.IQ5.fraud: [SBI $CF7AAB03] Program file (File, nothing done)
G:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
Properties.size=1179648
Properties.md5=013D640EE2BA28429AE422BF20A247D3
Properties.filedate=1318355354
Properties.filedatetext=2011-10-11 13:49:14

W3i.IQ5.fraud: [SBI $49BD358F] Program directory (Directory, nothing done)
G:\Documents and Settings\All Users\Application Data\W3i\

W3i.IQ5.fraud: [SBI $B9312FB7] Program directory (Directory, nothing done)
G:\Documents and Settings\All Users\Application Data\W3i\InstallIQUpdater\

W3i.IQ5.fraud: [SBI $1AC03E78] Data (File, nothing done)
G:\Documents and Settings\All Users\Application Data\W3i\InstallIQUpdater\data.xml
Properties.size=102
Properties.md5=FC4472C9A4D864AD685CF950C1B6ACB9
Properties.filedate=1353717679
Properties.filedatetext=2012-11-23 20:41:18

W3i.IQ5.fraud: [SBI $13C4F6E7] Data (File, nothing done)
G:\Documents and Settings\All Users\Application Data\W3i\InstallIQUpdater\iqu.ini
Properties.size=1553
Properties.md5=DA3AF66C865BF389C30FAD6D0C6B66B6
Properties.filedate=1376658126
Properties.filedatetext=2013-08-16 09:02:06

W3i.IQ5.fraud: [SBI $775A5CF1] Data (File, nothing done)
G:\Documents and Settings\All Users\Application Data\W3i\InstallIQUpdater\IQUMessageDlg.xsl
Properties.size=5110
Properties.md5=1900702C825CB794ADEF8A4F789591BF
Properties.filedate=1307369978
Properties.filedatetext=2011-06-06 10:19:38

W3i.IQ5.fraud: [SBI $1D0D84FC] Text file (File, nothing done)
G:\Documents and Settings\All Users\Application Data\W3i\InstallIQUpdater\updater.log
Properties.size=865
Properties.md5=DB22655B24208EA1812712F978DD1283
Properties.filedate=1376658730
Properties.filedatetext=2013-08-16 09:12:10

W3i.IQ5.fraud: [SBI $32305937] Program directory (Directory, nothing done)
G:\Documents and Settings\All Users\Application Data\W3i\InstallIQUpdater\import\

W3i.IQ5.fraud: [SBI $C2CA3ECA] Program directory (Directory, nothing done)
G:\Documents and Settings\All Users\Start Menu\Programs\InstallIQ Updater\

W3i.IQ5.fraud: [SBI $E745B5C2] Link (File, nothing done)
G:\Documents and Settings\All Users\Start Menu\Programs\InstallIQ Updater\InstallIQ Updater.lnk
Properties.size=912
Properties.md5=9F91A0F3AA9CA54B34ABC0F4BB91ABD0
Properties.filedate=1324690446
Properties.filedatetext=2011-12-23 21:34:06

W3i.IQ5.fraud: [SBI $6C917CD3] Link (File, nothing done)
G:\Documents and Settings\All Users\Start Menu\Programs\InstallIQ Updater\Privacy Policy.url
Properties.size=174
Properties.md5=B34BD752EB30603F8E696DB6A58DB8C6
Properties.filedate=1324690449
Properties.filedatetext=2011-12-23 21:34:09

W3i.IQ5.fraud: [SBI $BF311EC4] Link (File, nothing done)
G:\Documents and Settings\All Users\Start Menu\Programs\InstallIQ Updater\Terms & Conditions.url
Properties.size=181
Properties.md5=280779A40F593A246E90A382A00BCF13
Properties.filedate=1324690449
Properties.filedatetext=2011-12-23 21:34:09

W3i.IQ5.fraud: [SBI $D2E044A6] Link (File, nothing done)
G:\Documents and Settings\All Users\Start Menu\Programs\InstallIQ Updater\Uninstall InstallIQ Updater.lnk
Properties.size=1645
Properties.md5=03A759C977F31E967DB743726F46D10C
Properties.filedate=1324690446
Properties.filedatetext=2011-12-23 21:34:06

W3i.IQ5.fraud: [SBI $4E81E1C5] Program directory (Directory, nothing done)
G:\Program Files\W3i\

W3i.IQ5.fraud: [SBI $7A515EF8] Program directory (Directory, nothing done)
G:\Program Files\W3i\InstallIQUpdater\

W3i.IQ5.fraud: [SBI $791EEB9B] Data (File, nothing done)
G:\Program Files\W3i\InstallIQUpdater\iqu.xsl
Properties.size=15131
Properties.md5=FDAA28A21471CEF98EB021A83AF9816D
Properties.filedate=1324009384
Properties.filedatetext=2011-12-16 00:23:04

W3i.IQ5.fraud: [SBI $D9006140] Program directory (Directory, nothing done)
G:\WINDOWS\Installer\{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}\

Win32.Downloader.gen: [SBI $F03796FC] IE start page (Registry change, nothing done)
HKEY_USERS\S-1-5-21-789336058-308236825-682003330-500\Software\Microsoft\Internet Explorer\Main\Start Page=about:blank

Win32.Downloader.gen: [SBI $E6AD2227] Program directory (Directory, nothing done)
G:\Documents and Settings\Administrator\Local Settings\Application Data\Conduit\

Win32.Downloader.gen: [SBI $F65FFCFA] Library (File, nothing done)
G:\Program Files\Conduit\Community Alerts\Alert.dll
Properties.size=638560
Properties.md5=6796F6E449F90A543DC3345538ACC46F
Properties.filedate=1308838846
Properties.filedatetext=2011-06-23 10:20:46

Win32.Downloader.gen: [SBI $82F4FAFD] Data (File, nothing done)
G:\END
Properties.size=9
Properties.md5=A103FDF7348130EF3F3FEF56B1700A27
Properties.filedate=1353935790
Properties.filedatetext=2012-11-26 09:16:30


— Spybot - Search & Destroy version: 1.6.2 (build: 20090126) —

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe ([removed])
2010-08-23 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll ([removed])
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll ([removed])
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2013-04-11 Includes\Adware.sbi (*)
2013-04-24 Includes\AdwareC.sbi (*)
2010-08-12 Includes\Cookies.sbi (*)
2012-11-14 Includes\Dialer.sbi (*)
2013-04-11 Includes\DialerC.sbi (*)
2013-04-11 Includes\HeavyDuty.sbi (*)
2012-11-14 Includes\Hijackers.sbi (*)
2013-04-11 Includes\HijackersC.sbi (*)
2012-11-14 Includes\iPhone.sbi (*)
2013-06-25 Includes\Keyloggers.sbi (*)
2013-04-11 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2013-05-29 Includes\Malware.sbi (*)
2013-08-13 Includes\MalwareC.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2013-08-06 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-11-14 Includes\Security.sbi (*)
2013-04-11 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2013-05-22 Includes\Spyware.sbi (*)
2013-08-06 Includes\SpywareC.sbi (*)
2012-11-19 Includes\Tracks.uti
2013-01-16 Includes\Trojans.sbi (*)
2013-07-11 Includes\TrojansC-02.sbi (*)
2013-05-02 Includes\TrojansC-03.sbi (*)
2013-04-11 Includes\TrojansC-04.sbi (*)
2013-04-29 Includes\TrojansC-05.sbi (*)
2013-04-19 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



— System information —
Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB973688)
/ Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
/ Windows / SP1: Microsoft National Language Support Downlevel APIs
/ Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
/ Windows Media Player: Security Update for Windows Media Player (KB2378111)
/ Windows Media Player: Security Update for Windows Media Player (KB2834904)
/ Windows Media Player: Security Update for Windows Media Player (KB952069)
/ Windows Media Player: Security Update for Windows Media Player (KB954155)
/ Windows Media Player: Security Update for Windows Media Player (KB968816)
/ Windows Media Player: Security Update for Windows Media Player (KB973540)
/ Windows Media Player: Security Update for Windows Media Player (KB973540)
/ Windows Media Player: Security Update for Windows Media Player (KB975558)
/ Windows Media Player: Security Update for Windows Media Player (KB978695)
/ Windows Media Player: Security Update for Windows Media Player (KB979402)
/ Windows Media Player: Security Update for Windows Media Player (KB979402)
/ Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2183461)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2360131)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2416400)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2482017)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2497640)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2530548)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2544521)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2797052)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2809289)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2817183)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2829530)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2838727)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2846071)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB2862772)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127-v2)
/ Windows XP / SP0: Update for Windows Internet Explorer 7 (KB980182)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB982381)
/ Windows XP / SP10: Security Update for Microsoft Windows (KB2564958)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP3: Windows XP Service Pack 3
/ Windows XP / SP4: Security Update for Windows XP (KB2079403)
/ Windows XP / SP4: Security Update for Windows XP (KB2115168)
/ Windows XP / SP4: Security Update for Windows XP (KB2121546)
/ Windows XP / SP4: Security Update for Windows XP (KB2124261)
/ Windows XP / SP4: Update for Windows XP (KB2141007)
/ Windows XP / SP4: Hotfix for Windows XP (KB2158563)
/ Windows XP / SP4: Security Update for Windows XP (KB2160329)
/ Windows XP / SP4: Security Update for Windows XP (KB2229593)
/ Windows XP / SP4: Security Update for Windows XP (KB2259922)
/ Windows XP / SP4: Security Update for Windows XP (KB2279986)
/ Windows XP / SP4: Security Update for Windows XP (KB2286198)
/ Windows XP / SP4: Security Update for Windows XP (KB2290570)
/ Windows XP / SP4: Security Update for Windows XP (KB2296011)
/ Windows XP / SP4: Security Update for Windows XP (KB2296199)
/ Windows XP / SP4: Update for Windows XP (KB2345886)
/ Windows XP / SP4: Security Update for Windows XP (KB2347290)
/ Windows XP / SP4: Security Update for Windows XP (KB2360937)
/ Windows XP / SP4: Security Update for Windows XP (KB2387149)
/ Windows XP / SP4: Security Update for Windows XP (KB2393802)
/ Windows XP / SP4: Security Update for Windows XP (KB2412687)
/ Windows XP / SP4: Security Update for Windows XP (KB2419632)
/ Windows XP / SP4: Security Update for Windows XP (KB2423089)
/ Windows XP / SP4: Security Update for Windows XP (KB2436673)
/ Windows XP / SP4: Security Update for Windows XP (KB2440591)
/ Windows XP / SP4: Security Update for Windows XP (KB2443105)
/ Windows XP / SP4: Hotfix for Windows XP (KB2443685)
/ Windows XP / SP4: Update for Windows XP (KB2467659)
/ Windows XP / SP4: Security Update for Windows XP (KB2476490)
/ Windows XP / SP4: Security Update for Windows XP (KB2476687)
/ Windows XP / SP4: Security Update for Windows XP (KB2478960)
/ Windows XP / SP4: Security Update for Windows XP (KB2478971)
/ Windows XP / SP4: Security Update for Windows XP (KB2479628)
/ Windows XP / SP4: Security Update for Windows XP (KB2479943)
/ Windows XP / SP4: Security Update for Windows XP (KB2481109)
/ Windows XP / SP4: Security Update for Windows XP (KB2483185)
/ Windows XP / SP4: Security Update for Windows XP (KB2485376)
/ Windows XP / SP4: Security Update for Windows XP (KB2485663)
/ Windows XP / SP4: Security Update for Windows XP (KB2491683)
/ Windows XP / SP4: Security Update for Windows XP (KB2503658)
/ Windows XP / SP4: Security Update for Windows XP (KB2503665)
/ Windows XP / SP4: Security Update for Windows XP (KB2506212)
/ Windows XP / SP4: Security Update for Windows XP (KB2506223)
/ Windows XP / SP4: Security Update for Windows XP (KB2507618)
/ Windows XP / SP4: Security Update for Windows XP (KB2507938)
/ Windows XP / SP4: Security Update for Windows XP (KB2508272)
/ Windows XP / SP4: Security Update for Windows XP (KB2508429)
/ Windows XP / SP4: Security Update for Windows XP (KB2509553)
/ Windows XP / SP4: Security Update for Windows XP (KB2510581)
/ Windows XP / SP4: Security Update for Windows XP (KB2511455)
/ Windows XP / SP4: Security Update for Windows XP (KB2524375)
/ Windows XP / SP4: Security Update for Windows XP (KB2535512)
/ Windows XP / SP4: Security Update for Windows XP (KB2536276)
/ Windows XP / SP4: Security Update for Windows XP (KB2536276-v2)
/ Windows XP / SP4: Update for Windows XP (KB2541763)
/ Windows XP / SP4: Security Update for Windows XP (KB2544893)
/ Windows XP / SP4: Security Update for Windows XP (KB2544893-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB2555917)
/ Windows XP / SP4: Security Update for Windows XP (KB2566454)
/ Windows XP / SP4: Security Update for Windows XP (KB2570947)
/ Windows XP / SP4: Security Update for Windows XP (KB2584146)
/ Windows XP / SP4: Security Update for Windows XP (KB2585542)
/ Windows XP / SP4: Security Update for Windows XP (KB2592799)
/ Windows XP / SP4: Security Update for Windows XP (KB2598479)
/ Windows XP / SP4: Security Update for Windows XP (KB2603381)
/ Windows XP / SP4: Security Update for Windows XP (KB2618451)
/ Windows XP / SP4: Security Update for Windows XP (KB2619339)
/ Windows XP / SP4: Security Update for Windows XP (KB2620712)
/ Windows XP / SP4: Security Update for Windows XP (KB2624667)
/ Windows XP / SP4: Security Update for Windows XP (KB2631813)
/ Windows XP / SP4: Security Update for Windows XP (KB2646524)
/ Windows XP / SP4: Security Update for Windows XP (KB2653956)
/ Windows XP / SP4: Security Update for Windows XP (KB2655992)
/ Windows XP / SP4: Security Update for Windows XP (KB2659262)
/ Windows XP / SP4: Update for Windows XP (KB2661254-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB2661637)
/ Windows XP / SP4: Security Update for Windows XP (KB2676562)
/ Windows XP / SP4: Security Update for Windows XP (KB2686509)
/ Windows XP / SP4: Security Update for Windows XP (KB2691442)
/ Windows XP / SP4: Security Update for Windows XP (KB2698365)
/ Windows XP / SP4: Security Update for Windows XP (KB2705219-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB2712808)
/ Windows XP / SP4: Security Update for Windows XP (KB2719985)
/ Windows XP / SP4: Security Update for Windows XP (KB2723135-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB2727528)
/ Windows XP / SP4: Update for Windows XP (KB2736233)
/ Windows XP / SP4: Update for Windows XP (KB2749655)
/ Windows XP / SP4: Security Update for Windows XP (KB2753842-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB2757638)
/ Windows XP / SP4: Security Update for Windows XP (KB2758857)
/ Windows XP / SP4: Security Update for Windows XP (KB2770660)
/ Windows XP / SP4: Security Update for Windows XP (KB2778344)
/ Windows XP / SP4: Hotfix for Windows XP (KB2779562)
/ Windows XP / SP4: Security Update for Windows XP (KB2780091)
/ Windows XP / SP4: Security Update for Windows XP (KB2799494)
/ Windows XP / SP4: Security Update for Windows XP (KB2802968)
/ Windows XP / SP4: Security Update for Windows XP (KB2807986)
/ Windows XP / SP4: Security Update for Windows XP (KB2808735)
/ Windows XP / SP4: Security Update for Windows XP (KB2813170)
/ Windows XP / SP4: Security Update for Windows XP (KB2813345)
/ Windows XP / SP4: Security Update for Windows XP (KB2820197)
/ Windows XP / SP4: Security Update for Windows XP (KB2820917)
/ Windows XP / SP4: Security Update for Windows XP (KB2829361)
/ Windows XP / SP4: Security Update for Windows XP (KB2834886)
/ Windows XP / SP4: Security Update for Windows XP (KB2839229)
/ Windows XP / SP4: Security Update for Windows XP (KB2845187)
/ Windows XP / SP4: Security Update for Windows XP (KB2849470)
/ Windows XP / SP4: Security Update for Windows XP (KB2850851)
/ Windows XP / SP4: Security Update for Windows XP (KB2850869)
/ Windows XP / SP4: Security Update for Windows XP (KB2859537)
/ Windows XP / SP4: Update for Windows XP (KB2863058)
/ Windows XP / SP4: Hotfix for Windows XP (KB915800-v4)
/ Windows XP / SP4: Security Update for Windows XP (KB923561)
/ Windows XP / SP4: Security Update for Windows XP (KB946648)
/ Windows XP / SP4: Security Update for Windows XP (KB950760)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Update for Windows XP (KB951978)
/ Windows XP / SP4: Security Update for Windows XP (KB952004)
/ Windows XP / SP4: Hotfix for Windows XP (KB952287)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB953155)
/ Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
/ Windows XP / SP4: Security Update for Windows XP (KB955069)
/ Windows XP / SP4: Update for Windows XP (KB955759)
/ Windows XP / SP4: Security Update for Windows XP (KB956572)
/ Windows XP / SP4: Security Update for Windows XP (KB956744)
/ Windows XP / SP4: Security Update for Windows XP (KB956802)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB956844)
/ Windows XP / SP4: Security Update for Windows XP (KB958644)
/ Windows XP / SP4: Security Update for Windows XP (KB958869)
/ Windows XP / SP4: Security Update for Windows XP (KB959426)
/ Windows XP / SP4: Security Update for Windows XP (KB960225)
/ Windows XP / SP4: Security Update for Windows XP (KB960803)
/ Windows XP / SP4: Security Update for Windows XP (KB960859)
/ Windows XP / SP4: Hotfix for Windows XP (KB961118)
/ Windows XP / SP4: Security Update for Windows XP (KB961501)
/ Windows XP / SP4: Update for Windows XP (KB967715)
/ Windows XP / SP4: Update for Windows XP (KB968389)
/ Windows XP / SP4: Security Update for Windows XP (KB969059)
/ Windows XP / SP4: Security Update for Windows XP (KB969947)
/ Windows XP / SP4: Security Update for Windows XP (KB970238)
/ Windows XP / SP4: Security Update for Windows XP (KB970430)
/ Windows XP / SP4: Security Update for Windows XP (KB970483)
/ Windows XP / SP4: Update for Windows XP (KB971029)
/ Windows XP / SP4: Security Update for Windows XP (KB971468)
/ Windows XP / SP4: Security Update for Windows XP (KB971657)
/ Windows XP / SP4: Update for Windows XP (KB971737)
/ Windows XP / SP4: Security Update for Windows XP (KB971961)
/ Windows XP / SP4: Security Update for Windows XP (KB972270)
/ Windows XP / SP4: Security Update for Windows XP (KB973507)
/ Windows XP / SP4: Update for Windows XP (KB973687)
/ Windows XP / SP4: Update for Windows XP (KB973815)
/ Windows XP / SP4: Security Update for Windows XP (KB973869)
/ Windows XP / SP4: Security Update for Windows XP (KB973904)
/ Windows XP / SP4: Security Update for Windows XP (KB974112)
/ Windows XP / SP4: Security Update for Windows XP (KB974318)
/ Windows XP / SP4: Security Update for Windows XP (KB974392)
/ Windows XP / SP4: Security Update for Windows XP (KB974571)
/ Windows XP / SP4: Security Update for Windows XP (KB975025)
/ Windows XP / SP4: Security Update for Windows XP (KB975467)
/ Windows XP / SP4: Security Update for Windows XP (KB975560)
/ Windows XP / SP4: Security Update for Windows XP (KB975561)
/ Windows XP / SP4: Security Update for Windows XP (KB975562)
/ Windows XP / SP4: Security Update for Windows XP (KB975713)
/ Windows XP / SP4: Security Update for Windows XP (KB976323)
/ Windows XP / SP4: Security Update for Windows XP (KB977816)
/ Windows XP / SP4: Security Update for Windows XP (KB977914)
/ Windows XP / SP4: Security Update for Windows XP (KB978037)
/ Windows XP / SP4: Security Update for Windows XP (KB978262)
/ Windows XP / SP4: Security Update for Windows XP (KB978338)
/ Windows XP / SP4: Security Update for Windows XP (KB978542)
/ Windows XP / SP4: Security Update for Windows XP (KB978601)
/ Windows XP / SP4: Security Update for Windows XP (KB978706)
/ Windows XP / SP4: Security Update for Windows XP (KB979309)
/ Windows XP / SP4: Security Update for Windows XP (KB979482)
/ Windows XP / SP4: Security Update for Windows XP (KB979559)
/ Windows XP / SP4: Security Update for Windows XP (KB979683)
/ Windows XP / SP4: Security Update for Windows XP (KB979687)
/ Windows XP / SP4: Update for Windows XP (KB980182)
/ Windows XP / SP4: Security Update for Windows XP (KB980195)
/ Windows XP / SP4: Security Update for Windows XP (KB980218)
/ Windows XP / SP4: Security Update for Windows XP (KB980232)
/ Windows XP / SP4: Security Update for Windows XP (KB980436)
/ Windows XP / SP4: Security Update for Windows XP (KB981322)
/ Windows XP / SP4: Security Update for Windows XP (KB981349)
/ Windows XP / SP4: Hotfix for Windows XP (KB981793)
/ Windows XP / SP4: Security Update for Windows XP (KB981852)
/ Windows XP / SP4: Security Update for Windows XP (KB981957)
/ Windows XP / SP4: Security Update for Windows XP (KB981997)
/ Windows XP / SP4: Security Update for Windows XP (KB982132)
/ Windows XP / SP4: Security Update for Windows XP (KB982214)
/ Windows XP / SP4: Security Update for Windows XP (KB982665)
/ Windows XP / SP4: Security Update for Windows XP (KB982802)


— Startup entries list —
Located: HK_LM:Run, Adobe ARM
command: "G:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
file: G:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
size: 958576
MD5: 48BE298F7FD1BEF4D8FBACB04D8D95C4

Located: HK_LM:Run, ArcSoft Connection Service
command: G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
file: G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
size: 207424
MD5: A7810B302294793DE88542AAE177D1B1

Located: HK_LM:Run, Conime
command: %windir%\system32\conime.exe
file: G:\WINDOWS\system32\conime.exe
size: 27648
MD5: ABC9002269E569538901109441660DD2

Located: HK_LM:Run, HotKeysCmds
command: G:\WINDOWS\system32\hkcmd.exe
file: G:\WINDOWS\system32\hkcmd.exe
size: 126976
MD5: 2E8E2007269D3BD1A7942CF34AD77677

Located: HK_LM:Run, IgfxTray
command: G:\WINDOWS\system32\igfxtray.exe
file: G:\WINDOWS\system32\igfxtray.exe
size: 155648
MD5: 5CD294CB2AA8D7AFED70703CFEB385E5

Located: HK_LM:Run, iTunesHelper
command: "G:\Program Files\iTunes\iTunesHelper.exe"
file: G:\Program Files\iTunes\iTunesHelper.exe
size: 421776
MD5: 4AFFDCAADCB1DBBFFAF06C7F82E7F6FC

Located: HK_LM:Run, Lexmark 5400 Series Fax Server
command: "G:\Program Files\Lexmark 5400 Series\fm3032.exe" /s
file: G:\Program Files\Lexmark 5400 Series\fm3032.exe
size: 304048
MD5: 5A12A0CB6934A14078A962EF5D41F4AB

Located: HK_LM:Run, LXCTCATS
command: rundll32 G:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
file: G:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll
size: 106496
MD5: 5610D60C7230BB56647AB40B88AC9476

Located: HK_LM:Run, QuickTime Task
command: "G:\Program Files\QuickTime\QTTask.exe" -atboottime
file: G:\Program Files\QuickTime\QTTask.exe
size: 421888
MD5: 8DDA2B606279753601F9415DA503CA63

Located: HK_LM:Run, SystemProtect
command: G:\Program Files\System Protect\SysProtect_Tray.exe
file: G:\Program Files\System Protect\SysProtect_Tray.exe
size: 1223680
MD5: 02DD36CFBED4E5D3E87C1665B047595E

Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-789336058-308236825-682003330-500…
command: G:\WINDOWS\system32\ctfmon.exe
file: G:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3

Located: HK_CU:Run, InstallIQUpdater
where: S-1-5-21-789336058-308236825-682003330-500…
command: "G:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
file: G:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
size: 1179648
MD5: 013D640EE2BA28429AE422BF20A247D3

Located: HK_CU:Run, MSMSGS
where: S-1-5-21-789336058-308236825-682003330-500…
command: "G:\Program Files\Messenger\msmsgs.exe" /background
file: G:\Program Files\Messenger\msmsgs.exe
size: 1695232
MD5: 3E930C641079443D4DE036167A69CAA2

Located: HK_CU:Run, OnlineVault
where: S-1-5-21-789336058-308236825-682003330-500…
command: "G:\Program Files\Online Vault\OnlineVault.exe" /startup
file: G:\Program Files\Online Vault\OnlineVault.exe
size: 2459136
MD5: 7B19F4CA2AB839290EFF79B4FFC9D154

Located: HK_CU:Run, RoboForm
where: S-1-5-21-789336058-308236825-682003330-500…
command: "G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
file: G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
size: 109784
MD5: 040EF0A916C3C7CC698DBF8D7F873ECF

Located: Startup (user), OpenOffice.org 3.3.lnk
where: G:\Documents and Settings\Administrator\Start Menu\Programs\Startup…
command: G:\Program Files\OpenOffice.org 3\program\quickstart.exe
file: G:\Program Files\OpenOffice.org 3\program\quickstart.exe
size: 1198592
MD5: F7DCE54077EE9D8A351C4B1FFA866EE7

Located: Startup (user), ZooskMessenger.lnk
where: G:\Documents and Settings\Administrator\Start Menu\Programs\Startup…
command: G:\Program Files\ZooskMessenger\ZooskMessenger.exe
file: G:\Program Files\ZooskMessenger\ZooskMessenger.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: Startup (disabled), ERUNT AutoBackup (DISABLED)
command: G:\PROGRA~1\ERUNT\AUTOBACK.EXE %SystemRoot%\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow
file: G:\PROGRA~1\ERUNT\AUTOBACK.EXE
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: Startup (disabled), Microsoft Works Calendar Reminders (DISABLED)
command: G:\PROGRA~1\COMMON~1\MICROS~1\Works Shared\wkcalrem.exe
file: G:\PROGRA~1\COMMON~1\MICROS~1\Works Shared\wkcalrem.exe
size: 24633
MD5: 7084B58A098D2F83B304832251A8C6A8

Located: Startup (disabled), Windows Search (DISABLED)
command: G:\PROGRA~1\Windows Desktop Search\WindowsSearch.exe /startup
file: G:\PROGRA~1\Windows Desktop Search\WindowsSearch.exe
size: 123904
MD5: B5C9F63C01FCFEC3F64EC6A0940A1825

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, igfxcui
command: igfxsrvc.dll
file: igfxsrvc.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!



— Browser helper object list —
{1017A80C-6F09-4548-A84D-EDD6AC9525F0} (Lexmark Toolbar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Lexmark Toolbar
Path: G:\Program Files\Lexmark Toolbar\
Long name: toolband.dll
Short name:
Date (created): 6/12/2010 7:13:58 PM
Date (last access): 6/20/2010 4:29:06 AM
Date (last write): 8/9/2006 10:37:24 AM
Filesize: 184320
Attributes: readonly
MD5: 24F3A4F9F5FF3CBD589FB7AF614FB9FE
CRC32: C3FB3C60

{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:

{B4F3A835-0E21-4959-BA22-42B3008E02FF} (URLRedirectionBHO)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: URLRedirectionBHO
CLSID name: Office Document Cache Handler
Path: G:\PROGRA~1\Microsoft Office\Office14\
Long name: URLREDIR.DLL
Short name:
Date (created): 12/21/2010 1:05:22 AM
Date (last access): 5/17/2013 11:01:08 PM
Date (last write): 12/21/2010 1:05:22 AM
Filesize: 561552
Attributes: archive
MD5: A5D08B86E8A437AA6DEAF7A187BF6CA5
CRC32: CEA4973B
Version: 14.0.6015.1000

{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java™ Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java™ Plug-In 2 SSV Helper
Path: G:\Program Files\Java\jre7\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 6/25/2013 7:54:38 PM
Date (last access): 6/25/2013 7:54:38 PM
Date (last write): 6/25/2013 7:54:38 PM
Filesize: 171944
Attributes: archive
MD5: 5B1E711B7F870B355B1BCD8874037EEF
CRC32: 5776D394
Version: 10.25.2.17



— ActiveX list —
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.7.0)
DPF name: Java Runtime Environment 1.7.0
CLSID name: Java Plug-in 10.25.2
Installer:
Codebase: http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: G:\Program Files\Java\jre7\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 6/25/2013 7:54:38 PM
Date (last access): 6/25/2013 7:54:38 PM
Date (last write): 6/25/2013 7:54:38 PM
Filesize: 197032
Attributes: archive
MD5: C4D28736AE62A164FDA2130A9F75A20A
CRC32: F2920C14
Version: 10.25.2.17

{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name:
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab

{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} (Java Runtime Environment 1.7.0)
DPF name: Java Runtime Environment 1.7.0
CLSID name: Java Plug-in 1.7.0_25
Installer:
Codebase: http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab
Path: G:\Program Files\Java\jre7\bin\
Long name: npjpi170_25.dll
Short name:
Date (created): 6/25/2013 7:54:40 PM
Date (last access): 6/25/2013 7:54:40 PM
Date (last write): 6/25/2013 7:54:40 PM
Filesize: 223144
Attributes: archive
MD5: 87B41E7975298577BC56B6E82F0E6B34
CRC32: 8F76A1F2
Version: 10.25.2.17

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 10.25.2
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: G:\Program Files\Java\jre7\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 6/25/2013 7:54:38 PM
Date (last access): 6/25/2013 7:54:38 PM
Date (last write): 6/25/2013 7:54:38 PM
Filesize: 197032
Attributes: archive
MD5: C4D28736AE62A164FDA2130A9F75A20A
CRC32: F2920C14
Version: 10.25.2.17



— Process list —
PID: 0 ( 0) [System]
PID: 600 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 648 ( 600) \??\G:\WINDOWS\system32\csrss.exe
size: 6144
PID: 672 ( 600) \??\G:\WINDOWS\system32\winlogon.exe
size: 507904
PID: 716 ( 672) G:\WINDOWS\system32\services.exe
size: 110592
MD5: 65DF52F5B8B6E9BBD183505225C37315
PID: 728 ( 672) G:\WINDOWS\system32\lsass.exe
size: 13312
MD5: BF2466B3E18E970D8A976FB95FC1CA85
PID: 892 ( 716) G:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 968 ( 716) G:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1060 ( 716) G:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1156 ( 716) G:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1248 ( 716) G:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1444 ( 716) G:\WINDOWS\system32\spoolsv.exe
size: 58880
MD5: 60784F891563FB1B767F70117FC2428F
PID: 1488 ( 716) G:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
size: 450848
MD5: 67A95B9D129ED5399E7965CD09CF30E7
PID: 1780 (1724) G:\WINDOWS\Explorer.EXE
size: 1033728
MD5: 12896823FB95BFB3DC9B46BCAEDC9923
PID: 1792 ( 716) G:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1852 ( 716) G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
size: 113152
MD5: ADC420616C501B45D26C0FD3EF1E54E4
PID: 1880 ( 716) G:\Program Files\Bonjour\mDNSResponder.exe
size: 390504
MD5: DB5BEA73EDAF19AC68B2C0FAD0F92B1A
PID: 1992 ( 716) G:\WINDOWS\system32\inetsrv\inetinfo.exe
size: 15360
MD5: DB3C22745C0DA4666F3BE31F1AF36B2F
PID: 2020 ( 716) G:\WINDOWS\system32\lxctcoms.exe
size: 537520
MD5: 150CE94577E5DAD674E9E9E7F4617CAE
PID: 428 ( 716) G:\Program Files\CDBurnerXP\NMSAccessU.exe
size: 71096
MD5: 7AEA4DF1CA68FD45DD4BBE1F0243CE7F
PID: 1164 (1780) G:\WINDOWS\system32\igfxtray.exe
size: 155648
MD5: 5CD294CB2AA8D7AFED70703CFEB385E5
PID: 1176 (1780) G:\WINDOWS\system32\hkcmd.exe
size: 126976
MD5: 2E8E2007269D3BD1A7942CF34AD77677
PID: 1196 (1780) G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
size: 207424
MD5: A7810B302294793DE88542AAE177D1B1
PID: 1168 (1780) G:\Program Files\System Protect\SysProtect_Tray.exe
size: 1223680
MD5: 02DD36CFBED4E5D3E87C1665B047595E
PID: 1524 (1780) G:\Program Files\Online Vault\OnlineVault.exe
size: 2459136
MD5: 7B19F4CA2AB839290EFF79B4FFC9D154
PID: 1576 (1780) G:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
PID: 1552 (1780) G:\Program Files\Messenger\msmsgs.exe
size: 1695232
MD5: 3E930C641079443D4DE036167A69CAA2
PID: 1620 (1780) G:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
size: 1179648
MD5: 013D640EE2BA28429AE422BF20A247D3
PID: 1644 (1780) G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
size: 109784
MD5: 040EF0A916C3C7CC698DBF8D7F873ECF
PID: 1564 ( 716) G:\Program Files\Macrium\Reflect\ReflectService.exe
size: 220824
MD5: 7A8FD91FD806B1EB1743898DF4C6477A
PID: 192 ( 716) G:\WINDOWS\System32\snmp.exe
size: 33280
MD5: 60C377BE6B3CC83F6A8584934B181D2E
PID: 300 ( 716) G:\Program Files\System Protect\SysProtect_srv.exe
size: 598528
MD5: A11ECECD00E5B239F337DECCE01116B7
PID: 2028 ( 716) G:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1972 ( 716) G:\WINDOWS\system32\SearchIndexer.exe
size: 439808
MD5: 7778BDFA3F6F6FBA0E75B9594098F737
PID: 1304 (1060) G:\WINDOWS\system32\wscntfy.exe
size: 13824
MD5: F92E1076C42FCD6DB3D72D8CFE9816D5
PID: 2460 ( 716) G:\WINDOWS\System32\alg.exe
size: 44544
MD5: 8C515081584A38AA007909CD02020B3D
PID: 3752 (1780) G:\Program Files\Outlook Express\msimn.exe
size: 60416
MD5: 1EEAE496A51F017D04DD41322935D2B9
PID: 3976 (3752) G:\Program Files\Mozilla Firefox\firefox.exe
size: 276376
MD5: A6FE3BD4E3FC9C5583C92DF311A9C258
PID: 2380 (3976) G:\Program Files\Mozilla Firefox\plugin-container.exe
size: 17304
MD5: 254F08C0E70104FDFD72E58437CB4690
PID: 3760 (1780) G:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 4 ( 0) System
PID: 3460 (1972) G:\WINDOWS\system32\SearchProtocolHost.exe
size: 184832
MD5: C4894B3B448B647BEDC9E916D181BDBE
PID: 2576 (1972) G:\WINDOWS\system32\SearchFilterHost.exe
size: 87552
MD5: 87889A983C015080FA813D7E32910D1E


— Browser start & search pages list —
Spybot - Search & Destroy browser pages report, 8/16/2013 10:31:05 AM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
G:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://search.conduit.com?SearchSource=10&ctid=CT3247201
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\SearchAssistant
http://www.crawler.com/search/ie.aspx?tb_id=60347
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


— Winsock Layered Service Provider list —


— Uninstall list —
WebEx (ActiveTouchMeetingClient)
uninstall cmd: g:\docume~1\admini~1\applic~1\mozilla\plugins\atcliun.exe
publisher: Cisco WebEx LLC
contact: Customer Support
help link: http://support.webex.com/

(AddressBook)

Adobe AIR 3.5.0.600 (Adobe AIR)
version (major): 3
version (minor): 5
install location: G:\Program Files\Common Files\Adobe AIR\
uninstall cmd: G:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
publisher: Adobe Systems Incorporated

Adobe Flash Player 11 Plugin 11.7.700.224 (Adobe Flash Player Plugin)
version (major): 11
version (minor): 7
estimated size: 6144
uninstall cmd: G:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -maintain plugin
publisher: Adobe Systems Incorporated
help link: http://www.adobe.com/go/flashplayer_support/

Adobe Shockwave Player 12.0 12.0.2.122 (Adobe Shockwave Player)
version (major): 11
version (minor): 1
install location: G:\WINDOWS\system32\Adobe
uninstall cmd: "G:\WINDOWS\system32\Adobe\Shockwave 12\uninstaller.exe"
publisher: Adobe Systems, Inc.
help link: http://www.adobe.com/support/shockwave

RoboForm 7-9-0-0 (All Users) 7-9-0-0 (AI RoboForm)
estimated size: 20480
uninstall cmd: "G:\Program Files\Siber Systems\AI RoboForm\rfwipeout.exe"
publisher: Siber Systems
help link: http://support.roboform.com/php/rtss/main/?lang=

Ashampoo WinOptimizer 2010 Advanced 6.5.0 (Ashampoo WinOptimizer 2010 Advanced_is1)
install date: 20100620
install location: G:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\
uninstall cmd: "G:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\unins000.exe"
publisher: Ashampoo GmbH & Co. KG
help link: http://www.ashampoo.com/support

(Branding)

CCleaner 4.04 (CCleaner)
version (major): 4
version (minor): 4
install date: 20130722
install location: G:\Program Files\CCleaner
uninstall cmd: "G:\Program Files\CCleaner\uninst.exe"
publisher: Piriform

Acrobat.com 2.1.0.0 (com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1)
install location: G:\Program Files\Adobe\Acrobat_com\
uninstall cmd: msiexec /qb /x {F8131A35-47FD-27AD-116D-0E79AF5DE5EE}
publisher: Adobe Systems Incorporated

(Connection Manager)

Coupon Printer for Windows 5.0.0.0 (Coupon Printer for Windows5.0.0.0)
install location: G:\Program Files\Coupons
uninstall cmd: "G:\Program Files\Coupons\uninstall.exe" "/U:G:\Program Files\Coupons\Uninstall\uninstall.xml"
publisher: Coupons.com Incorporated
contact: Coupons.com Incorporated Support Department
help link: http://www.coupons.com

(DirectAnimation)

(DirectDrawEx)

(DXM_Runtime)

ESET Online Scanner v3 (ESET Online Scanner)
uninstall cmd: G:\Program Files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe

(Fontcore)

(ICW)

Microsoft Internationalized Domain Names Mitigation APIs (IDNMitigationAPIs)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
publisher: Microsoft Corporation

(IE40)

(IE4Data)

(IE5BAKEX)

Windows Internet Explorer 7 20070813.185237 (ie7)
install date: 20100606
publisher: Microsoft Corporation
help link: http://www.microsoft.com/ie

(IEData)

Security Update for Windows XP (KB2079403) 1 (KB2079403)
install date: 20100812
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2079403$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2079403

Security Update for Windows XP (KB2115168) 1 (KB2115168)
install date: 20100812
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2115168$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2115168

Security Update for Windows XP (KB2121546) 1 (KB2121546)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2121546$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2121546

Security Update for Windows XP (KB2124261) 1 (KB2124261)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2124261$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2124261

Update for Windows XP (KB2141007) 1 (KB2141007)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2141007$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2141007

Hotfix for Windows XP (KB2158563) 1 (KB2158563)
install date: 20100928
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2158563$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2158563

Security Update for Windows XP (KB2160329) 1 (KB2160329)
install date: 20100812
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2160329$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2160329

Security Update for Windows Internet Explorer 7 (KB2183461) 1 (KB2183461-IE7)
install date: 20100812
uninstall cmd: "G:\WINDOWS\ie7updates\KB2183461-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2183461

Security Update for Windows XP (KB2229593) 1 (KB2229593)
install date: 20100714
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2229593$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2229593

Security Update for Windows XP (KB2259922) 1 (KB2259922)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2259922$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2259922

Security Update for Windows XP (KB2279986) 1 (KB2279986)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2279986$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2279986

Security Update for Windows XP (KB2286198) 1 (KB2286198)
install date: 20100803
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2286198$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2286198

Security Update for Windows XP (KB2290570) 1 (KB2290570)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2290570$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2290570

Security Update for Windows XP (KB2296011) 1 (KB2296011)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2296011$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2296011

Security Update for Windows XP (KB2296199) 1 (KB2296199)
install date: 20101216
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2296199$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2296199

Update for Windows XP (KB2345886) 1 (KB2345886)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2345886$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2345886

Security Update for Windows XP (KB2347290) 1 (KB2347290)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2347290$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2347290

Security Update for Windows Internet Explorer 7 (KB2360131) 1 (KB2360131-IE7)
install date: 20101015
uninstall cmd: "G:\WINDOWS\ie7updates\KB2360131-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2360131

Security Update for Windows XP (KB2360937) 1 (KB2360937)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2360937$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2360937

Security Update for Windows Media Player (KB2378111) (KB2378111_WM9)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2378111_WM9$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=2378111

Security Update for Windows XP (KB2387149) 1 (KB2387149)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2387149$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2387149

Security Update for Windows XP (KB2393802) 1 (KB2393802)
install date: 20110221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2393802$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2393802

Security Update for Windows XP (KB2412687) 1 (KB2412687)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2412687$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2412687

Security Update for Windows Internet Explorer 7 (KB2416400) 1 (KB2416400-IE7)
install date: 20101216
uninstall cmd: "G:\WINDOWS\ie7updates\KB2416400-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2416400

Security Update for Windows XP (KB2419632) 1 (KB2419632)
install date: 20110112
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2419632$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2419632

Security Update for Windows XP (KB2423089) 1 (KB2423089)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2423089$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2423089

Security Update for Windows XP (KB2436673) 1 (KB2436673)
install date: 20101216
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2436673$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2436673

Security Update for Windows XP (KB2440591) 1 (KB2440591)
install date: 20101216
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2440591$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2440591

Security Update for Windows XP (KB2443105) 1 (KB2443105)
install date: 20101216
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2443105$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2443105

Hotfix for Windows XP (KB2443685) 1 (KB2443685)
install date: 20101216
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2443685$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2443685

Update for Windows XP (KB2467659) 1 (KB2467659)
install date: 20101216
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2467659$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2467659

Security Update for Windows XP (KB2476490) 1 (KB2476490)
install date: 20110616
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2476490$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2476490

Security Update for Windows XP (KB2476687) 1 (KB2476687)
install date: 20110221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2476687$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2476687

Security Update for Windows XP (KB2478960) 1 (KB2478960)
install date: 20110221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2478960$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2478960

Security Update for Windows XP (KB2478971) 1 (KB2478971)
install date: 20110221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2478971$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2478971

Security Update for Windows XP (KB2479628) 1 (KB2479628)
install date: 20110221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2479628$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2479628

Security Update for Windows XP (KB2479943) 1 (KB2479943)
install date: 20110309
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2479943$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2479943

Security Update for Windows XP (KB2481109) 1 (KB2481109)
install date: 20110309
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2481109$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2481109

Security Update for Windows Internet Explorer 7 (KB2482017) 1 (KB2482017-IE7)
install date: 20110221
uninstall cmd: "G:\WINDOWS\ie7updates\KB2482017-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2482017

Security Update for Windows XP (KB2483185) 1 (KB2483185)
install date: 20110221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2483185$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2483185

Security Update for Windows XP (KB2485376) 1 (KB2485376)
install date: 20110221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2485376$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2485376

Security Update for Windows XP (KB2485663) 1 (KB2485663)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2485663$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2485663

Security Update for Windows XP (KB2491683) 1 (KB2491683)
install date: 20130813
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2491683$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2491683

Security Update for Windows Internet Explorer 7 (KB2497640) 1 (KB2497640-IE7)
install date: 20110413
uninstall cmd: "G:\WINDOWS\ie7updates\KB2497640-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2497640

Security Update for Windows XP (KB2503658) 1 (KB2503658)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2503658$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2503658

Security Update for Windows XP (KB2503665) 1 (KB2503665)
install date: 20110616
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2503665$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2503665

Security Update for Windows XP (KB2506212) 1 (KB2506212)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2506212$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2506212

Security Update for Windows XP (KB2506223) 1 (KB2506223)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2506223$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2506223

Security Update for Windows XP (KB2507618) 1 (KB2507618)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2507618$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2507618

Security Update for Windows XP (KB2507938) 1 (KB2507938)
install date: 20110714
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2507938$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2507938

Security Update for Windows XP (KB2508272) 1 (KB2508272)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2508272$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2508272

Security Update for Windows XP (KB2508429) 1 (KB2508429)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2508429$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2508429

Security Update for Windows XP (KB2509553) 1 (KB2509553)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2509553$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2509553

Security Update for Windows XP (KB2510581) 1 (KB2510581)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2510581$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2510581

Security Update for Windows XP (KB2511455) 1 (KB2511455)
install date: 20110413
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2511455$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2511455

Security Update for Windows XP (KB2524375) 1 (KB2524375)
install date: 20110323
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2524375$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2524375

Security Update for Windows Internet Explorer 7 (KB2530548) 1 (KB2530548-IE7)
install date: 20110616
uninstall cmd: "G:\WINDOWS\ie7updates\KB2530548-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2530548

Security Update for Windows XP (KB2535512) 1 (KB2535512)
install date: 20110616
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2535512$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2535512

Security Update for Windows XP (KB2536276) 1 (KB2536276)
install date: 20110616
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2536276$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2536276

Security Update for Windows XP (KB2536276-v2) 2 (KB2536276-v2)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2536276-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2536276

Update for Windows XP (KB2541763) 1 (KB2541763)
install date: 20110629
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2541763$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2541763

Security Update for Windows Internet Explorer 7 (KB2544521) 1 (KB2544521-IE7)
install date: 20110616
uninstall cmd: "G:\WINDOWS\ie7updates\KB2544521-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2544521

Security Update for Windows XP (KB2544893) 1 (KB2544893)
install date: 20110616
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2544893$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2544893

Security Update for Windows XP (KB2544893-v2) 2 (KB2544893-v2)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2544893-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2544893

Security Update for Windows XP (KB2555917) 1 (KB2555917)
install date: 20110714
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2555917$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2555917

Security Update for Microsoft Windows (KB2564958) (KB2564958)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2564958$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/2564958

Security Update for Windows XP (KB2566454) 1 (KB2566454)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2566454$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2566454

Security Update for Windows XP (KB2570947) 1 (KB2570947)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2570947$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2570947

Security Update for Windows XP (KB2584146) 1 (KB2584146)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2584146$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2584146

Security Update for Windows XP (KB2585542) 1 (KB2585542)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2585542$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2585542

Security Update for Windows XP (KB2592799) 1 (KB2592799)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2592799$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2592799

Security Update for Windows XP (KB2598479) 1 (KB2598479)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2598479$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2598479

Security Update for Windows XP (KB2603381) 1 (KB2603381)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2603381$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2603381

Security Update for Windows XP (KB2618451) 1 (KB2618451)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2618451$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2618451

Security Update for Windows XP (KB2619339) 1 (KB2619339)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2619339$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2619339

Security Update for Windows XP (KB2620712) 1 (KB2620712)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2620712$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2620712

Security Update for Windows XP (KB2624667) 1 (KB2624667)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2624667$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2624667

Security Update for Windows XP (KB2631813) 1 (KB2631813)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2631813$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2631813

Security Update for Windows XP (KB2646524) 1 (KB2646524)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2646524$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2646524

Security Update for Windows XP (KB2653956) 1 (KB2653956)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2653956$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2653956

Security Update for Windows XP (KB2655992) 1 (KB2655992)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2655992$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2655992

Security Update for Windows XP (KB2659262) 1 (KB2659262)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2659262$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2659262

Update for Windows XP (KB2661254-v2) 2 (KB2661254-v2)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2661254-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2661254

Security Update for Windows XP (KB2661637) 1 (KB2661637)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2661637$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2661637

Security Update for Windows XP (KB2676562) 1 (KB2676562)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2676562$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2676562

Security Update for Windows XP (KB2686509) 1 (KB2686509)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2686509$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2686509

Security Update for Windows XP (KB2691442) 1 (KB2691442)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2691442$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2691442

Security Update for Windows XP (KB2698365) 1 (KB2698365)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2698365$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2698365

Security Update for Windows XP (KB2705219-v2) 2 (KB2705219-v2)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2705219-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2705219

Security Update for Windows XP (KB2712808) 1 (KB2712808)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2712808$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2712808

Security Update for Windows XP (KB2719985) 1 (KB2719985)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2719985$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2719985

Security Update for Windows XP (KB2723135-v2) 2 (KB2723135-v2)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2723135-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2723135

Security Update for Windows XP (KB2727528) 1 (KB2727528)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2727528$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2727528

Update for Windows XP (KB2736233) 1 (KB2736233)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2736233$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2736233

Update for Windows XP (KB2749655) 1 (KB2749655)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2749655$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2749655

Security Update for Windows XP (KB2753842-v2) 2 (KB2753842-v2)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2753842-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2753842

Security Update for Windows XP (KB2757638) 1 (KB2757638)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2757638$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2757638

Security Update for Windows XP (KB2758857) 1 (KB2758857)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2758857$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2758857

Security Update for Windows XP (KB2770660) 1 (KB2770660)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2770660$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2770660

Security Update for Windows XP (KB2778344) 1 (KB2778344)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2778344$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2778344

Hotfix for Windows XP (KB2779562) 1 (KB2779562)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2779562$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2779562

Security Update for Windows XP (KB2780091) 1 (KB2780091)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2780091$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2780091

Security Update for Windows Internet Explorer 7 (KB2797052) 1 (KB2797052-IE7)
install date: 20130322
uninstall cmd: "G:\WINDOWS\ie7updates\KB2797052-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2797052

Security Update for Windows XP (KB2799494) 1 (KB2799494)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2799494$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2799494

Security Update for Windows XP (KB2802968) 1 (KB2802968)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2802968$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2802968

Security Update for Windows XP (KB2807986) 1 (KB2807986)
install date: 20130322
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2807986$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2807986

Security Update for Windows XP (KB2808735) 1 (KB2808735)
install date: 20130411
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2808735$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2808735

Security Update for Windows Internet Explorer 7 (KB2809289) 1 (KB2809289-IE7)
install date: 20130322
uninstall cmd: "G:\WINDOWS\ie7updates\KB2809289-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2809289

Security Update for Windows XP (KB2813170) 1 (KB2813170)
install date: 20130411
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2813170$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2813170

Security Update for Windows XP (KB2813345) 1 (KB2813345)
install date: 20130411
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2813345$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2813345

Security Update for Windows Internet Explorer 7 (KB2817183) 1 (KB2817183-IE7)
install date: 20130411
uninstall cmd: "G:\WINDOWS\ie7updates\KB2817183-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2817183

Security Update for Windows XP (KB2820197) 1 (KB2820197)
install date: 20130515
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2820197$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2820197

Security Update for Windows XP (KB2820917) 1 (KB2820917)
install date: 20130411
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2820917$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2820917

Security Update for Windows XP (KB2829361) 1 (KB2829361)
install date: 20130515
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2829361$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2829361

Security Update for Windows Internet Explorer 7 (KB2829530) 1 (KB2829530-IE7)
install date: 20130515
uninstall cmd: "G:\WINDOWS\ie7updates\KB2829530-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2829530

Security Update for Windows XP (KB2834886) 1 (KB2834886)
install date: 20130711
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2834886$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2834886

Security Update for Windows Media Player (KB2834904) (KB2834904_WM11)
install date: 20130711
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2834904_WM11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=2834904

Security Update for Windows Internet Explorer 7 (KB2838727) 1 (KB2838727-IE7)
install date: 20130612
uninstall cmd: "G:\WINDOWS\ie7updates\KB2838727-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2838727

Security Update for Windows XP (KB2839229) 1 (KB2839229)
install date: 20130612
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2839229$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2839229

Security Update for Windows XP (KB2845187) 1 (KB2845187)
install date: 20130711
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2845187$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2845187

Security Update for Windows Internet Explorer 7 (KB2846071) 1 (KB2846071-IE7)
install date: 20130711
uninstall cmd: "G:\WINDOWS\ie7updates\KB2846071-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2846071

Security Update for Windows XP (KB2849470) 1 (KB2849470)
install date: 20130814
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2849470$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2849470

Security Update for Windows XP (KB2850851) 1 (KB2850851)
install date: 20130711
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2850851$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2850851

Security Update for Windows XP (KB2850869) 1 (KB2850869)
install date: 20130814
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2850869$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2850869

Security Update for Windows XP (KB2859537) 1 (KB2859537)
install date: 20130814
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2859537$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2859537

Security Update for Windows Internet Explorer 7 (KB2862772) 1 (KB2862772-IE7)
install date: 20130814
uninstall cmd: "G:\WINDOWS\ie7updates\KB2862772-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2862772

Update for Windows XP (KB2863058) 1 (KB2863058)
install date: 20130814
uninstall cmd: "G:\WINDOWS\$NtUninstallKB2863058$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=2863058

(KB884016)

(KB884267)

(KB885353)

(KB886612)

(KB887078)

(KB887626)

(KB888656)

(KB889858)

(KB891122)

Windows Genuine Advantage Validation Tool (KB892130) (KB892130)
install date: 20100606
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=892130

(KB892313)

(KB893240)

(KB893241)

(KB893803)

(KB895181)

(KB895316)

(KB895572)

(KB897586)

(KB898549)

(KB900399)

(KB902344)

(KB907658)

(KB911565)

(KB911854)

Hotfix for Windows XP (KB915800-v4) 4 (KB915800-v4)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=915800-v4

Security Update for Windows XP (KB923561) 1 (KB923561)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923561

Hotfix for Windows Media Format 11 SDK (KB929399) (KB929399)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=929399

Security Update for CAPICOM (KB931906) 2.1.0.2 (KB931906)
uninstall cmd: MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931906

Security Update for Windows Internet Explorer 7 (KB938127-v2) 2 (KB938127-v2-IE7)
install date: 20100606
uninstall cmd: "G:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938127-v2

Hotfix for Windows Media Player 11 (KB939683) (KB939683)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=939683

Windows Search 4.0 04.00.6001.503 (KB940157)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=940157

Security Update for Windows XP (KB941569) (KB941569)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941569

Security Update for Windows XP (KB946648) 1 (KB946648)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=946648

Security Update for Windows XP (KB950760) 1 (KB950760)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950760

Security Update for Windows XP (KB950762) 1 (KB950762)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950762

Security Update for Windows XP (KB950974) 1 (KB950974)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950974

Security Update for Windows XP (KB951376-v2) 2 (KB951376-v2)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951376

Security Update for Windows XP (KB951748) 1 (KB951748)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951748

Update for Windows XP (KB951978) 1 (KB951978)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951978

Security Update for Windows XP (KB952004) 1 (KB952004)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952004

Security Update for Windows Media Player (KB952069) (KB952069_WM9)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=952069

Hotfix for Windows XP (KB952287) 1 (KB952287)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952287

Security Update for Windows XP (KB952954) 1 (KB952954)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952954

Security Update for Windows XP (KB953155) 1 (KB953155)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=953155

Security Update for Windows Media Player 11 (KB954154) (KB954154_WM11)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=954154

Security Update for Windows Media Player (KB954155) (KB954155_WM9)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=954155

Hotfix for Windows XP (KB954550-v5) 5 (KB954550-v5)
install date: 20110623
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=954550

Security Update for Windows XP (KB955069) 1 (KB955069)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=955069

Update for Windows XP (KB955759) 1 (KB955759)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=955759

Security Update for Windows XP (KB956572) 1 (KB956572)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956572

Security Update for Windows XP (KB956744) 1 (KB956744)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956744

Security Update for Windows XP (KB956802) 1 (KB956802)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956802

Security Update for Windows XP (KB956803) 1 (KB956803)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956803

Security Update for Windows XP (KB956844) 1 (KB956844)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956844

Security Update for Windows XP (KB958644) 1 (KB958644)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=958644

Security Update for Windows XP (KB958869) 1 (KB958869)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=958869

Security Update for Windows XP (KB959426) 1 (KB959426)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=959426

Security Update for Windows XP (KB960225) 1 (KB960225)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=960225

Security Update for Windows XP (KB960803) 1 (KB960803)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=960803

Security Update for Windows XP (KB960859) 1 (KB960859)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=960859

Hotfix for Windows XP (KB961118) 1 (KB961118)
install date: 20110623
uninstall cmd: "G:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=961118

Security Update for Windows XP (KB961501) 1 (KB961501)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=961501

Security Update for Windows Search 4 - KB963093 (KB963093)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallKB963093$\spuninst\spuninst.exe"
publisher: Microsoft Corporation

Update for Windows XP (KB967715) 1 (KB967715)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=967715

Update for Windows XP (KB968389) 1 (KB968389)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=968389

Security Update for Windows Media Player (KB968816) (KB968816_WM9)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=968816

Security Update for Windows XP (KB969059) 1 (KB969059)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=969059

Security Update for Windows XP (KB969947) 1 (KB969947)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=969947

Security Update for Windows XP (KB970238) 1 (KB970238)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=970238

Security Update for Windows XP (KB970430) 1 (KB970430)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=970430

Security Update for Windows XP (KB970483) 1 (KB970483)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB970483$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=970483

Update for Windows XP (KB971029) 1 (KB971029)
install date: 20110316
uninstall cmd: "G:\WINDOWS\$NtUninstallKB971029$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=971029

Security Update for Windows XP (KB971468) 1 (KB971468)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=971468

Security Update for Windows XP (KB971657) 1 (KB971657)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=971657

Update for Windows XP (KB971737) 1 (KB971737)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=971737

Security Update for Windows XP (KB971961) 1 (KB971961)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=971961

Security Update for Windows XP (KB972270) 1 (KB972270)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=972270

Security Update for Windows XP (KB973507) 1 (KB973507)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=973507

Security Update for Windows Media Player (KB973540) (KB973540_WM9)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=973540

Security Update for Windows Media Player (KB973540) (KB973540_WM9L)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=973540

Update for Windows XP (KB973687) 1 (KB973687)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=973687

Update for Windows XP (KB973815) 1 (KB973815)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=973815

Security Update for Windows XP (KB973869) 1 (KB973869)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=973869

Security Update for Windows XP (KB973904) 1 (KB973904)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=973904

Security Update for Windows XP (KB974112) 1 (KB974112)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=974112

Security Update for Windows XP (KB974318) 1 (KB974318)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=974318

Security Update for Windows XP (KB974392) 1 (KB974392)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=974392

Security Update for Windows XP (KB974571) 1 (KB974571)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=974571

Security Update for Windows XP (KB975025) 1 (KB975025)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=975025

Security Update for Windows XP (KB975467) 1 (KB975467)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=975467

Security Update for Windows Media Player (KB975558) (KB975558_WM8)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB975558_WM8$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=975558

Security Update for Windows XP (KB975560) 1 (KB975560)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=975560

Security Update for Windows XP (KB975561) 1 (KB975561)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=975561

Security Update for Windows XP (KB975562) 1 (KB975562)
install date: 20100610
uninstall cmd: "G:\WINDOWS\$NtUninstallKB975562$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=975562

Security Update for Windows XP (KB975713) 1 (KB975713)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=975713

Security Update for Windows XP (KB976323) 1 (KB976323)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB976323$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=976323

Security Update for Windows XP (KB977816) 1 (KB977816)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=977816

Security Update for Windows XP (KB977914) 1 (KB977914)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=977914

Security Update for Windows XP (KB978037) 1 (KB978037)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=978037

Security Update for Windows XP (KB978262) 1 (KB978262)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=978262

Security Update for Windows XP (KB978338) 1 (KB978338)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=978338

Security Update for Windows XP (KB978542) 1 (KB978542)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB978542$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=978542

Security Update for Windows XP (KB978601) 1 (KB978601)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=978601

Security Update for Windows Media Player (KB978695) (KB978695_WM9)
install date: 20100610
uninstall cmd: "G:\WINDOWS\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=978695

Security Update for Windows XP (KB978706) 1 (KB978706)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=978706

Security Update for Windows XP (KB979309) 1 (KB979309)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=979309

Security Update for Windows Media Player (KB979402) (KB979402_WM9)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB979402_WM9$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=979402

Security Update for Windows Media Player (KB979402) (KB979402_WM9L)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB979402_WM9L$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=979402

Security Update for Windows XP (KB979482) 1 (KB979482)
install date: 20100610
uninstall cmd: "G:\WINDOWS\$NtUninstallKB979482$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=979482

Security Update for Windows XP (KB979559) 1 (KB979559)
install date: 20100610
uninstall cmd: "G:\WINDOWS\$NtUninstallKB979559$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=979559

Security Update for Windows XP (KB979683) 1 (KB979683)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=979683

Security Update for Windows XP (KB979687) 1 (KB979687)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB979687$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=979687

Update for Windows XP (KB980182) 1 (KB980182)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB980182$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=980182

Update for Windows Internet Explorer 7 (KB980182) 1 (KB980182-IE7)
install date: 20100606
uninstall cmd: "G:\WINDOWS\ie7updates\KB980182-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=980182

Security Update for Windows XP (KB980195) 1 (KB980195)
install date: 20100610
uninstall cmd: "G:\WINDOWS\$NtUninstallKB980195$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=980195

Security Update for Windows XP (KB980218) 1 (KB980218)
install date: 20100610
uninstall cmd: "G:\WINDOWS\$NtUninstallKB980218$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=980218

Security Update for Windows XP (KB980232) 1 (KB980232)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=980232

Security Update for Windows XP (KB980436) 1 (KB980436)
install date: 20100812
uninstall cmd: "G:\WINDOWS\$NtUninstallKB980436$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=980436

Security Update for Windows XP (KB981322) 1 (KB981322)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB981322$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=981322

Security Update for Windows XP (KB981349) 1 (KB981349)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB981349$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=981349

Hotfix for Windows XP (KB981793) 1 (KB981793)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtUninstallKB981793$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=981793

Security Update for Windows XP (KB981852) 1 (KB981852)
install date: 20100812
uninstall cmd: "G:\WINDOWS\$NtUninstallKB981852$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=981852

Security Update for Windows XP (KB981957) 1 (KB981957)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB981957$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=981957

Security Update for Windows XP (KB981997) 1 (KB981997)
install date: 20100812
uninstall cmd: "G:\WINDOWS\$NtUninstallKB981997$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=981997

Security Update for Windows XP (KB982132) 1 (KB982132)
install date: 20101015
uninstall cmd: "G:\WINDOWS\$NtUninstallKB982132$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=982132

Security Update for Windows XP (KB982214) 1 (KB982214)
install date: 20100812
uninstall cmd: "G:\WINDOWS\$NtUninstallKB982214$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=982214

Security Update for Windows Internet Explorer 7 (KB982381) 1 (KB982381-IE7)
install date: 20100610
uninstall cmd: "G:\WINDOWS\ie7updates\KB982381-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=982381

Security Update for Windows XP (KB982665) 1 (KB982665)
install date: 20100812
uninstall cmd: "G:\WINDOWS\$NtUninstallKB982665$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=982665

Security Update for Windows XP (KB982802) 1 (KB982802)
install date: 20100916
uninstall cmd: "G:\WINDOWS\$NtUninstallKB982802$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=982802

Lexmark 5400 Series (Lexmark 5400 Series)
uninstall cmd: G:\Program Files\Lexmark 5400 Series\Install\x86\Uninst.exe
publisher: Lexmark International, Inc.
help link: http://support.lexmark.com

Malwarebytes Anti-Malware version 1.75.0.1300 1.75.0.1300 (Malwarebytes' Anti-Malware_is1)
install date: 20130412
install location: G:\Program Files\Malwarebytes' Anti-Malware1\
uninstall cmd: "G:\Program Files\Malwarebytes' Anti-Malware1\unins000.exe"
publisher: Malwarebytes Corporation

Microsoft .NET Framework 3.5 SP1 (Microsoft .NET Framework 3.5 SP1)
install location: G:\WINDOWS\Microsoft.NET\Framework\v3.5\
uninstall cmd: G:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=120337

Microsoft .NET Framework 4 Client Profile 4.0.30319 (Microsoft .NET Framework 4 Client Profile)
estimated size: 39732
install location: G:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client
uninstall cmd: G:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
publisher: Microsoft Corporation
readme: http://go.microsoft.com/fwlink/?LinkId=164156

Microsoft .NET Framework 4 Extended 4.0.30319 (Microsoft .NET Framework 4 Extended)
estimated size: 53233
install location: G:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended
uninstall cmd: G:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /parameterfolder Extended
publisher: Microsoft Corporation
readme: http://go.microsoft.com/fwlink/?LinkId=164156

Microsoft Help Viewer 1.0 1.0.30319 (Microsoft Help Viewer 1.0)
estimated size: 4070
install location: g:\Program Files\Microsoft Help Viewer\v1.0\
uninstall cmd: g:\Program Files\Microsoft Help Viewer\v1.0\Microsoft Help Viewer 1.0\install.exe
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=133405

(MobileOptionPack)

Mozilla Firefox 23.0 (x86 en-US) 23.0 (Mozilla Firefox 23.0 (x86 en-US))
estimated size: 50279
install location: G:\Program Files\Mozilla Firefox
uninstall cmd: "G:\Program Files\Mozilla Firefox\uninstall\helper.exe"
publisher: Mozilla
comments: Mozilla Firefox 23.0 (x86 en-US)

Mozilla Maintenance Service 23.0 (MozillaMaintenanceService)
estimated size: 334
uninstall cmd: "G:\Program Files\Mozilla Maintenance Service\uninstall.exe"
publisher: Mozilla
comments: Mozilla Maintenance Service 23.0 (x86 en-US)

(MPlayer2)

Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=74087

(MSI30-Beta1)

(MSI30-Beta2)

(MSI30-KB884016)

(MSI30-RC1)

(MSI30-RC2)

(MSI30a-KB884016)

(MSI31-Beta)

(MSI31-RC1)

(NetMeeting)

Microsoft National Language Support Downlevel APIs (NLSDownlevelMapping)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
publisher: Microsoft Corporation

Microsoft Office Professional 2010 14.0.6029.1000 (Office14.SingleImage)
install location: G:\Program Files\Microsoft Office
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall SINGLEIMAGE /dll OSETUP.DLL
publisher: Microsoft Corporation

(OutlookExpress)

(PCHealth)
uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 G:\WINDOWS\INF\PCHealth.inf

Intel® PRO Network Connections Drivers (PROSet)
uninstall cmd: Prounstl.exe

(RealPlayer 12.0)

(SchedulingAgent)

Microsoft Windows SDK for Windows 7 (7.1) 7.1.7600.0.30514 (SDKSetup_7.1.7600.0.30514)
install date: 9/25/2011
install location: G:\Program Files\Microsoft SDKs\Windows\v7.1\
install source: http://download.microsoft.com/download/A/6…8E5D34E3D/setup
uninstall cmd: "G:\Program Files\Microsoft SDKs\Windows\v7.1\Setup\Setup.exe" -x "-source:http://download.microsoft.com/download/A/6/A/A6AC035D-DA3F-4F0C-ADA4-37C8E5D34E3D/setup;G:\Program Files\Microsoft SDKs\Windows\v7.1\;G:\Program Files\Microsoft SDKs\Windows\v7.1\Setup\1033\;G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDK\WinSDK\"
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

Shockwave (Shockwave)
uninstall cmd: G:\WINDOWS\system32\Macromed\Shockwave 8\UNWISE.EXE G:\WINDOWS\system32\Macromed\Shockwave 8\INSTALL.LOG

System Protect 1.0.0.83 (System Protect_is1)
install date: 20100605
install location: G:\Program Files\System Protect\
uninstall cmd: "G:\Program Files\System Protect\unins000.exe"
publisher: Xacti Corp.
help link: http://www.system-protect.com/faq.aspx

Windows Genuine Advantage Validation Tool (KB892130) 1.7.0069.2 (WGA)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=892130

(WIC)

Windows Media Format 11 runtime (Windows Media Format Runtime)
uninstall cmd: "G:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
help link: http://go.microsoft.com/fwlink/?LinkId=62768

Windows Media Player 11 (Windows Media Player)
uninstall cmd: "G:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall

Windows XP Service Pack 3 20080414.031525 (Windows XP Service Pack)
install date: 20100606
uninstall cmd: "G:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=936929

WinRAR archiver (WinRAR archiver)
uninstall cmd: G:\Program Files\WinRAR\uninstall.exe

(WMCSetup)

Windows Media Format 11 runtime (WMFDist11)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:

Windows Media Player 11 (wmp11)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:

Microsoft User-Mode Driver Framework Feature Pack 1.0 (Wudf01000)
install date: 20101221
uninstall cmd: "G:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
comments: Build Number 5716

Microsoft .NET Framework 4 Extended 4.0.30319 ({0A0CADCF-78DA-33C4-A350-CD51849B9702})
version: 67139183
version (major): 4
estimated size: 139559
install date: 20130323
install source: G:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\
uninstall cmd: MsiExec.exe /X{0A0CADCF-78DA-33C4-A350-CD51849B9702}
publisher: Microsoft Corporation
readme: http://go.microsoft.com/fwlink/?LinkId=164156

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2162169)

Security Update for Microsoft .NET Framework 4 Extended (KB2416472) 1 ({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2416472)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {7A2C18A1-D2A2-3177-82F1-5FE9CC08ECB0} /parameterfolder Extended
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Extended.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2416472.
help link: http://support.microsoft.com/kb/2416472

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2468871)

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2478063)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367) 1 ({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2487367)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {42A3562E-8B4E-39A4-B82D-CC12F82889E3} /parameterfolder Extended
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Extended.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2487367.
help link: http://support.microsoft.com/kb/2487367

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2533523)

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2544514)

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2572063)

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2599651)

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2600211)

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2600217)

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2604121)

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2639327)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351) 1 ({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2656351)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {4952F442-5C1A-38EB-8C23-B18EFE77E20C} /parameterfolder Extended
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Extended.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2656351.
help link: http://support.microsoft.com/kb/2656351

({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2682543)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428) 1 ({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2736428)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {FCBF8C05-F031-381A-8B7F-45403B55ADF5} /parameterfolder Extended
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Extended.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2736428.
help link: http://support.microsoft.com/kb/2736428

Security Update for Microsoft .NET Framework 4 Extended (KB2742595) 1 ({0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2742595)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {788818B1-B191-3217-A210-7ACFDE19CE4A} /parameterfolder Extended
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Extended.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2742595.
help link: http://support.microsoft.com/kb/2742595

Security Update for CAPICOM (KB931906) 2.1.0.2 ({0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A})
version: 33619968
version (major): 2
version (minor): 1
estimated size: 770
install date: 20130515
install source: G:\WINDOWS\TEMP\IXP000.TMP\
uninstall cmd: MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
publisher: Microsoft Corporation

iTunes 10.7.0.21 ({0F6F6876-6334-4977-B5DD-CFC12E193420})
version: 168230912
version (major): 10
version (minor): 7
estimated size: 185090
install date: 20121112
install location: G:\Program Files\iTunes\
install source: G:\Documents and Settings\Administrator\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{0F6F6876-6334-4977-B5DD-CFC12E193420}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]

Lexmark Toolbar ({1017A80C-6F09-4548-A84D-EDD6AC9525F0})
uninstall cmd: regsvr32.exe /s /u "G:\Program Files\Lexmark Toolbar\toolband.dll"

Adobe AIR 3.5.0.600 ({14DC0059-00F1-4F62-BD1A-AB23CD51A95E})
version: 50659328
version (major): 3
version (minor): 5
estimated size: 44975
install date: 20121123
install location: G:\Program Files\Common Files\Adobe AIR\
install source: G:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AIR17.tmp\
uninstall cmd: MsiExec.exe /I{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}
publisher: Adobe Systems Incorporated

Microsoft Picture It! Publishing 2001 5.0.0.0000 ({15D9EB74-998E-4A04-B468-51C2E7B32182})
version: 83886080
version (major): 5
estimated size: 312801
install date: 20100621
install location: INSTALLDIR
install source: D:\PIP\
uninstall cmd: MsiExec.exe /I{15D9EB74-998E-4A04-B468-51C2E7B32182}
publisher: Microsoft
comments: Microsoft Picture It! Publishing 2001
help link: http://www.microsoft.com
readme: Readme.txt

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 10.0.30319 ({196BB40D-1578-3D01-B289-BEFC77A11A1E})
version: 167802479
version (major): 10
estimated size: 15202
install date: 20130517
install source: g:\1954ef58af9ffb5a7e23\
uninstall cmd: MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}
publisher: Microsoft Corporation
comments: Caution. Removing this product might prevent some applications from running.
help link: http://go.microsoft.com/fwlink/?LinkId=146008

({196BB40D-1578-3D01-B289-BEFC77A11A1E}.KB2151757)

({196BB40D-1578-3D01-B289-BEFC77A11A1E}.KB982573)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 9.0.30729.4148 ({1F1C2DFC-2D24-3E06-BCB8-725134ADF989})
version: 151025673
version (major): 9
estimated size: 11608
install date: 20110214
install source: g:\1dfb58e4c9a1b23132d9069cc462\
uninstall cmd: MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
publisher: Microsoft Corporation

({26A24AE4-039D-4CA4-87B4-2F83216021FB})

({26A24AE4-039D-4CA4-87B4-2F83216022FB})

({26A24AE4-039D-4CA4-87B4-2F83216023FB})

({26A24AE4-039D-4CA4-87B4-2F83216026FB})

({26A24AE4-039D-4CA4-87B4-2F83216029FB})

({26A24AE4-039D-4CA4-87B4-2F83217010FB})

({26A24AE4-039D-4CA4-87B4-2F83217011FB})

({26A24AE4-039D-4CA4-87B4-2F83217021FB})

Java 7 Update 25 7.0.250 ({26A24AE4-039D-4CA4-87B4-2F83217025FF})
version: 117440762
version (major): 7
estimated size: 132404
install date: 20130625
install location: G:\Program Files\Java\jre7\
install source: G:\Documents and Settings\Administrator\Application Data\Sun\Java\jre1.7.0_25\
uninstall cmd: MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217025FF}
publisher: Oracle
contact: http://java.com
help link: http://java.com
readme: G:\Program Files\Java\jre7\README.txt

WebFldrs XP 9.50.7523 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227})
version: 154279267
version (major): 9
version (minor): 50
estimated size: 2472
install date: 20100605
install source: G:\WINDOWS\system32\
publisher: Microsoft Corporation
help link: http://www.microsoft.com/windows

Microsoft Visual C++ Compilers 2010 Standard - enu - x86 10.0.30319 ({370187B9-6964-38D0-851F-6C4898B0C2B1})
version: 167802479
version (major): 10
estimated size: 628619
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\vc_stdx86\vc_stdx86\
uninstall cmd: MsiExec.exe /X{370187B9-6964-38D0-851F-6C4898B0C2B1}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=133405

Microsoft Windows SDK for Visual Studio .NET 4.0 Framework Tools 7.1.30514 ({37AC7F94-2C0C-3DFF-8039-4B6AB79150D0})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 9251
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKNetFx40Tools\WinSDKNetFx40Tools\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

Microsoft .NET Framework 4 Client Profile 4.0.30319 ({3C3901C5-3455-3E0A-A214-0B093A5070A6})
version: 67139183
version (major): 4
estimated size: 492690
install date: 20130814
install source: G:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\
uninstall cmd: MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
publisher: Microsoft Corporation
readme: http://go.microsoft.com/fwlink/?LinkId=164156

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2160841)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2162169)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2446708)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {3E0806DB-3085-378A-840A-F0D3AE3609D1} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2446708.
help link: http://support.microsoft.com/kb/2446708

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2446708v2)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2468871)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2473228)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2478063)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2478663)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2478663.
help link: http://support.microsoft.com/kb/2478663

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2514805)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2518870)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2518870.
help link: http://support.microsoft.com/kb/2518870

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2533523)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2539636)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2544514)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2572063)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2572078)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2599651)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2600211)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2600217)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2604121)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {67A5F99B-5EBA-3812-8D2E-BC251490DD3F} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2604121.
help link: http://support.microsoft.com/kb/2604121

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2633870)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2639327)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656351)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {4952F442-5C1A-38EB-8C23-B18EFE77E20C} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2656351.
help link: http://support.microsoft.com/kb/2656351

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656368)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656368v2)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656405)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2686827)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2698021)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2729449)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {CD6D9B8A-BBC4-3FA7-B24D-D74CE90630CF} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2729449.
help link: http://support.microsoft.com/kb/2729449

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2732797)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2736428)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FCBF8C05-F031-381A-8B7F-45403B55ADF5} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2736428.
help link: http://support.microsoft.com/kb/2736428

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2737019)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {ECBEE23D-AB7E-3DAA-B66B-CD52003198F1} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2737019.
help link: http://support.microsoft.com/kb/2737019

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2742595)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {788818B1-B191-3217-A210-7ACFDE19CE4A} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2742595.
help link: http://support.microsoft.com/kb/2742595

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2789642)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {B7C20E16-9A3A-3F05-A6B5-E15AA09200E0} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2789642.
help link: http://support.microsoft.com/kb/2789642

Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2804576)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {CF581973-77E0-3093-A1AC-A03130DE990F} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2804576.
help link: http://support.microsoft.com/kb/2804576

Security Update for Microsoft .NET Framework 4 Client Profile (KB2832407) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2832407)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {80774950-A707-386B-9C9B-D052D20BD54B} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2832407.
help link: http://support.microsoft.com/kb/2832407

Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2835393)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {576C07F8-777C-3981-B8BF-063A6B57254E} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2835393.
help link: http://support.microsoft.com/kb/2835393

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2836939)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2836939v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628) 1 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2840628)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {90EA7C4E-7F03-31FD-BE27-B1A9B4AE56BD} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2840628.
help link: http://support.microsoft.com/kb/2840628

Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2) 2 ({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2840628v2)
uninstall cmd: g:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {1E88AFAE-CEF7-3540-8FF6-6D00877B2767} /parameterfolder Client
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 4 Client Profile.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2840628.
help link: http://support.microsoft.com/kb/2840628

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2858302)

({3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2861188)

ArcSoft MediaImpression 2 2.0.27.836 ({3DABE68E-FD6C-46FC-9045-AD1E3A09D106})
version (major): 2
install location: G:\Program Files\ArcSoft\MediaImpression 2
uninstall cmd: RunDll32 G:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "G:\Program Files\InstallShield Installation Information\{3DABE68E-FD6C-46FC-9045-AD1E3A09D106}\Setup.exe" -l0x9
publisher: ArcSoft

OpenOffice.org 3.3 3.3.9567 ({3E171899-0175-47CC-84C4-562ACDD4C021})
version: 50537823
version (major): 3
version (minor): 3
estimated size: 381270
install date: 20110412
install location: G:\Program Files\OpenOffice.org 3\
install source: G:\Documents and Settings\Administrator\Desktop\OpenOffice.org 3.3 (en-US) Installation Files\
uninstall cmd: MsiExec.exe /I{3E171899-0175-47CC-84C4-562ACDD4C021}
publisher: OpenOffice.org
comments: OpenOffice.org 3.3 (en-US) (OOO330m20(Build:9567))
contact: Department for technical support
help link: http://www.openoffice.org
help telephone: x-xxx-xxx-xxx

Microsoft Help Viewer 1.0 1.0.30319 ({47C39E4A-28F2-33B1-B9B7-97F24E52D917})
version: 16807535
version (major): 1
estimated size: 2924
install date: 20110925
install source: g:\0d2ccd5471ed441d53df6c860fc7\
uninstall cmd: MsiExec.exe /X{47C39E4A-28F2-33B1-B9B7-97F24E52D917}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=133405

Java Auto Updater 2.1.9.5 ({4A03706F-666A-4037-7777-5F2748764D10})
version: 33619977
version (major): 2
version (minor): 1
estimated size: 1209
install date: 20130425
install source: G:\Documents and Settings\Administrator\Application Data\Sun\Java\AU\
publisher: Sun Microsystems, Inc.

Microsoft Windows SDK .NET Framework Tools (30514) 7.1.30514 ({4B509F1E-BEA7-3D0E-BE94-3BBF85E8D698})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 10862
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKNetFxTools\WinSDKNetFxTools\
publisher: Microsoft
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

Microsoft Windows SDK for Windows 7 Headers and Libraries (30514) 7.1.30514 ({4F30BC2B-5441-3149-91D7-FAA2332E2F5F})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 169875
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKBuild\WinSDKBuild\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

VC80CRTRedist - 8.0.50727.4053 1.1.0 ({5EE7D259-D137-4438-9A5F-42F432EC0421})
version: 16842752
version (major): 1
version (minor): 1
estimated size: 1663
install date: 20100805
install source: G:\Program Files\Common Files\DivX Shared\
uninstall cmd: MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
publisher: DivX, Inc
comments: Install VC80 C++ Runtimes
contact: DivX, Inc

swMSM [removed] ({612C34C7-5E90-47D8-9B5C-0F717DD82726})
version: 201326592
version (major): 12
estimated size: 1439
install date: 20110826
install location: G:\WINDOWS\My Product Name\
install source: G:\WINDOWS\system32\Adobe\Shockwave 11\
uninstall cmd: MsiExec.exe /I{612C34C7-5E90-47D8-9B5C-0F717DD82726}
publisher: Adobe Systems, Inc
comments: Adobe Shockwave Player Merge Module
contact: http://www.adobe.com
help link: http://www.adobe.com/support
help telephone: [removed]

Revo Uninstaller Pro 2.5.9 2.5.9 ({67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1)
install date: 20121123
install location: G:\Program Files\VS Revo Group\Revo Uninstaller Pro\
uninstall cmd: "G:\Program Files\VS Revo Group\Revo Uninstaller Pro\unins000.exe"
publisher: VS Revo Group, Ltd.
help link: http://www.revouninstallerpro.com/

Microsoft Windows SDK for Windows 7 Samples (30514) 7.1.30514 ({699C970F-1E17-3CD8-A2EA-87AB9EDEDFF4})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 133581
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKSamples\WinSDKSamples\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

Microsoft Visual C++ 2005 Redistributable 8.0.61001 ({710f4c1c-cc18-4c49-8cbf-51240c89a1a2})
version: 134278729
version (major): 8
estimated size: 5403
install date: 20130515
install source: G:\WINDOWS\TEMP\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
publisher: Microsoft Corporation

Bonjour 3.0.0.10 ({79155F2B-9895-49D7-8612-D92580E0DE5B})
version: 50331648
version (major): 3
estimated size: 1090
install date: 20120412
install location: G:\Program Files\Bonjour\
install source: G:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP227.TMP\
uninstall cmd: MsiExec.exe /X{79155F2B-9895-49D7-8612-D92580E0DE5B}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]

Microsoft Windows SDK for Windows 7 Common Utilities (30514) 7.1.30514 ({7AFFE35D-047A-3D27-B204-1CD849933C02})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 16439
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKTools\WinSDKTools\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

({7B63B2922B174135AFC0E1377DD81EC2})

Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514) 7.1.30514 ({85C977FB-2A5B-3223-8AC5-828558EAF7D9})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 16312
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKWin32Tools\WinSDKWin32Tools\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

MSXML 4.0 SP2 (KB954430) 4.20.9870.0 ({86493ADD-824D-4B8E-BD72-8C5DCDC52A71})
version: 68429454
version (major): 4
version (minor): 20
estimated size: 1455
install date: 20110617
install source: g:\c1df4184eb7a85ad674f\
uninstall cmd: MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/954430

Microsoft Silverlight 5.1.20513.0 ({89F4137D-6C26-4A84-BDB8-2E5A4BB71E00})
version: 83972129
version (major): 5
version (minor): 1
estimated size: 66312
install date: 20130711
install location: g:\Program Files\Microsoft Silverlight\
install source: g:\453fc4cfd891050df39896473b56\
uninstall cmd: MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkID=91955

Intel® Extreme Graphics 2 Driver ({8A708DD8-A5E6-11D4-A706-000629E95E20})
uninstall cmd: RUNDLL32.EXE G:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572

InstallIQ Updater 1.4.3.0 ({8E1CB0F1-67BF-4052-AA23-FA22E94804C1})
version: 17039363
version (major): 1
version (minor): 4
estimated size: 1234
install date: 20111223
install location: G:\Program Files\W3i\InstallIQUpdater\
install source: G:\Documents and Settings\Administrator\Application Data\W3i, LLC\InstallIQ Updater\install\
uninstall cmd: MsiExec.exe /X{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}
publisher: W3i, LLC
help link: mailto:[removed]

TC Web Conferencing 7.89 ({8EB39AA7-4019-4550-AF6C-BE51BB27B446})
install source: G:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\installtemp
uninstall cmd: iwexec.exe /R {8EB39AA7-4019-4550-AF6C-BE51BB27B446}
publisher: Digitalweb
comments: Your Comments
help link: http://www.yourcompany.com/support

Microsoft Software Update for Web Folders (English) 14 14.0.4734.1000 ({90140000-0010-0409-0000-0000000FF1CE})
version: 234885758
version (major): 14
estimated size: 2188
install date: 20110930
install source: G:\MSOCache\All Users\{90140000-0010-0409-0000-0000000FF1CE}-G\
publisher: Microsoft Corporation

Microsoft Office Proof (English) 2010 14.0.4734.1000 ({90140000-001F-0409-0000-0000000FF1CE})
version: 234885758
version (major): 14
estimated size: 21119
install date: 20110930
install location: G:\Program Files\Microsoft Office\
install source: G:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-G\Proof.en\
uninstall cmd: MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

Microsoft Office Proof (French) 2010 14.0.4734.1000 ({90140000-001F-040C-0000-0000000FF1CE})
version: 234885758
version (major): 14
estimated size: 41913
install date: 20110930
install location: G:\Program Files\Microsoft Office\
install source: G:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-G\Proof.fr\
uninstall cmd: MsiExec.exe /X{90140000-001F-040C-0000-0000000FF1CE}
publisher: Microsoft Corporation

Microsoft Office Proof (Spanish) 2010 14.0.4734.1000 ({90140000-001F-0C0A-0000-0000000FF1CE})
version: 234885758
version (major): 14
estimated size: 24993
install date: 20110930
install location: G:\Program Files\Microsoft Office\
install source: G:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-G\Proof.es\
uninstall cmd: MsiExec.exe /X{90140000-001F-0C0A-0000-0000000FF1CE}
publisher: Microsoft Corporation

Microsoft Office Proofing (English) 2010 14.0.4734.1000 ({90140000-002C-0409-0000-0000000FF1CE})
version: 234885758
version (major): 14
estimated size: 602
install date: 20110930
install location: G:\Program Files\Microsoft Office\
install source: G:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-G\
uninstall cmd: MsiExec.exe /X{90140000-002C-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

Microsoft Office Single Image 2010 14.0.6029.1000 ({90140000-003D-0000-0000-0000000FF1CE})
version: 234887053
version (major): 14
estimated size: 1812489
install date: 20130711
install location: G:\Program Files\Microsoft Office\
install source: G:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-G\
uninstall cmd: MsiExec.exe /X{90140000-003D-0000-0000-0000000FF1CE}
publisher: Microsoft Corporation

Microsoft Office 2010 Service Pack 1 (SP1) ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{047B0968-E622-4FAA-9B4B-121FA109EDDE}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2460049

Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{0690E5CB-319C-4FA5-8513-2E255BBB29B9})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{0690E5CB-319C-4FA5-8513-2E255BBB29B9}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2687505

Security Update for Microsoft Office 2010 (KB2553091) ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{07CA44F3-F5B3-4D12-8C91-EDC5FE91D45C})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{07CA44F3-F5B3-4D12-8C91-EDC5FE91D45C}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553091

Security Update for Microsoft Office 2010 (KB2553096) ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{10802A6D-EDBF-4383-BCBD-9D5B32F56D35})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{10802A6D-EDBF-4383-BCBD-9D5B32F56D35}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553096

Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{14B7142F-D7E2-4FB0-9E3B-7CAA8D7FFC56})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{14B7142F-D7E2-4FB0-9E3B-7CAA8D7FFC56}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553378

Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{18B3CF2A-73F7-4716-B1AE-86D68726D408})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{18B3CF2A-73F7-4716-B1AE-86D68726D408}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553267

Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{1CBEDB37-C438-473F-8BA0-2535B0D237E2})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{1CBEDB37-C438-473F-8BA0-2535B0D237E2}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2687509

Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{280E2D43-11CC-4ADE-A171-9286CCB5412B})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{280E2D43-11CC-4ADE-A171-9286CCB5412B}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2760600

Security Update for Microsoft Office 2010 (KB2687276) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{294CFDA0-FFD3-4C74-A26C-F4AE246783D6})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{294CFDA0-FFD3-4C74-A26C-F4AE246783D6}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2687276

Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{35698CB7-AAA2-4577-B505-DBFF504AEF23}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2760631

Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{48E1B6C2-7299-4F3F-AA63-42F0ACE55AA4})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{48E1B6C2-7299-4F3F-AA63-42F0ACE55AA4}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553181

Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{54A1B66B-F5B2-45AD-8B19-5F51A027A1B9})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{54A1B66B-F5B2-45AD-8B19-5F51A027A1B9}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2597986

Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{6B6DDDCE-B456-4FE1-9A07-DBC1708E4158})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{6B6DDDCE-B456-4FE1-9A07-DBC1708E4158}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2598240

Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{73CC972E-6ABF-456B-9E1E-BADC0E65B57A})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{73CC972E-6ABF-456B-9E1E-BADC0E65B57A}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2597126

Security Update for Microsoft Publisher 2010 (KB2553147) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{77AA05C3-6499-49F2-801D-55BD0E587579})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{77AA05C3-6499-49F2-801D-55BD0E587579}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553147

Security Update for Microsoft InfoPath 2010 (KB2760406) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{89F78B33-4282-4698-844D-E306D4260C02})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{89F78B33-4282-4698-844D-E306D4260C02}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2760406

Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9CFD026D-EB1C-48C2-9DD2-8E8875F251B2})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{9CFD026D-EB1C-48C2-9DD2-8E8875F251B2}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2767886

Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9FF4E0C9-11BB-4B32-AC5E-EAB896CB4216})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{9FF4E0C9-11BB-4B32-AC5E-EAB896CB4216}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2687501

Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{A3AD381D-848C-4478-80DC-228E37309308})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{A3AD381D-848C-4478-80DC-228E37309308}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/982726

Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{A5E549EB-FDD3-4CD1-8163-50D429A36516})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{A5E549EB-FDD3-4CD1-8163-50D429A36516}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2687510

Update for Microsoft Office 2010 (KB2553065) ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{A8686D24-1E89-43A1-973E-05A258D2B3F8})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{A8686D24-1E89-43A1-973E-05A258D2B3F8}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553065

Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B5489515-6DD4-47A5-AE4E-64751D15F10E})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{B5489515-6DD4-47A5-AE4E-64751D15F10E}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2598243

Security Update for Microsoft Visio 2010 (KB2810068) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{BC3AD7F4-A075-4C9E-A33A-0FA4F8EBCA96})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{BC3AD7F4-A075-4C9E-A33A-0FA4F8EBCA96}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2810068

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{BC6DFBFD-16DD-47E1-A7EF-2C062930FA4F})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{BC6DFBFD-16DD-47E1-A7EF-2C062930FA4F}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553406

Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{CC39BA1F-7A25-440C-86A7-77E35D8CC88C})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{CC39BA1F-7A25-440C-86A7-77E35D8CC88C}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553447

Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{CCC48FE2-175F-4CDE-82DF-F7BC4672C1A3})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{CCC48FE2-175F-4CDE-82DF-F7BC4672C1A3}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553371

Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DCE6D0BF-93E4-46C5-9A7C-F1EFF9707C02})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{DCE6D0BF-93E4-46C5-9A7C-F1EFF9707C02}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2589320

Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ED31DE9A-3E13-4E2C-9106-E0D8AFFB9FA6})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{ED31DE9A-3E13-4E2C-9106-E0D8AFFB9FA6}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2596964

Update for Microsoft Office 2010 (KB2566458) ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFB525A0-E1C0-4E32-9968-FE401BC87363})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{EFB525A0-E1C0-4E32-9968-FE401BC87363}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2566458

Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F0CF1EB7-3E57-4F85-843F-B3C79088510D})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{F0CF1EB7-3E57-4F85-843F-B3C79088510D}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2553501

Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1CBE095-403D-466D-BB13-B185A5F33231})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{F1CBE095-403D-466D-BB13-B185A5F33231}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2597090

Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition ({90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F8243081-3FB0-4EE8-9B2A-6F7D70AF5269})
uninstall cmd: "G:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-003D-0000-0000-0000000FF1CE}" "{F8243081-3FB0-4EE8-9B2A-6F7D70AF5269}" "1033" "0"
publisher: Microsoft
help link: http://support.microsoft.com/kb/2760410

Microsoft Office Shared Setup Metadata MUI (English) 2010 14.0.4734.1000 ({90140000-0115-0409-0000-0000000FF1CE})
version: 234885758
version (major): 14
estimated size: 558
install date: 20110930
install location: G:\Program Files\Microsoft Office\
install source: G:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-G\
uninstall cmd: MsiExec.exe /X{90140000-0115-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

Microsoft Office Access Setup Metadata MUI (English) 2010 14.0.4734.1000 ({90140000-0117-0409-0000-0000000FF1CE})
version: 234885758
version (major): 14
estimated size: 646
install date: 20110930
install location: G:\Program Files\Microsoft Office\
install source: G:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-G\
uninstall cmd: MsiExec.exe /X{90140000-0117-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation

Microsoft Windows SDK for Windows 7 (7.1) 7.1.30514 ({928D2FB1-291A-362B-89A4-7075A9D904A4})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 20317
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDK\WinSDK\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

Microsoft Windows SDK Intellisense and Reference Assemblies (30514) 7.1.30514 ({9A9C11FA-AE85-3B48-86BE-5FA83D0384B3})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 6617
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKIntellisenseRefAssys\WinSDKIntellisenseRefAssys\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 9.0.30729.6161 ({9BE518E6-ECC6-35A9-88E4-87755C07200F})
version: 151025673
version (major): 9
estimated size: 10444
install date: 20130515
install source: g:\e136193f9d7884edb52d\
uninstall cmd: MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
publisher: Microsoft Corporation

Microsoft .NET Framework 3.0 Service Pack 2 3.2.30729 ({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7})
version: 50493449
version (major): 3
version (minor): 2
estimated size: 277264
install date: 20130711
install source: g:\03328b8405a0616232abfa19\dotnetfx30\
uninstall cmd: MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=98075

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB2604110)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB2656407)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB2756918)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB2832411)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB300003)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB958483)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB960043)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB975195)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976570)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976578)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976578v2)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976769)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976769v2)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB977354)

({A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB977354v2)

MSXML 6.0 Parser 6.10.1129.0 ({A43BF6A5-D5F0-4AAA-BF41-65995063EC44})
version: 101319785
version (major): 6
version (minor): 10
estimated size: 1496
install date: 20110616
install source: D:\printer\msxml6\
uninstall cmd: MsiExec.exe /I{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=52156

Adobe Reader XI (11.0.03) 11.0.03 ({AC76BA86-7AD7-1033-7B44-AB0000000001})
version: 184549379
version (major): 11
estimated size: 131088
install date: 20130515
install location: G:\Program Files\Adobe\Reader 11.0\Reader\
install source: G:\Documents and Settings\All Users\Application Data\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\
uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-AB0000000001}
publisher: Adobe Systems Incorporated
comments:
contact: Customer Support
help link: http://www.adobe.com/support/main.html
readme: G:\Program Files\Adobe\Reader 11.0\Readme.htm

QuickTime 7.73.80.64 ({AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A})
version: 122224720
version (major): 7
version (minor): 73
estimated size: 74941
install date: 20121112
install location: G:\Program Files\QuickTime\
install source: G:\Documents and Settings\Administrator\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]

Spybot - Search & Destroy 1.6.2 ({B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1)
install date: 20100823
install location: G:\Program Files\Spybot - Search & Destroy\
uninstall cmd: "G:\Program Files\Spybot - Search & Destroy\unins000.exe"
publisher: Safer Networking Limited
help link: http://www.safer-networking.org/index.php?page=support

Microsoft Windows SDK MSHelp (30514) 7.1.30514 ({B7072091-4582-396F-87E2-412C85AC7095})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 1632
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKHelp\WinSDKhelp\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

({BB8B979E-E336-47E7-96BC-1031C1B94561})

Macrium Reflect - Free Edition 4.2.3775 ({BB912177-24CC-4AEE-8329-97D7ACD125D4})
version: 67243711
version (major): 4
version (minor): 2
estimated size: 29134
install date: 20110829
install source: G:\WINDOWS\Installer\
uninstall cmd: MsiExec.exe /I{BB912177-24CC-4AEE-8329-97D7ACD125D4}
publisher: Macrium
comments: Windows imaging and backup software
contact: Macrium
help link: http://www.macrium.com

Microsoft .NET Framework 2.0 Service Pack 2 2.2.30729 ({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F})
version: 33716233
version (major): 2
version (minor): 2
estimated size: 187299
install date: 20130816
install source: g:\03328b8405a0616232abfa19\dotnetfx20\
uninstall cmd: MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=98073
I'm sorry, it said the last post was to long, so I had to split it up into 2 posts. Here is the other half of the Spybot Search & Destroy scan …………..

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB200003)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2418241)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2446704)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2446704v2)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2478658)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2518864)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2539631)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2572058)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2572073)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2604092)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2616155)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2633880)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2639328)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2656352)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2656369)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2656369v2)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2686828)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2698022)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2729450)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2742596)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2789643)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2804577)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2833940)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2836941)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2836941v2)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2844285)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2844285v2)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB2863239)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB431780)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB946922)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB947748)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB949272)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB952137)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB952677)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB953300)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB953990)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB954832)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB956860)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB957541)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB957542)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB957543)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB958129)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB958481)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB960043)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB971111)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB974417)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB976569)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB976576)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB976765v2)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB979909)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB980773)

({C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB983583)

Microsoft Windows SDK Net Fx Interop Headers And Libraries (30514) 7.1.30514 ({C617EC41-9E21-3915-AA7E-F156B74F7D07})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 3517
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKInterop\WinSDKInterop\
publisher: Microsoft Corporation
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

Microsoft .NET Framework 3.5 SP1 3.5.30729 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9})
version: 50690057
version (major): 3
version (minor): 5
estimated size: 78992
install date: 20130711
install source: G:\WINDOWS\TEMP\IXP0113D.tmp\dotnetfx35\x86\
uninstall cmd: MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
publisher: Microsoft Corporation

({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) 1 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2604111)
uninstall cmd: G:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {94EFE014-E577-310B-B2D5-6973A21D8A90} /qb+ REBOOTPROMPT=""
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2604111.
help link: http://support.microsoft.com/kb/2604111

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) 1 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2657424)
uninstall cmd: G:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {F6F5AC31-9833-3E77-AC8E-8E910CAB39AE} /qb+ REBOOTPROMPT=""
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2657424.
help link: http://support.microsoft.com/kb/2657424

({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2695869)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) 1 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2736416)
uninstall cmd: G:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {939AF4BC-EC42-38D1-AE82-91D4A7ED8911} /qb+ REBOOTPROMPT=""
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2736416.
help link: http://support.microsoft.com/kb/2736416

({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2836940)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629) 1 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2840629)
uninstall cmd: G:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8433C01-319F-3370-850E-87C35496299A} /qb+ REBOOTPROMPT=""
publisher: Microsoft Corporation
comments: This security update is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this security update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/2840629.
help link: http://support.microsoft.com/kb/2840629

({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB350003)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) 1 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595)
uninstall cmd: G:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
publisher: Microsoft Corporation
comments: This hotfix is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this hotfix will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/953595.
help link: http://support.microsoft.com/kb/953595

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) 1 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484)
uninstall cmd: G:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
publisher: Microsoft Corporation
comments: This hotfix is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this hotfix will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/958484.
help link: http://support.microsoft.com/kb/958484

({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB960043)

Update for Microsoft .NET Framework 3.5 SP1 (KB963707) 1 ({CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707)
uninstall cmd: G:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
publisher: Microsoft Corporation
comments: This update is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/963707.
help link: http://support.microsoft.com/kb/963707

Microsoft .NET Framework 4 Multi-Targeting Pack 4.0.30319 ({CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE})
version: 67139183
version (major): 4
estimated size: 85460
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\NetFxRefAssys\MTPack\
uninstall cmd: MsiExec.exe /I{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}
publisher: Microsoft Corporation

PreReq 6.2.2.60 ({DA5BDB2A-12F0-4343-8351-21AAEB293990})
version: 100794370
version (major): 6
version (minor): 2
estimated size: 6532
install date: 20110616
install source: D:\printer\prereq\
uninstall cmd: MsiExec.exe /I{DA5BDB2A-12F0-4343-8351-21AAEB293990}
publisher: Eastman Kodak Company
comments: _
contact: Customer Support Department
help link: _
help telephone: _

Windows SDK IntellisenseNFX 7.1.30514 ({E4197D6B-F046-33E7-ABDE-51FF373FDC76})
version: 117536562
version (major): 7
version (minor): 1
estimated size: 230325
install date: 20110925
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKIntellisenseNFX\WinSDKIntellisenseNFX\
publisher: Microsoft
comments: Update/Uninstall/Repair this SDK
help link: http://go.microsoft.com/fwlink/?linkid=156449

Microsoft Windows Performance Toolkit 4.8.0 ({E7F9E526-2324-437B-A609-E8C5309465CB})
version: 67633152
version (major): 4
version (minor): 8
estimated size: 5789
install date: 20110925
install location: G:\Program Files\Microsoft Windows Performance Toolkit\
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\SDKSetup\WinSDKPerformanceToolKit\WinSDKPerformanceToolKit\
uninstall cmd: MsiExec.exe /I{E7F9E526-2324-437B-A609-E8C5309465CB}
publisher: Microsoft Corporation
help link: http://msdn.microsoft.com/en-us/performance

SoundMAX ({F0A37341-D692-11D4-A984-009027EC0A9C})
install location: G:\Program Files\Analog Devices\SoundMAX
uninstall cmd: RunDll32 G:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "G:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe"

MSXML 4.0 SP2 (KB973688) 4.20.9876.0 ({F662A8E6-F4DC-41A2-901E-8C11F044BDEC})
version: 68429460
version (major): 4
version (minor): 20
estimated size: 2833
install date: 20110617
install source: g:\0fa5d48d1d0da28ad5942cff62f94154\
uninstall cmd: MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/973688

System Requirements Lab for Intel 4.1.66.0 ({F7FC9307-374E-4017-8E9D-DE1154780480})
version: 67174466
version (major): 4
version (minor): 1
estimated size: 686
install date: 20100607
install source: G:\Documents and Settings\Administrator\Application Data\SystemRequirementsLab\
uninstall cmd: MsiExec.exe /I{F7FC9307-374E-4017-8E9D-DE1154780480}
publisher: Husdawg, LLC

Acrobat.com 2.1.0 ({F8131A35-47FD-27AD-116D-0E79AF5DE5EE})
version: 33619968
version (major): 2
version (minor): 1
estimated size: 4039
install date: 20100610
install location: G:\Program Files\Adobe\Acrobat_com
install source: G:\Documents and Settings\Administrator\Local Settings\Temp\fla26A.tmp\
uninstall cmd: MsiExec.exe /I{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}
publisher: Adobe Systems Incorporated

Online Vault 1.0.0.61 ({FA32182A-EA44-4583-803B-AA827F0D4E06}_is1)
install date: 20100605
install location: G:\Program Files\Online Vault\
uninstall cmd: "G:\Program Files\Online Vault\unins000.exe"
publisher: Crawler, LLC
help link: http://www.onlinevault.com/faq.aspx



— System Services —
Service (registry key): .NET CLR Data
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET CLR Networking
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET CLR Networking 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET Data Provider for Oracle
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET Data Provider for SqlServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NET Memory Cache 4.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): .NETFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Abiosdsk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): abp480n5
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ACDaemon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ArcSoft Connect Daemon
Object name: LocalSystem
Image path: G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
Image size: 113152
Image MD5: ADC420616C501B45D26C0FD3EF1E54E4
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0

Service (registry key): ACPI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft ACPI Driver
Image path: system32\DRIVERS\ACPI.sys
Image size: 187776
Image MD5: 8FD99680A539792A30E97944FDAECF17
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ACPIEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): AdobeFlashPlayerUpdateSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Adobe Flash Player Update Service
Description: This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes.
Object name: LocalSystem
Image path: G:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Image size: 256904
Image MD5: 9915504F602D277EE47FD843A677FD15
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): adpu160m
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): adsi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): aeaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\drivers\aeaudio.sys
Image size: 4816
Image MD5: 11C04B17ED2ABBB4833694BCD644AC90
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): aec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Acoustic Echo Canceller
Image path: system32\drivers\aec.sys
Image size: 142592
Image MD5: 8BED39E3C35D6A489438B8141717A557
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Afc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PPdus ASPI Shell
Image path: system32\drivers\Afc.sys
Image size: 18688
Image MD5: FE3EA6E9AFC1A78E6EDCA121E006AFB7
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): AFD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AFD
Description: AFD Networking Support Environment
Image path: \SystemRoot\System32\drivers\afd.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): Aha154x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): aic78u2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): aic78xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Alerter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Alerter
Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): ALG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Layer Gateway Service
Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\alg.exe
Image size: 44544
Image MD5: 8C515081584A38AA007909CD02020B3D
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): AliIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): amsint
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): AppMgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Management
Description: Provides software installation services such as Assign, Publish, and Remove.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): asc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): asc3350p
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): asc3550
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ASP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ASP.NET
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ASP.NET_2.0.50727
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ASP.NET_4.0.30319
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): aspnet_state
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ASP.NET State Service
Description: Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
Image size: 35160
Image MD5: 776ACEFA0CA9DF0FAA51A5FB2F435705
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): AsyncMac
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: RAS Asynchronous Media Driver
Description: RAS Asynchronous Media Driver
Image path: system32\DRIVERS\asyncmac.sys
Image size: 14336
Image MD5: B153AFFAC761E7F5FCFA822B9C4E97BC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): atapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Standard IDE/ESDI Hard Disk Controller
Image path: system32\DRIVERS\atapi.sys
Image size: 96512
Image MD5: 9F3A2F5AA6875C72BF062C712CFA2674
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Atdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): Atmarpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ATM ARP Client Protocol
Description: ATM ARP Client Protocol
Image path: system32\DRIVERS\atmarpc.sys
Image size: 59904
Image MD5: 9916C1225104BA14794209CFA8012159
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): AudioSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Audio
Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs

Service (registry key): audstub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Audio Stub Driver
Image path: system32\DRIVERS\audstub.sys
Image size: 3072
Image MD5: D9F724AA26C010A217C97606B160ED68
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): BattC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Beep
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): BITS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: BITS
Description: Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RpcSs

Service (registry key): Bonjour Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bonjour Service
Description: Enables hardware devices and software services to automatically configure themselves on the network and advertise their presence.
Object name: LocalSystem
Image path: "G:\Program Files\Bonjour\mDNSResponder.exe"
Image size: 390504
Image MD5: DB5BEA73EDAF19AC68B2C0FAD0F92B1A
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: Tcpip

Service (registry key): Browser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Computer Browser
Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,LanmanServer

Service (registry key): catchme
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \??\G:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): cbidf2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): CCDECODE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Closed Caption Decoder
Image path: system32\DRIVERS\CCDECODE.sys
Image size: 17024
Image MD5: 0BE5AEF125BE881C4F854C554F2B025C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): cd20xrnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Cdaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): Cdfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Depends On group: "SCSI CDROM Class"

Service (registry key): Cdrom
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-ROM Driver
Image path: system32\DRIVERS\cdrom.sys
Image size: 62976
Image MD5: 1F4260CC5B42272D71F79E570A27A4FE
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"

Service (registry key): Changer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): CiSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Indexing Service
Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
Object name: LocalSystem
Image path: %SystemRoot%\system32\cisvc.exe
Image size: 5632
Image MD5: 1CFE720EB8D93A7158A4EBC3AB178BDE
Control Set: CurrentControlSet
Start: 3
Type: 288
Error Control: 1
Depends On services: RPCSS

Service (registry key): ClipSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ClipBook
Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\clipsrv.exe
Image size: 33280
Image MD5: 34CBE729F38138217F9C80212A2A0C82
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: NetDDE

Service (registry key): clr_optimization_v2.0.50727_32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: .NET Runtime Optimization Service v2.0.50727_X86
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
Image size: 69632
Image MD5: D87ACAED61E417BBA546CED5E7E36D9C
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 0

Service (registry key): clr_optimization_v4.0.30319_32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft .NET Framework NGEN v4.0.30319_X86
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: G:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
Image size: 130384
Image MD5: C5A75EB48E2344ABDC162BDA79E16841
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0

Service (registry key): CmdIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): COMSysApp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ System Application
Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Image size: 5120
Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: rpcss

Service (registry key): ContentFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ContentIndex
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Cpqarray
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): cpudrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: cpudrv
Image path: \??\G:\Program Files\SystemRequirementsLab\cpudrv.sys
Image size: 11336
Image MD5: D01F685F8B4598D144B0CCE9FF95D8D5
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): CryptSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CryptSvc
Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): dac2w2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0

Service (registry key): dac960nt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): DcomLaunch
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DCOM Server Process Launcher
Description: Provides launch functionality for DCOM services.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k DcomLaunch
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): DfSdkS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Defragmentation-Service
Description: Ashampoo Defrag Service – powered by mst software
Object name: LocalSystem
Image path: "G:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe"
Image size: 406016
Image MD5: 92AE26F2CAF4A67E24A0BA6DDF32CC3C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): Dhcp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DHCP Client
Description: Manages network configuration by registering and updating IP addresses and DNS names.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd,NetBT

Service (registry key): Disk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Disk Driver
Image path: system32\DRIVERS\disk.sys
Image size: 36352
Image MD5: 044452051F3E02E7963599FC8F4F3E25
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"

Service (registry key): dmadmin
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager Administrative Service
Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops.
Object name: LocalSystem
Image path: %SystemRoot%\System32\dmadmin.exe /com
Image size: 224768
Image MD5: E46050330BD42F33609117F861E32D3C
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay,DmServer

Service (registry key): dmboot
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmboot.sys
Image size: 799744
Image MD5: D992FE1274BDE0F84AD826ACAE022A41
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): dmio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager Driver
Image path: system32\DRIVERS\dmio.sys
Image size: 153344
Image MD5: 7C824CF7BBDE77D95C08005717A95F6F
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): dmload
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): dmserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager
Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay

Service (registry key): DMusic
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DLS Syntheiszer
Image path: system32\drivers\DMusic.sys
Image size: 52864
Image MD5: 8A208DFCF89792A484E76C40E5F50B45
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Dnscache
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DNS Client
Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip

Service (registry key): Dot3svc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wired AutoConfig
Description: This service performs IEEE 802.1X authentication on Ethernet interfaces
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k dot3svc
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Ndisuio,eaphost

Service (registry key): dpti2o
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): drmkaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DRM Audio Descrambler
Image path: system32\drivers\drmkaud.sys
Image size: 2944
Image MD5: 8F5FCFF8E8848AFAC920905FBD9D33C8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): E1000
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Intel® PRO/1000 Network Connection Driver
Image path: system32\DRIVERS\e1000325.sys
Image size: 163840
Image MD5: D94437E7EE086677B266099F695CDEA1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): EapHost
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Extensible Authentication Protocol Service
Description: Provides windows clients Extensible Authentication Protocol Service
Object name: localSystem
Image path: %SystemRoot%\System32\svchost.exe -k eapsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): ERSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Error Reporting Service
Description: Allows error reporting for services and applictions running in non-standard environments.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs

Service (registry key): Eventlog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Event Log
Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 110592
Image MD5: 65DF52F5B8B6E9BBD183505225C37315
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): EventSystem
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ Event System
Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: G:\WINDOWS\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): Fastfat
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): FastUserSwitchingCompatibility
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Fast User Switching Compatibility
Description: Provides management for applications that require assistance in a multiple user environment.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: TermService

Service (registry key): Fdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Floppy Disk Controller Driver
Image path: system32\DRIVERS\fdc.sys
Image size: 27392
Image MD5: 92CDD60B6730B9F50F6A1A0C1F8CDC81
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Fips
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): Flpydisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): FltMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: FltMgr
Description: File System Filter Manager Driver
Image path: system32\drivers\fltmgr.sys
Image size: 129792
Image MD5: B2CF4B0786F8212CB92ED2B50C6DB6B0
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): FontCache3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Presentation Foundation Font Cache 3.0.0.0
Description: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
Object name: NT AUTHORITY\LocalService
Image path: g:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
Image size: 46104
Image MD5: 8BA7C024070F2B7FDD98ED8A4BA41789
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): Fs_Rec
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 8
Error Control: 0

Service (registry key): Ftdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Manager Driver
Image path: system32\DRIVERS\ftdisk.sys
Image size: 125056
Image MD5: 6AC26732762483366C3969C9E4D2259D
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): GEARAspiWDM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: GEAR ASPI Filter Driver
Image path: system32\DRIVERS\GEARAspiWDM.sys
Image size: 26840
Image MD5: 185ADA973B5020655CEE342059A86CBB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Gpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Generic Packet Classifier
Description: Generic Packet Classifier
Image path: system32\DRIVERS\msgpc.sys
Image size: 35072
Image MD5: 0A02C63C8B144BD8C86B103DEE7C86A2
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): helpsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Help and Support
Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): HidServ
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Human Interface Device Access
Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): hidusb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft HID Class Driver
Image path: system32\DRIVERS\hidusb.sys
Image size: 10368
Image MD5: CCF82C5EC8A7326C3066DE870C06DAF1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): hkmsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Health Key and Certificate Management Service
Description: Manages health certificates and keys (used by NAP)
Object name: localSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): hpn
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): HTTP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP
Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start.
Image path: System32\Drivers\HTTP.sys
Image size: 265728
Image MD5: F80A415EF82CD06FFAF0D971528EAD38
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): HTTPFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP SSL
Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP

Service (registry key): i2omgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): i2omp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): i8042prt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: i8042 Keyboard and PS/2 Mouse Port Driver
Image path: system32\DRIVERS\i8042prt.sys
Image size: 52480
Image MD5: 4A0B06AA8943C1E332520F7440C0AA30
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): ialm
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\ialmnt5.sys
Image size: 807804
Image MD5: 3CA41CDB9C912AED354B0C7ABE4A4654
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): idsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows CardSpace
Description: Securely enables the creation, management, and disclosure of digital identities.
Object name: LocalSystem
Image path: "g:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
Image size: 881664
Image MD5: C01AC32DC5C03076CFB852CB5DA5229C
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): IISADMIN
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IIS Admin
Description: Allows administration of Web and FTP services through the Internet Information Services snap-in
Object name: LocalSystem
Image path: G:\WINDOWS\system32\inetsrv\inetinfo.exe
Image size: 15360
Image MD5: DB3C22745C0DA4666F3BE31F1AF36B2F
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS,SamSS

Service (registry key): Imapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-Burning Filter Driver
Image path: system32\DRIVERS\imapi.sys
Image size: 42112
Image MD5: 083A052659F5310DD8B6A6CB05EDCF8E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): ImapiService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IMAPI CD-Burning COM Service
Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %systemroot%\system32\imapi.exe
Image size: 150528
Image MD5: 30DEAF54A9755BB8546168CFE8A6B5E1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): inetaccs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): InetInfo
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ini910u
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Inport
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): IntelIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\intelide.sys
Image size: 5504
Image MD5: B5466A9250342A7AA0CD1FBA13420678
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): intelppm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Intel Processor Driver
Image path: system32\DRIVERS\intelppm.sys
Image size: 36352
Image MD5: 8C953733D8F36EB2133F5BB58808B66B
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): Ip6Fw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPv6 Windows Firewall Driver
Description: Provides intrusion prevention service for a home or small office network.
Image path: system32\drivers\ip6fw.sys
Image size: 36608
Image MD5: 3BB22519A194418D5FEC05D800A19AD0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): IpFilterDriver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Traffic Filter Driver
Description: IP Traffic Filter Driver
Image path: system32\DRIVERS\ipfltdrv.sys
Image size: 32896
Image MD5: 731F22BA402EE4B62748ADAF6363C182
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): IpInIp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP in IP Tunnel Driver
Description: IP in IP Tunnel Driver
Image path: system32\DRIVERS\ipinip.sys
Image size: 20864
Image MD5: B87AB476DCF76E72010632B5550955F5
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): IpNat
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Network Address Translator
Description: IP Network Address Translator
Image path: system32\DRIVERS\ipnat.sys
Image size: 152832
Image MD5: CC748EA12C6EFFDE940EE98098BF96BB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): iPod Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPod Service
Description: iPod hardware management services
Object name: LocalSystem
Image path: "G:\Program Files\iPod\bin\iPodService.exe"
Image size: 821648
Image MD5: BC0EA61246F8D940FBC5F652D337D6BD
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RpcSs

Service (registry key): IPSec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC driver
Description: IPSEC driver
Image path: system32\DRIVERS\ipsec.sys
Image size: 75264
Image MD5: 23C74D75E36E7158768DD63D92789A91
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): IRENUM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IR Enumerator Service
Image path: system32\DRIVERS\irenum.sys
Image size: 11264
Image MD5: C93C9FF7B04D772627A3646D89F7BF89
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ISAPISearch
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): isapnp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PnP ISA/EISA Bus Driver
Image path: system32\DRIVERS\isapnp.sys
Image size: 37248
Image MD5: 05A299EC56E52649B1CF2FC52D20F2D7
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3

Service (registry key): Kbdclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Keyboard Class Driver
Image path: system32\DRIVERS\kbdclass.sys
Image size: 24576
Image MD5: 463C1EC80CD17420A542B7F36A36F128
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): kmixer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Wave Audio Mixer
Image path: system32\drivers\kmixer.sys
Image size: 172416
Image MD5: 692BCF44383D056AED41B045A323D378
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): KSecDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): lanmanserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Server
Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): lanmanworkstation
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Workstation
Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): lbrtfdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): ldap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): LicenseService
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): LmHosts
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP NetBIOS Helper
Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: NetBT,Afd

Service (registry key): LVRS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logitech RightSound Filter Driver
Image path: system32\DRIVERS\lvrs.sys
Image size: 312096
Image MD5: ED643E777BA3F7151EF3F0FB6BE4F7F0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): LVUVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logitech HD Webcam C310(UVC)
Image path: system32\DRIVERS\lvuvc.sys
Image size: 4332960
Image MD5: 5BC80451109A8DD7F2DDD35BCE2929A3
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): lxct_device
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: lxct_device
Object name: LocalSystem
Image path: G:\WINDOWS\system32\lxctcoms.exe -service
Image size: 537520
Image MD5: 150CE94577E5DAD674E9E9E7F4617CAE
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1

Service (registry key): Messenger
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Messenger
Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS

Service (registry key): mnmdd
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): mnmsrvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetMeeting Remote Desktop Sharing
Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: G:\WINDOWS\system32\mnmsrvc.exe
Image size: 32768
Image MD5: D18F1F0C101D06A1C1ADF26EED16FCDD
Control Set: CurrentControlSet
Start: 4
Type: 272
Error Control: 1

Service (registry key): Modem
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): Mouclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mouse Class Driver
Image path: system32\DRIVERS\mouclass.sys
Image size: 23040
Image MD5: 35C9E97194C8CFB8430125F8DBC34D04
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): MountMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mount Point Manager
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): MozillaMaintenance
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mozilla Maintenance Service
Description: The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled.
Object name: LocalSystem
Image path: "G:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe"
Image size: 117656
Image MD5: E6DB6C61739E18906DC2C4191F6EDEA2
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): mraid35x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): MRxDAV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebDav Client Redirector
Description: WebDav Client Redirector
Image path: system32\DRIVERS\mrxdav.sys
Image size: 180608
Image MD5: 11D42BB6206F33FBB3BA0288D3EF81BD
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1

Service (registry key): MRxSmb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MRXSMB
Description: MRXSMB
Image path: system32\DRIVERS\mrxsmb.sys
Image size: 456320
Image MD5: 7D304A5EB4344EBEEAB53A2FE3FFB9F0
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): MSDTC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Transaction Coordinator
Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: G:\WINDOWS\system32\msdtc.exe
Image size: 6144
Image MD5: A137F1470499A205ABBB9AAFB3B6F2B1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS,SamSS

Service (registry key): MSDTC Bridge 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): MSDTC Bridge 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Msfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): MSIServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Installer
Description: Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %systemroot%\system32\msiexec.exe /V
Image size: 78848
Image MD5: 5879D691E842574A20FE63817CB76DF9
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): MSKSSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Service Proxy
Image path: system32\drivers\MSKSSRV.sys
Image size: 7552
Image MD5: D1575E71568F4D9E14CA56B7B0453BF1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSPCLOCK
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Clock Proxy
Image path: system32\drivers\MSPCLOCK.sys
Image size: 5376
Image MD5: 325BB26842FC7CCC1FCCE2C457317F3E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSPQM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Quality Manager Proxy
Image path: system32\drivers\MSPQM.sys
Image size: 4992
Image MD5: BAD59648BA099DA4A17680B39730CB3D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSSCNTRS
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): mssmbios
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft System Management BIOS Driver
Image path: system32\DRIVERS\mssmbios.sys
Image size: 15488
Image MD5: AF5F4F3F14A8EA2C26DE30F7A1E17136
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): MSTEE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Tee/Sink-to-Sink Converter
Image path: system32\drivers\MSTEE.sys
Image size: 5504
Image MD5: E53736A9E30C45FA9E7B5EAC55056D1D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Mup
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mup
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): NABTSFEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NABTS/FEC VBI Codec
Image path: system32\DRIVERS\NABTSFEC.sys
Image size: 85248
Image MD5: 5B50F1B2A2ED47D560577B221DA734DB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): napagent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Access Protection Agent
Description: Allows windows clients to participate in Network Access Protection
Object name: localSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): NDIS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS System Driver
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): NdisIP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft TV/Video Connection
Image path: system32\DRIVERS\NdisIP.sys
Image size: 10880
Image MD5: 7FF1F1FD8609C149AA432F95A8163D97
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NdisTapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS TAPI Driver
Description: Remote Access NDIS TAPI Driver
Image path: system32\DRIVERS\ndistapi.sys
Image size: 10496
Image MD5: 0109C4F3850DFBAB279542515386AE22
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Ndisuio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS Usermode I/O Protocol
Description: NDIS Usermode I/O Protocol
Image path: system32\DRIVERS\ndisuio.sys
Image size: 14592
Image MD5: F927A4434C5028758A842943EF1A3849
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NdisWan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS WAN Driver
Description: Remote Access NDIS WAN Driver
Image path: system32\DRIVERS\ndiswan.sys
Image size: 91520
Image MD5: EDC1531A49C80614B2CFDA43CA8659AB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NDProxy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): NetBIOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBIOS Interface
Description: NetBIOS Interface
Image path: system32\DRIVERS\netbios.sys
Image size: 34688
Image MD5: 5D81CF9A2F1A3A756B66CF684911CDF0
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): NetBT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBios over Tcpip
Description: NetBios over Tcpip
Image path: system32\DRIVERS\netbt.sys
Image size: 162816
Image MD5: 74B2B2F5BEA5E9A3DC021D685551BD3D
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: Tcpip

Service (registry key): NetDDE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE
Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: B857BA82860D7FF85AE29B095645563B
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: NetDDEDSDM

Service (registry key): NetDDEdsdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE DSDM
Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: B857BA82860D7FF85AE29B095645563B
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1

Service (registry key): Netlogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Net Logon
Description: Supports pass-through authentication of account logon events for computers in a domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): Netman
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Connections
Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 288
Error Control: 1
Depends On services: RpcSs

Service (registry key): NetTcpPortSharing
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Net.Tcp Port Sharing Service
Description: Provides ability to share TCP ports over the net.tcp protocol.
Object name: NT AUTHORITY\LocalService
Image path: "g:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
Image size: 132096
Image MD5: D34612C5D02D026535B3095D620626AE
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1

Service (registry key): Nla
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Location Awareness (NLA)
Description: Collects and stores network configuration and location information, and notifies applications when this information changes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd

Service (registry key): NMSAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NMSAccess
Description: Allows Non-Admins to use the CDBurnerXP Application
Object name: LocalSystem
Image path: G:\Program Files\CDBurnerXP\NMSAccessU.exe
Image size: 71096
Image MD5: 7AEA4DF1CA68FD45DD4BBE1F0243CE7F
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): NMSAccessU
Registry path: \SYSTEM\CurrentControlSet\Services\
Description: Allows Non-Admins to use the CDBurnerXP Application
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Npfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): Ntfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): NTFSDRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): NtLmSsp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NT LM Security Support Provider
Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): NtmsSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Removable Storage
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): Null
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): NwlnkFlt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Filter Driver
Description: IPX Traffic Filter Driver
Image path: system32\DRIVERS\nwlnkflt.sys
Image size: 12416
Image MD5: B305F3FAD35083837EF46A0BBCE2FC57
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: NwlnkFwd

Service (registry key): NwlnkFwd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Forwarder Driver
Description: IPX Traffic Forwarder Driver
Image path: system32\DRIVERS\nwlnkfwd.sys
Image size: 32512
Image MD5: C99B3415198D1AAB7227F2C88FD664B9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ose
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Office Source Engine
Description: Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.
Object name: LocalSystem
Image path: "G:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Image size: 149352
Image MD5: 9D10F99A6712E28F8ACD5641E3A7EA6B
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): osppsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Office Software Protection Platform
Description: Office Software Protection Platform Service (unlocalized description)
Object name: NT AUTHORITY\NetworkService
Image path: "G:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
Image size: 4640000
Image MD5: 358A9CCA612C68EB2F07DDAD4CE1D8D7
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RpcSs

Service (registry key): Outlook
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Parport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Parallel port driver
Image path: system32\DRIVERS\parport.sys
Image size: 80128
Image MD5: 5575FAF8F97CE5E713D108C2A58D7C7C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): PartMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Partition Manager
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ParVdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0
Depends On services: Parport
Depends On group: "Parallel arbitrator"

Service (registry key): PCI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PCI Bus Driver
Image path: system32\DRIVERS\pci.sys
Image size: 68224
Image MD5: A219903CCF74233761D92BEF471A07B1
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3

Service (registry key): PCIDump
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): PCIIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\pciide.sys
Image size: 3328
Image MD5: CCF5F451BB1A5A2A522A76E670000FF0
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Pcmcia
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): PDCOMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDRELI
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): PDRFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): perc2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): perc2hib
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): PerfDisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfNet
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PerfProc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): PEVSystemStart
Registry path: \SYSTEM\CurrentControlSet\Services\
Object name: LocalSystem
Image path: "G:\ComboFix\pev.3XE" EXEC /i "G:\ComboFix\HIDEC.3XE" "G:\ComboFix\SWREG.3XE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q
Image size: 256000
Image MD5: F042EE4C8D66248D9B86DCF52ABAE416
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 0

Service (registry key): PlugPlay
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Plug and Play
Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 110592
Image MD5: 65DF52F5B8B6E9BBD183505225C37315
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): PolicyAgent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC Services
Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS,Tcpip,IPSec

Service (registry key): PptpMiniport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (PPTP)
Description: WAN Miniport (PPTP)
Image path: system32\DRIVERS\raspptp.sys
Image size: 48384
Image MD5: EFEEC01B1D3CF84F16DDD24D9D9D8F99
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): ProtectedStorage
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Protected Storage
Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 1
Depends On services: RpcSs

Service (registry key): PSched
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: QoS Packet Scheduler
Description: QoS Packet Scheduler
Image path: system32\DRIVERS\psched.sys
Image size: 69120
Image MD5: 09298EC810B07E5D582CB3A3F9255424
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Gpc

Service (registry key): PSMounter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Macrium Reflect Image Explorer Service
Description: Macrium Reflect Image Explorer Service. Allows images and backups to be accessed by Windows Explorer
Image path: \??\G:\WINDOWS\system32\drivers\psmounter.sys
Image size: 45208
Image MD5: E69FED2E51D196A4A5665B9230DE7C45
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): pssnap
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Paramount Software Snapshot Filter
Image path: system32\DRIVERS\pssnap.sys
Image size: 16024
Image MD5: AC7BD82678401A89CC80359806C80364
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): Ptilink
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel Link Driver
Description: Direct Parallel Link Driver
Image path: system32\DRIVERS\ptilink.sys
Image size: 17792
Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): PxHelp20
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PxHelp20
Image path: System32\Drivers\PxHelp20.sys
Image size: 45648
Image MD5: E42E3433DBB4CFFE8FDD91EAB29AEA8E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): ql1080
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): Ql10wnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql12160
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql1240
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): ql1280
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): RasAcd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Driver
Description: Remote Access Auto Connection Driver
Image path: system32\DRIVERS\rasacd.sys
Image size: 8832
Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): RasAuto
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Manager
Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RasMan,Tapisrv

Service (registry key): Rasl2tp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (L2TP)
Description: WAN Miniport (L2TP)
Image path: system32\DRIVERS\rasl2tp.sys
Image size: 51328
Image MD5: 11B4A627BC9614B885C4969BFA5FF8A6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): RasMan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Connection Manager
Description: Creates a network connection.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tapisrv

Service (registry key): RasPppoe
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access PPPOE Driver
Description: Remote Access PPPOE Driver
Image path: system32\DRIVERS\raspppoe.sys
Image size: 41472
Image MD5: 5BC962F2654137C9909C3D4603587DEE
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Raspti
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel
Description: Direct Parallel
Image path: system32\DRIVERS\raspti.sys
Image size: 16512
Image MD5: FDBB1D60066FCFBB7452FD8F9829B242
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Rdbss
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Rdbss
Description: Rdbss
Image path: system32\DRIVERS\rdbss.sys
Image size: 175744
Image MD5: 7AD224AD1A1437FE28D89CF22B17780A
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1

Service (registry key): RDPCDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\DRIVERS\RDPCDD.sys
Image size: 4224
Image MD5: 4912D5B403614CE99C28420F75353332
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): RDPDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): rdpdr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Server Device Redirector Driver
Image path: system32\DRIVERS\rdpdr.sys
Image size: 196224
Image MD5: 15CABD0F7C00C47C70124907916AF3F1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): RDPNP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): RDPWD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): RDSessMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Desktop Help Session Manager
Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box.
Object name: LocalSystem
Image path: G:\WINDOWS\system32\sessmgr.exe
Image size: 141312
Image MD5: 3C37BF86641BDA977C3BF8A840F3B7FA
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): redbook
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Digital CD Audio Playback Filter Driver
Image path: system32\DRIVERS\redbook.sys
Image size: 57600
Image MD5: F828DD7E1419B6653894A8F97A0094C5
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): ReflectService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Macrium Reflect Image Mounting Service
Description: Macrium Reflect Image Mounting Service
Object name: LocalSystem
Image path: "G:\Program Files\Macrium\Reflect\ReflectService.exe"
Image size: 220824
Image MD5: 7A8FD91FD806B1EB1743898DF4C6477A
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): RemoteAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Routing and Remote Access
Description: Offers routing services to businesses in local area and wide area network environments.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RpcSS
Depends On group: NetBIOSGroup

Service (registry key): RemoteRegistry
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Registry
Description: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): Revoflt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Revoflt
Description: Revo Uninstaller Filter driver
Image path: system32\DRIVERS\revoflt.sys
Image size: 27064
Image MD5: 8B5B8A11306190C6963D3473F052D3C8
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1
Depends On services: FltMgr

Service (registry key): RpcLocator
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC) Locator
Description: Manages the RPC name service database.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\locator.exe
Image size: 75264
Image MD5: AAED593F84AFA419BBAE8572AF87CF6A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: LanmanWorkstation

Service (registry key): RpcSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC)
Description: Provides the endpoint mapper and other miscellaneous RPC services.
Object name: NT Authority\NetworkService
Image path: %SystemRoot%\system32\svchost.exe -k rpcss
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): RSVP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: QoS RSVP
Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
Object name: LocalSystem
Image path: %SystemRoot%\system32\rsvp.exe
Image size: 132608
Image MD5: 471B3F9741D762ABE75E9DEEA4787E47
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: TcpIp,Afd,RpcSs

Service (registry key): SamSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Accounts Manager
Description: Stores security information for local user accounts.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: BF2466B3E18E970D8A976FB95FC1CA85
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): SCardSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Smart Card
Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\SCardSvr.exe
Image size: 95744
Image MD5: 86D007E7A654B9A71D1D7D856B104353
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 0
Depends On services: PlugPlay

Service (registry key): Schedule
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Task Scheduler
Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): ScsiPort
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: %SystemRoot%\system32\drivers\scsiport.sys
Image size: 96384
Image MD5: 76C465F570E90C28942D52CCB2580A10
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Secdrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secdrv
Description: SafeDisc driver
Image path: system32\DRIVERS\secdrv.sys
Image size: 20480
Image MD5: 90A3935D05B494A5A39D37E71F09A677
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): seclogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secondary Logon
Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 0

Service (registry key): SENS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Event Notification
Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: EventSystem

Service (registry key): serenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Serenum Filter Driver
Image path: system32\DRIVERS\serenum.sys
Image size: 15744
Image MD5: 0F29512CCD6BEAD730039FB4BD2C85CE
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Serial
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Serial port driver
Image path: system32\DRIVERS\serial.sys
Image size: 64512
Image MD5: CCA207A8896D4C6A0C9CE29A4AE411A7
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): ServiceModelEndpoint 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelEndpoint 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelOperation 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelOperation 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelService 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ServiceModelService 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Sfloppy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Depends On group: "SCSI miniport"

Service (registry key): SharedAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Firewall/Internet Connection Sharing (ICS)
Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Netman,WinMgmt

Service (registry key): ShellHWDetection
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Shell Hardware Detection
Description: Provides notifications for AutoPlay hardware events.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs

Service (registry key): Simbad
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): SLIP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: BDA Slip De-Framer
Image path: system32\DRIVERS\SLIP.sys
Image size: 11136
Image MD5: 866D538EBE33709A5C9F5C62B73B7D14
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SMSvcHost 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): SMSvcHost 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): SMTPSVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Simple Mail Transfer Protocol (SMTP)
Description: Transports electronic mail across the network
Object name: LocalSystem
Image path: G:\WINDOWS\system32\inetsrv\inetinfo.exe
Image size: 15360
Image MD5: DB3C22745C0DA4666F3BE31F1AF36B2F
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: IISADMIN,Eventlog

Service (registry key): smwdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\drivers\smwdm.sys
Image size: 545024
Image MD5: 31FD0707C7DBE715234F2823B27214FE
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SNMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SNMP Service
Description: Includes agents that monitor the activity in network devices and report to the network console workstation.
Object name: LocalSystem
Image path: %SystemRoot%\System32\snmp.exe
Image size: 33280
Image MD5: 60C377BE6B3CC83F6A8584934B181D2E
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: EventLog

Service (registry key): SNMPTRAP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SNMP Trap Service
Description: Receives trap messages generated by local or remote SNMP agents and forwards the messages to SNMP management programs running on this computer.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\snmptrap.exe
Image size: 8704
Image MD5: 80A050795A107A76C2B1CD4CFBE010E6
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: EventLog

Service (registry key): Sparrow
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): splitter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Audio Splitter
Image path: system32\drivers\splitter.sys
Image size: 6272
Image MD5: AB8B92451ECB048A4D1DE7C3FFCB4A9F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): Spooler
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Print Spooler
Description: Loads files to memory for later printing.
Object name: LocalSystem
Image path: %SystemRoot%\system32\spoolsv.exe
Image size: 58880
Image MD5: 60784F891563FB1B767F70117FC2428F
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS

Service (registry key): sp_prot
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Protect Filter Driver
Image path: \??\G:\WINDOWS\system32\drivers\sp_prot.sys
Image size: 12288
Image MD5: A88B18B8926B92A96934E0A06CB77F96
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1
Depends On services: FltMgr

Service (registry key): SP_Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Protect Deletion Prevention Service
Description: System Protect helps keep your operating system stable and protect important programs, documents and files from being deleted by viruses, other users on your computer or even by mistake.
Object name: LocalSystem
Image path: "G:\Program Files\System Protect\SysProtect_srv.exe"
Image size: 598528
Image MD5: A11ECECD00E5B239F337DECCE01116B7
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): sr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Filter Driver
Image path: system32\DRIVERS\sr.sys
Image size: 73472
Image MD5: 76BB022C2FB6902FD5BDD4F78FC13A5D
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1

Service (registry key): srservice
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Service
Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): Srv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Srv
Description: Srv
Image path: system32\DRIVERS\srv.sys
Image size: 357888
Image MD5: 47DDFC2F003F7F9F0592C6874962A2E7
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1

Service (registry key): SSDPSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SSDP Discovery Service
Description: Enables discovery of UPnP devices on your home network.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP

Service (registry key): StarOpen
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1

Service (registry key): StillCam
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Still Serial Digital Camera Driver
Image path: system32\DRIVERS\serscan.sys
Image size: 6784
Image MD5: A9573045BAA16EAB9B1085205B82F1ED
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): stisvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Image Acquisition (WIA)
Description: Provides image acquisition services for scanners and cameras.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k imgsvc
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): streamip
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: BDA IPSink
Image path: system32\DRIVERS\StreamIP.sys
Image size: 15232
Image MD5: 77813007BA6265C4B6098187E6ED79D2
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): swenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Software Bus Driver
Image path: system32\DRIVERS\swenum.sys
Image size: 4352
Image MD5: 3941D127AEF12E93ADDF6FE6EE027E0F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): swmidi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel GS Wavetable Synthesizer
Image path: system32\drivers\swmidi.sys
Image size: 56576
Image MD5: 8CE882BCC6CF8A62F2B2323D95CB3D01
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SwPrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MS Software Shadow Copy Provider
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: G:\WINDOWS\system32\dllhost.exe /Processid:{21E76FE8-946C-40EA-BF2B-D0CA6277F875}
Image size: 5120
Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Depends On services: rpcss

Service (registry key): swwd
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): symc810
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): symc8xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): sym_hi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): sym_u3
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): sysaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel System Audio Device
Image path: system32\drivers\sysaudio.sys
Image size: 60800
Image MD5: 8B83F3ED0F1688B4958F77CD6D2BF290
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): SysmonLog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Performance Logs and Alerts
Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT Authority\NetworkService
Image path: %SystemRoot%\system32\smlogsvc.exe
Image size: 89600
Image MD5: C7ABBC59B43274B1109DF6B24D617051
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): TapiSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telephony
Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs

Service (registry key): Tcpip
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP Protocol Driver
Description: TCP/IP Protocol Driver
Image path: system32\DRIVERS\tcpip.sys
Image size: 361600
Image MD5: 9AEFA14BD6B182D61E3119FA5F436D3D
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: IPSec

Service (registry key): TDPIPE
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): TDTCP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): TermDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Device Driver
Image path: system32\DRIVERS\termdd.sys
Image size: 40840
Image MD5: 88155247177638048422893737429D9E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): TermService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Services
Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k DComLaunch
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RPCSS

Service (registry key): Themes
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Themes
Description: Provides user experience theme management.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): TlntSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telnet
Description: Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: G:\WINDOWS\system32\tlntsvr.exe
Image size: 73216
Image MD5: DB7205804759FF62C34E3EFD8A4CC76A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS,TCPIP,NTLMSSP

Service (registry key): TosIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): TrkWks
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Link Tracking Client
Description: Maintains links between NTFS files within a computer or across computers in a network domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): TSDDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Udfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1

Service (registry key): UGatherer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): UGTHRSVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): ultra
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): UMVPFSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Description: UMVPF is a user mode Logitech driver
Object name: LocalSystem
Image path: G:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
Image size: 450848
Image MD5: 67A95B9D129ED5399E7965CD09CF30E7
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1

Service (registry key): upnphost
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Universal Plug and Play Device Host
Description: Provides support to host Universal Plug and Play devices.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: SSDPSRV,HTTP

Service (registry key): UPS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Uninterruptible Power Supply
Description: Manages an uninterruptible power supply (UPS) connected to the computer.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\ups.exe
Image size: 18432
Image MD5: 05365FB38FCA1E98F7A566AAAF5D1815
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): USBAAPL
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Apple Mobile USB Driver
Image path: System32\Drivers\usbaapl.sys
Image size: 43520
Image MD5: EAFE1E00739AFE6C51487A050E772E17
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Audio Driver (WDM)
Image path: system32\drivers\usbaudio.sys
Image size: 60032
Image MD5: E919708DB44ED8543A7C017953148330
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbccgp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Generic Parent Driver
Image path: system32\DRIVERS\usbccgp.sys
Image size: 32128
Image MD5: 173F317CE0DB8E21322E71B7E60A27E8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbehci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
Image path: system32\DRIVERS\usbehci.sys
Image size: 30208
Image MD5: 65DCF09D0E37D4C6B11B5B0B76D470A7
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbhub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB2 Enabled Hub
Image path: system32\DRIVERS\usbhub.sys
Image size: 59520
Image MD5: 1AB3CDDE553B6E064D2E754EFE20285C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbprint
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB PRINTER Class
Image path: system32\DRIVERS\usbprint.sys
Image size: 25856
Image MD5: A717C8721046828520C9EDF31288FC00
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbscan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Scanner Driver
Image path: system32\DRIVERS\usbscan.sys
Image size: 15104
Image MD5: A0B8CF9DEB1184FBDD20784A58FA75D4
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbstor
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Mass Storage Driver
Image path: system32\DRIVERS\USBSTOR.SYS
Image size: 26368
Image MD5: A32426D9B14A089EAA1D922E0C5801A9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbuhci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Universal Host Controller Miniport Driver
Image path: system32\DRIVERS\usbuhci.sys
Image size: 20608
Image MD5: 26496F9DEE2D787FC3E61AD54821FFE6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): usbvideo
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Video Device (WDM)
Image path: System32\Drivers\usbvideo.sys
Image size: 121984
Image MD5: 63BBFCA7F390F4C49ED4B96BFB1633E0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): VgaSave
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: VGA Display Controller.
Description: Controls the VGA display adapter to provide basic display capabilities.
Image path: \SystemRoot\System32\drivers\vga.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0

Service (registry key): ViaIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1

Service (registry key): VolSnap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1

Service (registry key): VSS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Shadow Copy
Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\vssvc.exe
Image size: 289792
Image MD5: 7A9DB3A67C333BF0BD42E42B8596854B
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): W32Time
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Time
Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): W3SVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: World Wide Web Publishing
Description: Provides Web connectivity and administration through the Internet Information Services snap-in
Object name: LocalSystem
Image path: %SystemRoot%\system32\inetsrv\inetinfo.exe
Image size: 15360
Image MD5: DB3C22745C0DA4666F3BE31F1AF36B2F
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: IISADMIN

Service (registry key): Wanarp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access IP ARP Driver
Description: Remote Access IP ARP Driver
Image path: system32\DRIVERS\wanarp.sys
Image size: 34560
Image MD5: E20B95BAEDB550F32DD489265C1DA1F6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WDICA
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0

Service (registry key): wdmaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft WINMM WDM Audio Compatibility Driver
Image path: system32\drivers\wdmaud.sys
Image size: 83072
Image MD5: 6768ACF64B18196494413695F0C3A00F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WebClient
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebClient
Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: MRxDAV

Service (registry key): Windows Workflow Foundation 3.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): Windows Workflow Foundation 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): winmgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation
Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RPCSS

Service (registry key): Winsock
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 4
Error Control: 1

Service (registry key): WinSock2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WinTrust
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WmdmPmSN
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Portable Media Serial Number Service
Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): Wmi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation Driver Extensions
Description: Provides systems management information to and from drivers.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1

Service (registry key): WmiApRpl
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WmiApSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WMI Performance Adapter
Description: Provides performance library information from WMI HiPerf providers.
Object name: LocalSystem
Image path: G:\WINDOWS\system32\wbem\wmiapsrv.exe
Image size: 126464
Image MD5: E0673F1106E62A68D2257E376079F821
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS

Service (registry key): WMPNetworkSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Media Player Network Sharing Service
Description: Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
Object name: NT AUTHORITY\NetworkService
Image path: "G:\Program Files\Windows Media Player\WMPNetwk.exe"
Image size: 913408
Image MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: upnphost,http,HTTPFilter

Service (registry key): WPFFontCache_v0400
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Presentation Foundation Font Cache 4.0.0.0
Description: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
Object name: NT AUTHORITY\LocalService
Image path: G:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
Image size: 754856
Image MD5: B800EEC15851597405784126C407188C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1

Service (registry key): WS2IFSL
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Socket 2.0 Non-IFS Service Provider Support Environment
Image path: \SystemRoot\System32\drivers\ws2ifsl.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1

Service (registry key): wscsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Center
Description: Monitors system security settings and configurations.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,winmgmt

Service (registry key): WSearch
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Search
Description: Provides content indexing and property caching for file, email and other content (via extensibility APIs). The service responds to file and email notifications to index modified content. If the service is stopped or disabled, the Explorer will not be able to display virtual folder views of items, and search in the Explorer will fall back to item-by-item slow search.
Object name: LocalSystem
Image path: %systemroot%\system32\SearchIndexer.exe /Embedding
Image size: 439808
Image MD5: 7778BDFA3F6F6FBA0E75B9594098F737
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: TermService

Service (registry key): WSearchIdxPi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): WSTCODEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: World Standard Teletext Codec
Image path: system32\DRIVERS\WSTCODEC.SYS
Image size: 19200
Image MD5: C98B39829C2BBD34E454150633C62C78
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): wuauserv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Automatic Updates
Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1

Service (registry key): WudfPf
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver
Description: Provide communciation services for UMDF components.
Image path: system32\DRIVERS\WudfPf.sys
Image size: 77568
Image MD5: F15FEAFFFBB3644CCC80C5DA584E6311
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WudfRd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Reflector
Description: Reflect device requests to user-mode driver drivers
Image path: system32\DRIVERS\wudfrd.sys
Image size: 82944
Image MD5: 28B524262BCE6DE1F7EF9F510BA3985B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1

Service (registry key): WudfSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework
Description: Manages user-mode driver host processes
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: PlugPlay

Service (registry key): WZCSVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wireless Zero Configuration
Description: Provides automatic configuration for the 802.11 adapters
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,Ndisuio

Service (registry key): xmlprov
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Provisioning Service
Description: Manages XML configuration files on a domain basis for automatic network provisioning.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs

Service (registry key): {665C15FA-82B0-48E8-86A0-9E1CBD56CD45}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0

Service (registry key): {D324D9CA-CA59-482C-ACF1-952D35364848}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Just for the heck of it, I tried downloading Combofix from the other link just to see if that might work. But, it didn't. I tried using it regular mode and in safe mode.
Skip that.


Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.
Great. Thanks. I downloaded the FRST and ran the scan(and it actually scanned) and here are the results for FRST and Addition…..

FRST scan results ………….

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-08-2013
Ran by [removed] (administrator) on 19-08-2013 07:46:17
Running from G:\Documents and Settings\[removed]\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 7
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Logitech Inc.) G:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(ArcSoft Inc.) G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) G:\WINDOWS\system32\inetsrv\inetinfo.exe
( ) G:\WINDOWS\system32\lxctcoms.exe
() G:\Program Files\CDBurnerXP\NMSAccessU.exe
() G:\Program Files\Macrium\Reflect\ReflectService.exe
(Microsoft Corporation) G:\WINDOWS\System32\snmp.exe
(Xacti Corporation) G:\Program Files\System Protect\SysProtect_srv.exe
(Microsoft Corporation) G:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) G:\WINDOWS\system32\wscntfy.exe
(Intel Corporation) G:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) G:\WINDOWS\system32\hkcmd.exe
(ArcSoft Inc.) G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Xacti Corporation) G:\Program Files\System Protect\SysProtect_Tray.exe
(W3i, LLC) G:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
(Siber Systems) G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [Lexmark 5400 Series Fax Server] - G:\Program Files\Lexmark 5400 Series\fm3032.exe [304048 2007-03-19] ()
HKLM\…\Run: [Conime] - G:\Windows\system32\conime.exe [27648 2008-04-13] (Microsoft Corporation)
HKLM\…\Run: [ArcSoft Connection Service] - G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\…\Run: [LXCTCATS] - G:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll [106496 2006-11-21] (Lexmark International Inc.)
HKLM\…\Run: [SystemProtect] - G:\Program Files\System Protect\SysProtect_Tray.exe [1223680 2010-06-05] (Xacti Corporation)
HKLM\…\Run: [Adobe ARM] - G:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: igfxsrvc.dll (Intel Corporation)
HKCU\…\Run: [OnlineVault] - G:\Program Files\Online Vault\OnlineVault.exe [2459136 2010-05-28] (Xacti Corporation)
HKCU\…\Run: [MSMSGS] - G:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-13] (Microsoft Corporation)
HKCU\…\Run: [InstallIQUpdater] - G:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe [1179648 2011-10-11] (W3i, LLC)
HKCU\…\Run: [RoboForm] - G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [109784 2013-06-26] (Siber Systems)
Startup: G:\Documents and Settings\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> G:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: G:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ZooskMessenger.lnk
ShortcutTarget: ZooskMessenger.lnk -> G:\Program Files\ZooskMessenger\ZooskMessenger.exe (No File)
BootExecute: autocheck autochk *

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT3247201
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60347
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM - {09971cee-01b8-42bc-9d91-456b1faad6be} URL = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
SearchScopes: HKCU - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3247201
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKCU - {09971cee-01b8-42bc-9d91-456b1faad6be} URL = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3247201
BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - G:\Program Files\Lexmark Toolbar\toolband.dll ()
BHO: No Name - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - No File
BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - G:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: RoboForm Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - G:\PROGRA~1\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
Toolbar: HKLM - Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - G:\Program Files\Lexmark Toolbar\toolband.dll ()
Toolbar: HKCU -No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
Toolbar: HKCU -Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - G:\Program Files\Lexmark Toolbar\toolband.dll ()
Toolbar: HKCU -&RoboForm; Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - G:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - G:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog5 04 G:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default
FF user.js: detected! => G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\user.js
FF NewTab: about:blank
FF Homepage: hxxp://search.conduit.com/?ctid=CT3247201&SearchSource;=13&CUI;=SB_CUI
FF Keyword.URL: hxxp://websearch.shopathome.com?user_id={fc7a4f8b-ce1a-4b33-820b-dbd6b1768029}&q;=
FF Plugin: @adobe.com/FlashPlayer - G:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - G:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - G:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - G:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin - G:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - G:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - g:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - G:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - G:\PROGRA~1\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - g:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.0 - G:\Program Files\VideoLAN\VLC\npvlc.dll No File
FF Plugin: Adobe Reader - G:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @yahoo.com/BrowserPlus,version=2.9.8 - G:\Documents and Settings\Administrator\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF SearchPlugin: G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\searchplugins\internethelper15-customized-web-search.xml
FF SearchPlugin: G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\searchplugins\web-search.xml
FF SearchPlugin: G:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml
FF Extension: No Name - G:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\btpersonas@brandthunder(2).com
FF Extension: United States English Spellchecker - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\[removed]
FF Extension: No Name - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\nostmp
FF Extension: ShopAtHome.com Toolbar - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\[removed]
FF Extension: Microsoft .NET Framework Assistant - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: Yahoo! Toolbar - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF Extension: abb - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\[removed]
FF Extension: amznUWL2 - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\[removed]
FF Extension: amznUWL - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\[removed]
FF Extension: firefox - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\[removed]
FF Extension: info - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\[removed]
FF Extension: No Name - G:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\avpujchl.default\Extensions\{891f0410-aaa2-11e0-9f1c-0800200c9a66}.xpi
FF Extension: Default - G:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] g:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - g:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] G:\Program Files\Siber Systems\AI RoboForm\Firefox
FF Extension: RoboForm Toolbar for Firefox - G:\Program Files\Siber Systems\AI RoboForm\Firefox

Chrome:
=======
CHR HomePage: http:\/\/search.conduit.com\/?ctid=CT3247201&SearchSource;=48
CHR RestoreOnStartup: "http:\/\/search.conduit.com\/?ctid=CT3247201&SearchSource;=48"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - G:\Program Files\Google\Chrome\Application\23.0.1271.95\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - G:\Program Files\Google\Chrome\Application\23.0.1271.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - G:\Program Files\Google\Chrome\Application\23.0.1271.95\pdf.dll No File
CHR Plugin: (ActiveTouch General Plugin Container) - G:\Documents and Settings\Administrator\Application Data\Mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
CHR Plugin: (Adobe Acrobat) - G:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - G:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll (Coupons, Inc.)
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - G:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll (Coupons, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - G:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - G:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - G:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - G:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - G:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - G:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - G:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft\u00AE DRM) - G:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - G:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft\u00AE DRM) - G:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (BrowserPlus (from Yahoo!) v2.9.8) - G:\Documents and Settings\Administrator\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
CHR Plugin: (Microsoft Office 2010) - G:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - G:\PROGRA~1\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (MindSpark Toolbar Platform Plugin Stub) - G:\Program Files\CouponAlert_2p\bar\1.bin\NP2pStub.dll No File
CHR Plugin: (DivX Web Player) - G:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Update) - G:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java™ Platform SE 7 U9) - G:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (MindSpark Toolbar Platform Plugin Stub) - G:\Program Files\MyScrapNook_12\bar\1.bin\NP12Stub.dll No File
CHR Plugin: (iTunes Application Detector) - G:\Program Files\iTunes\Mozilla Plugins\npitunes.dll No File
CHR Plugin: (Shockwave for Director) - G:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll No File
CHR Plugin: (Shockwave Flash) - G:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - G:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - g:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - g:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (YouTube) - G:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - G:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (InternetHelper1.5) - G:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\fgkbmedckhcibhkdhaokebnllokeokek\10.13.20.29_0
CHR Extension: (InfoAtoms) - G:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\hhbgpoakplhahbklhkcfbpicgjcaoglk\1.4.0.0_0
CHR Extension: (Gmail) - G:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\…\Chrome\Extension: [fgkbmedckhcibhkdhaokebnllokeokek] - G:\Documents and Settings\Administrator\Local Settings\Application Data\CRE\fgkbmedckhcibhkdhaokebnllokeokek.crx

========================== Services (Whitelisted) =================

R2 ACDaemon; G:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S3 DfSdkS; G:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe [406016 2009-08-24] (mst software GmbH, Germany)
R2 IISADMIN; G:\WINDOWS\system32\inetsrv\inetinfo.exe [15360 2008-04-13] (Microsoft Corporation)
R2 lxct_device; G:\WINDOWS\system32\lxctcoms.exe [537520 2007-03-19] ( )
R2 NMSAccess; G:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
R2 ReflectService; G:\Program Files\Macrium\Reflect\ReflectService.exe [220824 2011-07-01] ()
R2 SMTPSVC; G:\WINDOWS\system32\inetsrv\inetinfo.exe [15360 2008-04-13] (Microsoft Corporation)
R2 SP_Service; G:\Program Files\System Protect\SysProtect_srv.exe [598528 2010-06-05] (Xacti Corporation)
R2 UMVPFSrv; G:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
R2 W3SVC; G:\Windows\system32\inetsrv\inetinfo.exe [15360 2008-04-13] (Microsoft Corporation)
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]

==================== Drivers (Whitelisted) ====================

R3 Afc; G:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 cpudrv; G:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2009-12-18] ()
R3 E1000; G:\Windows\System32\DRIVERS\e1000325.sys [163840 2005-06-29] (Intel Corporation)
R3 ialm; G:\Windows\System32\DRIVERS\ialmnt5.sys [807804 2006-05-25] (Intel Corporation)
S3 NdisIP; G:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 PSMounter; G:\WINDOWS\system32\drivers\psmounter.sys [45208 2011-07-01] (Macrium Software)
R0 pssnap; G:\Windows\System32\DRIVERS\pssnap.sys [16024 2011-07-01] (Macrium Software)
R3 sp_prot; G:\WINDOWS\system32\drivers\sp_prot.sys [12288 2010-06-05] ()
S3 StarOpen; G:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] ()
S3 catchme; \??\G:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-19 07:37 - 2013-08-19 07:37 - 01069895 _____ (Farbar) G:\Documents and Settings\Administrator\Desktop\FRST.exe
2013-08-17 04:18 - 2013-08-17 14:23 - 00000000 ____D G:\Program Files\Mozilla Firefox
2013-08-16 10:59 - 2013-08-17 10:00 - 00000000 __SDC G:\ComboFix
2013-08-16 10:58 - 2013-08-16 10:58 - 05104782 ____R (Swearware) G:\Documents and Settings\Administrator\Desktop\ComboFix.exe
2013-08-16 10:31 - 2013-08-16 10:31 - 00312851 _____ G:\Documents and Settings\Administrator\My Documents\SpybotSD.Results.txt 8-16-13.txt
2013-08-16 01:07 - 2013-08-19 07:41 - 00363565 ____N G:\WINDOWS\WindowsUpdate.log
2013-08-16 01:07 - 2013-08-19 07:40 - 00000312 ____N G:\WINDOWS\wiaservc.log
2013-08-16 01:07 - 2013-08-19 07:40 - 00000159 ____N G:\WINDOWS\wiadebug.log
2013-08-16 01:07 - 2013-08-16 01:07 - 00000000 ____N G:\WINDOWS\Sti_Trace.log
2013-08-16 00:37 - 2011-06-26 02:45 - 00256000 _____ G:\WINDOWS\PEV.exe
2013-08-16 00:37 - 2010-11-07 13:20 - 00208896 _____ G:\WINDOWS\MBR.exe
2013-08-16 00:37 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) G:\WINDOWS\NIRCMD.exe
2013-08-16 00:37 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) G:\WINDOWS\SWREG.exe
2013-08-16 00:37 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) G:\WINDOWS\SWSC.exe
2013-08-16 00:37 - 2000-08-30 20:00 - 00212480 _____ (SteelWerX) G:\WINDOWS\SWXCACLS.exe
2013-08-16 00:37 - 2000-08-30 20:00 - 00098816 _____ G:\WINDOWS\sed.exe
2013-08-16 00:37 - 2000-08-30 20:00 - 00080412 _____ G:\WINDOWS\grep.exe
2013-08-16 00:37 - 2000-08-30 20:00 - 00068096 _____ G:\WINDOWS\zip.exe
2013-08-14 05:05 - 2013-08-14 05:06 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 05:04 - 2013-08-14 05:04 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 05:04 - 2013-08-14 05:04 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 05:03 - 2013-08-14 05:03 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2849470$
2013-08-14 02:36 - 2013-08-14 02:39 - 00000000 ___DC G:\Qoobox
2013-08-13 20:39 - 2013-08-13 20:39 - 00688779 ____R (Swearware) G:\Documents and Settings\Administrator\Desktop\dds.pif
2013-08-13 20:39 - 2013-08-13 20:39 - 00000000 ___HD G:\WINDOWS\PIF
2013-08-13 00:25 - 2013-08-13 00:25 - 00011968 _____ G:\Documents and Settings\Administrator\Desktop\hijackthis.log
2013-08-12 21:58 - 2013-08-12 21:58 - 00388608 _____ (Trend Micro Inc.) G:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
2013-08-12 19:36 - 2013-08-12 19:36 - 00000000 ____D G:\Program Files\Common Files\Adobe AIR
2013-08-12 19:36 - 2013-08-12 19:36 - 00000000 ____D G:\Documents and Settings\Default User\Application Data\Macromedia
2013-08-12 03:02 - 2013-08-12 03:16 - 00004585 _____ G:\Documents and Settings\Administrator\My Documents\ville fsecure virus.txt
2013-08-09 05:05 - 2013-08-13 05:04 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2491683$
2013-08-09 02:42 - 2013-08-12 19:35 - 00000000 ____D G:\Program Files\7-Zip
2013-08-09 02:36 - 2013-08-09 02:36 - 00000000 _____ G:\Documents and Settings\Administrator\EXE
2013-08-08 18:39 - 2013-08-08 18:39 - 04837752 _____ (F-Secure Corporation) G:\Documents and Settings\Administrator\My Documents\F-SecureOnlineScanner.exe
2013-08-08 10:29 - 2013-08-12 19:36 - 00000000 ___DC G:\WINDOWS\$NtUninstallKB926139-v2$
2013-08-08 10:29 - 2013-08-08 11:09 - 00065536 _____ G:\WINDOWS\system32\config\WindowsPowerShell.evt
2013-08-08 10:29 - 2013-08-08 10:29 - 00000000 ____D G:\WINDOWS\system32\windowspowershell
2013-08-08 10:00 - 2013-08-08 10:00 - 00000000 ____D G:\Documents and Settings\Administrator\Application Data\DriverCure
2013-07-24 10:05 - 2013-07-24 10:05 - 00398408 _____ G:\Documents and Settings\Administrator\Desktop\VzSpeedOptimizer100.exe
2013-07-24 05:03 - 2013-08-14 05:21 - 00000000 ____D G:\WINDOWS\system32\MRT

==================== One Month Modified Files and Folders =======

2013-08-19 07:44 - 2010-06-04 20:06 - 00000000 ____D G:\WINDOWS\system32\inetsrv
2013-08-19 07:43 - 2010-06-05 00:40 - 00000000 ____D G:\Documents and Settings\Administrator
2013-08-19 07:42 - 2013-05-07 22:20 - 00000000 __SHD G:\Documents and Settings\Administrator\UserData
2013-08-19 07:41 - 2013-08-16 01:07 - 00363565 ____N G:\WINDOWS\WindowsUpdate.log
2013-08-19 07:40 - 2013-08-16 01:07 - 00000312 ____N G:\WINDOWS\wiaservc.log
2013-08-19 07:40 - 2013-08-16 01:07 - 00000159 ____N G:\WINDOWS\wiadebug.log
2013-08-19 07:40 - 2010-06-12 18:55 - 00000000 ____D G:\Program Files\lx_cats
2013-08-19 07:40 - 2010-06-06 01:35 - 00000274 ____C G:\WINDOWS\Tasks\WGASetup.job
2013-08-19 07:40 - 2010-06-05 00:39 - 00000006 ___HC G:\WINDOWS\Tasks\SA.DAT
2013-08-19 07:37 - 2013-08-19 07:37 - 01069895 _____ (Farbar) G:\Documents and Settings\Administrator\Desktop\FRST.exe
2013-08-19 07:09 - 2013-06-17 21:44 - 00000830 ____C G:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-19 05:06 - 2010-06-24 19:34 - 00000000 ____D G:\WINDOWS\Microsoft.NET
2013-08-19 01:37 - 2010-06-05 00:32 - 00000000 ____D G:\WINDOWS\Registration
2013-08-18 17:09 - 2011-02-13 11:22 - 00032466 ____N G:\WINDOWS\SchedLgU.Txt
2013-08-18 03:25 - 2012-05-14 07:09 - 00000000 ____D G:\Program Files\Mozilla Maintenance Service
2013-08-17 14:23 - 2013-08-17 04:18 - 00000000 ____D G:\Program Files\Mozilla Firefox
2013-08-17 10:00 - 2013-08-16 10:59 - 00000000 __SDC G:\ComboFix
2013-08-17 09:58 - 2010-08-23 03:35 - 00000000 ____D G:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2013-08-16 15:57 - 2011-02-07 12:48 - 00000000 ____D G:\Program Files\QuickTime
2013-08-16 15:55 - 2011-02-07 12:48 - 00000000 ____D G:\Documents and Settings\All Users\Application Data\Apple Computer
2013-08-16 15:54 - 2012-11-12 12:30 - 00000000 ____D G:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-08-16 15:53 - 2011-11-16 01:05 - 00000000 ____D G:\Program Files\Common Files\Apple
2013-08-16 10:58 - 2013-08-16 10:58 - 05104782 ____R (Swearware) G:\Documents and Settings\Administrator\Desktop\ComboFix.exe
2013-08-16 10:57 - 2011-07-17 03:22 - 00000000 __SHD G:\WINDOWS\CSC
2013-08-16 10:31 - 2013-08-16 10:31 - 00312851 _____ G:\Documents and Settings\Administrator\My Documents\SpybotSD.Results.txt 8-16-13.txt
2013-08-16 01:07 - 2013-08-16 01:07 - 00000000 ____N G:\WINDOWS\Sti_Trace.log
2013-08-16 00:23 - 2010-06-05 00:40 - 00000178 __SHC G:\Documents and Settings\Administrator\ntuser.ini
2013-08-16 00:22 - 2011-07-17 01:35 - 00000000 ____D G:\Documents and Settings\All Users\Application Data\F-Secure
2013-08-14 05:21 - 2013-07-24 05:03 - 00000000 ____D G:\WINDOWS\system32\MRT
2013-08-14 05:14 - 2010-06-06 01:48 - 75778376 ____C (Microsoft Corporation) G:\WINDOWS\system32\MRT.exe
2013-08-14 05:08 - 2010-06-04 20:14 - 00691634 ____C G:\WINDOWS\system32\PerfStringBackup.INI
2013-08-14 05:06 - 2013-08-14 05:05 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 05:04 - 2013-08-14 05:04 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 05:04 - 2013-08-14 05:04 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 05:04 - 2010-06-06 01:49 - 00024400 ____C G:\WINDOWS\system32\TZLog.log
2013-08-14 05:03 - 2013-08-14 05:03 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2849470$
2013-08-14 05:01 - 2010-06-06 02:20 - 00000000 ____D G:\WINDOWS\ie7updates
2013-08-14 02:39 - 2013-08-14 02:36 - 00000000 ___DC G:\Qoobox
2013-08-14 02:35 - 2010-08-29 00:19 - 00000000 ____D G:\WINDOWS\ERDNT
2013-08-13 21:56 - 2004-08-12 04:34 - 00013646 ____C G:\WINDOWS\system32\wpa.dbl
2013-08-13 20:39 - 2013-08-13 20:39 - 00688779 ____R (Swearware) G:\Documents and Settings\Administrator\Desktop\dds.pif
2013-08-13 20:39 - 2013-08-13 20:39 - 00000000 ___HD G:\WINDOWS\PIF
2013-08-13 05:04 - 2013-08-09 05:05 - 00000000 __HDC G:\WINDOWS\$NtUninstallKB2491683$
2013-08-13 00:25 - 2013-08-13 00:25 - 00011968 _____ G:\Documents and Settings\Administrator\Desktop\hijackthis.log
2013-08-12 21:58 - 2013-08-12 21:58 - 00388608 _____ (Trend Micro Inc.) G:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
2013-08-12 19:38 - 2010-06-05 00:39 - 00000000 __SHD G:\Documents and Settings\NetworkService
2013-08-12 19:38 - 2010-06-05 00:39 - 00000000 __SHD G:\Documents and Settings\LocalService
2013-08-12 19:36 - 2013-08-12 19:36 - 00000000 ____D G:\Program Files\Common Files\Adobe AIR
2013-08-12 19:36 - 2013-08-12 19:36 - 00000000 ____D G:\Documents and Settings\Default User\Application Data\Macromedia
2013-08-12 19:36 - 2013-08-08 10:29 - 00000000 ___DC G:\WINDOWS\$NtUninstallKB926139-v2$
2013-08-12 19:35 - 2013-08-09 02:42 - 00000000 ____D G:\Program Files\7-Zip
2013-08-12 19:35 - 2011-08-27 09:17 - 00000000 ____D G:\Documents and Settings\All Users\Application Data\boost_interprocess
2013-08-12 19:33 - 2010-06-10 02:43 - 00000000 ____D G:\Program Files\Adobe
2013-08-12 03:16 - 2013-08-12 03:02 - 00004585 _____ G:\Documents and Settings\Administrator\My Documents\ville fsecure virus.txt
2013-08-09 02:36 - 2013-08-09 02:36 - 00000000 _____ G:\Documents and Settings\Administrator\EXE
2013-08-08 20:11 - 2010-06-06 01:02 - 00000000 ___HD G:\WINDOWS\$hf_mig$
2013-08-08 18:39 - 2013-08-08 18:39 - 04837752 _____ (F-Secure Corporation) G:\Documents and Settings\Administrator\My Documents\F-SecureOnlineScanner.exe
2013-08-08 17:56 - 2010-06-12 02:16 - 00000000 ____D G:\WINDOWS\system32\NtmsData
2013-08-08 11:09 - 2013-08-08 10:29 - 00065536 _____ G:\WINDOWS\system32\config\WindowsPowerShell.evt
2013-08-08 10:29 - 2013-08-08 10:29 - 00000000 ____D G:\WINDOWS\system32\windowspowershell
2013-08-08 10:00 - 2013-08-08 10:00 - 00000000 ____D G:\Documents and Settings\Administrator\Application Data\DriverCure
2013-08-08 09:26 - 2010-06-10 02:41 - 00000000 ____D G:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe
2013-08-08 07:00 - 2011-04-22 00:57 - 00000000 ____D G:\Documents and Settings\Administrator\My Documents\Affiliate Marketing Folder
2013-08-08 06:26 - 2010-06-04 20:06 - 00000000 ____D G:\WINDOWS\security
2013-08-08 00:59 - 2012-10-15 02:07 - 00000000 ____D G:\Program Files\Common Files\LogiShrd
2013-08-08 00:56 - 2012-10-15 02:09 - 00000000 ____D G:\Program Files\Common Files\LWS
2013-08-08 00:54 - 2010-06-20 04:37 - 00000000 ____D G:\Program Files\Ashampoo
2013-08-08 00:03 - 2010-12-13 04:11 - 00000000 ____D G:\Documents and Settings\All Users\Application Data\Microsoft Help
2013-08-07 23:17 - 2011-12-16 18:23 - 00000000 ____D G:\Program Files\Google
2013-07-26 16:40 - 2010-10-29 11:07 - 00000682 ____C G:\Documents and Settings\All Users\Desktop\CCleaner.lnk
2013-07-26 16:40 - 2010-06-21 02:26 - 00000000 ____D G:\Program Files\CCleaner
2013-07-25 14:08 - 2010-06-06 02:20 - 01172992 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\urlmon.dll
2013-07-25 14:08 - 2010-06-06 02:20 - 00841216 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\wininet.dll
2013-07-25 14:08 - 2010-06-06 02:20 - 00233472 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\webcheck.dll
2013-07-25 14:08 - 2010-06-05 00:33 - 00766464 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\vgx.dll
2013-07-25 14:08 - 2004-08-12 04:33 - 00841216 _____ (Microsoft Corporation) G:\WINDOWS\system32\wininet.dll
2013-07-25 14:08 - 2004-08-12 04:33 - 00233472 _____ (Microsoft Corporation) G:\WINDOWS\system32\webcheck.dll
2013-07-25 14:08 - 2004-08-12 04:31 - 01172992 _____ (Microsoft Corporation) G:\WINDOWS\system32\urlmon.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 06108672 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\ieframe.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 01830912 ____N (Microsoft Corporation) G:\WINDOWS\system32\inetcpl.cpl
2013-07-25 14:07 - 2010-06-06 02:20 - 01830912 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\inetcpl.cpl
2013-07-25 14:07 - 2010-06-06 02:20 - 00671232 ____N (Microsoft Corporation) G:\WINDOWS\system32\mstime.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00671232 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\mstime.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00496128 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\msfeeds.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00268288 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\iertutil.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00193024 ____N (Microsoft Corporation) G:\WINDOWS\system32\msrating.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00193024 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\msrating.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00106496 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\url.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00102912 ____N (Microsoft Corporation) G:\WINDOWS\system32\occache.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00102912 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\occache.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00052224 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\msfeedsbs.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00044544 ____N (Microsoft Corporation) G:\WINDOWS\system32\iernonce.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00044544 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\pngfilt.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00044544 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\iernonce.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00044544 _____ (Microsoft Corporation) G:\WINDOWS\system32\pngfilt.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00028160 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\jsproxy.dll
2013-07-25 14:07 - 2010-06-06 02:20 - 00028160 _____ (Microsoft Corporation) G:\WINDOWS\system32\jsproxy.dll
2013-07-25 14:07 - 2007-08-13 18:54 - 06108672 _____ (Microsoft Corporation) G:\WINDOWS\system32\ieframe.dll
2013-07-25 14:07 - 2007-08-13 18:54 - 00496128 _____ (Microsoft Corporation) G:\WINDOWS\system32\msfeeds.dll
2013-07-25 14:07 - 2007-08-13 18:54 - 00052224 _____ (Microsoft Corporation) G:\WINDOWS\system32\msfeedsbs.dll
2013-07-25 14:07 - 2007-08-13 18:34 - 00268288 _____ (Microsoft Corporation) G:\WINDOWS\system32\iertutil.dll
2013-07-25 14:07 - 2004-08-12 04:31 - 00106496 _____ (Microsoft Corporation) G:\WINDOWS\system32\url.dll
2013-07-25 14:07 - 2004-08-12 04:23 - 03626496 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\mshtml.dll
2013-07-25 14:07 - 2004-08-12 04:23 - 03626496 _____ (Microsoft Corporation) G:\WINDOWS\system32\mshtml.dll
2013-07-25 14:07 - 2004-08-12 04:23 - 00480256 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\mshtmled.dll
2013-07-25 14:07 - 2004-08-12 04:23 - 00480256 _____ (Microsoft Corporation) G:\WINDOWS\system32\mshtmled.dll
2013-07-25 14:07 - 2004-08-12 04:19 - 00193024 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\iepeers.dll
2013-07-25 14:07 - 2004-08-12 04:19 - 00193024 _____ (Microsoft Corporation) G:\WINDOWS\system32\iepeers.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00388608 ____N (Microsoft Corporation) G:\WINDOWS\system32\iedkcs32.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00388608 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\iedkcs32.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00380928 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\ieapfltr.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00230400 ____N (Microsoft Corporation) G:\WINDOWS\system32\ieaksie.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00230400 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\ieaksie.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00153088 ____N (Microsoft Corporation) G:\WINDOWS\system32\ieakeng.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00153088 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\ieakeng.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00132608 ____N (Microsoft Corporation) G:\WINDOWS\system32\extmgr.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00132608 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\extmgr.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00078336 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\ieencode.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00078336 _____ (Microsoft Corporation) G:\WINDOWS\system32\ieencode.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00063488 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\icardie.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00017408 ____N (Microsoft Corporation) G:\WINDOWS\system32\corpol.dll
2013-07-25 14:06 - 2010-06-06 02:20 - 00017408 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\corpol.dll
2013-07-25 14:06 - 2007-08-13 18:36 - 00063488 _____ (Microsoft Corporation) G:\WINDOWS\system32\icardie.dll
2013-07-25 14:06 - 2007-07-11 12:27 - 00380928 _____ (Microsoft Corporation) G:\WINDOWS\system32\ieapfltr.dll
2013-07-25 14:06 - 2004-08-12 04:18 - 00347136 ____N (Microsoft Corporation) G:\WINDOWS\system32\dxtmsft.dll
2013-07-25 14:06 - 2004-08-12 04:18 - 00347136 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\dxtmsft.dll
2013-07-25 14:06 - 2004-08-12 04:18 - 00214528 ____N (Microsoft Corporation) G:\WINDOWS\system32\dxtrans.dll
2013-07-25 14:06 - 2004-08-12 04:18 - 00214528 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\dxtrans.dll
2013-07-25 14:06 - 2004-08-12 04:17 - 00124928 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\advpack.dll
2013-07-25 14:06 - 2004-08-12 04:17 - 00124928 _____ (Microsoft Corporation) G:\WINDOWS\system32\advpack.dll
2013-07-25 13:12 - 2010-06-06 02:20 - 00070656 ____N (Microsoft Corporation) G:\WINDOWS\system32\ie4uinit.exe
2013-07-25 13:12 - 2010-06-06 02:20 - 00070656 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\ie4uinit.exe
2013-07-25 13:12 - 2010-06-06 02:20 - 00013824 ____N (Microsoft Corporation) G:\WINDOWS\system32\ieudinit.exe
2013-07-25 13:12 - 2010-06-06 02:20 - 00013824 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\ieudinit.exe
2013-07-25 13:08 - 2010-06-05 00:33 - 00643224 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\iexplore.exe
2013-07-25 13:07 - 2010-06-06 02:20 - 00161792 ____N (Microsoft Corporation) G:\WINDOWS\system32\ieakui.dll
2013-07-25 13:07 - 2010-06-06 02:20 - 00161792 ____C (Microsoft Corporation) G:\WINDOWS\system32\dllcache\ieakui.dll
2013-07-24 10:05 - 2013-07-24 10:05 - 00398408 _____ G:\Documents and Settings\Administrator\Desktop\VzSpeedOptimizer100.exe

==================== Bamital & volsnap Check =================

G:\Windows\explorer.exe => MD5 is legit
G:\Windows\System32\winlogon.exe => MD5 is legit
G:\Windows\System32\svchost.exe => MD5 is legit
G:\Windows\System32\services.exe => MD5 is legit
G:\Windows\System32\User32.dll => MD5 is legit
G:\Windows\System32\userinit.exe => MD5 is legit
G:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================

And this is the Addition…………….

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-08-2013
Ran by [removed] at 2013-08-19 07:47:24
Running from G:\Documents and Settings\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Acrobat.com (Version: 2.1.0)
Acrobat.com (Version: 2.1.0.0)
Adobe AIR (Version: 3.5.0.600)
Adobe Flash Player 11 Plugin (Version: 11.7.700.224)
Adobe Reader XI (11.0.03) (Version: 11.0.03)
Adobe Shockwave Player 12.0 (Version: 12.0.2.122)
ArcSoft MediaImpression 2 (Version: 2.0.27.836)
Ashampoo WinOptimizer 2010 Advanced (Version: 6.5.0)
Bonjour (Version: 3.0.0.10)
CCleaner (Version: 4.04)
Coupon Printer for Windows (Version: 5.0.0.0)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
ESET Online Scanner v3
GoToMeeting 5.4.0.1082 (HKCU Version: 5.4.0.1082)
InstallIQ Updater (Version: 1.4.3.0)
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Connections Drivers
Java 7 Update 25 (Version: 7.0.250)
Java Auto Updater (Version: 2.1.9.5)
Lexmark 5400 Series
Lexmark Toolbar
Macrium Reflect - Free Edition (Version: 4.2.3775)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Multi-Targeting Pack (Version: 4.0.30319)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Help Viewer 1.0 (Version: 1.0.30319)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.4734.1000)
Microsoft Office Professional 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.4734.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.4734.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.4734.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.4734.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.4734.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Picture It! Publishing 2001 (Version: 5.0.0.0000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Software Update for Web Folders (English) 14 (Version: 14.0.4734.1000)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (Version: 10.0.30319)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Windows Performance Toolkit (Version: 4.8.0)
Microsoft Windows SDK .NET Framework Tools (30514) (Version: 7.1.30514)
Microsoft Windows SDK for Visual Studio .NET 4.0 Framework Tools (Version: 7.1.30514)
Microsoft Windows SDK for Windows 7 (7.1) (Version: 7.1.30514)
Microsoft Windows SDK for Windows 7 (7.1) (Version: 7.1.7600.0.30514)
Microsoft Windows SDK for Windows 7 Common Utilities (30514) (Version: 7.1.30514)
Microsoft Windows SDK for Windows 7 Headers and Libraries (30514) (Version: 7.1.30514)
Microsoft Windows SDK for Windows 7 Samples (30514) (Version: 7.1.30514)
Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514) (Version: 7.1.30514)
Microsoft Windows SDK Intellisense and Reference Assemblies (30514) (Version: 7.1.30514)
Microsoft Windows SDK MSHelp (30514) (Version: 7.1.30514)
Microsoft Windows SDK Net Fx Interop Headers And Libraries (30514) (Version: 7.1.30514)
Mozilla Firefox 23.0.1 (x86 en-US) (Version: 23.0.1)
Mozilla Maintenance Service (Version: 23.0.1)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 6.0 Parser (Version: 6.10.1129.0)
Online Vault (Version: 1.0.0.61)
OpenOffice.org 3.3 (Version: 3.3.9567)
PreReq (Version: 6.2.2.60)
Revo Uninstaller Pro 2.5.9 (Version: 2.5.9)
RoboForm 7-9-0-0 (All Users) (Version: 7-9-0-0)
SoundMAX
Spybot - Search & Destroy (Version: 1.6.2)
swMSM (Version: 12.0.0.1)
System Protect (Version: 1.0.0.83)
System Requirements Lab for Intel (Version: 4.1.66.0)
TC Web Conferencing (Version: 7.89)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
Update for Windows Internet Explorer 7 (KB980182) (Version: 1)
Update for Windows XP (KB2141007) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2467659) (Version: 1)
Update for Windows XP (KB2541763) (Version: 1)
Update for Windows XP (KB2661254-v2) (Version: 2)
Update for Windows XP (KB2736233) (Version: 1)
Update for Windows XP (KB2749655) (Version: 1)
Update for Windows XP (KB2863058) (Version: 1)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
Update for Windows XP (KB980182) (Version: 1)
VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0)
WebEx
WebFldrs XP (Version: 9.50.7523)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Internet Explorer 7 (Version: 20070813.185237)
Windows Media Format 11 runtime
Windows Media Player 11
Windows SDK IntellisenseNFX (Version: 7.1.30514)
Windows Search 4.0 (Version: 04.00.6001.503)
Windows XP Service Pack 3 (Version: 20080414.031525)
WinRAR archiver
Yahoo! BrowserPlus 2.9.8


==================== Restore Points =========================

08-08-2013 10:23:11 Removed iTunes
08-08-2013 10:32:15 Software Distribution Service 3.0
08-08-2013 11:08:19 Revo Uninstaller Pro's restore point - QuickTime
08-08-2013 11:19:16 Removed QuickTime
08-08-2013 11:52:18 Software Distribution Service 3.0
08-08-2013 12:19:33 Software Distribution Service 3.0
08-08-2013 12:42:58 Software Distribution Service 3.0
08-08-2013 14:29:45 Installed %1 %2.
08-08-2013 15:06:26 Software Distribution Service 3.0
08-08-2013 21:31:40 Software Distribution Service 3.0
08-08-2013 21:46:28 Software Distribution Service 3.0
09-08-2013 09:00:23 Software Distribution Service 3.0
10-08-2013 00:57:04 Restore Operation
10-08-2013 01:04:45 Software Distribution Service 3.0
10-08-2013 01:25:10 Removed QuickTime
10-08-2013 09:00:20 Software Distribution Service 3.0
11-08-2013 09:00:29 Software Distribution Service 3.0
12-08-2013 09:00:21 Software Distribution Service 3.0
12-08-2013 21:33:02 Software Distribution Service 3.0
12-08-2013 23:29:12 Restore Operation
12-08-2013 23:41:24 Software Distribution Service 3.0
13-08-2013 09:00:21 Software Distribution Service 3.0
14-08-2013 09:00:29 Software Distribution Service 3.0
15-08-2013 06:07:08 Software Distribution Service 3.0
15-08-2013 09:00:17 Software Distribution Service 3.0
16-08-2013 09:00:16 Software Distribution Service 3.0
16-08-2013 19:52:39 Removed iTunes
16-08-2013 19:55:29 Revo Uninstaller Pro's restore point - QuickTime
16-08-2013 19:55:48 Removed QuickTime
17-08-2013 06:36:32 Software Distribution Service 3.0
17-08-2013 09:00:16 Software Distribution Service 3.0
18-08-2013 09:00:16 Software Distribution Service 3.0
19-08-2013 09:00:23 Software Distribution Service 3.0

==================== Hosts content: ==========================

2004-08-12 04:19 - 2011-09-21 06:25 - 00436898 ___RC G:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

Task: G:\WINDOWS\Tasks\Adobe Flash Player Updater.job => G:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: G:\WINDOWS\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job => G:\Program Files\Spybot - Search & Destroy\SDUpdate.exe
Task: G:\WINDOWS\Tasks\WGASetup.job => G:\WINDOWS\system32\KB905474\wgasetup.exe

==================== Faulty Device Manager Devices =============

Name: Microcode Update Device
Description: Microcode Update Device
Class Guid: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Manufacturer: (Standard system devices)
Service: update
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/18/2013 09:51:01 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (08/18/2013 03:30:13 AM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (08/16/2013 01:07:33 AM) (Source: Windows Search Service) (User: )
Description: The application cannot be initialized.

Context: Windows Application


Details:
The content index metadata cannot be read. (0xc0041801)

Error: (08/16/2013 01:07:33 AM) (Source: Windows Search Service) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
The content index metadata cannot be read. (0xc0041801)

Error: (08/16/2013 01:07:33 AM) (Source: Windows Search Service) (User: )
Description: The plug-in in cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
Element not found. (0x80070490)

Error: (08/16/2013 01:07:32 AM) (Source: Windows Search Service) (User: )
Description: The plug-in in cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
The content index metadata cannot be read. (0xc0041801)

Error: (08/16/2013 01:07:32 AM) (Source: Windows Search Service) (User: )
Description: The Windows Search Service cannot load the property store information.

Context: Windows Application, SystemIndex Catalog


Details:
0x%08x (0x8004117f - The content index server cannot update or access information because of a database error. Stop and restart the search service. If the problem persists, reset and recrawl the content index. In some cases it may be necessary to delete and recreate the content index. )

Error: (08/16/2013 01:07:32 AM) (Source: Windows Search Service) (User: )
Description: The Windows Search Service cannot open the Jet property store.


Details:
0x%08x (0x8004117f - The content index server cannot update or access information because of a database error. Stop and restart the search service. If the problem persists, reset and recrawl the content index. In some cases it may be necessary to delete and recreate the content index. )

Error: (08/16/2013 00:17:04 AM) (Source: F-Secure Anti-Virus) (User: )
Description: 1 2013-08-16 00:17:04-04:00 P-071A7C4D21704\Administrator F-Secure Anti-Virus
Crash detected.
\Device\HarddiskVolume1\Documents and Settings\Administrator\Local Settings\temp\pft29.tmp\UninstallationTool.exe

Error: (08/15/2013 11:34:48 PM) (Source: Windows Search Service) (User: )
Description: The entry in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)


System errors:
=============
Error: (08/19/2013 01:37:27 AM) (Source: Service Control Manager) (User: )
Description: The COM+ System Application service terminated unexpectedly. It has done this 3 time(s).

Error: (08/19/2013 01:37:13 AM) (Source: Service Control Manager) (User: )
Description: The COM+ System Application service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.

Error: (08/19/2013 01:36:55 AM) (Source: Service Control Manager) (User: )
Description: The COM+ System Application service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.

Error: (08/17/2013 09:57:36 AM) (Source: Service Control Manager) (User: )
Description: The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).

Error: (08/16/2013 04:13:23 PM) (Source: Service Control Manager) (User: )
Description: The SNMP Service service terminated unexpectedly. It has done this 1 time(s).

Error: (08/16/2013 03:38:00 PM) (Source: Service Control Manager) (User: )
Description: The System Protect Deletion Prevention Service service terminated unexpectedly. It has done this 1 time(s).

Error: (08/16/2013 03:37:53 PM) (Source: Service Control Manager) (User: )
Description: The SNMP Service service terminated unexpectedly. It has done this 1 time(s).

Error: (08/16/2013 11:00:37 AM) (Source: Service Control Manager) (User: )
Description: The World Wide Web Publishing service terminated unexpectedly. It has done this 1 time(s).

Error: (08/16/2013 11:00:37 AM) (Source: Service Control Manager) (User: )
Description: The Simple Mail Transfer Protocol (SMTP) service terminated unexpectedly. It has done this 1 time(s).

Error: (08/16/2013 11:00:36 AM) (Source: Service Control Manager) (User: )
Description: The IIS Admin service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1 milliseconds: Run the configured recovery program.


Microsoft Office Sessions:
=========================
Error: (12/15/2010 03:34:16 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: 2Microsoft Office Access12.0.4518.101412.0.4518.101421391800


==================== Memory info ===========================

Percentage of memory in use: 38%
Total physical RAM: 1021.98 MB
Available physical RAM: 632.95 MB
Total Pagefile: 2464.69 MB
Available Pagefile: 2229.88 MB
Total Virtual: 2047.88 MB
Available Virtual: 1951.47 MB

==================== Drives ================================

Drive d: (Windows XP SP3 C) (CDROM) (Total:0.59 GB) (Free:0 GB) CDFS
Drive g: () (Fixed) (Total:104.01 GB) (Free:77.06 GB) NTFS ==>[Drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 466 GB) (Disk ID: 69205244)
Partition 1: (Active) - (Size=104 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=812 GB) - (Type=72)
Partition 3: (Not Active) - (Size=259 GB) - (Type=74)

==================== End Of Log ============================

Thanks so much again for all your help! I'm just sorry that I couldn't get anything to work right before.
Thanks again!
I'm not going to go over what has already been done.


Lets start all over.


First:

Potentially Unwanted Programs (PUPs)

You will need to modify your MBAM settings, if you haven't already, and want them checked for removal. By default it will scan them but will not mark them for removal.

Please open Malwarebytes.
Click the Settings Tab
Click the Scanner Settings Tab
Change the Action for (PUP) and (PUM) to Show in results list and check for removal

Run a new scan and remove whatever is found.

Attach the scan results in your next reply.

Next:


Please download AdwCleaner and save it on your Desktop.
Note: Be sure to select Save as Type > All Types

http://general-changelog-team.fr/en/downlo…de/2-adwcleaner


Double click on AdwCleaner.exe to run the tool.
Click on Scan.
A logfile will automatically open after the scan has finished. Please attach that log in your reply.
You can find the logfile at C:\AdwCleaner\AdwCleaner[Rn].txt ('n' is the scan order number).

Please attach both logs
Thank you very much for your help! I keep trying to run the Malwarebytes scan but it keeps going into sleep mode after about a minute of running the scan. When it goes into sleep mode, it won't come out. I have to shut my computer down and restart it and hope to be able to get back to my desktop. A lot of times when I restart it will go into sleep mode before I can get back to my desktop. So, I have to shut down and start all over again. I've been trying to run the Malwarebytes scan(with the changed scan settings) all of last night and all of today, with no luck of getting it to run all the way through because of it going into sleep mode. I've also tried running the scan in safe mode but the same thing happens, it goes into sleep mode and won't come out. I'm not sure what to do. I will keep trying and I will try the other scan too but I'm not sure they are going to work. Do you happen to have any suggestions? Thanks again!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI