calvin_hobbes
Topic Starter
Hope you can help :-)
HJT log (after reboot)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:53 PM, on 12/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\MCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\SvcLncher.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Suss.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\TEMP\XZ8E65.EXE
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\Program Files\OfficeScan NT\TmPfw.exe
C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\svchost.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\stsystra.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\WINNT\system32\WLTRAY.exe
C:\WINNT\system32\taskswitch.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINNT\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINNT\Managed\MCDesk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interwise\Participant\pull.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINNT\system32\HPZinw12.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://inside.nokiasiemensnetworks.com/global/search.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://inside.nokiasiemensnetworks.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by NSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://nsnproxy.rt.nsn-intra.net/proxy.pac
F2 - REG:system.ini: UserInit=c:\winnt\system32\userinit.exe
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Copernic Desktop Search - Home - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand300000081.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinZip Quick Pick] C:\Program Files\WinZip\WZQKPICK.EXE
O4 - HKLM\..\Run: [ServicesSynchronizationUtility] "C:\Program Files\Siemens\Services Synchronization Utility\vbs.exe" SyncServices.vbe r "C:\" "C:\WINNT\" "C:\WINNT\system32\" "\\nsn-intra.net\dfsres\s_lw\global\etc\"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINNT\system32\WLTRAY.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINNT\system32\taskswitch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MCDesk] %MgmtFolder%\MCDesk.exe %MgmtFolder%\MCDesk.ini
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy; - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Edit with Altova X&MLSpy; - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy; - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://inside.nokiasiemensnetworks.com
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: *.placeware.com
O15 - Trusted Zone: *.sap-ag.de
O15 - Trusted Zone: *.sap.com
O15 - Trusted Zone: http://communication-market1.siemens.de
O15 - Trusted Zone: http://icm-km.erlm.siemens.de
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de
O15 - Trusted Zone: http://ikuddq.icn.siemens.it
O15 - Trusted Zone: virtualtrainingroom.vodafone.com
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: *.placeware.com (HKLM)
O15 - Trusted Zone: *.sap-ag.de (HKLM)
O15 - Trusted Zone: *.sap.com (HKLM)
O15 - Trusted Zone: http://communication-market1.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://ikuddq.icn.siemens.it (HKLM)
O15 - Trusted Zone: virtualtrainingroom.vodafone.com (HKLM)
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webattend.com/components/wt0523.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218817069823
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components) - https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
O16 - DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} (Xerox_Services_Portal.XrxPrinter_Inst) - https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\Software\..\Telephony: DomainName = nsn-intra.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nsn-intra.net
O20 - AppInit_DLLs: cdmcvw.dll
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: eBOSS Helper (eBOSS) - Nortel Networks - (no file)
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\IP VPN Remote Services\Extranet_serv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: HTTP Poster Service (HTTP Poster) - Nokia - C:\WINNT\system32\HTTP_Poster.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Managed Client Service (MCsvc) - © 2005 - 2008 Siemens AG - C:\WINNT\System32\MCSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Service Launcher - SIS GO GIO DS PSU6 - C:\WINNT\system32\SvcLncher.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScanNT Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmProxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINNT\System32\WLTRYSVC.EXE
–
End of file - 16457 bytes
Spybot Log (after reboot)
— Search result list —
Hint of the Day: Click the bar at the right of this to see more information! ()
Smitfraud-C.: [SBI $99619F8C] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\instkey
Microsoft.Windows.ActiveDesktop: [SBI $B6472C30] User settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoAddingComponents
Microsoft.Windows.ActiveDesktop: [SBI $B6472C30] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoAddingComponents
Microsoft.Windows.ActiveDesktop: [SBI $B6472C30] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoAddingComponents
Microsoft.Windows.ActiveDesktop: [SBI $76BCFD1C] User settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoDeletingComponents
Microsoft.Windows.ActiveDesktop: [SBI $76BCFD1C] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoDeletingComponents
Microsoft.Windows.ActiveDesktop: [SBI $76BCFD1C] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoDeletingComponents
Microsoft.Windows.ActiveDesktop: [SBI $5C7BE05C] User settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoEditingComponents
Microsoft.Windows.ActiveDesktop: [SBI $5C7BE05C] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoEditingComponents
Microsoft.Windows.ActiveDesktop: [SBI $5C7BE05C] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoEditingComponents
Microsoft.Windows.ActiveDesktop: [SBI $C565A534] User settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoClosingComponents
Microsoft.Windows.ActiveDesktop: [SBI $C565A534] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoClosingComponents
Microsoft.Windows.ActiveDesktop: [SBI $C565A534] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoClosingComponents
Microsoft.Windows.Explorer: [SBI $1931FF4D] Settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges
Microsoft.Windows.Explorer: [SBI $1931FF4D] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges
Microsoft.Windows.Explorer: [SBI $1931FF4D] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges
Microsoft.Windows.disableSystemRestore: [SBI $1645D19C] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig
Microsoft.Windows.disableSystemRestore: [SBI $6296EC95] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableSR
Virtumonde: [SBI $8F2A4A7E] Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Virtumonde.generic: [SBI $1BB1339D] Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Virtumonde.generic: [SBI $2F10E03B] Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Virtumonde: [SBI $4D2BC948] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim
Virtumonde: [SBI $779C9C0D] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP
Virtumonde: [SBI $FD08B4B7] Configuration file (File, nothing done)
C:\WINNT\system32\VGfLmnpo.ini2
Virtumonde: [SBI $2A2DCEAC] Configuration file (File, nothing done)
C:\WINNT\system32\VGfLmnpo.ini
Virtumonde.prx: [SBI $3F5CA9DA] Autorun settings (d0dcc578) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d0dcc578
Virtumonde.prx: [SBI $3F5CA9DA] Program file (File, nothing done)
C:\WINNT\system32\ytflnqpf.dll
Win32.Agent.amyy: [SBI $DC8955FA] Program directory (Directory, nothing done)
C:\Documents and Settings\vm092543\Application Data\gadcom\
— Spybot - Search & Destroy version: 1.6.0 (build: 20080707) —
2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe ([removed])
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe ([removed])
2008-07-07 SDUpdate.exe ([removed])
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe ([removed])
2008-09-16 TeaTimer.exe ([removed])
2008-09-25 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-10-22 advcheck.dll ([removed])
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2008-11-04 Includes\Adware.sbi (*)
2008-11-25 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-09-02 Includes\Dialer.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-11-18 Includes\Hijackers.sbi (*)
2008-11-18 Includes\HijackersC.sbi (*)
2008-09-09 Includes\Keyloggers.sbi (*)
2008-11-18 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-11-18 Includes\Malware.sbi (*)
2008-12-03 Includes\MalwareC.sbi (*)
2008-11-03 Includes\PUPS.sbi (*)
2008-12-02 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-12-02 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-11-04 Includes\Spyware.sbi (*)
2008-12-02 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-11-04 Includes\Trojans.sbi (*)
2008-12-02 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
— System information —
Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB928367)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Service Pack 3 (KB867461)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ Microsoft .NET Framework 2.0: This Security Update is for Microsoft .NET Framework 2.0. \n
If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
For more information, visit http://support.microsoft.com/kb/917283
/ Microsoft .NET Framework 2.0: This Security Update is for Microsoft .NET Framework 2.0. \n
If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
For more information, visit http://support.microsoft.com/kb/922770
/ Microsoft .NET Framework 2.0: This Security Update is for Microsoft .NET Framework 2.0. \n
If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
For more information, visit http://support.microsoft.com/kb/928365
/ MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
/ Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB890937
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Windows XP Hotfix - KB892050
/ Windows XP / SP3: Hotfix for Windows XP (KB893357)
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Hotfix for Windows XP (KB896256)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Update for Windows XP (KB896427)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Update for Windows XP (KB897663)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901190)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Update for Windows XP (KB908531)
/ Windows XP / SP3: Hotfix for Windows XP (KB909095)
/ Windows XP / SP3: Update for Windows XP (KB911280)
/ Windows XP / SP3: Security Update for Windows XP (KB911562)
/ Windows XP / SP3: Security Update for Windows XP (KB911927)
/ Windows XP / SP3: Hotfix for Windows XP (KB912761)
/ Windows XP / SP3: Security Update for Windows XP (KB913580)
/ Windows XP / SP3: Security Update for Windows XP (KB914388)
/ Windows XP / SP3: Security Update for Windows XP (KB914389)
/ Windows XP / SP3: Hotfix for Windows XP (KB916191)
/ Windows XP / SP3: Hotfix for Windows XP (KB917021)
/ Windows XP / SP3: Security Update for Windows XP (KB917344)
/ Windows XP / SP3: Security Update for Windows XP (KB917953)
/ Windows XP / SP3: Security Update for Windows XP (KB918118)
/ Windows XP / SP3: Security Update for Windows XP (KB918439)
/ Windows XP / SP3: Security Update for Windows XP (KB919007)
/ Windows XP / SP3: Security Update for Windows XP (KB920213)
/ Windows XP / SP3: Security Update for Windows XP (KB920670)
/ Windows XP / SP3: Security Update for Windows XP (KB920683)
/ Windows XP / SP3: Security Update for Windows XP (KB920685)
/ Windows XP / SP3: Security Update for Windows XP (KB921503)
/ Windows XP / SP3: Security Update for Windows XP (KB922819)
/ Windows XP / SP3: Security Update for Windows XP (KB923191)
/ Windows XP / SP3: Security Update for Windows XP (KB923414)
/ Windows XP / SP3: Security Update for Windows XP (KB923980)
/ Windows XP / SP3: Security Update for Windows XP (KB924191)
/ Windows XP / SP3: Security Update for Windows XP (KB924270)
/ Windows XP / SP3: Security Update for Windows XP (KB924496)
/ Windows XP / SP3: Security Update for Windows XP (KB924667)
/ Windows XP / SP3: Security Update for Windows XP (KB925902)
/ Windows XP / SP3: Hotfix for Windows XP (KB926239)
/ Windows XP / SP3: Security Update for Windows XP (KB926255)
/ Windows XP / SP3: Security Update for Windows XP (KB926436)
/ Windows XP / SP3: Security Update for Windows XP (KB927779)
/ Windows XP / SP3: Security Update for Windows XP (KB927802)
/ Windows XP / SP3: Security Update for Windows XP (KB928255)
/ Windows XP / SP3: Security Update for Windows XP (KB928843)
/ Windows XP / SP3: Security Update for Windows XP (KB929123)
/ Windows XP / SP3: Security Update for Windows XP (KB929969)
/ Windows XP / SP3: Security Update for Windows XP (KB930178)
/ Windows XP / SP3: Security Update for Windows XP (KB931261)
/ Windows XP / SP3: Security Update for Windows XP (KB931784)
/ Windows XP / SP3: Update for Windows XP (KB931836)
/ Windows XP / SP3: Security Update for Windows XP (KB932168)
/ Windows XP / SP3: Hotfix for Windows XP (KB933062)
/ Windows XP / SP3: Update for Windows XP (KB933360)
/ Windows XP / SP3: Security Update for Windows XP (KB933566)
/ Windows XP / SP3: Security Update for Windows XP (KB933729)
/ Windows XP / SP3: Hotfix for Windows XP (KB935448)
/ Windows XP / SP3: Security Update for Windows XP (KB935839)
/ Windows XP / SP3: Security Update for Windows XP (KB935840)
/ Windows XP / SP3: Security Update for Windows XP (KB936021)
/ Windows XP / SP3: Security Update for Windows XP (KB937894)
/ Windows XP / SP3: Security Update for Windows XP (KB938127)
/ Windows XP / SP3: Security Update for Windows XP (KB938829)
/ Windows XP / SP3: Hotfix for Windows XP (KB939273)
/ Windows XP / SP3: Security Update for Windows XP (KB941202)
/ Windows XP / SP3: Security Update for Windows XP (KB941568)
/ Windows XP / SP3: Security Update for Windows XP (KB941693)
/ Windows XP / SP3: Security Update for Windows XP (KB942615)
/ Windows XP / SP3: Security Update for Windows XP (KB943055)
/ Windows XP / SP3: Security Update for Windows XP (KB943460)
/ Windows XP / SP3: Security Update for Windows XP (KB943485)
/ Windows XP / SP3: Security Update for Windows XP (KB944338-v2)
/ Windows XP / SP3: Security Update for Windows XP (KB944653)
/ Windows XP / SP3: Security Update for Windows XP (KB945553)
/ Windows XP / SP3: Security Update for Windows XP (KB946026)
/ Windows XP / SP3: Security Update for Windows XP (KB948590)
/ Windows XP / SP3: Security Update for Windows XP (KB950749)
/ Windows XP / SP4: Security Update for Windows XP (KB938464)
/ Windows XP / SP4: Security Update for Windows XP (KB946648)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Update for Windows XP (KB951072-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951698)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB953838)
/ Windows XP / SP4: Security Update for Windows XP (KB954211)
/ Windows XP / SP4: Security Update for Windows XP (KB955069)
/ Windows XP / SP4: Security Update for Windows XP (KB956390)
/ Windows XP / SP4: Security Update for Windows XP (KB956391)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB956841)
/ Windows XP / SP4: Security Update for Windows XP (KB957095)
/ Windows XP / SP4: Security Update for Windows XP (KB957097)
/ Windows XP / SP4: Security Update for Windows XP (KB958644)
— Startup entries list —
Located: HK_LM:Run, AccessManager
command: C:\Program Files\AccessManager\Client\AccessMgr.exe
file: C:\Program Files\AccessManager\Client\AccessMgr.exe
size: 786432
MD5: E00A56C2B8ABF31C433EBE9EAD54EEAE
Located: HK_LM:Run, Acrobat Assistant 8.0
command: "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
file: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
size: 620152
MD5: A21E70B4F972CA396A80013D0D436350
Located: HK_LM:Run, Apoint
command: C:\Program Files\DellTPad\Apoint.exe
file: C:\Program Files\DellTPad\Apoint.exe
size: 159744
MD5: 5EF24621ABCE6965E32A365CA613A544
Located: HK_LM:Run, Broadcom Wireless Manager UI
command: C:\WINNT\system32\WLTRAY.exe
file: C:\WINNT\system32\WLTRAY.exe
size: 1392640
MD5: 17CEC1CB41C5580DBE20984FC73BC4F4
Located: HK_LM:Run, CoolSwitch
command: C:\WINNT\system32\taskswitch.exe
file: C:\WINNT\system32\taskswitch.exe
size: 45632
MD5: EBD2EA535FC47D426D0C2FC7C7293534
Located: HK_LM:Run, d0dcc578
command: rundll32.exe "C:\WINNT\system32\ytflnqpf.dll",b
file: C:\WINNT\system32\ytflnqpf.dll
size: 72704
MD5: 1FC555C50D0092F36D76636A0F84D1FE
Located: HK_LM:Run, HotKeysCmds
command: C:\WINNT\system32\hkcmd.exe
file: C:\WINNT\system32\hkcmd.exe
size: 162584
MD5: 48ED49A40D09A6CF258E8BF398B9CF79
Located: HK_LM:Run, IgfxTray
command: C:\WINNT\system32\igfxtray.exe
file: C:\WINNT\system32\igfxtray.exe
size: 138008
MD5: 16219958FA5A3948C983D821C669F7A6
Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 267048
MD5: 04A9F0C58B170F30445BCC0683EF9FFC
Located: HK_LM:Run, KernelFaultCheck
command: %systemroot%\system32\dumprep 0 -k
file: C:\WINNT\system32\dumprep 0 -k
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, MCDesk
command: %MgmtFolder%\MCDesk.exe %MgmtFolder%\MCDesk.ini
file: C:\WINNT\Managed\MCDesk.exe
size: 53248
MD5: 89DA9CF9227744A7A6C0D582AED94EA5
Located: HK_LM:Run, OfficeScanNT Monitor
command: "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
file: C:\Program Files\OfficeScan NT\pccntmon.exe
size: 714024
MD5: 71056AD9643BA2DCEBB1A5E49A2F4070
Located: HK_LM:Run, Persistence
command: C:\WINNT\system32\igfxpers.exe
file: C:\WINNT\system32\igfxpers.exe
size: 138008
MD5: B922482FA05828762EA1FD8D24D3AD62
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\QTTask.exe" -atboottime
file: C:\Program Files\QuickTime\QTTask.exe
size: 413696
MD5: 6DF76965A0FB8237E9C3B3CAB9815EC2
Located: HK_LM:Run, ServicesSynchronizationUtility
command: "C:\Program Files\Siemens\Services Synchronization Utility\vbs.exe" SyncServices.vbe r "C:\" "C:\WINNT\" "C:\WINNT\system32\" "\\nsn-intra.net\dfsres\s_lw\global\etc\"
file: C:\Program Files\Siemens\Services Synchronization Utility\vbs.exe
size: 20480
MD5: 2E807FF6F78DA11CEDBC4916BF70CFCA
Located: HK_LM:Run, SigmatelSysTrayApp
command: stsystra.exe
file: C:\WINNT\stsystra.exe
size: 303104
MD5: 34F44FE583D16815AD848855E7618E0D
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre6\bin\jusched.exe"
file: C:\Program Files\Java\jre6\bin\jusched.exe
size: 136600
MD5: AB68B7C232293F6B09E5C29CB31AE76D
Located: HK_LM:Run, Synchronization Manager
command: mobsync.exe /logon
file: C:\WINNT\system32\mobsync.exe
size: 143360
MD5: 5531C63F05C7D041F7DA9F8B7D88F00E
Located: HK_LM:Run, WinZip Quick Pick
command: C:\Program Files\WinZip\WZQKPICK.EXE
file: C:\Program Files\WinZip\WZQKPICK.EXE
size: 106560
MD5: 2FE253973433442C2CB234FB2BC4BF29
Located: HK_CU:Run, Nokia.PCSync
where: .DEFAULT…
command: "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog
file: C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, AdobeUpdater
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
file: C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
size: 2321600
MD5: CEBB4703FE0A875947E5F0A3A95FE577
Located: HK_CU:Run, Copernic Desktop Search - Home
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
file: C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
size: 1698816
MD5: 950F6A67AE3FBB1DA12842D0927F6035
Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: C:\WINNT\system32\ctfmon.exe
file: C:\WINNT\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8
Located: HK_CU:Run, Google Update
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
file: C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
size: 133104
MD5: 626A24ED1228580B9518C01930936DF9
Located: HK_CU:Run, Nokia.PCSync
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
file: C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
size: 1249280
MD5: 457C3DD5F4655EB0F1A564110319B9D0
Located: HK_CU:Run, PC Suite Tray
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: "C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe" -onlytray
file: C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe
size: 1124352
MD5: 67576EBBAD86E5F92B327A9F83443628
Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: C:\Program Files\Spybot\TeaTimer.exe
file: C:\Program Files\Spybot\TeaTimer.exe
size: 1833296
MD5: 63B3FF83B87AFCEBA89CED54695DA0F6
Located: HK_CU:Run, Nokia.PCSync
where: S-1-5-18…
command: "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog
file: C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: Startup (common), Adobe Acrobat Speed Launcher.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\WINNT\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe
file: C:\WINNT\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe
size: 295606
MD5: 21638D0E7F02D6CB855B76243521F409
Located: Startup (common), Adobe Acrobat Synchronizer.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
file: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
size: 734872
MD5: 169C293CE9460A05646D17DC6AA2FB2C
Located: Startup (common), Adobe Reader - Schnellstart.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
size: 29696
MD5: 43362B96870CE8649F4F2EC893DA93F0
Located: Startup (common), Bluetooth Manager.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
file: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
size: 2150400
MD5: E8DD777F7AA93648894574CC418B0624
Located: Startup (common), Digital Line Detect.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\Digital Line Detect\DLG.exe
file: C:\Program Files\Digital Line Detect\DLG.exe
size: 50688
MD5: F03FFC962E18F36A922E61F96BE09925
Located: Startup (common), HP Digital Imaging Monitor.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
file: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
size: 288472
MD5: 4543367E50BD35E7D1269D42841B156E
Located: Startup (common), Push Client.LNK
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\interwise\Participant\pull.exe
file: C:\Program Files\interwise\Participant\pull.exe
size: 886000
MD5: 21B7263CFB2360727B2CE61866FF1B86
Located: Startup (disabled), Infotriever (DISABLED)
command: C:\PROGRA~1\INFOTR~1\Agent\INFOCL~1.EXE -startup
file: C:\PROGRA~1\INFOTR~1\Agent\INFOCL~1.EXE
size: 111976
MD5: 30A04467118710C03750D093853B86AC
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, igfxcui
command: igfxdev.dll
file: igfxdev.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, urqRLfCr
command: urqRLfCr.dll
file: urqRLfCr.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
— Browser helper object list —
{53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D; IE Protection)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Spybot-S&D; IE Protection
description: Spybot-S&D; IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\Spybot\
Long name: SDHelper.dll
Short name:
Date (created): 9/25/2008 10:22:20 PM
Date (last access): 12/7/2008 8:06:14 PM
Date (last write): 9/15/2008 1:25:44 PM
Filesize: 1562960
Attributes: readonly hidden sysfile archive
MD5: 35F73F1936BDE91F1B6995510A61E7A8
CRC32: BE6A5D15
Version: 1.6.2.14
{57AF5BDF-F2F5-42CC-AB33-CD39B6DD6DC0} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\WINNT\system32\
Long name: opnmLfGV.dll
Short name:
Date (created): 12/7/2008 4:46:28 PM
Date (last access): 12/7/2008 6:41:14 PM
Date (last write): 12/7/2008 4:46:30 PM
Filesize: 302592
Attributes:
MD5: 84FBB985EEBF04AA18540D86B2791E13
CRC32: CE6440AC
{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\WINNT\system32\
Long name: urqRLfCr.dll
Short name:
Date (created): 12/7/2008 4:41:22 PM
Date (last access): 12/7/2008 6:55:20 PM
Date (last write): 12/7/2008 4:41:22 PM
Filesize: 34816
Attributes: archive
MD5: 1201DB328B213337DA604FA636D6FBF8
CRC32: F8BB58B2
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Java™ Plug-In SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java™ Plug-In SSV Helper
Path: C:\Program Files\Java\jre6\bin\
Long name: ssv.dll
Short name:
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 4:59:24 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 320920
Attributes: archive
MD5: DC090E320775F1B1FE896F6E1D393D7F
CRC32: 068B5AFC
Version: 6.0.100.33
{7CAB59B4-55A3-4737-9FD5-B93C6430BF78} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\WINNT\system32\
Long name: pohxirds.dll
Short name:
Date (created): 12/7/2008 4:47:20 PM
Date (last access): 12/7/2008 6:55:20 PM
Date (last write): 12/7/2008 4:47:20 PM
Filesize: 116224
Attributes: archive
MD5: 451CD6EFFE6E4454BF0226CAB847CEA3
CRC32: 17D40512
{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java™ Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java™ Plug-In 2 SSV Helper
Path: C:\Program Files\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 4:59:24 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 34816
Attributes: archive
MD5: 27771CDC5D464818C8F92356AE840A6F
CRC32: B0BC1BD4
Version: 6.0.100.33
{fc0299ec-3e9a-4425-8697-219e2fc5e21f} ({f12e5cf2-e912-7968-5244-a9e3ce9920cf})
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: {f12e5cf2-e912-7968-5244-a9e3ce9920cf}
CLSID name:
Path: C:\WINNT\system32\
Long name: yxqdgw.dll
Short name:
Date (created): 12/7/2008 5:14:24 PM
Date (last access): 12/7/2008 6:40:12 PM
Date (last write): 12/7/2008 5:14:24 PM
Filesize: 129024
Attributes: archive
MD5: 4BA37AFDF4AEC72C0E47F87E8FC3601B
CRC32: DE571456
— ActiveX list —
{21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain)
DPF name:
CLSID name: WebTrain.ctlWebTrain
Installer: C:\WINNT\Downloaded Program Files\WEB_TRAIN.INF
Codebase: http://www.webattend.com/components/wt0523.cab
Path: C:\WINNT\system32\
Long name: WEBTRAIN.OCX
Short name:
Date (created): 6/1/2006 9:30:06 AM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 6/1/2006 9:30:06 AM
Filesize: 5023232
Attributes: archive
MD5: 29F676053EBF97DD31BDADA03D701E5B
CRC32: 76B3920F
Version: 3.5.0.10
{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Installer: C:\WINNT\Downloaded Program Files\wuweb.inf
Codebase: http://www.update.microsoft.com/windowsupd…b?1218817069823
description:
classification: Legitimate
known filename: wuweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINNT\system32\
Long name: wuweb.dll
Short name:
Date (created): 9/26/2007 1:48:38 PM
Date (last access): 12/7/2008 6:01:58 PM
Date (last write): 7/18/2008 9:09:44 PM
Filesize: 205000
Attributes: archive
MD5: 4889720E56E85E1FE4659039BB5F6E3F
CRC32: EE278BD5
Version: 7.2.6001.784
{7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control)
DPF name:
CLSID name: JNILoader Control
Installer: C:\WINNT\Downloaded Program Files\STJNILoader.inf
Codebase: https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
description:
classification: Open for discussion
known filename: STJNIL~1.OCX
info link:
info source: Safer Networking Ltd.
Path: C:\WINNT\DOWNLO~1\
Long name: STJNILoader.ocx
Short name: STJNIL~1.OCX
Date (created): 6/2/2005 10:41:50 AM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 6/2/2005 10:41:50 AM
Filesize: 274432
Attributes: archive
MD5: 7CF21AEC4A39199EE44C10415A97A5E3
CRC32: FE340101
Version: 3.1.1.104
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_10
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_10.dll
Short name: NPJPI1~1.DLL
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 132504
Attributes: archive
MD5: 3CEF7A7DE0D5141E016A862B1D86B1CD
CRC32: CC232AC8
Version: 6.0.100.33
{8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components)
DPF name:
CLSID name: Whale Client Components
Installer: C:\WINNT\Downloaded Program Files\WhlCompMgr.inf
Codebase: https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
description:
classification: Legitimate
known filename: WhlMgr.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINNT\Downloaded Program Files\
Long name: WhlMgr.dll
Short name:
Date (created): 1/17/2008 12:53:56 PM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 1/17/2008 12:53:56 PM
Filesize: 945816
Attributes: archive
MD5: 493035BD9564C65DE8FCE1C0EB2F7A3F
CRC32: E08FA9DB
Version: 3.7.196.0
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name:
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_04
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Path: C:\Program Files\Java\jre1.6.0_04\bin\
Long name: npjpi160_04.dll
Short name: NPJPI1~1.DLL
Date (created): 12/14/2007 1:59:16 AM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 12/14/2007 3:42:38 AM
Filesize: 132496
Attributes: archive
MD5: 58A1C3B13CC79E76F66CA6F8FED3B36A
CRC32: A4EACB48
Version: 6.0.40.12
{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_10
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_10.dll
Short name: NPJPI1~1.DLL
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 8:06:18 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 132504
Attributes: archive
MD5: 3CEF7A7DE0D5141E016A862B1D86B1CD
CRC32: CC232AC8
Version: 6.0.100.33
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_10
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_10.dll
Short name: NPJPI1~1.DLL
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 8:06:18 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 132504
Attributes: archive
MD5: 3CEF7A7DE0D5141E016A862B1D86B1CD
CRC32: CC232AC8
Version: 6.0.100.33
{D3E01836-60CD-480D-BBDB-19D5A7D23128} (Xerox_Services_Portal.XrxPrinter_Inst)
DPF name:
CLSID name: Xerox_Services_Portal.XrxPrinter_Inst
Installer: C:\WINNT\Downloaded Program Files\Xerox_Services_Portal_Pref.INF
Codebase: https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
Path: C:\WINNT\Downloaded Program Files\
Long name: Xerox_Services_Portal_Pref.ocx
Short name: XEROX_~1.OCX
Date (created): 1/28/2008 3:27:56 PM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 1/28/2008 3:27:56 PM
Filesize: 73728
Attributes: archive
MD5: D065C5D8051318F3EFA53AC61D3D772B
CRC32: CB3E80CD
Version: 3.8.0.22
— Process list —
PID: 0 ( 0) [System]
PID: 1168 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 1412 (1168) \??\C:\WINNT\system32\csrss.exe
size: 6144
PID: 1696 (1168) \??\C:\WINNT\system32\winlogon.exe
size: 502272
PID: 1740 (1696) C:\WINNT\system32\services.exe
size: 108032
MD5: C6CE6EEC82F187615D1002BB3BB50ED4
PID: 1752 (1696) C:\WINNT\system32\lsass.exe
size: 13312
MD5: 84885F9B82F4D55C6146EBF6065D75D2
PID: 1988 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 128 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 368 (1740) C:\WINNT\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 400 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 468 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 776 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1020 (1740) C:\WINNT\System32\WLTRYSVC.EXE
size: 20480
MD5: 60714B1C15F815F55798C0B3D4819BEB
PID: 1032 (1020) C:\WINNT\System32\bcmwltry.exe
size: 1253376
MD5: 7C19764A2EC7AC4AE8DB4BBF0B7F20C5
PID: 1104 (1740) C:\WINNT\system32\spoolsv.exe
size: 57856
MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
PID: 1160 (1740) C:\WINNT\System32\SCardSvr.exe
size: 95744
MD5: 25D8DE134DF108E3DBC8D7D23B1AA58E
PID: 1272 (1740) C:\Program Files\AccessManager\Client\AMBroker.exe
size: 77824
MD5: 0A8446FEA210A30C07B8DD879858ED35
PID: 1340 (1740) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
size: 110592
MD5: 1961CB10BB48EB4D97E37DB6373E9E63
PID: 1436 (1740) C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
size: 86016
MD5: 52A4ED0D41DD3652B1DB311FC0765BC4
PID: 1448 (1740) C:\Program Files\Java\jre6\bin\jqs.exe
size: 152984
MD5: 5FD5865DC1A2100F8D4CF000EE5409A3
PID: 1544 (1740) C:\WINNT\System32\MCSvc.exe
size: 69632
MD5: 86EC5A1FAEEE67FCE1287150E635A64C
PID: 1596 (1740) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
size: 322120
MD5: 11F714F85530A2BD134074DC30E99FCA
PID: 1644 (1740) C:\Program Files\OfficeScan NT\ntrtscan.exe
size: 906536
MD5: EC539F17431F5FA73DD4F44FF64E9C0B
PID: 1672 (1740) C:\WINNT\system32\HPZipm12.exe
size: 69632
MD5: D31F88C5F19EEFA366A415D6BC5F2ABC
PID: 1824 (1740) C:\WINNT\system32\SvcLncher.exe
size: 229376
MD5: 8E21F9A309FDA5BA391682527E48A6AF
PID: 2004 (1740) C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
size: 118784
MD5: EF1F7335F0285599438A2E713CE8772A
PID: 2020 (1740) C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
size: 90112
MD5: 686FA4ACFDCB4E16B7F0230B88F6D17E
PID: 516 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 528 (1740) C:\WINNT\system32\Suss.exe
size: 12048
MD5: 7A375DBDAC196606E0CA92F4580B87D2
PID: 580 (1740) C:\Program Files\AccessManager\Client\sygman.exe
size: 126976
MD5: B3B3ABC9FCD0720587F12F7649DC664F
PID: 696 (1740) C:\Program Files\OfficeScan NT\tmlisten.exe
size: 984360
MD5: 89D686F4656CDEAEC3936ABCCE9DF11D
PID: 964 (1740) C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
size: 251256
MD5: E5F1614AE616C9C1B00E92031867F48F
PID: 992 (1740) C:\WINNT\system32\CCM\CcmExec.exe
size: 590712
MD5: E4B94F8EDB3540D43A473D552C30D395
PID: 1480 (1644) C:\WINNT\TEMP\XZ8E65.EXE
size: 296224
MD5: B8BEE3B4802F23FCC809082DFB5A663B
PID: 2312 (1740) C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
size: 135168
MD5: BEDE742D051F3F848C10F59FC85C0DEB
PID: 2664 (1740) C:\WINNT\System32\alg.exe
size: 44544
MD5: F1958FBF86D5C004CF19A5951A9514B7
PID: 2836 (1740) C:\Program Files\OfficeScan NT\TmPfw.exe
size: 488768
MD5: 3341EDF8769BC1967E2CA097792C370C
PID: 3188 (1988) C:\WINNT\system32\wbem\wmiprvse.exe
size: 218112
MD5: 075EA6C849AB0FE416A3D6DD65C3CF41
PID: 3588 (1988) C:\WINNT\system32\wbem\wmiprvse.exe
size: 218112
MD5: 075EA6C849AB0FE416A3D6DD65C3CF41
PID: 3860 ( 696) C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
size: 435576
MD5: 42F903C87ABDC68176A1A436470D4B0F
PID: 828 (3992) C:\WINNT\Explorer.EXE
size: 1032192
MD5: A0732187050030AE399B241436565E64
PID: 2068 ( 828) C:\Program Files\Spybot\SpybotSD.exe
size: 4891472
MD5: 3B1B5D09D3C9C4CD39D4DB06ED7A0855
PID: 3476 (1740) C:\WINNT\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 3380 ( 368) C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
size: 133104
MD5: 626A24ED1228580B9518C01930936DF9
PID: 4 ( 0) System
— Browser start & search pages list —
Spybot - Search & Destroy browser pages report, 12/7/2008 8:06:19 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINNT\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
https://inside.nokiasiemensnetworks.com/global/search.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
https://inside.nokiasiemensnetworks.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
https://inside.nokiasiemensnetworks.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
— Winsock Layered Service Provider list —
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{82050D99-E21F-4151-BB2B-BDFB81A15DB1}] SEQPACKET 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{82050D99-E21F-4151-BB2B-BDFB81A15DB1}] DATAGRAM 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{67C55556-3A19-425C-AE9D-6F311F24CF5B}] SEQPACKET 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{67C55556-3A19-425C-AE9D-6F311F24CF5B}] DATAGRAM 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{5E8875FA-BF7D-4B93-8D00-F179F4FEF81F}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{5E8875FA-BF7D-4B93-8D00-F179F4FEF81F}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FAFCE09D-8A2E-4F21-A092-B020C58316EB}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FAFCE09D-8A2E-4F21-A092-B020C58316EB}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{31129AF3-2CDF-4692-8126-6AEED5019D8A}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{31129AF3-2CDF-4692-8126-6AEED5019D8A}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CF321070-626F-48AE-B65A-3105209C4985}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CF321070-626F-48AE-B65A-3105209C4985}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{126BA951-FA38-47DE-9561-C5BE92FE0776}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{126BA951-FA38-47DE-9561-C5BE92FE0776}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F20EE0C8-D5BD-413F-844F-D76262EE0E81}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F20EE0C8-D5BD-413F-844F-D76262EE0E81}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EC26FC9D-9BB7-4038-839E-642242A7CF10}] SEQPACKET 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EC26FC9D-9BB7-4038-839E-642242A7CF10}] DATAGRAM 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 23: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BDE3CAD2-30AD-4E60-982B-A8FCFBAE8ECC}] SEQPACKET 9
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 24: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BDE3CAD2-30AD-4E60-982B-A8FCFBAE8ECC}] DATAGRAM 9
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
Namespace Provider 3: mdnsNSP
GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
Filename: C:\Program Files\Bonjour\mdnsNSP.dll
Description: Apple Rendezvous protocol
DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
DB protocol: mdnsNSP
— Uninstall list —
Windows Driver Package - Nokia Modem (02/15/2007 3.1) 02/15/2007 3.1 (0C5EDC3653FED5B121F464339EAC12534D253B25)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\pccs_bluet_8B37DC72918CCD58A6EC20373AF6242B037A293B\pccs_bluetooth.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (08/08/2007 3.3) 08/08/2007 3.3 (24894EA20BE8E62AA4FC3DD3AA85785356B52BF5)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\pccs_bluet_32E2E448B53EE5B28E074D88802D0BAF984038DA\pccs_bluetooth.inf
publisher: Nokia
Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) 10/12/2007 6.85.4.0 (3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (10/12/2007 3.6) 10/12/2007 3.6 (6A630DCEC5EEC912115F2FF59D8C2C769798D930)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokia_blue_0A5D98F754C6588B2E3DDE89DDEF097075ADFFB7\nokia_bluetooth.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2) 08/03/2007 6.84.0.2 (819D45A9F73817F5B6D7C71A33ADAB88C5DA1765)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokbtmdm_1EB5F2E6F54A6BEDE9F436D1BA5D830FC71739BE\nokbtmdm.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1) 05/22/2008 7.00.0.1 (9CD348AE9C64C4B939B624E8E24F3903EFDFC82B)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9\nokbtmdm.inf
publisher: Nokia
WebEx (ActiveTouchMeetingClient)
uninstall cmd: C:\PROGRA~1\MOZILL~1\plugins\atcliun.exe
publisher: WebEx Communications, Inc
contact: Customer Support
help link: http://support.webex.com/
(AddressBook)
Adobe Acrobat 8 Professional - English, Français, Deutsch 8.0.0 (Adobe Acrobat 8 Professional - English, Français, Deutsch)
version (major): 8
install date: 10/6/2007
install location: C:\Program Files\Adobe\Acrobat 8.0\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\Adobe Acrobat 8.0\
uninstall cmd: msiexec /I {AC76BA86-1033-F400-7760-000000000003}
publisher: Adobe Systems
contact: Customer Support
help link: http://www.adobe.com/support/main.html
help telephone:
readme: C:\Program Files\Adobe\Acrobat 8.0\Readme.htm
Adobe Flash Player 10 Plugin 10.0.12.36 (Adobe Flash Player Plugin)
uninstall cmd: C:\WINNT\system32\Macromed\Flash\uninstall_plugin.exe
publisher: Adobe Systems Incorporated
Adobe Shockwave Player 11 11 (Adobe Shockwave Player)
version (major): 11
install location: C:\WINNT\system32\Adobe\
uninstall cmd: C:\WINNT\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINNT\system32\Adobe\SHOCKW~1\Install.log
publisher: Adobe Systems, Inc.
help link: http://www.adobe.com/support/shockwave
AT&T; Connect Participant (AT&T; Connect Participant)
install location: C:\Program Files\Interwise\Participant
uninstall cmd: C:\Program Files\Interwise\Participant\iwuninst.exe
Windows Driver Package - Nokia Modem (02/15/2007 3.1) 02/15/2007 3.1 (B726756F5B5A5AA9D798B399386FC6205A45F19E)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\pccs_bluet_F12A08B6F776984A95553486F64C541356F86E38\pccs_bluetooth.inf
publisher: Nokia
(Branding)
Dell Wireless WLAN Card 4.100.15.8 (Broadcom 802.11b Network Adapter)
uninstall cmd: "C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
publisher: Dell Inc.
Windows Driver Package - Nokia Modem (05/22/2008 3.8) 05/22/2008 3.8 (C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181E\nokia_bluetooth.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (03/05/2008 3.7) 03/05/2008 3.7 (CBF192A85B624E32B8D19ADEEF2DCFC5BC3AA73A)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokia_blue_635B28EFCFA9395123BB1C251595CB16129E2560\nokia_bluetooth.inf
publisher: Nokia
CCleaner (remove only) (CCleaner)
uninstall cmd: "C:\Program Files\CCleaner\uninst.exe"
Windows Driver Package - Nokia Modem (05/24/2007 6.84.0.1) 05/24/2007 6.84.0.1 (CD8424B9400BFF7D34AA18F816C71322AC4BDAA7)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokbtmdm_5E1541AFF1E1EA3554CE566743CCAD323ED1C108\nokbtmdm.inf
publisher: Nokia
Conexant HDA D330 MDC V.92 Modem (CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F)
uninstall cmd: C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F\HXFSETUP.EXE -U -Idel000f5.inf
(Connection Manager)
Copernic Desktop Search - Home (CopernicDesktopSearch2)
uninstall cmd: C:\Program Files\Copernic Desktop Search 2\uninst.exe
publisher: Copernic Inc.
(DirectAnimation)
(DirectDrawEx)
DVD Decrypter (Remove Only) (DVD Decrypter)
uninstall cmd: "C:\Program Files\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2 (DVD Shrink_is1)
install location: C:\Program Files\DVD Shrink\
uninstall cmd: "C:\Program Files\DVD Shrink\unins000.exe"
publisher: DVD Shrink
help link: http://www.dvdshrink.org
(DXM_Runtime)
Windows Driver Package - Nokia Modem (03/13/2008 6.86.0.1) 03/13/2008 6.86.0.1 (E092B2EBF2FFE83E896F8F7F829A7B5D7D1B2F9D)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokbtmdm_28F2EAC406838DA65AFF6C6886FE9FE96AEF5186\nokbtmdm.inf
publisher: Nokia
Firefly Media Server svn-1359 (Firefly Media Server)
uninstall cmd: C:\Program Files\Firefly Media Server\uninst.exe
publisher: Ron Pedde
(Fontcore)
GSplit 2.0 2.0.0.2 (GSplit20S)
uninstall cmd: C:\Program Files\GSplit\Uninst.exe
publisher: The G.D.G. Software Team
Intel® Graphics Media Accelerator Driver (HDMI)
uninstall cmd: C:\WINNT\system32\igxpun.exe -uninstall
HijackThis 2.0.0 2.0.0 (HijackThis)
uninstall cmd: "D:\Data\Downloads\HijackThis.exe" /uninstall
publisher: TrendMicro
HP Imaging Device Functions 7.0 7.0 (HP Imaging Device Functions)
uninstall cmd: C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
publisher: HP
help link: http://www.hp.com/support
HP Solution Center 7.0 7.0 (HP Solution Center & Imaging Support Tools)
uninstall cmd: C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
publisher: HP
help link: http://www.hp.com/support
OCR Software by I.R.I.S 7.0 7.0 (HPOCR)
uninstall cmd: C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
publisher: HP
help link: http://www.hp.com/support
(ICW)
(IE40)
(IE4Data)
(IE5BAKEX)
(IEData)
(InstallShield Uninstall Information)
BlackBerry Connect Desktop for Nokia 4.0.0 (InstallShield_{5238A932-32B7-4F62-B384-869A23DEA4BE})
version: 67108864
version (major): 4
estimated size: 3624
install date: 20080103
install source: C:\Documents and Settings\vm092543\Local Settings\Application Data\{D76BC089-A308-4D85-AF2F-5CBBF3E3ACC5}\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{5238A932-32B7-4F62-B384-869A23DEA4BE} /l1033
publisher: Research In Motion, Ltd.
20040929.110854 (KB834707)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=834707
20041117.092459 (KB873339)
uninstall cmd: C:\WINNT\$NtUninstallKB873339$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=873339
(KB884016)
(KB884267)
(KB885353)
20041027.181713 (KB885835)
uninstall cmd: C:\WINNT\$NtUninstallKB885835$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=885835
20041028.173203 (KB885836)
uninstall cmd: C:\WINNT\$NtUninstallKB885836$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=885836
20041021.090540 (KB886185)
uninstall cmd: C:\WINNT\$NtUninstallKB886185$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=886185
(KB886612)
(KB887078)
20041014.162858 (KB887472)
uninstall cmd: C:\WINNT\$NtUninstallKB887472$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=887472
(KB887626)
High Definition Audio Driver Package - KB888111 20040219.000000 (KB888111WXPSP2)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=KB888111
20041207.111426 (KB888302)
uninstall cmd: C:\WINNT\$NtUninstallKB888302$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=888302
(KB888656)
(KB889858)
Security Update for Windows XP (KB890046) 1 (KB890046)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB890046$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=890046
1 (KB890859)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB890859$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=890859
20041229.171115 (KB890937)
uninstall cmd: C:\WINNT\$NtUninstallKB890937$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=890937
(KB891122)
20050110.165439 (KB891781)
uninstall cmd: C:\WINNT\$NtUninstallKB891781$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=891781
3 (KB892050)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB892050$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=892050
(KB892313)
(KB893240)
(KB893241)
2 (KB893357)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB893357$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=893357
1 (KB893756)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB893756$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=893756
3.1 (KB893803)
help link: http://go.microsoft.com/fwlink/?LinkId=42467
(KB893803v2)
uninstall cmd: "C:\WINNT\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=42467
(KB895181)
(KB895316)
(KB895572)
Hotfix for Windows XP (KB896256) 3 (KB896256)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896256
1 (KB896358)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB896358$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896358
1 (KB896423)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB896423$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896423
3 (KB896427)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB896427$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896427
1 (KB896428)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB896428$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896428
(KB897586)
1 (KB897663)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB897663$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=897663
(KB898549)
1 (KB899587)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB899587$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=899587
1 (KB899591)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB899591$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=899591
(KB900399)
1 (KB900725)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB900725$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=900725
1 (KB901017)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB901017$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=901017
1 (KB901190)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB901190$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=901190
1 (KB901214)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB901214$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=901214
(KB902344)
1 (KB902400)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB902400$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=902400
1 (KB904706)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB904706$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=904706
1 (KB905414)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB905414$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=905414
1 (KB905749)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB905749$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=905749
(KB907658)
1 (KB908519)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB908519$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=908519
2 (KB908531)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB908531$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=908531
1 (KB909095)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB909095$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=909095
2 (KB911280)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB911280$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911280
1 (KB911562)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB911562$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911562
(KB911565)
(KB911854)
1 (KB911927)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB911927$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911927
1 (KB912761)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB912761$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=912761
1 (KB913580)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB913580$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=913580
1 (KB914388)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB914388$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=914388
1 (KB914389)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB914389$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=914389
Hotfix for Windows XP (KB916191) 1 (KB916191)
install date: 20080915
uninstall cmd: "C:\WINNT\$NtUninstallKB916191$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=916191
3 (KB917021)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB917021$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=917021
1 (KB917344)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB917344$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=917344
1 (KB917953)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB917953$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=917953
1 (KB918118)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB918118$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=918118
1 (KB918439)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB918439$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=918439
1 (KB919007)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB919007$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=919007
1 (KB920213)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB920213$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920213
1 (KB920670)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB920670$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920670
1 (KB920683)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB920683$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920683
1 (KB920685)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB920685$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920685
1 (KB921503)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB921503$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=921503
1 (KB922819)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB922819$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=922819
1 (KB923191)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB923191$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923191
1 (KB923414)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB923414$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923414
1 (KB923980)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB923980$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923980
1 (KB924191)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB924191$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924191
1 (KB924270)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB924270$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924270
1 (KB924496)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB924496$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924496
1 (KB924667)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB924667$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924667
(KB925398_WMP64)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=925398
1 (KB925902)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB925902$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=925902
Hotfix for Windows XP (KB926239) 2 (KB926239)
install date: 20080707
uninstall cmd: "C:\WINNT\$NtUninstallKB926239$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926239
1 (KB926255)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB926255$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926255
1 (KB926436)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB926436$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926436
1 (KB927779)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB927779$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=927779
1 (KB927802)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB927802$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=927802
1 (KB928255)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB928255$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=928255
2 (KB928365.T1_1ToU569_1)
uninstall cmd: C:\WINNT\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/928365
1 (KB928843)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB928843$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=928843
1 (KB929123)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB929123$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=929123
1 (KB929969)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB929969$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=929969
1 (KB930178)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB930178$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=930178
1 (KB931261)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB931261$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931261
1 (KB931784)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB931784$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931784
1 (KB931836)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB931836$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931836
1 (KB932168)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB932168$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=932168
Hotfix for Windows XP (KB933062) 1 (KB933062)
install date: 20080915
uninstall cmd: "C:\WINNT\$NtUninstallKB933062$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933062
1 (KB933360)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB933360$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933360
1 (KB933566)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB933566$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933566
1 (KB933729)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB933729$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933729
1 (KB935448)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB935448$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=935448
1 (KB935839)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB935839$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=935839
1 (KB935840)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB935840$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=935840
1 (KB936021)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB936021$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=936021
Security Update for Windows Media Player 11 (KB936782) (KB936782_WMP11)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=936782
1 (KB937894)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB937894$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=937894
1 (KB938127)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB938127$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938127
Security Update for Windows XP (KB938464) 1 (KB938464)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB938464$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938464
1 (KB938829)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB938829$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938829
Hotfix for Windows XP (KB939273) 1 (KB939273)
install date: 20080916
uninstall cmd: "C:\WINNT\$NtUninstallKB939273$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=939273
1 (KB941202)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB941202$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941202
1 (KB941568)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB941568$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941568
Security Update for Windows XP (KB941569) (KB941569)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB941569$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941569
Security Update for Windows XP (KB941693) 1 (KB941693)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB941693$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941693
1 (KB942615)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB942615$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=942615
Security Update for Windows XP (KB943055) 1 (KB943055)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB943055$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943055
1 (KB943460)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB943460$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943460
Security Update for Windows XP (KB943485) 1 (KB943485)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB943485$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943485
Security Update for Windows XP (KB944338-v2) 2 (KB944338-v2)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=944338
1 (KB944653)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB944653$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=944653
Security Update for Windows XP (KB945553) 1 (KB945553)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB945553$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=945553
Security Update for Windows XP (KB946026) 1 (KB946026)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB946026$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=946026
Security Update for Windows XP (KB946648) 1 (KB946648)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB946648$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=946648
Security Update for Windows XP (KB948590) 1 (KB948590)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB948590$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=948590
Security Update for Windows XP (KB950749) 1 (KB950749)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB950749$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950749
Security Update for Windows XP (KB950762) 1 (KB950762)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB950762$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950762
Security Update for Windows XP (KB950974) 1 (KB950974)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB950974$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950974
Security Update for Windows XP (KB951066) 1 (KB951066)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB951066$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951066
Update for Windows XP (KB951072-v2) 2 (KB951072-v2)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951072
Security Update for Windows XP (KB951376-v2) 2 (KB951376-v2)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951376
Security Update for Windows XP (KB951698) 1 (KB951698)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB951698$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951698
Security Update for Windows XP (KB951748) 1 (KB951748)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB951748$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951748
Security Update for Windows XP (KB952954) 1 (KB952954)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB952954$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952954
Security Update for Windows XP (KB953838) 1 (KB953838)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB953838$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=953838
Security Update for Windows XP (KB954211) 1 (KB954211)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB954211$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=954211
Security Update for Windows XP (KB955069) 1 (KB955069)
install date: 20081124
uninstall cmd: "C:\WINNT\$NtUninstallKB955069$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=955069
Security Update for Windows XP (KB956390) 1 (KB956390)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB956390$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956390
Security Update for Windows XP (KB956391) 1 (KB956391)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB956391$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956391
Security Update for Windows XP (KB956803) 1 (KB956803)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB956803$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956803
Security Update for Windows XP (KB956841) 1 (KB956841)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB956841$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956841
Security Update for Windows XP (KB957095) 1 (KB957095)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB957095$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=957095
Security Update for Windows XP (KB957097) 1 (KB957097)
install date: 20081124
uninstall cmd: "C:\WINNT\$NtUninstallKB957097$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=957097
Security Update for Windows XP (KB958644) 1 (KB958644)
install date: 20081024
uninstall cmd: "C:\WINNT\$NtUninstallKB958644$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=958644
(M928366)
uninstall cmd: "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
(M928367)
uninstall cmd: "C:\WINNT\Microsoft.NET\Framework\v1.0.3705\Updates\hotfix.exe" "C:\WINNT\Microsoft.NET\Framework\v1.0.3705\Updates\M928367\M928367Uninstall.msp"
Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033))
uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
readme: file://C:\WINNT\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm
(Microsoft .NET Framework Full v1.0.3705 (1033))
readme: file://C:\WINNT\Microsoft.NET\Framework\v1.0.3705\repair.htm
(MobileOptionPack)
Mozilla Firefox (3.0.4) 3.0.4 (en-US) (Mozilla Firefox (3.0.4))
install location: C:\Program Files\Mozilla Firefox
uninstall cmd: C:\Program Files\Mozilla Firefox\uninstall\helper.exe
publisher: Mozilla
comments: Mozilla Firefox
(MPlayer2)
Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1)
install date: 20080707
uninstall cmd: "C:\WINNT\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=74087
(MSI30-Beta1)
(MSI30-Beta2)
(MSI30-KB884016)
(MSI30-RC1)
(MSI30-RC2)
(MSI30a-KB884016)
(MSI31-Beta)
(MSI31-RC1)
(Nero - Burning Rom!UninstallKey)
uninstall cmd: C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
(NeroRecode!UninstallKey)
uninstall cmd: C:\WINNT\UNRecode.exe /UNINSTALL
(NetMeeting)
Nokia Multimedia Factory 1.3 (Nokia Multimedia Factory{4CFB3821-1582-4F3B-BF8D-30986923B36B})
estimated size: 25000
install location: C:\Program Files\Nokia\Nokia PC Suite 6\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{4CFB3821-1582-4f3b-BF8D-30986923B36B}\Installations\Nokia Multimedia Factory\
uninstall cmd: "C:\Documents and Settings\All Users\Application Data\Installations\{4CFB3821-1582-4f3b-BF8D-30986923B36B}\Nokia_Multimedia_Factory_2_0.exe" /MAINTENANCE /SILENT="SWLPCER" /LANG="2057" /MSI_COMMON_OPTIONS="PCSLANG= MMFLANG=eng"
publisher: Nokia
Nokia PC Suite 7.0.9.2 (Nokia PC Suite)
install location: C:\Program Files\Nokia\Nokia PC Suite 7\
uninstall cmd: C:\Documents and Settings\All Users\Application Data\Installations\{D5577624-0626-4C4B-87AA-D966DA1739D6}\Nokia_PC_Suite_rel_7_0_9_2_eng.exe
publisher: Nokia
NVIDIA Drivers (NVIDIA Drivers)
Trend Micro OfficeScan Client (OfficeScanNT)
uninstall cmd: "C:\Program Files\OfficeScan NT\ntrmv.exe"
(OutlookExpress)
Password Safe (Password Safe)
uninstall cmd: "C:\Program Files\Password Safe\Uninstall.exe"
(PCHealth)
uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINNT\INF\PCHealth.inf
(SchedulingAgent)
(Shockwave)
Tweak UI (Tweak UI 2.10)
uninstall cmd: "C:\WINNT\system32\mshta.exe" "res://C:\WINNT\system32\TweakUI.exe/uninstall.hta"
DVD Video Player 0.8.6e (VideoLAN)
estimated size: 25344
install location: %systemroot%\AddOns\VLCPlayer
uninstall cmd: %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 128 %systemroot%\AddOns\VLCPlayer\vlc.inf
publisher: VideoLAN Team
help link: http://mchp9vga.gmo.siemens.com/WSBP
VideoLAN VLC media player 0.8.6h 0.8.6h (VLC media player)
uninstall cmd: C:\Program Files\VideoLAN\VLC\uninstall.exe
publisher: VideoLAN Team
(Wdf01000)
(Wdf01001)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 (Wdf01005)
install date: 20080302
uninstall cmd: "C:\WINNT\$NtUninstallWdf01005$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 (Wdf01007)
install date: 20081204
uninstall cmd: "C:\WINNT\$NtUninstallWdf01007$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
Whale Communications' Client Components v3.7.1 (Whale Communications' Client Components 3.1.0)
uninstall cmd: rundll32.exe C:\WINNT\DOWNLO~1\WhlMgr.dll,UnInstall 3.1.0 63 0 1 3.7.1
Windows Media Format 11 runtime (Windows Media Format Runtime)
uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
help link: http://go.microsoft.com/fwlink/?LinkId=62768
Windows Media Player 11 (Windows Media Player)
uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
WinPcap 4.0.1 4.0.0.901 (WinPcapInst)
uninstall cmd: C:\Program Files\WinPcap\uninstall.exe
publisher: CACE Technologies
WinRAR archiver (WinRAR archiver)
uninstall cmd: C:\Program Files\WinRAR\uninstall.exe
WinSCP 4.1.7 4.1.7 (winscp3_is1)
install date: 20081013
install location: C:\Program Files\WinSCP\
uninstall cmd: "C:\Program Files\WinSCP\unins000.exe"
publisher: Martin Prikryl
help link: http://winscp.net/forum/
Wireshark 0.99.6a 0.99.6a (Wireshark)
uninstall cmd: "C:\Program Files\Ethereal\uninstall.exe"
publisher: The Wireshark developer community, http://www.wireshark.org
help link: mailto:[removed]
(WMCSetup)
Windows Media Format 11 runtime (WMFDist11)
install date: 20080707
uninstall cmd: "C:\WINNT\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:
Windows Media Player 11 (wmp11)
install date: 20080707
uninstall cmd: "C:\WINNT\$NtUninstallwmp11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:
Microsoft User-Mode Driver Framework Feature Pack 1.5 (Wudf01005)
install date: 20080713
uninstall cmd: "C:\WINNT\$NtUninstallWudf01005$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
comments: Build Number 5730
Yahoo! Messenger (Yahoo! Messenger)
uninstall cmd: C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Apple Software Update 2.1.0.110 ({02DFF6B1-1654-411C-8D7B-FD6052EF016F})
version: 33619968
version (major): 2
version (minor): 1
estimated size: 2196
install date: 20080606
install location: C:\Program Files\Apple Software Update\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
Nokia Software Updater 01.04.064.36264 ({0332234E-09D1-4B74-A5F3-73E34BA29F5B})
version: 17039424
version (major): 1
version (minor): 4
estimated size: 39306
install date: 20081203
install location: C:\Program Files\Nokia\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{0332234E-09D1-4B74-A5F3-73E34BA29F5B}\Packages\NokiaSoftwareUpdater\Setup\
uninstall cmd: MsiExec.exe /X{0332234E-09D1-4B74-A5F3-73E34BA29F5B}
publisher: Nokia Corporation
NokiaFonts 1.0.0.0 ({039D9222-849C-497D-86D4-1E082825334C})
version: 16777216
version (major): 1
estimated size: 1427
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0300139\
uninstall cmd: MsiExec.exe /I{039D9222-849C-497D-86D4-1E082825334C}
publisher: Nokia
comments: Software package provided by Siemens AG
contact: For support call your local help desk
IBM Lotus Sametime Connect 8.0 for NSN v8.0080205 (NSWP) 8.0.080205 ({051AB369-C32F-4643-87E0-06685E20577A})
version: 134297933
version (major): 8
estimated size: 31289
install date: 20081021
install location: C:\Program Files\IBM\Lotus\Sametime Connect\
install source: C:\Temp\ST8\
uninstall cmd: C:\WINNT\Unwise.exe /S /Z C:\PROGRA~1\IBM\Lotus\SAMETI~1\NSN80.log
publisher: IT Service Desk
contact: Service Desk
help telephone: Call your local Service Desk
Services Synchronization Utility 1.0 1.0.0.0 ({08D41F8C-6495-40C7-B502-5BD6EC625FC7})
version: 16777216
version (major): 1
estimated size: 18
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\AP0000135\
uninstall cmd: MsiExec.exe /I{08D41F8C-6495-40C7-B502-5BD6EC625FC7}
publisher: Siemens AG
comments: Software package provided by Siemens AG
contact: For support call your local help desk
Altova XMLSpy® 2008 rel. 2 sp1 Enterprise Edition 2008.02.01 ({1418A0A6-D816-4537-AE4F-6F97E418387A})
version (major): 2008
version (minor): 2
estimated size: 118075
install date: 20081031
install location: C:\Program Files\Altova\
install source: C:\WINNT\Downloaded Installations\{B69BB392-1645-4A01-8A29-C7CD595F97D8}\
uninstall cmd: MsiExec.exe /I{1418A0A6-D816-4537-AE4F-6F97E418387A}
publisher: Altova
comments: Please use the Support URL unless you have a telephone support contract
contact: Customer Support Department
help link: http://www.altova.com/support
help telephone: [removed]
QuickTime 7.4.5.67 ({1838C5A2-AB32-4145-85C1-BB9B8DFA24CD})
version: 117702661
version (major): 7
version (minor): 4
estimated size: 80580
install date: 20080606
install location: C:\Program Files\QuickTime\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
PC Connectivity Solution 8.22.4.0 ({1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C})
version: 135659524
version (major): 8
version (minor): 22
estimated size: 10783
install date: 20080907
install location: C:\Program Files\PC Connectivity Solution\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Packages\PCCS\Setup\
uninstall cmd: MsiExec.exe /I{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}
publisher: Nokia
MSXML 6 Service Pack 2 (KB954459) 6.20.1099.0 ({1A528690-6A2D-4BC5-B143-8C4AE8D19D96})
version: 101975115
version (major): 6
version (minor): 20
estimated size: 1369
install date: 20081124
install source: d:\ebe4829cbf29e27f7176cc8f\
uninstall cmd: MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/954459
Access Manager 1.24.0000 ({1A748F80-F0D9-4E0E-AA17-DA940E355864})
version: 18350080
version (major): 1
version (minor): 24
estimated size: 37870
install date: 20070927
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\
uninstall cmd: MsiExec.exe /I{1A748F80-F0D9-4E0E-AA17-DA940E355864}
publisher: MCI, Inc.
comments: Software package provided by Siemens AG
contact: For support contact your local Help Desk
help link:
help telephone:
Image Resizer Powertoy for Windows XP 1.00.0001 ({1CB92574-96F2-467B-B793-5CEB35C40C29})
version: 16777217
version (major): 1
estimated size: 17
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{1CB92574-96F2-467B-B793-5CEB35C40C29}
publisher: Microsoft Corporation
comments: Image Resizer Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
GUI 4.11.0000 ({209617C6-3666-40B0-A708-C8B027A1534E})
version: 67829760
version (major): 4
version (minor): 11
estimated size: 18305
install date: 20070927
install location: C:\Program Files\AccessManager\Client\
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\
publisher: MCI, Inc.
comments:
contact:
help link:
help telephone:
readme:
MSVC80_x86 1.0.1.0 ({212748BB-0DA5-46DE-82A1-403736DC9F27})
version: 16777217
version (major): 1
estimated size: 4095
install date: 20080103
install source: C:\Documents and Settings\All Users\Application Data\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Packages\VC80_x86\Setup\
uninstall cmd: MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
publisher: Nokia
HPPhotoSmartExpress 70.0.170.000 ({2376813B-2E5A-4641-B7B3-A0D5ADB55229})
version: 1174405290
version (major): 70
estimated size: 10150
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\HPPhotoSmartExpress\
publisher: Hewlett-Packard
Java™ 6 Update 10 6.0.100 ({26A24AE4-039D-4CA4-87B4-2F83216010FF})
version: 100663396
version (major): 6
estimated size: 92664
install date: 20081126
install location: C:\Program Files\Java\jre6\
install source: C:\Documents and Settings\vm092543\Application Data\Sun\Java\jre1.6.0_10\
uninstall cmd: MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
publisher: Sun Microsystems, Inc.
contact: http://java.com
help link: http://java.com
readme: C:\Program Files\Java\jre6\README.txt
Nokia Flashing Cable Driver 8.23.0.0 ({2A0A6470-FD0F-4F45-9B11-85F3167DB943})
version: 135725056
version (major): 8
version (minor): 23
estimated size: 580
install date: 20080901
install location: C:\Program Files\Nokia\Flashing Cable Driver\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{48110A46-A3A4-481E-8230-7873B7F4C696}\Packages\FCD\Setup\
uninstall cmd: MsiExec.exe /X{2A0A6470-FD0F-4F45-9B11-85F3167DB943}
publisher: Nokia
Adobe SVG Viewer 3.0.3 3.0.3 ({2DA60A68-199E-4D51-A7C7-EFF5F912D751})
version: 50331651
version (major): 3
estimated size: 4741
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\BR0100199\
uninstall cmd: MsiExec.exe /I{2DA60A68-199E-4D51-A7C7-EFF5F912D751}
publisher: Adobe Inc.
comments: Software Package authored based on system capture by Siemens AG,CAT@Siemens
contact: For support call your local HelpDesk
Microsoft RAW Image Thumbnailer and Viewer for Windows XP Version 1.0 (Build 50) 01.1.0050.00 ({2E5A5B57-57FC-4C79-A239-9DB280ADEC2A})
version: 16842802
version (major): 1
version (minor): 1
estimated size: 20333
install date: 20071006
install location: C:\Program Files\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\
install source: C:\WINNT\Downloaded Installations\{3C270D9D-E9B3-4B32-9CEE-011D8DE7F2E3}\
uninstall cmd: MsiExec.exe /X{2E5A5B57-57FC-4C79-A239-9DB280ADEC2A}
publisher: Microsoft
help link: www.microsoft.com/prophoto
readme: C:\Program Files\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\readme.htm
Magnifier Powertoy for Windows XP 1.00.0001 ({2FBF04DC-404C-4FA4-BA28-99903080D2B9})
version: 16777217
version (major): 1
estimated size: 5
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{2FBF04DC-404C-4FA4-BA28-99903080D2B9}
publisher: Microsoft Corporation
comments: Powertoys for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
PMAC 1.3.57.0 ({30EA517D-2BEB-4E2E-BB85-49AC61D25B3E})
version: 16973881
version (major): 1
version (minor): 3
estimated size: 567
install date: 20070927
install location: C:\Program Files\AccessManager\PMAC\
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\
publisher:
help link:
help telephone:
Java™ 6 Update 3 1.6.0.30 ({3248F0A8-6813-11D6-A77B-00B0D0160030})
version: 17170432
version (major): 1
version (minor): 6
estimated size: 138186
install date: 20080226
install source: C:\Documents and Settings\vm092543\Application Data\Sun\Java\jre1.6.0_03\
uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
publisher: Sun Microsystems, Inc.
contact: http://java.com
help link: http://java.com
readme: C:\Program Files\Java\jre1.6.0_03\README.txt
Java™ 6 Update 4 1.6.0.40 ({3248F0A8-6813-11D6-A77B-00B0D0160040})
version: 17170432
version (major): 1
version (minor): 6
estimated size: 141042
install date: 20080226
install source: C:\Documents and Settings\vm092543\Application Data\Sun\Java\jre1.6.0_04\
uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
publisher: Sun Microsystems, Inc.
contact: http://java.com
help link: http://java.com
readme: C:\Program Files\Java\jre1.6.0_04\README.txt
WebFldrs XP 9.50.7523 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227})
version: 154279267
version (major): 9
version (minor): 50
estimated size: 2472
install date: 20070926
install source: C:\WINNT\system32\
publisher: Microsoft Corporation
help link: http://www.microsoft.com/windows
PanoStandAlone 70.0.170.000 ({363790D2-DA98-41DD-9C9F-69FA36B169DE})
version: 1174405290
version (major): 70
estimated size: 1775
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\PanoStandAlone\
publisher: Hewlett-Packard
Macromedia Shockwave 8.5.1 8.5.1.106 ({3694346F-8370-4CAC-B0F8-68AA1F9EC9C3})
version: 134545409
version (major): 8
version (minor): 5
estimated size: 7098
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\BR0100092\
uninstall cmd: MsiExec.exe /I{3694346F-8370-4CAC-B0F8-68AA1F9EC9C3}
publisher: Macromedia
comments: Software Package authored based on system capture by Siemens AG,CAT@Siemens
contact: For support call your local HelpDesk
help link: " "
help telephone: " "
readme: " "
Xerox Walk-Up Printing Driver 2.0 2.0 ({39D03604-22DA-48A4-A8EB-E9691C1F9556})
version: 33554432
version (major): 2
estimated size: 818
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\RarSFX0\
uninstall cmd: MsiExec.exe /X{39D03604-22DA-48A4-A8EB-E9691C1F9556}
publisher: Xerox
help link: http://www.xerox.com
({3E70509C-A2D6-4C55-915D-50CD11155FBF})
PKI2 Basis Client V2.0.0.8 2.0.0.8 ({3FFCF6D9-157B-4F2F-93E2-DDC68059B1A3})
version: 33554432
version (major): 2
estimated size: 11637
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\ST0000119\
uninstall cmd: MsiExec.exe /I{3FFCF6D9-157B-4F2F-93E2-DDC68059B1A3}
publisher: ICN, iC ComPass, SBS SOL, SBS SEC3
comments: Software Package provided by Siemens AG
contact: For support call your local help desk
Apple Mobile Device Support [removed] ({44734179-8A79-4DEE-BB08-73037F065543})
version: 16842756
version (major): 1
version (minor): 1
estimated size: 34842
install date: 20080606
install location: C:\Program Files\Common Files\Apple\Mobile Device Support\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
BufferChm 70.0.170.000 ({45B8A76B-57EC-4242-B019-066400CD8428})
version: 1174405290
version (major): 70
estimated size: 1657
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\BufferChm\
publisher: Hewlett-Packard
Bonjour 1.0.104 ({47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3})
version: 16777320
version (major): 1
estimated size: 3317
install date: 20080405
install location: C:\Program Files\Bonjour\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\IXP759.TMP\
uninstall cmd: MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
Flash Player 9 9.0.115.0 ({4841D7F0-C0EE-485E-8F34-FD6CFF854FF1})
version: 150995059
version (major): 9
estimated size: 2897
install date: 20080125
install source: C:\WINNT\CatPC\LIA\LSDP\BR0100263\
uninstall cmd: MsiExec.exe /I{4841D7F0-C0EE-485E-8F34-FD6CFF854FF1}
publisher: Adobe Inc.
comments: Software Package authored based on system capture by Siemens AG,CAT@Siemens
contact: For support call your local HelpDesk
help link: ""
help telephone: ""
readme: ""
SMS Advanced Client 2.50.4253.3000 ({4A39A27F-005B-407E-8CF5-F4D8065658E4})
version: 36835485
version (major): 2
version (minor): 50
estimated size: 11074
install date: 20080915
install source: C:\WINNT\system32\ccmsetup\{2FBB7E06-7665-442B-98E3-189CB634C5CC}\
publisher: Microsoft Corporation
Nokia Multimedia Factory 1.3.2.0 ({4CFB3821-1582-4F3B-BF8D-30986923B36B})
version: 16973826
version (major): 1
version (minor): 3
estimated size: 9299
install date: 20080216
install location: C:\Program Files\Nokia\Nokia PC Suite 6\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{4CFB3821-1582-4f3b-BF8D-30986923B36B}\Installations\NokiaMultimediaFactoryMSI\
uninstall cmd: MsiExec.exe /I{4CFB3821-1582-4F3B-BF8D-30986923B36B}
publisher: Nokia
help link: http://www.nokia.com/pcsuite
HTML Slideshow Powertoy for Windows XP 1.0.2.0 ({4E475FD4-4513-4B1D-8DDA-43912B068C99})
version: 16777218
version (major): 1
estimated size: 600
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{4E475FD4-4513-4B1D-8DDA-43912B068C99}
publisher: Microsoft Corporation
comments: HTML Slideshow Powertoy for Windows XP
contact: Microsoft Corporation>
help link: http://www.microsoft.com/windowsxp
readme: http://www.microsoft.com/windowsxp
HPProductAssistant 70.0.170.000 ({4EA684E9-5C81-4033-A696-3019EC57AC3A})
version: 1174405290
version (major): 70
estimated size: 4531
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\hpproductassistant\
publisher: Hewlett-Packard
ICM PowerPoint Templates 1.0 1.0.0.0 ({4ED3CBA6-8984-41BF-BE3E-116476140436})
version: 16777216
version (major): 1
estimated size: 18537
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0300082\
uninstall cmd: MsiExec.exe /I{4ED3CBA6-8984-41BF-BE3E-116476140436}
publisher: Siemens AG
comments: Software package provided by Siemens AG
contact: For support call your local help desk
BlackBerry Connect Desktop for Nokia 4.0.0 ({5238A932-32B7-4F62-B384-869A23DEA4BE})
version: 67108864
version (major): 4
estimated size: 3632
install date: 20080103
install source: C:\Documents and Settings\vm092543\Local Settings\Application Data\{D76BC089-A308-4D85-AF2F-5CBBF3E3ACC5}\
publisher: Research In Motion, Ltd.
DirXdiscover 5.0C English 5.0.5.5 ({55603446-2604-4B67-973F-152588683D8B})
version: 83886085
version (major): 5
estimated size: 10118
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\MC0100027\
uninstall cmd: MsiExec.exe /I{55603446-2604-4B67-973F-152588683D8B}
publisher: Siemens AG
comments: Software Package authored based on system capture by Siemens AG, CAT@Siemens
contact: For support call your local HelpDesk
help link: " "
help telephone: " "
readme: " "
TriggerPointEditor 6.1.0 ({556E7F99-8A88-49C5-BA3D-47C2A1430DC5})
version: 100728832
version (major): 6
version (minor): 1
estimated size: 1068
install date: 20081118
install source: D:\Data\Documents\IMS\6.0\HSSd\Trigger Point Editor\
uninstall cmd: MsiExec.exe /I{556E7F99-8A88-49C5-BA3D-47C2A1430DC5}
publisher: Nokia Siemens Networks
contact: Paul Kubitscheck
help telephone: +49 89 72263706
neroxml 1.0.0 ({56C049BE-79E9-4502-BEA7-9754A3E60F9B})
version: 16777216
version (major): 1
estimated size: 48
install date: 20071021
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\NERO13390\Redist\
uninstall cmd: MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
publisher: Nero AG
contact: Nero AG
SMOC 1.3.54.0 ({580343FF-B12B-49A6-BAB7-D1CF407FA9FB})
version: 16973878
version (major): 1
version (minor): 3
estimated size: 1176
install date: 20070927
install location: C:\Program Files\AccessManager\SMOC\
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\
publisher:
help link:
help telephone:
iTunes 7.6.2.9 ({585776BC-4BD6-4BD2-A19A-1D6CB44A403B})
version: 117833730
version (major): 7
version (minor): 6
estimated size: 75108
install date: 20080606
install location: C:\Program Files\iTunes\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
ServiceLauncher 1.0.1.36 ({5AFAA589-F446-4D9E-AAD6-B8C9B43BEB08})
version: 16777217
version (major): 1
estimated size: 265
install date: 20080513
install source: \\nsn-intra.net\dfsres\nsndp\P-\N-CP0005001\
publisher: SIS GO GIO DS PSU3
comments: Software Package authored based on system capture by Siemens AG.
contact: For support call your local help desk
Shockwave Player 10.1.1 10.1.1.16 ({5C4CA537-82B3-48EF-B5F8-ABA673107567})
version: 167837697
version (major): 10
version (minor): 1
estimated size: 4298
install date: 20070926
install location: C:\WINNT\system32\Macromed\
install source: \\nsn-intra.net\dfsres\nsndp\P-\BR0100179\
uninstall cmd: MsiExec.exe /I{5C4CA537-82B3-48EF-B5F8-ABA673107567}
publisher: Macromedia
comments: ""
contact: ""
IP VPN RS Nortel 4.00.0020 ({5D1DEA4B-1BC3-438B-B75A-01827209B916})
version: 67108884
version (major): 4
estimated size: 4384
install date: 20070927
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\software\vpnclnt\
uninstall cmd: MsiExec.exe /X{5D1DEA4B-1BC3-438B-B75A-01827209B916}
publisher: MCI
comments: .
contact: .
help link: .
help telephone:
Internet Explorer 6.0 SP2 6.0.2900.2180 ({5DD0FD76-DFA1-4274-BF35-09D2B4386E31})
version: 100666196
version (major): 6
estimated size: 143
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\br0000042\
uninstall cmd: MsiExec.exe /I{5DD0FD76-DFA1-4274-BF35-09D2B4386E31}
publisher: Microsoft Corp.
comments: Software Package authored based on system capture by Siemens AG, CAT@Siemens
contact: For support call your local HelpDesk
help link: " "
help telephone: " "
readme: " "
WebReg 70.0.170.000 ({66910000-8B30-4973-A159-6371345AFFA5})
version: 1174405290
version (major): 70
estimated size: 525
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\WebReg\
publisher: Hewlett-Packard
eSupportQFolder 1.00.0000 ({66E6CE0C-5A1E-430C-B40A-0C90FF1804A8})
version: 16777216
version (major): 1
estimated size: 124
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\QFolder\
publisher: Hewlett-Packard
CmdHere Powertoy For Windows XP 1.00.0001 ({6855CCDD-BDF9-48E4-B80A-80DFB96FE36C})
version: 16777217
version (major): 1
estimated size: 5
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}
publisher: Microsoft Corporation
comments: CmdHere Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
AiOSoftwareNPI 70.0.231.000 ({68763C27-235D-4165-A961-FDEA228CE504})
version: 1174405351
version (major): 70
estimated size: 3366
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\AiOSoftwarenpi\
publisher: Hewlett-Packard
Toolbox 70.0.170.000 ({6909F917-5499-482e-9AA1-FAD06A99F231})
version: 1174405290
version (major): 70
estimated size: 5709
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\Toolbox\
publisher: Hewlett-Packard
iPassConnect English 3.55.0.0 ({6E6547D1-34A8-4105-857B-BC21FC70DAD3})
version: 53936128
version (major): 3
version (minor): 55
estimated size: 157158
install date: 20081202
install location: C:\Program Files\iPass\iPassConnect\
install source: C:\ccmcache\Z0100319.9.System\
uninstall cmd: MsiExec.exe /I{6E6547D1-34A8-4105-857B-BC21FC70DAD3}
publisher: iPass Inc.
comments: Software package provided by NSN
contact: For support call the NSN Service Desk
Microsoft .NET Framework 2.0 2.0.50727 ({7131646D-CD3C-40F4-97B9-CD9E4E6262EF})
version: 33605159
version (major): 2
estimated size: 234943
install date: 20070926
install source: C:\WINNT\CatPC\temp\OS0200031\
publisher: Microsoft Corporation
Microsoft Visual C++ 2005 Redistributable 8.0.56336 ({7299052b-02a4-4627-81f2-1818da5d550d})
version: 134274064
version (major): 8
estimated size: 5330
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\IXP001.TMP\
uninstall cmd: MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
publisher: Microsoft Corporation
Readme 70.0.231.000 ({736C803C-DD3B-4015-BC51-AFB9E67B9076})
version: 1174405351
version (major): 70
estimated size: 44
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\readme\
publisher: Hewlett-Packard
({7A926FF0-3E6E-4BA0-9EBD-4D03448FA769})
ProductContextNPI 70.0.231.000 ({7E7B7865-6C80-4373-8BC1-C2EB9431F9DE})
version: 1174405351
version (major): 70
estimated size: 1
install date: 20071006
install source: C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\
publisher: Hewlett-Packard
Status 70.0.170.000 ({8331C3EA-0C91-43AA-A4D4-27221C631139})
version: 1174405290
version (major): 70
estimated size: 3260
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\Status\
publisher: Hewlett-Packard
MSXML 4.0 SP2 (KB954430) 4.20.9870.0 ({86493ADD-824D-4B8E-BD72-8C5DCDC52A71})
version: 68429454
version (major): 4
version (minor): 20
estimated size: 2729
install date: 20081124
install source: d:\38f00d96e5ab374948\
uninstall cmd: MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/954430
DocProcQFolder 1.00.0000 ({87E2B986-07E8-477a-93DC-AF0B6758B192})
version: 16777216
version (major): 1
estimated size: 120
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\QFolder\
publisher: Hewlett-Packard
Microsoft Silverlight 2.0.30523.8 ({89F4137D-6C26-4A84-BDB8-2E5A4BB71E00})
version: 33584955
version (major): 2
estimated size: 4704
install date: 20080815
install source: d:\5763206a7b40bc5e09f0b954ac5de0b8\
uninstall cmd: MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkID=91955
DocProc 7.0.0.0 ({8A4CE7FD-9657-4B06-9943-E1819F3D5D67})
version: 117440512
version (major): 7
estimated size: 77615
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\DocProc\
publisher: Hewlett-Packard
comments: 0
contact: 0
help link: 0
help telephone: 0
readme: 0
3.0.7.009 ({8ADC27DB-E2C8-446C-A576-166C05C2DD24})
version: 50331655
version (major): 3
estimated size: 184
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\HPSoftwareUpdate\
publisher: Hewlett-Packard
Unload 7.0.0 ({8CE4E6E9-9D55-43FB-9DDB-688C976BFC05})
version: 117440512
version (major): 7
estimated size: 8361
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\UnloadIntent\
publisher: Hewlett-Packard
comments: 0
contact: 0
help link: 0
help telephone: 0
readme: 0
Microsoft Office Professional Edition 2003 11.0.7969.0 ({90110409-6000-11D3-8CFE-0150048383C9})
version: 184557345
version (major): 11
estimated size: 518782
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0000116\
uninstall cmd: MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Office\OFFICE11\1033\OFREADME.HTM
Compatibility Pack for the 2007 Office system 12.0.4518.1014 ({90120000-0020-0409-0000-0000000FF1CE})
version: 201331110
version (major): 12
estimated size: 63775
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0200532\
uninstall cmd: MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation
comments: Software Package provided by Siemens AG; CAT@Siemens
contact: For support call your local help desk
Microsoft Office 2003 German User Interface Pack 11.0.7969.0 ({901E0407-6000-11D3-8CFE-0150048383C9})
version: 184557345
version (major): 11
estimated size: 205423
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\LP0000071\
uninstall cmd: MsiExec.exe /I{901E0407-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Office\OFFICE11\MUIREAD.HTM
Microsoft Office Visio Professional 2003 11.0.3216.5614 ({90510409-6000-11D3-8CFE-0150048383C9})
version: 184552592
version (major): 11
estimated size: 195109
install date: 20071006
install location: C:\Program Files\Microsoft Office\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\pftDE.tmp\
uninstall cmd: MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Office\Visio11\1033\VIREADME.HTM
Microsoft Organization Chart 2.0 11.0.5614.0 ({90AE0409-6000-11D3-8CFE-0150048383C9})
version: 184554990
version (major): 11
estimated size: 1889
install date: 20070926
install location: C:\Program Files\Microsoft Office\
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0600032\
uninstall cmd: MsiExec.exe /I{90AE0409-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
Remove Hidden Data Tool 11.0.6361.0 ({90F80409-6000-11D3-8CFE-0150048383C9})
version: 184555737
version (major): 11
estimated size: 365
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{90F80409-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
InterVideo WinDVD ({98E8A2EF-4EAE-43B8-A172-74842B764777})
version (major): 4
install location: C:\Program Files\InterVideo\WinDVD
uninstall cmd: "C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALL
publisher: InterVideo Inc.
ScannerCopy 7.0.0.0 ({996512CF-F35B-48DE-9291-557FA5316967})
version: 117440512
version (major): 7
estimated size: 3202
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\ScannerCopy\
publisher: Hewlett-Packard
comments: 0
contact: 0
help link: 0
help telephone: 0
readme: 0
Dell Touchpad 7.1.102.7 ({9F72EF8B-AEC9-4CA5-B483-143980AFD6FD})
uninstall cmd: C:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
publisher: Alps Electric
SigmaTel Audio 5.10.4820.0 ({A462213D-EED4-42C2-9A60-7BDD4D4B0B17})
version: 84546260
install date: 20070927
install location: C:\Program Files\SigmaTel\C-Major Audio
install source: C:\dell\drivers\R153908\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
publisher: SigmaTel
Microsoft Visual C++ 2005 Redistributable 8.0.50727.42 ({A49F249F-0C91-497F-86DF-B2585E8E76B7})
version: 134268455
version (major): 8
estimated size: 4584
install date: 20081021
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
publisher: Microsoft Corporation
MATLAB Component Runtime 7.4 ({A5A65472-F1BD-4EB3-B244-0A8007365FBA})
version: 117702656
version (major): 7
version (minor): 4
estimated size: 268976
install date: 20071112
install location: C:\Program Files\MATLAB\MATLAB Component Runtime\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\_is49\
uninstall cmd: MsiExec.exe /I{A5A65472-F1BD-4EB3-B244-0A8007365FBA}
publisher: The MathWorks
comments: MATLAB Component Runtime Installer
contact: The MathWorks, Inc.
help link: www.mathworks.com
help telephone: [removed]
Alt-Tab Task Switcher Powertoy for Windows XP 1.00.0001 ({A7050037-F0EA-4BAB-BCD5-FC05507D6147})
version: 16777217
version (major): 1
estimated size: 41
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{A7050037-F0EA-4BAB-BCD5-FC05507D6147}
publisher: Microsoft Corporation
comments: Alt-Tab Task Switcher Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
Timershot Powertoy for Windows XP 1.00.0001 ({A743BBCC-3438-4BB3-8397-6C9D9AC125A6})
version: 16777217
version (major): 1
estimated size: 184
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{A743BBCC-3438-4BB3-8397-6C9D9AC125A6}
publisher: Microsoft Corporation
comments: Timershot Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
Lotus Notes 5.0.12.0 ({A7D69D97-BD43-4708-BC68-245E5B7B6C1E})
version: 83886092
version (major): 5
estimated size: 109476
install date: 20070927
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licensed\Notes\
uninstall cmd: MsiExec.exe /I{A7D69D97-BD43-4708-BC68-245E5B7B6C1E}
publisher: Lotus Development GmbH
comments: Software package provided by Siemens AG
contact: For support contact you local Help Desk
OSCE_MSI_NT_CLIENT 7.3 ({A97792EC-E172-4B38-85DD-0F853599D5EF})
version: 117637120
version (major): 7
version (minor): 3
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\AV0000062\
publisher: Trend Micro
help link: http://www.trendmicro.com
DeviceManagementQFolder 1.00.0000 ({AB5D51AE-EBC3-438D-872C-705C7C2084B0})
version: 16777216
version (major): 1
estimated size: 124
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\QFolder\
publisher: Hewlett-Packard
Adobe Acrobat 8 Professional - English, Français, Deutsch 8.0.0 ({AC76BA86-1033-F400-7760-000000000003})
version: 134217728
version (major): 8
estimated size: 1322821
install date: 20071006
install location: C:\Program Files\Adobe\Acrobat 8.0\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\Adobe Acrobat 8.0\
publisher: Adobe Systems
comments:
contact: Customer Support
help link: http://www.adobe.com/support/main.html
help telephone:
readme: C:\Program Files\Adobe\Acrobat 8.0\Readme.htm
Adobe Reader 7.0.9 German 7.0.9 ({AC76BA86-7AD7-1031-7B44-A70000000000})
version: 117440521
version (major): 7
estimated size: 78108
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\WT0000144\
uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A70000000000}
publisher: Adobe Systems Incorporated
comments:
contact: Customer Support Department
help link: http://www.adobe.de/support/main.html
help telephone:
readme: C:\Program Files\Adobe\Acrobat 7.0\Reader\Readme.htm
Adobe Reader Japanese Fonts 7.00.000 ({AC76BA86-7AD7-5A76-5A64-7E8A45000001})
version: 117440512
version (major): 7
estimated size: 21462
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0600062\
uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-5A76-5A64-7E8A45000001}
publisher: Adobe Systems
comments: ""
contact: Customer Support
help link: http://www.adobe.com/support/main.html
help telephone: [removed]
WebTrain Communicator 3.5.0.10 ({AF833083-331F-4EC2-8FAA-FE0B8BF12C0E})
version: 50659328
version (major): 3
version (minor): 5
estimated size: 13270
install date: 20071115
install source: C:\Documents and Settings\vm092543\Local Settings\Temporary Internet Files\Content.IE5\QN5FZ02X\
uninstall cmd: MsiExec.exe /I{AF833083-331F-4EC2-8FAA-FE0B8BF12C0E}
publisher: WebTrain Communications
comments: Zip / Authenticode CAB versions also available on website
contact: WebTrain Technical Support
help link: http://www.microsoft.com/management
help telephone: [removed]
Calculator Powertoy for Windows XP 1.00.0001 ({B37C842A-B624-46B8-A727-654E72F1C91A})
version: 16777217
version (major): 1
estimated size: 224
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{B37C842A-B624-46B8-A727-654E72F1C91A}
publisher: Microsoft Corporation
comments: Calculator Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
Spybot - Search & Destroy 1.6.0 ({B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1)
install date: 20080925
install location: C:\Program Files\Spybot\
uninstall cmd: "C:\Program Files\Spybot\unins000.exe"
publisher: Safer Networking Limited
help link: http://www.safer-networking.org/index.php?page=support
Microsoft .NET Framework (English) 1.0.3705 ({B43357AA-3A6D-4D94-B56E-43C44D09E548})
version: 16780921
version (major): 1
estimated size: 48744
install date: 20070926
install source: C:\WINNT\CatPC\temp\OS0200007\
uninstall cmd: MsiExec.exe /X{B43357AA-3A6D-4D94-B56E-43C44D09E548}
publisher: Microsoft
SyncToy 1.4 ({B5688129-7595-4E5B-9990-CEF981A31264})
version: 17039360
version (major): 1
version (minor): 4
estimated size: 2656
install date: 20080626
install source: D:\Data\Downloads\
uninstall cmd: MsiExec.exe /I{B5688129-7595-4E5B-9990-CEF981A31264}
publisher: Microsoft
comments: Synchronization Powertoy
contact: Microsoft
TextPad 5 5.2.0 ({B6EC7388-E277-4A5B-8C8F-71067A41BA64})
version: 84017152
version (major): 5
version (minor): 2
estimated size: 4780
install date: 20080810
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\{B7F69EDA-28A2-41A5-B411-2EEDB1008E7C}\
uninstall cmd: MsiExec.exe /X{B6EC7388-E277-4A5B-8C8F-71067A41BA64}
publisher: Helios
comments: Your Comments
contact: Customer Support Department
help link: http://www.textpad.com/support/
help telephone: http://www.textpad.com/support/
DivX Web Player 1.3.1 ({B7050CBDB2504B34BC2A9CA0A692CC29})
install location: C:\Program Files\DivX
uninstall cmd: C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
publisher: DivX,Inc.
HP Software Update 3.0.7.014 ({BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E})
version: 50331655
version (major): 3
estimated size: 3506
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\HPSoftwareUpdate\
uninstall cmd: MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
publisher: HEWLET~1|Hewlett-Packard
contact: http://www.hp.com/support
Netflix Movie Viewer 1.2.211 ({BCE72AED-3332-4863-9567-C5DCB9052CA2})
version: 16908499
version (major): 1
version (minor): 2
estimated size: 1564
install date: 20081201
install location: C:\Program Files\Netflix\Netflix Movie Viewer\
install source: C:\Documents and Settings\vm092543\Local Settings\Temporary Internet Files\Content.IE5\VHRMMI1K\
uninstall cmd: MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}
publisher: Netflix
comments: Netflix Movie Viewer
contact: Netflix Customer Service
help link: www.netflix.com/Help
HP Photosmart, Officejet and Deskjet 7.0.A ({BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C})
uninstall cmd: C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
publisher: HP
help link: http://www.hp.com/support
4.20.9848.0 ({C04E32E0-0416-434D-AFB9-6969D703A9EF})
version: 68429432
version (major): 4
version (minor): 20
estimated size: 2681
install date: 20080125
install source: C:\WINNT\CatPC\LIA\LSDP\BR0100248\
uninstall cmd: MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/936181
Slideshow Generator Powertoy for Windows XP 1.00.0001 ({C39DE425-6CCF-4B12-A101-3CB5CF3AF3AD})
version: 16777217
version (major): 1
estimated size: 81
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{C39DE425-6CCF-4B12-A101-3CB5CF3AF3AD}
publisher: Microsoft Corporation
comments: Slideshow Generator Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
German Menus and Dialogs for Internet Explorer 6.0 6.0.2800.1106 ({C69EF57A-2F95-4188-8B22-1D03D2673C62})
version: 100666096
version (major): 6
estimated size: 5175
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\LP0000041\
uninstall cmd: MsiExec.exe /I{C69EF57A-2F95-4188-8B22-1D03D2673C62}
publisher: Microsoft Corp.
comments: Software Package authored based on system capture by Siemens AG, CAT@Siemens
contact: For support call your local HelpDesk
help link: " "
help telephone: " "
readme: " "
SolutionCenter 70.0.170.000 ({C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476})
version: 1174405290
version (major): 70
estimated size: 7940
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\SolutionCenter\
publisher: Hewlett-Packard
AiO_Scan_CDA 70.0.231.000 ({C8753E28-2680-49BF-BD48-DD38FD086EFE})
version: 1174405351
version (major): 70
estimated size: 701
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\AiO_Scan\
publisher: Hewlett-Packard
ClearType Tuning Control Panel Applet 1.01.0000 ({C9E4932C-8417-4E4C-A0E3-EE534810AB4D})
version: 16842752
version (major): 1
version (minor): 1
estimated size: 253
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\_is41\
uninstall cmd: MsiExec.exe /I{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}
publisher: Microsoft Corporation
comments: Your Comments
contact: Customer Support Department
help link: http://www.microsoft.com
help telephone:
Microsoft .NET Framework 1.1 1.1.4322 ({CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1})
version: 16847074
version (major): 1
version (minor): 1
estimated size: 69906
install date: 20070926
install source: C:\WINNT\CatPC\temp\OS0200009\
uninstall cmd: MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
publisher: Microsoft
Nokia Connectivity Cable Driver 7.1.6.0 ({CBDE9C7D-CF52-4558-B23E-B66359CB586A})
version: 117506054
version (major): 7
version (minor): 1
estimated size: 2730
install date: 20081203
install location: C:\Program Files\Nokia\Connectivity Cable Driver\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{0332234E-09D1-4B74-A5F3-73E34BA29F5B}\Packages\CCD\Setup\
uninstall cmd: MsiExec.exe /X{CBDE9C7D-CF52-4558-B23E-B66359CB586A}
publisher: Nokia
help link: http://www.nokia.com/nokia/0,8764,75877,00.html
Bluetooth Stack for Windows by Toshiba v4.31.02.6(D) ({CEBB6BFB-D708-4F99-A633-BC2600E01EF6})
version: 67108864
version (major): 4
version (minor): 31
estimated size: 31267
install date: 20071008
install location: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
install source: C:\dell\drivers\R155172\2kxp\
uninstall cmd: MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
3100_3200_3300_Help 70.0.231.000 ({D002159B-91CD-48E5-96D1-C476BA3DECB3})
version: 1174405351
version (major): 70
estimated size: 6545
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\Setup\AiOHelp\
publisher: Hewlett-Packard
DivX Content Uploader 1.2.1 ({D050D7362D214723AD585B541FFB6C11})
install location: C:\Program Files\DivX
uninstall cmd: C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
publisher: DivX, Inc.
3100_3200_3300trb 70.0.231.000 ({D3227BD6-7D66-4B96-BA01-C21FB1F2224D})
version: 1174405351
version (major): 70
estimated size: 233
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\Setup\AiOHelp\
publisher: Hewlett-Packard
Broadcom Gigabit Integrated Controller 10.15.08 ({D3B3B9B2-FE73-44CB-8C0A-F737D92F991B})
version: 168755208
version (major): 10
version (minor): 15
estimated size: 480
install date: 20070927
install location: C:\Program Files\Broadcom\
install source: C:\dell\drivers\R151327\
uninstall cmd: MsiExec.exe /X{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}
publisher: Broadcom Corporation
contact: Dell Customer Support
help link: http://www.support.dell.com
Altova AltovaXML™ 2008 rel. 2 sp2 2008.02.02 ({D49BC58E-7680-4101-A511-6603C8A3B2DB})
version (major): 2008
version (minor): 2
estimated size: 28286
install date: 20081030
install location: C:\Program Files\Altova\
install source: C:\WINNT\Downloaded Installations\{AB927108-21D7-4197-B5F4-1198BE0F157E}\
uninstall cmd: MsiExec.exe /I{D49BC58E-7680-4101-A511-6603C8A3B2DB}
publisher: Altova
comments: Please use the Support URL unless you have a telephone support contract
contact: Customer Support Department
help link: http://www.altova.com/support
help telephone: [removed]
Nokia PC Suite 7.0.9.2 ({D5577624-0626-4C4B-87AA-D966DA1739D6})
version: 117440521
version (major): 7
estimated size: 53886
install date: 20081109
install location: C:\Program Files\Nokia\Nokia PC Suite 7\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{D5577624-0626-4C4B-87AA-D966DA1739D6}\Packages\Nokia_PC_Suite\Setup\
uninstall cmd: MsiExec.exe /I{D5577624-0626-4C4B-87AA-D966DA1739D6}
publisher: Nokia
help link: http://www.nokia.com/nokia/0,8764,75877,00.html
Remove Hidden Data Tool 11.0.6361.0 ({D5A55E84-1C14-46F1-8718-1D91F2351FC5})
version: 184555737
version (major): 11
estimated size: 366
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0600038\
uninstall cmd: MsiExec.exe /X{D5A55E84-1C14-46F1-8718-1D91F2351FC5}
publisher: Microsoft Corporation
TrayApp 70.0.170.000 ({DBC20735-34E6-4E97-A9E5-2066B66B243D})
version: 1174405290
version (major): 70
estimated size: 707
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\TrayApp\
publisher: Hewlett-Packard
Microsoft Capicom 2.1.0.2 ({DEAECFA9-FC4E-4AE5-9B1B-14A3A7EC1DE8})
version: 33619968
version (major): 2
version (minor): 1
estimated size: 969
install date: 20080125
install source: C:\WINNT\CatPC\LIA\LSDP\CP0100407\
uninstall cmd: MsiExec.exe /X{DEAECFA9-FC4E-4AE5-9B1B-14A3A7EC1DE8}
publisher: Microsoft Corp.
comments: Software package provided by Siemens AG
contact: For support call your local help desk
help link: ""
help telephone: ""
readme: ""
3300 70.0.231.000 ({E1D94FAD-CFA4-4B76-91D9-28F5AB18A431})
version: 1174405351
version (major): 70
estimated size: 66
install date: 20071006
install source: C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\Product\
publisher: Hewlett-Packard
Digital Line Detect 1.21 ({E646DCF0-5A68-11D5-B229-002078017FBF})
version: 18153472
install date: 20070927
install location: C:\Program Files\Digital Line Detect
install source: C:\dell\drivers\R148605\
uninstall cmd: C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\Setup.exe -runfromtemp -l0x0009 -removeonly
publisher: BVRP Software, Inc
WinZip 8.1 SR2 English 14.0.5791.0 ({E817FC5E-170A-493E-82F8-95C1C64A54FA})
version: 234886815
version (major): 14
estimated size: 4311
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\PA0000025\
uninstall cmd: MsiExec.exe /I{E817FC5E-170A-493E-82F8-95C1C64A54FA}
publisher: Winzip
comments: Software package provided by Siemens AG
contact: For support call your local help desk
IP VPN Remote Services ({EF964A78-078C-11D1-B7A7-0000C0134CE6})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF964A78-078C-11D1-B7A7-0000C0134CE6}\setup.exe" Uninstall
Nero 7 Ultra Edition 7.02.0936 ({F14B8ECC-BDA0-4987-9201-D7B7DBE11033})
version: 117572520
version (major): 7
version (minor): 2
estimated size: 222528
install date: 20071021
install location: C:\Program Files\Nero\Nero 7\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\NeroDemo11237\
uninstall cmd: MsiExec.exe /I{F14B8ECC-BDA0-4987-9201-D7B7DBE11033}
publisher: Nero AG
comments: Nero AG
contact: [removed]
help link: http://www.nero.com/
InstantShareDevicesMFC 70.0.170.000 ({F157460F-720E-482f-8625-AD7843891E5F})
version: 1174405290
version (major): 70
estimated size: 2580
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\InstantShareDevicesMFC\
publisher: Hewlett-Packard
({F1BC653B-BBDD-4B32-A9FD-3E709833BAF8})
Virtual Desktop Manager Powertoy for Windows XP 1.00.0001 ({F251B999-08A9-4704-999C-9962F0DFD88E})
version: 16777217
version (major): 1
estimated size: 149
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{F251B999-08A9-4704-999C-9962F0DFD88E}
publisher: Microsoft Corporation
comments: Virtual Desktop Manager Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
Scan 7.0.0.0 ({F3760724-B29D-465B-BC53-E5D72095BCC4})
version: 117440512
version (major): 7
estimated size: 9900
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\Scan\
publisher: Hewlett-Packard
comments: 0
contact: 0
help link: 0
help telephone: 0
readme: 0
Fax_CDA 70.0.231.000 ({F6076EF9-08E1-442F-B6A2-BFB61B295A14})
version: 1174405351
version (major): 70
estimated size: 22006
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\fax\
publisher: Hewlett-Packard
Destinations 70.0.170.000 ({FB15E224-67C3-491F-9F5C-F257BC418412})
version: 1174405290
version (major): 70
estimated size: 17221
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\Destinations\
publisher: Hewlett-Packard
NewCopy_CDA 70.0.231.000 ({FBB980B0-63F8-4B48-8D65-90F1D9F81D9F})
version: 1174405351
version (major): 70
estimated size: 1513
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\newcopy\
publisher: Hewlett-Packard
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 9.0.21022 ({FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4})
version: 151015966
version (major): 9
estimated size: 6844
install date: 20081201
install source: d:\37472a24a871e7d62279a55f328f6b5a\
uninstall cmd: MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
publisher: Microsoft Corporation
— System Services —
Service (registry key): .NET CLR Data
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET CLR Networking
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET Data Provider for Oracle
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET Data Provider for SqlServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NETFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Abiosdsk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0
Service (registry key): abp480n5
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ACPI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft ACPI Driver
Image path: system32\DRIVERS\ACPI.sys
Image size: 187776
Image MD5: A10C7534F7223F4A73A948967D00E69B
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): ACPIEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): adpu160m
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): aec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Acoustic Echo Canceller
Image path: system32\drivers\aec.sys
Image size: 142464
Image MD5: 841F385C6CFAF66B58FBD898722BB4F0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): AFD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AFD
Description: AFD Networking Support Environment
Image path: \SystemRoot\System32\drivers\afd.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Aha154x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): aic78u2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): aic78xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Alerter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Alerter
Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation
Service (registry key): ALG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Layer Gateway Service
Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\alg.exe
Image size: 44544
Image MD5: F1958FBF86D5C004CF19A5951A9514B7
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): AliIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): AMBroker
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Access Manager Configuration Service
Object name: LocalSystem
Image path: "C:\Program Files\AccessManager\Client\AMBroker.exe"
Image size: 77824
Image MD5: 0A8446FEA210A30C07B8DD879858ED35
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): amsint
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ApfiltrService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Alps Touch Pad Filter Driver for Windows 2000/XP/Vista
Image path: system32\DRIVERS\Apfiltr.sys
Image size: 155136
Image MD5: 350F19EB5FE4EC37A2414DF56CDE1AA8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): Apple Mobile Device
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Apple Mobile Device
Description: Provides the interface to Apple mobile devices.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
Image size: 110592
Image MD5: 1961CB10BB48EB4D97E37DB6373E9E63
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: Tcpip
Service (registry key): AppMgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Management
Description: Provides software installation services such as Assign, Publish, and Remove.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): Arp1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 ARP Client Protocol
Description: 1394 ARP Client Protocol
Image path: system32\DRIVERS\arp1394.sys
Image size: 60800
Image MD5: F0D692B0BFFB46E30EB3CEA168BBC49F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): asc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): asc3350p
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): asc3550
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ASP.NET
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): ASP.NET_1.1.4322
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): ASP.NET_2.0.50727
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): aspnet_state
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ASP.NET State Service
Description: Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
Image size: 33632
Image MD5: E1633440859F9A1B3CEAF73BA85225CA
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): AsyncMac
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: RAS Asynchronous Media Driver
Description: RAS Asynchronous Media Driver
Image path: system32\DRIVERS\asyncmac.sys
Image size: 14336
Image MD5: 02000ABF34AF4C218C35D257024807D6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): atapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Standard IDE/ESDI Hard Disk Controller
Image path: system32\DRIVERS\atapi.sys
Image size: 95360
Image MD5: CDFE4411A69C224BD1D11B2DA92DAC51
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): Atdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0
Service (registry key): Atmarpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ATM ARP Client Protocol
Description: ATM ARP Client Protocol
Image path: system32\DRIVERS\atmarpc.sys
Image size: 59904
Image MD5: EC88DA854AB7D7752EC8BE11A741BB7F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): AudioSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Audio
Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs
Service (registry key): audstub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Audio Stub Driver
Image path: system32\DRIVERS\audstub.sys
Image size: 3072
Image MD5: D9F724AA26C010A217C97606B160ED68
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): b57w2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Broadcom NetXtreme Gigabit Ethernet
Image path: system32\DRIVERS\b57xp32.sys
Image size: 160256
Image MD5: F96038AA1EC4013A93D2420FC689D1E9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BattC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): BCM43XX
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Dell Wireless WLAN Card Driver
Image path: system32\DRIVERS\bcmwl5.sys
Image size: 604928
Image MD5: B89BCF0A25AEB3B47030AC83287F894A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BCMLogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: BCMLogon
Description: Provides credential information (user name, password, domain) used by wireless management software for login to wireless networks. Optionally enables wireless login at startup for SSO environments.
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Beep
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): BITS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Background Intelligent Transfer Service
Description: Transfers data between clients and servers in the background. If BITS is disabled, features such as Windows Update will not work correctly.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): Bonjour Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bonjour Service
Description: Enables hardware devices and software services to automatically configure themselves on the network and advertise their presence, so that users can discover and use those services without any unnecessary manual setup or administration.
Object name: LocalSystem
Image path: "C:\Program Files\Bonjour\mDNSResponder.exe"
Image size: 229376
Image MD5: CFD4C3352E29A8B729536648466E8DF5
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: Tcpip
Service (registry key): Browser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Computer Browser
Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,LanmanServer
Service (registry key): cbidf2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): CcmExec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SMS Agent Host
Description: Provides change and configuration services for computer management systems.
Object name: LocalSystem
Image path: C:\WINNT\system32\CCM\CcmExec.exe
Image size: 590712
Image MD5: E4B94F8EDB3540D43A473D552C30D395
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: winmgmt
Service (registry key): CcmFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): cd20xrnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Cdaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): Cdfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Depends On group: "SCSI CDROM Class"
Service (registry key): Cdrom
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-ROM Driver
Image path: system32\DRIVERS\cdrom.sys
Image size: 49536
Image MD5: AF9C19B3100FE010496B1A27181FBF72
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"
Service (registry key): Changer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): CiSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Indexing Service
Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
Object name: LocalSystem
Image path: %SystemRoot%\system32\cisvc.exe
Image size: 5632
Image MD5: 3192BD04D032A9C4A85A3278C268A13A
Control Set: CurrentControlSet
Start: 4
Type: 288
Error Control: 1
Depends On services: RPCSS
Service (registry key): ClipSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ClipBook
Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\clipsrv.exe
Image size: 33280
Image MD5: C8DEC22C4137D7A90F8BDF41CA4B82AE
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: NetDDE
Service (registry key): clr_optimization_v2.0.50727_32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: .NET Runtime Optimization Service v2.0.50727_X86
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
Image size: 68952
Image MD5: 3D560AF01BDC50B4A1E1BFB5CDC06D63
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Service (registry key): CmBatt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft AC Adapter Driver
Image path: system32\DRIVERS\CmBatt.sys
Image size: 14080
Image MD5: 4266BE808F85826AEDF3C64C1E240203
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): CmdIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Compbatt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Composite Battery Driver
Image path: system32\DRIVERS\compbatt.sys
Image size: 9344
Image MD5: DF1B1A24BF52D0EBC01ED4ECE8979F50
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): COMSysApp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ System Application
Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Image size: 5120
Image MD5: DD87DB7387B9EB441C5674888A0D840C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: rpcss
Service (registry key): ContentFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): ContentIndex
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Cpqarray
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): CryptSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Cryptographic Services
Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): CSRBC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CSRBC.Sys CSR test driver
Image path: System32\Drivers\csrbcxp.sys
Image size: 31744
Image MD5: 8E1945984E147562F9F08E1D344A69CC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): dac2w2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0
Service (registry key): dac960nt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): DAPlugin
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Visual Insight DA Plugin
Object name: LocalSystem
Image path: C:\Program Files\AccessManager\Client\DAPlugin.exe
Image size: 81920
Image MD5: 82636E971E7EAFEE84DC3A6CE7B36026
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): DcomLaunch
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DCOM Server Process Launcher
Description: Provides launch functionality for DCOM services.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost -k DcomLaunch
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): Dhcp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DHCP Client
Description: Manages network configuration by registering and updating IP addresses and DNS names.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd,NetBT
Service (registry key): Disk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Disk Driver
Image path: system32\DRIVERS\disk.sys
Image size: 36352
Image MD5: 00CA44E4534865F8A3B64F7C0984BFF0
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"
Service (registry key): dmadmin
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager Administrative Service
Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops.
Object name: LocalSystem
Image path: %SystemRoot%\System32\dmadmin.exe /com
Image size: 224768
Image MD5: 554C7CB178FE3BD12450B81AD63ADBC3
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay,DmServer
Service (registry key): dmboot
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmboot.sys
Image size: 799744
Image MD5: C0FBB516E06E243F0CF31F597E7EBF7D
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): dmio
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmio.sys
Image size: 153344
Image MD5: F5E7B358A732D09F4BCF2824B88B9E28
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): dmload
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmload.sys
Image size: 5888
Image MD5: E9317282A63CA4D188C0DF5E09C6AC5F
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): dmserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager
Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay
Service (registry key): DMService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Whale Component Manager
Description: Manages the Whale Client Components.
Object name: LocalSystem
Image path: C:\WINNT\DOWNLO~1\DMService.exe
Image size: 423576
Image MD5: 18637209B4F263124EAC3DB5A77B24D1
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): DMusic
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DLS Syntheiszer
Image path: system32\drivers\DMusic.sys
Image size: 52864
Image MD5: A6F881284AC1150E37D9AE47FF601267
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Dnscache
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DNS Client
Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip
Service (registry key): dpti2o
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): drmkaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DRM Audio Descrambler
Image path: system32\drivers\drmkaud.sys
Image size: 2944
Image MD5: 1ED4DBBAE9F5D558DBBA4CC450E3EB2E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Eacfilt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Eacfilt Miniport
Image path: system32\DRIVERS\eacfilt.sys
Image size: 9817
Image MD5: D5B58855861FB5DD21087788BD1995EA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): eBOSS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: eBOSS Helper
Object name: LocalSystem
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0
Service (registry key): el575nd5
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 3Com Megahertz 10/100 LAN CardBus PC Card Driver
Image path: system32\DRIVERS\el575nd5.sys
Image size: 69692
Image MD5: 23F6B9CF432F492EBBD8105D78CB008C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ERSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Error Reporting Service
Description: Allows error reporting for services and applictions running in non-standard environments.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs
Service (registry key): Eventlog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Event Log
Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 108032
Image MD5: C6CE6EEC82F187615D1002BB3BB50ED4
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): EventSystem
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ Event System
Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): ExtranetAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Contivity VPN Service
Object name: LocalSystem
Image path: "C:\Program Files\IP VPN Remote Services\Extranet_serv.exe"
Image size: 643072
Image MD5: D049BB8445005592967A71B7F3B089FE
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 0
Service (registry key): Fastfat
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Service (registry key): FastUserSwitchingCompatibility
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Fast User Switching Compatibility
Description: Provides management for applications that require assistance in a multiple user environment.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: TermService
Service (registry key): Fdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): Fips
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Firefly Media Server
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Firefly Media Server
Object name: LocalSystem
Image path: C:\Program Files\Firefly Media Server\firefly.exe
Image size: 499712
Image MD5: 23D720C989580B1A2CF79789BA2F8738
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: "Bonjour Service"
Service (registry key): FLEXnet Licensing Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: FLEXnet Licensing Service
Description: This service performs licensing functions on behalf of FLEXnet enabled products.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
Image size: 654848
Image MD5: 227846995AFEEFA70D328BF5334A86A5
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): Flpydisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): FltMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: FltMgr
Description: File System Filter Manager Driver
Image path: system32\DRIVERS\fltMgr.sys
Image size: 124800
Image MD5: 157754F0DF355A9E0A6F54721914F9C6
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1
Service (registry key): Fs_Rec
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 8
Error Control: 0
Service (registry key): Ftdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Manager Driver
Image path: system32\DRIVERS\ftdisk.sys
Image size: 125056
Image MD5: 6AC26732762483366C3969C9E4D2259D
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): GEARAspiWDM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: GEARAspiWDM
Image path: System32\Drivers\GEARAspiWDM.sys
Image size: 16168
Image MD5: 5DC17164F66380CBFEFD895C18467773
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Gpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Generic Packet Classifier
Description: Generic Packet Classifier
Image path: system32\DRIVERS\msgpc.sys
Image size: 35072
Image MD5: C0F1D4A21DE5A415DF8170616703DEBF
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): HDAudBus
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft UAA Bus Driver for High Definition Audio
Image path: system32\DRIVERS\HDAudBus.sys
Image size: 138752
Image MD5: 3FCC124B6E08EE0E9351F717DD136939
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): helpsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Help and Support
Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): HidServ
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HID Input Service
Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): HidUsb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft HID Class Driver
Image path: system32\DRIVERS\hidusb.sys
Image size: 9600
Image MD5: 1DE6783B918F540149AA69943BDFEBA8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): HP Port Resolver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HP Port Resolver
Object name: LocalSystem
Image path: C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE
Image size: 81920
Image MD5: C5F00D15AA15CB7F55A027FF75E44BB7
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): HP Status Server
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HP Status Server
Object name: LocalSystem
Image path: C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE
Image size: 73728
Image MD5: C5A288E4CEEF5A26D105117BAA3763AB
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): hpn
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): HSFHWAZL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\HSFHWAZL.sys
Image size: 209152
Image MD5: B1526810210980BED9D22315946C919D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): HSF_DPV
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\HSF_DPV.sys
Image size: 989696
Image MD5: DDBD528E60F5961C142A490DC4EA7780
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): HTTP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP
Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start.
Image path: System32\Drivers\HTTP.sys
Image size: 263040
Image MD5: C19B522A9AE0BBC3293397F3055E80A1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): HTTP Poster
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP Poster Service
Object name: LocalSystem
Image path: C:\WINNT\system32\HTTP_Poster.exe
Image size: 45056
Image MD5: D5B0476AFB0C425180FF60B0EE4735EC
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 0
Service (registry key): HTTPFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP SSL
Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP
Service (registry key): i2omgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): i2omp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): i8042prt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: i8042 Keyboard and PS/2 Mouse Port Driver
Image path: system32\DRIVERS\i8042prt.sys
Image size: 52736
Image MD5: 5502B58EEF7486EE6F93F3F164DCB808
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): ialm
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\igxpmp32.sys
Image size: 5707744
Image MD5: 200CCA76CD0E0F7EEC78FA56C29B4D67
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): idisntkm
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 0
Error Control: 0
Service (registry key): idisw2km
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\idisw2km.sys
Image size: 8992
Image MD5: E9CCE03BCE0585226DA5B2AB2A3E342E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): IDriverT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: InstallDriver Table Manager
Description: Provides support for the Running Object Table for InstallShield Drivers
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"
Image size: 69632
Image MD5: DAF66902F08796F9C694901660E5A64A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Service (registry key): Imapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-Burning Filter Driver
Image path: system32\DRIVERS\imapi.sys
Image size: 41856
Image MD5: F8AA320C6A0409C0380E5D8A99D76EC6
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): ImapiService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IMAPI CD-Burning COM Service
Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\imapi.exe
Image size: 150016
Image MD5: FA788520BCAC0F5D9D5CDE5615C0D931
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): inetaccs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): ini910u
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Inport
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): IntelIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): intelppm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Intel Processor Driver
Image path: system32\DRIVERS\intelppm.sys
Image size: 36096
Image MD5: 279FB78702454DFF2BB445F238C048D2
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Ip6Fw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPv6 Windows Firewall Driver
Description: Provides intrusion prevention service for a home or small office network.
Image path: system32\DRIVERS\Ip6Fw.sys
Image size: 29056
Image MD5: 4448006B6BC60E6C027932CFC38D6855
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): iPassConnectEngine
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPassConnectEngine
Object name: LocalSystem
Image path: C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
Image size: 1396736
Image MD5: 1C045B834B7A852E8741B0138C682114
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): iPassP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPass Protocol (IEEE 802.1x) v3.7.4.0
Description: iPass Protocol (IEEE 802.1x) v3.7.4.0
Image path: system32\DRIVERS\iPassP.sys
Image size: 21393
Image MD5: 468422B9137C884AB8FBA05A590989D7
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): iPassPeriodicUpdateApp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPassPeriodicUpdateApp
Object name: LocalSystem
Image path: "C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe"
Image size: 135168
Image MD5: BEDE742D051F3F848C10F59FC85C0DEB
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): iPassPeriodicUpdateService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPassPeriodicUpdateService
Object name: LocalSystem
Image path: "C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe"
Image size: 86016
Image MD5: 52A4ED0D41DD3652B1DB311FC0765BC4
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): IpFilterDriver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Traffic Filter Driver
Description: IP Traffic Filter Driver
Image path: system32\DRIVERS\ipfltdrv.sys
Image size: 32896
Image MD5: 731F22BA402EE4B62748ADAF6363C182
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): IpInIp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP in IP Tunnel Driver
Description: IP in IP Tunnel Driver
Image path: system32\DRIVERS\ipinip.sys
Image size: 20992
Image MD5: E1EC7F5DA720B640CD8FB8424F1B14BB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): IpNat
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Network Address Translator
Description: IP Network Address Translator
Image path: system32\DRIVERS\ipnat.sys
Image size: 134912
Image MD5: E2168CBC7098FFE963C6F23F472A3593
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): iPod Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPod Service
Description: iPod hardware management services
Object name: LocalSystem
Image path: "C:\Program Files\iPod\bin\iPodService.exe"
Image size: 504104
Image MD5: 1CB96E83FD76EB5580451CEF29E24303
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RpcSs
Service (registry key): IPSec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC driver
Description: IPSEC driver
Image path: system32\DRIVERS\ipsec.sys
Image size: 74752
Image MD5: 64537AA5C003A6AFEEE1DF819062D0D1
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): IPSECEXT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nortel Extranet Access Protocol
Description: Nortel Extranet Access Protocol
Image path: system32\DRIVERS\ipsecw2k.sys
Image size: 117760
Image MD5: 6DB37F829B27C0F59B840F94F9DD1122
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): IPSECSHM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nortel IPSECSHM Adapter
Description: Nortel IPSECSHM Adapter
Image path: system32\DRIVERS\ipsecw2k.sys
Image size: 117760
Image MD5: 6DB37F829B27C0F59B840F94F9DD1122
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): IRENUM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IR Enumerator Service
Image path: system32\DRIVERS\irenum.sys
Image size: 11264
Image MD5: 50708DAA1B1CBB7D6AC1CF8F56A24410
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ISAPISearch
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): isapnp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PnP ISA/EISA Bus Driver
Image path: system32\DRIVERS\isapnp.sys
Image size: 35840
Image MD5: E504F706CCB699C2596E9A3DA1596E87
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3
Service (registry key): JavaQuickStarterService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Java Quick Starter
Description: Prefetches JRE files for faster startup of Java applets and applications
Object name: LocalSystem
Image path: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
Image size: 152984
Image MD5: 5FD5865DC1A2100F8D4CF000EE5409A3
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): Kbdclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Keyboard Class Driver
Image path: system32\DRIVERS\kbdclass.sys
Image size: 24576
Image MD5: EBDEE8A2EE5393890A1ACEE971C4C246
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): kbdhid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Keyboard HID Driver
Image path: system32\DRIVERS\kbdhid.sys
Image size: 14848
Image MD5: E182FA8E49E8EE41B4ADC53093F3C7E6
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): kbstuff
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SMS Virtual Mouse
Image path: system32\DRIVERS\kbstuff5.sys
Image size: 11744
Image MD5: 5CB887962A98B4E11D62858B75D87580
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): kmixer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Wave Audio Mixer
Image path: system32\drivers\kmixer.sys
Image size: 171776
Image MD5: D93CAD07C5683DB066B0B2D2D3790EAD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): KMW_KBD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Kensington Input Devices Class filter driver
Image path: System32\DRIVERS\KMW_KBD.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): KMW_USB
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Kensington MouseWorks USB filter driver
Image path: system32\DRIVERS\KMW_USB.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): KSecDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): lanmanserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Server
Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): lanmanworkstation
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Workstation
Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): lbrtfdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): ldap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): LicenseService
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): LmHosts
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP NetBIOS Helper
Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: NetBT,Afd
Service (registry key): MCsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Managed Client Service
Description: Performs support functions for the Managed Client including receiving notification messages.
Object name: LocalSystem
Image path: C:\WINNT\System32\MCSvc.exe
Image size: 69632
Image MD5: 86EC5A1FAEEE67FCE1287150E635A64C
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Service (registry key): MDM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Machine Debug Manager
Description: Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
Image size: 322120
Image MD5: 11F714F85530A2BD134074DC30E99FCA
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): mdmxsdk
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\mdmxsdk.sys
Image size: 12672
Image MD5: 0CEA2D0D3FA284B85ED5B68365114F76
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0
Service (registry key): Messenger
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Messenger
Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS
Service (registry key): mnmdd
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): mnmsrvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetMeeting Remote Desktop Sharing
Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\mnmsrvc.exe
Image size: 32768
Image MD5: F6415361201915B9FE3896B0E4E724FF
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Service (registry key): Modem
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): Mouclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mouse Class Driver
Image path: system32\DRIVERS\mouclass.sys
Image size: 23040
Image MD5: 34E1F0031153E491910E12551400192C
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): mouhid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mouse HID Driver
Image path: system32\DRIVERS\mouhid.sys
Image size: 12160
Image MD5: B1C303E17FB9D46E87A98E4BA6769685
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): MountMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): mraid35x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): MRxDAV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebDav Client Redirector
Description: WebDav Client Redirector
Image path: system32\DRIVERS\mrxdav.sys
Image size: 179584
Image MD5: 29414447EB5BDE2F8397DC965DBB3156
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1
Service (registry key): MRxSmb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MRXSMB
Description: MRXSMB
Image path: system32\DRIVERS\mrxsmb.sys
Image size: 453632
Image MD5: 6F2D483B97B395544E59749C47963C6A
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): MSDTC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Transaction Coordinator
Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: C:\WINNT\system32\msdtc.exe
Image size: 6144
Image MD5: C7C3D89EB0A6F3DBA622EA737FA335B1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS,SamSS
Service (registry key): MSExchangeIMC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Msfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): MSIServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Installer
Description: Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\msiexec.exe /V
Image size: 78848
Image MD5: F5F0146580E7023ADB963879840777F8
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): MSKSSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Service Proxy
Image path: system32\drivers\MSKSSRV.sys
Image size: 7552
Image MD5: AE431A8DD3C1D0D0610CDBAC16057AD0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): MSPCLOCK
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Clock Proxy
Image path: system32\drivers\MSPCLOCK.sys
Image size: 5376
Image MD5: 13E75FEF9DFEB08EEDED9D0246E1F448
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): MSPQM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Quality Manager Proxy
Image path: system32\drivers\MSPQM.sys
Image size: 4992
Image MD5: 1988A33FF19242576C3D0EF9CE785DA7
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): mssmbios
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft System Management BIOS Driver
Image path: system32\DRIVERS\mssmbios.sys
Image size: 15488
Image MD5: 469541F8BFD2B32659D5D463A6714BCE
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Mup
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mup
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1
Service (registry key): NbtDet
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBoot PCI Detection Service
Image path: system32\DRIVERS\nbtdet.sys
Image size: 4992
Image MD5: BBC9F2882ADC411876DEC75E281471BA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): NDIS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS System Driver
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): NdisTapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS TAPI Driver
Description: Remote Access NDIS TAPI Driver
Image path: system32\DRIVERS\ndistapi.sys
Image size: 9600
Image MD5: 08D43BBDACDF23F34D79E44ED35C1B4C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Ndisuio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS Usermode I/O Protocol
Description: NDIS Usermode I/O Protocol
Image path: system32\DRIVERS\ndisuio.sys
Image size: 14592
Image MD5: 5146C3D286E66C72328F6CE6E4D983A8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): NdisWan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS WAN Driver
Description: Remote Access NDIS WAN Driver
Image path: system32\DRIVERS\ndiswan.sys
Image size: 91776
Image MD5: 0B90E255A9490166AB368CD55A529893
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): NDProxy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): NetBIOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBIOS Interface
Description: NetBIOS Interface
Image path: system32\DRIVERS\netbios.sys
Image size: 34560
Image MD5: 3A2ACA8FC1D7786902CA434998D7CEB4
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): NetBT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBios over Tcpip
Description: NetBios over Tcpip
Image path: system32\DRIVERS\netbt.sys
Image size: 162816
Image MD5: 0C80E410CD2F47134407EE7DD19CC86B
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): NetDDE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE
Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: 05AFB5AD06462257BEA7495283C86D50
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: NetDDEDSDM
Service (registry key): NetDDEdsdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE DSDM
Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: 05AFB5AD06462257BEA7495283C86D50
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Service (registry key): Netlogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Net Logon
Description: Supports pass-through authentication of account logon events for computers in a domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation
Service (registry key): Netman
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Connections
Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 288
Error Control: 1
Depends On services: RpcSs
Service (registry key): NIC1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 Net Driver
Image path: system32\DRIVERS\nic1394.sys
Image size: 61824
Image MD5: 5C5C53DB4FEF16CF87B9911C7E8C6FBC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Nla
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Location Awareness (NLA)
Description: Collects and stores network configuration and location information, and notifies applications when this information changes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd
Service (registry key): nm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Monitor Driver
Image path: system32\DRIVERS\NMnt.sys
Image size: 40320
Image MD5: 60CF8C7192B3614F240838DDBAA4A245
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): nmwcd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nokia USB Phone Parent
Image path: system32\drivers\ccdcmb.sys
Image size: 17664
Image MD5: 9A908A9BB857C2CCEB2907EB9DCAEB8B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): nmwcdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nokia USB Generic
Image path: system32\drivers\ccdcmbo.sys
Image size: 22016
Image MD5: 68EC3EE2348E475EA62C66E6AAFCFC9B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): NPF
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetGroup Packet Filter Driver
Image path: system32\drivers\npf.sys
Image size: 42512
Image MD5: 243126DA7BA441D7C7C3262DCF435A9C
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): Npfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): Ntfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Service (registry key): NtLmSsp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NT LM Security Support Provider
Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): NtmsSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Removable Storage
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): ntrtscan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OfficeScanNT RealTime Scan
Description: Performs Real-time, Scheduled, and Manual scan on OfficeScan clients.
Object name: LocalSystem
Image path: "C:\Program Files\OfficeScan NT\ntrtscan.exe"
Image size: 906536
Image MD5: EC539F17431F5FA73DD4F44FF64E9C0B
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Service (registry key): Null
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): NwlnkFlt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Filter Driver
Description: IPX Traffic Filter Driver
Image path: system32\DRIVERS\nwlnkflt.sys
Image size: 12416
Image MD5: B305F3FAD35083837EF46A0BBCE2FC57
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: NwlnkFwd
Service (registry key): NwlnkFwd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Forwarder Driver
Description: IPX Traffic Forwarder Driver
Image path: system32\DRIVERS\nwlnkfwd.sys
Image size: 32512
Image MD5: C99B3415198D1AAB7227F2C88FD664B9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ohci1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OHCI Compliant IEEE 1394 Host Controller
Image path: system32\DRIVERS\ohci1394.sys
Image size: 61056
Image MD5: 0951DB8E5823EA366B0E408D71E1BA2A
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): ose
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Office Source Engine
Description: Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Image size: 89136
Image MD5: 7A56CF3E3F12E8AF599963B16F50FB6A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): Outlook
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Parport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Parallel port driver
Image path: system32\DRIVERS\parport.sys
Image size: 80128
Image MD5: 29744EB4CE659DFE3B4122DEB45BC478
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): PartMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): ParVdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0
Depends On services: Parport
Depends On group: "Parallel arbitrator"
Service (registry key): pccsmcfd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PCCS Mode Change Filter Driver
Image path: system32\DRIVERS\pccsmcfd.sys
Image size: 21632
Image MD5: 175CC28DCF819F78CAA3FBD44AD9E52A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): PCI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PCI Bus Driver
Image path: system32\DRIVERS\pci.sys
Image size: 68224
Image MD5: 8086D9979234B603AD5BC2F5D890B234
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3
Service (registry key): PCIDump
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): PCIIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\pciide.sys
Image size: 3328
Image MD5: CCF5F451BB1A5A2A522A76E670000FF0
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): Pcmcia
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\pcmcia.sys
Image size: 119936
Image MD5: 82A087207DECEC8456FBE8537947D579
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): PDCOMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): PDFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): PDRELI
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): PDRFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): perc2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): perc2hib
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): PerfDisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): PerfNet
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): PerfOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): PerfProc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): PlugPlay
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Plug and Play
Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 108032
Image MD5: C6CE6EEC82F187615D1002BB3BB50ED4
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): Pml Driver HPZ12
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Pml Driver HPZ12
Object name: LocalSystem
Image path: C:\WINNT\system32\HPZipm12.exe
Image size: 69632
Image MD5: D31F88C5F19EEFA366A415D6BC5F2ABC
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): PolicyAgent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC Services
Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RPCSS,Tcpip,IPSec
Service (registry key): PptpMiniport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (PPTP)
Description: WAN Miniport (PPTP)
Image path: system32\DRIVERS\raspptp.sys
Image size: 48384
Image MD5: 1C5CC65AAC0783C344F16353E60B72AC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): prepdrvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SMS Process Event Driver
Image path: \??\C:\WINNT\system32\CCM\prepdrv.sys
Image size: 23416
Image MD5: 19505C4134F3181FC2203E087140C192
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ProtectedStorage
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Protected Storage
Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 1
Depends On services: RpcSs
Service (registry key): Ptilink
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel Link Driver
Description: Direct Parallel Link Driver
Image path: system32\DRIVERS\ptilink.sys
Image size: 17792
Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ql1080
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Ql10wnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ql12160
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ql1240
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ql1280
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): RasAcd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Driver
Description: Remote Access Auto Connection Driver
Image path: system32\DRIVERS\rasacd.sys
Image size: 8832
Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): RasAuto
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Manager
Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RasMan,Tapisrv
Service (registry key): Rasl2tp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (L2TP)
Description: WAN Miniport (L2TP)
Image path: system32\DRIVERS\rasl2tp.sys
Image size: 51328
Image MD5: 98FAEB4A4DCF812BA1C6FCA4AA3E115C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): RasMan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Connection Manager
Description: Creates a network connection.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tapisrv
Service (registry key): RasPppoe
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access PPPOE Driver
Description: Remote Access PPPOE Driver
Image path: system32\DRIVERS\raspppoe.sys
Image size: 41472
Image MD5: 7306EEED8895454CBED4669BE9F79FAA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Raspti
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel
Description: Direct Parallel
Image path: system32\DRIVERS\raspti.sys
Image size: 16512
Image MD5: FDBB1D60066FCFBB7452FD8F9829B242
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): RCHelp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 0
Error Control: 0
Service (registry key): Rdbss
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Rdbss
Description: Rdbss
Image path: system32\DRIVERS\rdbss.sys
Image size: 174592
Image MD5: 03B965B1CA47F6EF60EB5E51CB50E0AF
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): RDPCDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\DRIVERS\RDPCDD.sys
Image size: 4224
Image MD5: 4912D5B403614CE99C28420F75353332
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): RDPDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): rdpdr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Server Device Redirector Driver
Image path: system32\DRIVERS\rdpdr.sys
Image size: 196864
Image MD5: A2CAE2C60BC37E0751EF9DDA7CEAF4AD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): RDPNP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): RDPWD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): RDSessMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Desktop Help Session Manager
Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box.
Object name: LocalSystem
Image path: C:\WINNT\system32\sessmgr.exe
Image size: 140800
Image MD5: 729798E0933076B8FCFCD9934698F164
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): redbook
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Digital CD Audio Playback Filter Driver
Image path: system32\DRIVERS\redbook.sys
Image size: 57472
Image MD5: B31B4588E4086D8D84ADBF9845C2402B
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): RemoteAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Routing and Remote Access
Description: Offers routing services to businesses in local area and wide area network environments.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RpcSS
Depends On group: NetBIOSGroup
Service (registry key): RemoteRegistry
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Registry
Description: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): ROOTMODEM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Legacy Modem Driver
Image path: System32\Drivers\RootMdm.sys
Image size: 5888
Image MD5: D8B0B4ADE32574B2D9C5CC34DC0DBBE7
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): rpcapd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Packet Capture Protocol v.0 (experimental)
Description: Allows to capture traffic on this machine from a remote machine.
Object name: LocalSystem
Image path: "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini"
Image size: 92792
Image MD5: 8738CAD3F5D285D544A4D6553FF61BCC
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): RpcLocator
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC) Locator
Description: Manages the RPC name service database.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\locator.exe
Image size: 75264
Image MD5: 793F04A09B15E7C6C11DBDFFAF06C0AB
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: LanmanWorkstation
Service (registry key): RpcSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC)
Description: Provides the endpoint mapper and other miscellaneous RPC services.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\svchost -k rpcss
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): RSVP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: QoS RSVP
Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
Object name: LocalSystem
Image path: %SystemRoot%\system32\rsvp.exe
Image size: 132608
Image MD5: 471B3F9741D762ABE75E9DEEA4787E47
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: TcpIp,Afd,RpcSs
Service (registry key): SamSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Accounts Manager
Description: Stores security information for local user accounts.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): SCardSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Smart Card
Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\SCardSvr.exe
Image size: 95744
Image MD5: 25D8DE134DF108E3DBC8D7D23B1AA58E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: PlugPlay
Service (registry key): Schedule
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Task Scheduler
Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): Secdrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secdrv
Description: SafeDisc driver
Image path: system32\DRIVERS\secdrv.sys
Image size: 20480
Image MD5: 90A3935D05B494A5A39D37E71F09A677
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): seclogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secondary Logon
Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 0
Service (registry key): SENS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Event Notification
Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: EventSystem
Service (registry key): serenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Serenum Filter Driver
Image path: system32\DRIVERS\serenum.sys
Image size: 15488
Image MD5: A2D868AEEFF612E70E213C451A70CAFB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Serial
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Serial port driver
Image path: system32\DRIVERS\serial.sys
Image size: 64896
Image MD5: CD9404D115A00D249F70A371B46D5A26
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): Service Launcher
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Service Launcher
Description: Service Launcher
Object name: LocalSystem
Image path: C:\WINNT\system32\SvcLncher.exe
Image size: 229376
Image MD5: 8E21F9A309FDA5BA391682527E48A6AF
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0
Service (registry key): ServiceLayer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ServiceLayer
Object name: LocalSystem
Image path: "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"
Image size: 575488
Image MD5: 277D0890E10584C216BCCFA4EF6B9B3D
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): Sfloppy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Depends On group: "SCSI miniport"
Service (registry key): SharedAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Firewall/Internet Connection Sharing (ICS)
Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Netman,WinMgmt
Service (registry key): ShellHWDetection
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Shell Hardware Detection
Description: Provides notifications for AutoPlay hardware events.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs
Service (registry key): Simbad
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): SP Software Installer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SP Software Installer
Description: Enables software updates and installations.
Object name: LocalSystem
Image path: C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
Image size: 118784
Image MD5: EF1F7335F0285599438A2E713CE8772A
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): Sparrow
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): splitter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Audio Splitter
Image path: system32\drivers\splitter.sys
Image size: 6400
Image MD5: 8E186B8F23295D1E42C573B82B80D548
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Spooler
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Print Spooler
Description: Loads files to memory for later printing.
Object name: LocalSystem
Image path: %SystemRoot%\system32\spoolsv.exe
Image size: 57856
Image MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): sp_spi_da
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Visual Insight Dial Analysis
Object name: LocalSystem
Image path: C:\Program Files\AccessManager\SMOC\spi_da.exe
Image size: 81920
Image MD5: 570861636E49AC292051D102CD1379E1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): sr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Filter Driver
Image path: \SystemRoot\system32\DRIVERS\sr.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Service (registry key): srservice
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Service
Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): Srv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Srv
Description: Srv
Image path: system32\DRIVERS\srv.sys
Image size: 333056
Image MD5: 7A0111577D8046633D5162A3CE15E9E1
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1
Service (registry key): SSDPSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SSDP Discovery Service
Description: Enables discovery of UPnP devices on your home network.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP
Service (registry key): STacSV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SigmaTel Audio Service
Description: Manages SigmaTel Audio Universal Jack configurations.
Object name: LocalSystem
Image path: C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
Image size: 90112
Image MD5: 686FA4ACFDCB4E16B7F0230B88F6D17E
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): STHDA
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SigmaTel High Definition Audio CODEC
Image path: system32\drivers\sthda.sys
Image size: 1228296
Image MD5: 31BA85E1CFF39A57F702A2A0877BB8E1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): StillCam
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Still Serial Digital Camera Driver
Image path: system32\DRIVERS\serscan.sys
Image size: 6784
Image MD5: A9573045BAA16EAB9B1085205B82F1ED
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): stisvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Image Acquisition (WIA)
Description: Provides image acquisition services for scanners and cameras.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k imgsvc
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): SU
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SU Service
Object name: LocalSystem
Image path: C:\WINNT\system32\Suss.exe
Image size: 12048
Image MD5: 7A375DBDAC196606E0CA92F4580B87D2
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RpcSs
Service (registry key): swenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Software Bus Driver
Image path: system32\DRIVERS\swenum.sys
Image size: 4352
Image MD5: 03C1BAE4766E2450219D20B993D6E046
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): swmidi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel GS Wavetable Synthesizer
Image path: system32\drivers\swmidi.sys
Image size: 54272
Image MD5: 94ABC808FC4B6D7D2BBF42B85E25BB4D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): SwPrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MS Software Shadow Copy Provider
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\dllhost.exe /Processid:{2FB04F5C-5388-4800-BAAC-7D4ED1D99E25}
Image size: 5120
Image MD5: DD87DB7387B9EB441C5674888A0D840C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Depends On services: rpcss
Service (registry key): Sygman
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SSA Integration Manager
Description: SSA integration management services.
Object name: LocalSystem
Image path: "C:\Program Files\AccessManager\Client\sygman.exe"
Image size: 126976
Image MD5: B3B3ABC9FCD0720587F12F7649DC664F
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): symc810
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): symc8xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): sym_hi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): sym_u3
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): sysaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel System Audio Device
Image path: system32\drivers\sysaudio.sys
Image size: 60800
Image MD5: 650AD082D46BAC0E64C9C0E0928492FD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): SysmonLog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Performance Logs and Alerts
Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT Authority\NetworkService
Image path: %SystemRoot%\system32\smlogsvc.exe
Image size: 89600
Image MD5: 8B54AA346D1B1B113FFAA75501B8B1B2
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): TapiSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telephony
Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs
Service (registry key): Tcpip
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP Protocol Driver
Description: TCP/IP Protocol Driver
Image path: system32\DRIVERS\tcpip.sys
Image size: 360320
Image MD5: 2A5554FC5B1E04E131230E3CE035C3F9
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: IPSec
Service (registry key): TDPIPE
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): TDTCP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): TermDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Device Driver
Image path: system32\DRIVERS\termdd.sys
Image size: 40840
Image MD5: A540A99C281D933F3D69D55E48727F47
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): TermService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Services
Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost -k DComLaunch
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): Themes
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Themes
Description: Provides user experience theme management.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): TlntSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telnet
Description: Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\tlntsvr.exe
Image size: 73216
Image MD5: 37DB0A7D097310E8B4DE803FC3119C78
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: RPCSS,TCPIP,NTLMSSP
Service (registry key): tmcfw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro Common Firewall Service
Image path: system32\DRIVERS\TM_CFW.sys
Image size: 335888
Image MD5: C353B24CCBF0227621EB0FA72C9572DB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): tmcomm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: tmcomm
Image path: \??\C:\WINNT\system32\drivers\tmcomm.sys
Image size: 142096
Image MD5: F65E545771FD922693F0EC68B2141012
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): TmFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro Filter
Image path: \??\C:\Program Files\OfficeScan NT\TmXPFlt.sys
Image size: 205328
Image MD5: F23C38F5EDEB8D0FBD512632F5421651
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Depends On services: VSApiNt,TmPreFilter
Service (registry key): tmlisten
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OfficeScan NT Listener
Description: Receives commands and notifications from the OfficeScan server and facilitates communication from the client to the server.
Object name: LocalSystem
Image path: "C:\Program Files\OfficeScan NT\tmlisten.exe"
Image size: 984360
Image MD5: 89D686F4656CDEAEC3936ABCCE9DF11D
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Service (registry key): TmPfw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OfficeScanNT Personal Firewall
Description: Provides packet level firewall, network virus scanning and intrusion detection capabilities.
Object name: LocalSystem
Image path: "C:\Program Files\OfficeScan NT\TmPfw.exe"
Image size: 488768
Image MD5: 3341EDF8769BC1967E2CA097792C370C
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: tmcfw
Service (registry key): TmPreFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro PreFilter
Image path: \??\C:\Program Files\OfficeScan NT\TmPreFlt.sys
Image size: 36368
Image MD5: DE9E8269185A7614A5A4F39CACD266EC
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): TmProxy
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OfficeScan NT Proxy Service
Description: Scans network traffic before passing it to the target application.
Object name: LocalSystem
Image path: "C:\Program Files\OfficeScan NT\TmProxy.exe"
Image size: 652552
Image MD5: D49903A8B0EEA75A6EC1E162CDB6D473
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: tmtdi
Service (registry key): tmtdi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro TDI Driver
Image path: system32\DRIVERS\tmtdi.sys
Image size: 72072
Image MD5: 1A72B37AFA1C9B05488D9871D04C7AC5
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): toshidpt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth HID Port
Image path: system32\drivers\Toshidpt.sys
Image size: 3712
Image MD5: E362D54FD394999C4178936396664E57
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): TosIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): tosporte
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth COM Port
Image path: system32\DRIVERS\tosporte.sys
Image size: 41600
Image MD5: 8D624D3BD1F2D78BD1C01A2D4E954B4E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): tosrfbd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth RFBUS
Image path: system32\DRIVERS\tosrfbd.sys
Image size: 113920
Image MD5: 435AC6CC2ABED508AC5A495658CBAF0F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): tosrfbnp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth RFBNEP
Image path: System32\Drivers\tosrfbnp.sys
Image size: 36480
Image MD5: 90C8525BC578AAFFE87C2D0ED4379E9E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Tosrfcom
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth RFCOMM
Image path: System32\Drivers\tosrfcom.sys
Image size: 64896
Image MD5: 5BA1CA3B3CDDB1DDC67DF473F05D1EC2
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Tosrfhid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth RFHID
Image path: system32\DRIVERS\Tosrfhid.sys
Image size: 73600
Image MD5: 28099A4E52148319AFA685D93A2244D0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): tosrfnds
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth Personal Area Network
Image path: system32\DRIVERS\tosrfnds.sys
Image size: 18612
Image MD5: C52FD27B9ADF3A1F22CB90E6BCF9B0CB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Tosrfusb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth USB Controller
Image path: system32\DRIVERS\tosrfusb.sys
Image size: 41856
Image MD5: 6BC529C5ECA0C7654943FD6FAB21C5FA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): TrkWks
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Link Tracking Client
Description: Maintains links between NTFS files within a computer or across computers in a network domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): TSDDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Udfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Service (registry key): UIUSys
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Conexant Setup API
Image path: system32\DRIVERS\UIUSYS.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ultra
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Update
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microcode Update Driver
Image path: system32\DRIVERS\update.sys
Image size: 209408
Image MD5: AFF2E5045961BBC0A602BB6F95EB1345
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): upnphost
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Universal Plug and Play Device Host
Description: Provides support to host Universal Plug and Play devices.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: SSDPSRV,HTTP
Service (registry key): upperdev
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\usbser_lowerflt.sys
Image size: 8064
Image MD5: A34560A5D516A2F5240180370866B99D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): UPS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Uninterruptible Power Supply
Description: Manages an uninterruptible power supply (UPS) connected to the computer.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\ups.exe
Image size: 18432
Image MD5: 3F5DF65B0758675F95A2D43918A740A3
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): usbccgp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Generic Parent Driver
Image path: system32\DRIVERS\usbccgp.sys
Image size: 31616
Image MD5: BFFD9F120CC63BCBAA3D840F3EEF9F79
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): USBCCID
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Smart Card reader
Image path: system32\DRIVERS\usbccid.sys
Image size: 28672
Image MD5: 6B5E4D5E6E5ECD6ACD14AED59768CE5C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbehci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
Image path: system32\DRIVERS\usbehci.sys
Image size: 27008
Image MD5: 7481D843E672B51039B7E8A161B746B8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbhub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Standard Hub Driver
Image path: system32\DRIVERS\usbhub.sys
Image size: 57600
Image MD5: C72F40947F92CEA56A8FB532EDF025F1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbprint
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB PRINTER Class
Image path: system32\DRIVERS\usbprint.sys
Image size: 25856
Image MD5: A42369B7CD8886CD7C70F33DA6FCBCF5
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbscan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Scanner Driver
Image path: system32\DRIVERS\usbscan.sys
Image size: 15104
Image MD5: A6BC71402F4F7DD5B77FD7F4A8DDBA85
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nokia USB Serial Port
Image path: system32\DRIVERS\usbser.sys
Image size: 25600
Image MD5: 49106EE29074E6A3D3AC9E24C6D791D8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): UsbserFilt
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\usbser_lowerfltj.sys
Image size: 8064
Image MD5: 6410EEBD6E0427466812858EE84C8467
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): USBSTOR
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Mass Storage Driver
Image path: system32\DRIVERS\USBSTOR.SYS
Image size: 26496
Image MD5: 6CD7B22193718F1D17A47A1CD6D37E75
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbuhci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Universal Host Controller Miniport Driver
Image path: system32\DRIVERS\usbuhci.sys
Image size: 20480
Image MD5: F8FD1400092E23C8F2F31406EF06167B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): VgaSave
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\drivers\vga.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): ViaIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): VolSnap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): VSApiNt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro VSAPI NT
Image path: \??\C:\Program Files\OfficeScan NT\VSApiNt.sys
Image size: 1195448
Image MD5: EB80F44FE19E0CD7CE998CA11CD790DD
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): VSS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Shadow Copy
Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\vssvc.exe
Image size: 289792
Image MD5: 3EE00364AE0FD8D604F46CBAF512838A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): W32Time
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Time
Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): W3SVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Wanarp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access IP ARP Driver
Description: Remote Access IP ARP Driver
Image path: system32\DRIVERS\wanarp.sys
Image size: 34560
Image MD5: 984EF0B9788ABF89974CFED4BFBAACBC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Wdf01000
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wdf01000
Image path: system32\DRIVERS\Wdf01000.sys
Image size: 503008
Image MD5: BBCFEAB7E871CDDAC2D397EE7FA91FDC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): WDICA
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): wdmaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft WINMM WDM Audio Compatibility Driver
Image path: system32\drivers\wdmaud.sys
Image size: 82944
Image MD5: 2797F33EBF50466020C430EE4F037933
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): WebClient
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebClient
Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: MRxDAV
Service (registry key): winachsf
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\HSF_CNXT.sys
Image size: 730112
Image MD5: 96AFF1738271755A39B52EEF7E35F98F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): winmgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation
Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RPCSS
Service (registry key): Winsock
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 4
Error Control: 1
Service (registry key): WinSock2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): WinTrust
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): wltrysvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Dell Wireless WLAN Tray Service
Description: Provides automatic configuration for the 802.11 adapter using the Broadcom supplicant.
Object name: LocalSystem
Image path: %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe
Image size: 20480
Image MD5: 60714B1C15F815F55798C0B3D4819BEB
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Service (registry key): WmdmPmSN
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Portable Media Serial Number Service
Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): Wmi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation Driver Extensions
Description: Provides systems management information to and from drivers.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): WmiAcpi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Windows Management Interface for ACPI
Image path: system32\DRIVERS\wmiacpi.sys
Image size: 8832
Image MD5: AE2C8544E747C20062DB27456EA2D67A
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): WmiApRpl
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): WmiApSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WMI Performance Adapter
Description: Provides performance library information from WMI HiPerf providers.
Object name: LocalSystem
Image path: C:\WINNT\system32\wbem\wmiapsrv.exe
Image size: 126464
Image MD5: BA8CECC3E813E1F7C441B20393D4F86C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): WMPNetworkSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Media Player Network Sharing Service
Description: Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
Object name: NT AUTHORITY\NetworkService
Image path: "C:\Program Files\Windows Media Player\WMPNetwk.exe"
Image size: 913408
Image MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: upnphost,http,HTTPFilter
Service (registry key): WS2IFSL
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 0
Error Control: 0
Service (registry key): wscsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Center
Description: Monitors system security settings and configurations.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,winmgmt
Service (registry key): wuauserv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Automatic Updates
Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Service (registry key): WudfPf
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver
Description: Provide communciation services for UMDF components.
Image path: system32\DRIVERS\WudfPf.sys
Image size: 76544
Image MD5: 50EB9E21963B4F06FD010D007D54351B
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): WudfRd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Reflector
Description: Reflect device requests to user-mode driver drivers
Image path: system32\DRIVERS\wudfrd.sys
Image size: 82688
Image MD5: 6E209664BDEA8A15B5E8E480D6C607C2
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): WudfSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework
Description: Manages user-mode driver host processes
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay
Service (registry key): Wuser32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SMS Remote Control Agent
Object name: LocalSystem
Image path: C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
Image size: 251256
Image MD5: E5F1614AE616C9C1B00E92031867F48F
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 0
Service (registry key): WZCSVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wireless Zero Configuration
Description: Provides automatic configuration for the 802.11 adapters
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,Ndisuio
Service (registry key): xmlprov
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Provisioning Service
Description: Manages XML configuration files on a domain basis for automatic network provisioning.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): {31129AF3-2CDF-4692-8126-6AEED5019D8A}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {5E8875FA-BF7D-4B93-8D00-F179F4FEF81F}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {67C55556-3A19-425C-AE9D-6F311F24CF5B}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {82050D99-E21F-4151-BB2B-BDFB81A15DB1}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {CF321070-626F-48AE-B65A-3105209C4985}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {FAFCE09D-8A2E-4F21-A092-B020C58316EB}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
HJT startup list
StartupList report, 12/7/2008, 8:42:59 PM
StartupList version: 1.52.2
Started from : C:\Program Files\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\MCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\SvcLncher.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Suss.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\TEMP\XZ8E65.EXE
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\Program Files\OfficeScan NT\TmPfw.exe
C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\svchost.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\stsystra.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\WINNT\system32\WLTRAY.exe
C:\WINNT\system32\taskswitch.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINNT\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINNT\Managed\MCDesk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interwise\Participant\pull.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINNT\system32\HPZinw12.exe
————————————————–
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\vm092543\Start Menu\Programs\Startup]
*No files*
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Acrobat Speed Launcher.lnk = ?
Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Bluetooth Manager.lnk = ?
Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = c:\winnt\system32\userinit.exe
[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
OfficeScanNT Monitor = "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
Synchronization Manager = mobsync.exe /logon
WinZip Quick Pick = C:\Program Files\WinZip\WZQKPICK.EXE
ServicesSynchronizationUtility = "C:\Program Files\Siemens\Services Synchronization Utility\vbs.exe" SyncServices.vbe r "C:\" "C:\WINNT\" "C:\WINNT\system32\" "\\nsn-intra.net\dfsres\s_lw\global\etc\"
SigmatelSysTrayApp = stsystra.exe
IgfxTray = C:\WINNT\system32\igfxtray.exe
HotKeysCmds = C:\WINNT\system32\hkcmd.exe
Persistence = C:\WINNT\system32\igfxpers.exe
AccessManager = C:\Program Files\AccessManager\Client\AccessMgr.exe
Broadcom Wireless Manager UI = C:\WINNT\system32\WLTRAY.exe
CoolSwitch = C:\WINNT\system32\taskswitch.exe
Acrobat Assistant 8.0 = "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
Apoint = C:\Program Files\DellTPad\Apoint.exe
QuickTime Task = "C:\Program Files\QuickTime\QTTask.exe" -atboottime
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe"
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No values found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No values found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No values found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PC Suite Tray = "C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe" -onlytray
ctfmon.exe = C:\WINNT\system32\ctfmon.exe
AdobeUpdater = C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
Google Update = "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
SpybotSD TeaTimer = C:\Program Files\Spybot\TeaTimer.exe
Copernic Desktop Search - Home = "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
Nokia.PCSync = "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No values found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No values found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No values found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
*No values found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
————————————————–
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default) = "%1" %*
————————————————–
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command
(Default) = "%1" %*
————————————————–
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command
(Default) = "%1" %*
————————————————–
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command
(Default) = "%1" %*
————————————————–
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" /S
————————————————–
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
(Default) = C:\WINNT\system32\mshta.exe "%1" %*
————————————————–
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1
————————————————–
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINNT\inf\unregmp2.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf
[{5084F01D-458E-45EB-A6FD-692D4C9D2789}] *
StubPath = C:\WINNT\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}
[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msmsgs.inf,BLC.QuietInstall.PerUser
[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp11.inf,PerUserStub
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe
[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINNT\system32\Rundll32.exe C:\WINNT\system32\mscories.dll,Install
[{A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}] *
StubPath = C:\WINNT\system32\msiexec.exe /qn /fpu {A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}
————————————————–
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps
*Registry key not found*
————————————————–
Load/Run keys from C:\WINNT\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=cdmcvw.dll
————————————————–
Shell & screensaver key from C:\WINNT\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=LOGON.SCR
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Checking for EXPLORER.EXE instances:
C:\WINNT\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINNT\Explorer\Explorer.exe: not present
C:\WINNT\System\Explorer.exe: not present
C:\WINNT\System32\Explorer.exe: not present
C:\WINNT\Command\Explorer.exe: not present
C:\WINNT\Fonts\Explorer.exe: not present
————————————————–
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
————————————————–
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINNT
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
Registry check passed
————————————————–
Enumerating Browser Helper Objects:
*No BHO's found*
————————————————–
Enumerating Task Scheduler jobs:
AppleSoftwareUpdate.job
GoogleUpdateTaskUser.job
————————————————–
Enumerating Download Program Files:
[WebTrain.ctlWebTrain]
InProcServer32 = C:\WINNT\system32\WEBTRAIN.OCX
CODEBASE = http://www.webattend.com/components/wt0523.cab
[WUWebControl Class]
InProcServer32 = C:\WINNT\system32\wuweb.dll
CODEBASE = http://www.update.microsoft.com/windowsupd…b?1218817069823
[JNILoader Control]
InProcServer32 = C:\WINNT\DOWNLO~1\STJNIL~1.OCX
CODEBASE = https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
[Java Plug-in 1.6.0_10]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Whale Client Components]
InProcServer32 = C:\WINNT\Downloaded Program Files\WhlMgr.dll
CODEBASE = https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
[Java Plug-in 1.6.0_03]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Java Plug-in 1.6.0_04]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Java Plug-in 1.6.0_10]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Java Plug-in 1.6.0_10]
InProcServer32 = C:\Program Files\Java\jre6\bin\npjpi160_10.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Xerox_Services_Portal.XrxPrinter_Inst]
InProcServer32 = C:\WINNT\Downloaded Program Files\Xerox_Services_Portal_Pref.ocx
CODEBASE = https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
————————————————–
Enumerating Winsock LSP files:
NameSpace #1: C:\WINNT\System32\mswsock.dll
NameSpace #2: C:\WINNT\System32\winrnr.dll
NameSpace #3: C:\WINNT\System32\mswsock.dll
NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll
Protocol #1: C:\WINNT\system32\mswsock.dll
Protocol #2: C:\WINNT\system32\mswsock.dll
Protocol #3: C:\WINNT\system32\mswsock.dll
Protocol #4: C:\WINNT\system32\rsvpsp.dll
Protocol #5: C:\WINNT\system32\rsvpsp.dll
Protocol #6: C:\WINNT\system32\mswsock.dll
Protocol #7: C:\WINNT\system32\mswsock.dll
Protocol #8: C:\WINNT\system32\mswsock.dll
Protocol #9: C:\WINNT\system32\mswsock.dll
Protocol #10: C:\WINNT\system32\mswsock.dll
Protocol #11: C:\WINNT\system32\mswsock.dll
Protocol #12: C:\WINNT\system32\mswsock.dll
Protocol #13: C:\WINNT\system32\mswsock.dll
Protocol #14: C:\WINNT\system32\mswsock.dll
Protocol #15: C:\WINNT\system32\mswsock.dll
Protocol #16: C:\WINNT\system32\mswsock.dll
Protocol #17: C:\WINNT\system32\mswsock.dll
Protocol #18: C:\WINNT\system32\mswsock.dll
Protocol #19: C:\WINNT\system32\mswsock.dll
Protocol #20: C:\WINNT\system32\mswsock.dll
Protocol #21: C:\WINNT\system32\mswsock.dll
Protocol #22: C:\WINNT\system32\mswsock.dll
Protocol #23: C:\WINNT\system32\mswsock.dll
Protocol #24: C:\WINNT\system32\mswsock.dll
Protocol #25: C:\WINNT\system32\mswsock.dll
————————————————–
Enumerating Windows NT/2000/XP services
Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
Access Manager Configuration Service: "C:\Program Files\AccessManager\Client\AMBroker.exe" (autostart)
Alps Touch Pad Filter Driver for Windows 2000/XP/Vista: system32\DRIVERS\Apfiltr.sys (manual start)
Apple Mobile Device: "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" (autostart)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: system32\DRIVERS\arp1394.sys (manual start)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Broadcom NetXtreme Gigabit Ethernet: system32\DRIVERS\b57xp32.sys (manual start)
Dell Wireless WLAN Card Driver: system32\DRIVERS\bcmwl5.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Bonjour Service: "C:\Program Files\Bonjour\mDNSResponder.exe" (disabled)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
SMS Agent Host: C:\WINNT\system32\CCM\CcmExec.exe (autostart)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (disabled)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
.NET Runtime Optimization Service v2.0.50727_X86: C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (manual start)
Microsoft AC Adapter Driver: system32\DRIVERS\CmBatt.sys (manual start)
Microsoft Composite Battery Driver: system32\DRIVERS\compbatt.sys (system)
COM+ System Application: C:\WINNT\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
CSRBC.Sys CSR test driver: System32\Drivers\csrbcxp.sys (manual start)
Visual Insight DA Plugin: C:\Program Files\AccessManager\Client\DAPlugin.exe (manual start)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Whale Component Manager: C:\WINNT\DOWNLO~1\DMService.exe (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Eacfilt Miniport: system32\DRIVERS\eacfilt.sys (manual start)
3Com Megahertz 10/100 LAN CardBus PC Card Driver: system32\DRIVERS\el575nd5.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINNT\system32\svchost.exe -k netsvcs (manual start)
Contivity VPN Service: "C:\Program Files\IP VPN Remote Services\Extranet_serv.exe" (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Firefly Media Server: C:\Program Files\Firefly Media Server\firefly.exe (disabled)
FLEXnet Licensing Service: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
GEARAspiWDM: System32\Drivers\GEARAspiWDM.sys (manual start)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Microsoft UAA Bus Driver for High Definition Audio: system32\DRIVERS\HDAudBus.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
HID Input Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft HID Class Driver: system32\DRIVERS\hidusb.sys (manual start)
HP Port Resolver: C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE (manual start)
HP Status Server: C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE (manual start)
HSFHWAZL: system32\DRIVERS\HSFHWAZL.sys (manual start)
HSF_DPV: system32\DRIVERS\HSF_DPV.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP Poster Service: C:\WINNT\system32\HTTP_Poster.exe (autostart)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
ialm: system32\DRIVERS\igxpmp32.sys (manual start)
idisw2km: system32\DRIVERS\idisw2km.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINNT\system32\imapi.exe (manual start)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
iPassConnectEngine: C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe (manual start)
iPass Protocol (IEEE 802.1x) v3.7.4.0: system32\DRIVERS\iPassP.sys (autostart)
iPassPeriodicUpdateApp: "C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe" (manual start)
iPassPeriodicUpdateService: "C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe" (autostart)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
Nortel Extranet Access Protocol: system32\DRIVERS\ipsecw2k.sys (autostart)
Nortel IPSECSHM Adapter: system32\DRIVERS\ipsecw2k.sys (manual start)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
Java Quick Starter: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" (autostart)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Keyboard HID Driver: system32\DRIVERS\kbdhid.sys (system)
SMS Virtual Mouse: system32\DRIVERS\kbstuff5.sys (manual start)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Kensington Input Devices Class filter driver: System32\DRIVERS\KMW_KBD.sys (manual start)
Kensington MouseWorks USB filter driver: system32\DRIVERS\KMW_USB.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Managed Client Service: C:\WINNT\System32\MCSvc.exe (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
mdmxsdk: system32\DRIVERS\mdmxsdk.sys (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
NetMeeting Remote Desktop Sharing: C:\WINNT\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINNT\system32\msdtc.exe (manual start)
Windows Installer: C:\WINNT\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
NetBoot PCI Detection Service: system32\DRIVERS\nbtdet.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (autostart)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
1394 Net Driver: system32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Network Monitor Driver: system32\DRIVERS\NMnt.sys (manual start)
Nokia USB Phone Parent: system32\drivers\ccdcmb.sys (manual start)
Nokia USB Generic: system32\drivers\ccdcmbo.sys (manual start)
NetGroup Packet Filter Driver: system32\drivers\npf.sys (autostart)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
OfficeScanNT RealTime Scan: "C:\Program Files\OfficeScan NT\ntrtscan.exe" (autostart)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
Parallel port driver: system32\DRIVERS\parport.sys (manual start)
PCCS Mode Change Filter Driver: system32\DRIVERS\pccsmcfd.sys (manual start)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
Pcmcia: system32\DRIVERS\pcmcia.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
Pml Driver HPZ12: C:\WINNT\system32\HPZipm12.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (disabled)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
SMS Process Event Driver: \??\C:\WINNT\system32\CCM\prepdrv.sys (manual start)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINNT\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Remote Registry: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Microsoft Legacy Modem Driver: System32\Drivers\RootMdm.sys (manual start)
Remote Packet Capture Protocol v.0 (experimental): "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" (manual start)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (autostart)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: system32\DRIVERS\secdrv.sys (manual start)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: system32\DRIVERS\serenum.sys (manual start)
Serial port driver: system32\DRIVERS\serial.sys (system)
Service Launcher: C:\WINNT\system32\SvcLncher.exe (autostart)
ServiceLayer: "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe" (manual start)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SP Software Installer: C:\Program Files\AccessManager\PMAC\sp_SWIns.exe (autostart)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Visual Insight Dial Analysis: C:\Program Files\AccessManager\SMOC\spi_da.exe (manual start)
System Restore Filter Driver: \SystemRoot\system32\DRIVERS\sr.sys (disabled)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Srv: system32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
SigmaTel Audio Service: C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe (autostart)
SigmaTel High Definition Audio CODEC: system32\drivers\sthda.sys (manual start)
Still Serial Digital Camera Driver: system32\DRIVERS\serscan.sys (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart)
SU Service: C:\WINNT\system32\Suss.exe (autostart)
Software Bus Driver: system32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINNT\system32\dllhost.exe /Processid:{2FB04F5C-5388-4800-BAAC-7D4ED1D99E25} (manual start)
SSA Integration Manager: "C:\Program Files\AccessManager\Client\sygman.exe" (autostart)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: system32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (autostart)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Telnet: C:\WINNT\system32\tlntsvr.exe (disabled)
Trend Micro Common Firewall Service: system32\DRIVERS\TM_CFW.sys (manual start)
tmcomm: \??\C:\WINNT\system32\drivers\tmcomm.sys (autostart)
Trend Micro Filter: \??\C:\Program Files\OfficeScan NT\TmXPFlt.sys (autostart)
OfficeScan NT Listener: "C:\Program Files\OfficeScan NT\tmlisten.exe" (autostart)
OfficeScanNT Personal Firewall: "C:\Program Files\OfficeScan NT\TmPfw.exe" (manual start)
Trend Micro PreFilter: \??\C:\Program Files\OfficeScan NT\TmPreFlt.sys (autostart)
OfficeScan NT Proxy Service: "C:\Program Files\OfficeScan NT\TmProxy.exe" (manual start)
Trend Micro TDI Driver: system32\DRIVERS\tmtdi.sys (system)
Bluetooth HID Port: system32\drivers\Toshidpt.sys (manual start)
Bluetooth COM Port: system32\DRIVERS\tosporte.sys (manual start)
Bluetooth RFBUS: system32\DRIVERS\tosrfbd.sys (manual start)
Bluetooth RFBNEP: System32\Drivers\tosrfbnp.sys (manual start)
Bluetooth RFCOMM: System32\Drivers\tosrfcom.sys (system)
Bluetooth RFHID: system32\DRIVERS\Tosrfhid.sys (manual start)
Bluetooth Personal Area Network: system32\DRIVERS\tosrfnds.sys (manual start)
Bluetooth USB Controller: system32\DRIVERS\tosrfusb.sys (manual start)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Conexant Setup API: system32\DRIVERS\UIUSYS.SYS (manual start)
Microcode Update Driver: system32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
upperdev: system32\DRIVERS\usbser_lowerflt.sys (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
USB Smart Card reader: system32\DRIVERS\usbccid.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
Microsoft USB Standard Hub Driver: system32\DRIVERS\usbhub.sys (manual start)
Microsoft USB PRINTER Class: system32\DRIVERS\usbprint.sys (manual start)
USB Scanner Driver: system32\DRIVERS\usbscan.sys (manual start)
Nokia USB Serial Port: system32\DRIVERS\usbser.sys (manual start)
UsbserFilt: system32\DRIVERS\usbser_lowerfltj.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
Trend Micro VSAPI NT: \??\C:\Program Files\OfficeScan NT\VSApiNt.sys (autostart)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
Wdf01000: system32\DRIVERS\Wdf01000.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
winachsf: system32\DRIVERS\HSF_CNXT.sys (manual start)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Dell Wireless WLAN Tray Service: %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Windows Management Interface for ACPI: system32\DRIVERS\wmiacpi.sys (system)
WMI Performance Adapter: C:\WINNT\system32\wbem\wmiapsrv.exe (manual start)
Windows Media Player Network Sharing Service: "C:\Program Files\Windows Media Player\WMPNetwk.exe" (manual start)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (disabled)
Windows Driver Foundation - User-mode Driver Framework Platform Driver: system32\DRIVERS\WudfPf.sys (system)
Windows Driver Foundation - User-mode Driver Framework Reflector: system32\DRIVERS\wudfrd.sys (manual start)
Windows Driver Foundation - User-mode Driver Framework: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup (autostart)
SMS Remote Control Agent: C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
————————————————–
Enumerating Windows NT logon/logoff scripts:
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\WINNT\system32\ytflnqpf.dll||C:\WINNT\system32\vfpdpcfw.dll||C:\WINNT\system32\vfpdpcfw.dll||C:\DOCUME~1\vm092543\LOCALS~1\Temp\_iu14D2N.tmp|||N
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINNT\system32\SHELL32.dll
CDBurn: C:\WINNT\system32\SHELL32.dll
WebCheck: C:\WINNT\system32\webcheck.dll
SysTray: C:\WINNT\system32\stobject.dll
WPDShServiceObj: C:\WINNT\system32\WPDShServiceObj.dll
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
*Registry key not found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
*Registry key not found*
————————————————–
End of report, 43,588 bytes
Report generated in 0.469 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hope the provided information is sufficient :-)
- Computer: Windows XP w/ latest ServicePacks and security bulleteins installed, Trend Microvirus w/ updated definitions, Spyware Search and Destroy, Tea Timer
- Problem: computer started to act very sluggish, since yesterday, severe performance issues, and random websites opening up
- Actions done so far: Trend flagged it as Vundo, and automatically tried to remove it (unsuccessfully). Then i ran Spybot search and destroy followed by a reboot. Tea-timer flagged attempts to write registry entries for changing rundll settings (amongst others)
HJT log (after reboot)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:53 PM, on 12/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\MCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\SvcLncher.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Suss.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\TEMP\XZ8E65.EXE
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\Program Files\OfficeScan NT\TmPfw.exe
C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\svchost.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\stsystra.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\WINNT\system32\WLTRAY.exe
C:\WINNT\system32\taskswitch.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINNT\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINNT\Managed\MCDesk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interwise\Participant\pull.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINNT\system32\HPZinw12.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://inside.nokiasiemensnetworks.com/global/search.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://inside.nokiasiemensnetworks.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by NSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://nsnproxy.rt.nsn-intra.net/proxy.pac
F2 - REG:system.ini: UserInit=c:\winnt\system32\userinit.exe
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Copernic Desktop Search - Home - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand300000081.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinZip Quick Pick] C:\Program Files\WinZip\WZQKPICK.EXE
O4 - HKLM\..\Run: [ServicesSynchronizationUtility] "C:\Program Files\Siemens\Services Synchronization Utility\vbs.exe" SyncServices.vbe r "C:\" "C:\WINNT\" "C:\WINNT\system32\" "\\nsn-intra.net\dfsres\s_lw\global\etc\"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINNT\system32\WLTRAY.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINNT\system32\taskswitch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MCDesk] %MgmtFolder%\MCDesk.exe %MgmtFolder%\MCDesk.ini
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy; - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Edit with Altova X&MLSpy; - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy; - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://inside.nokiasiemensnetworks.com
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: *.placeware.com
O15 - Trusted Zone: *.sap-ag.de
O15 - Trusted Zone: *.sap.com
O15 - Trusted Zone: http://communication-market1.siemens.de
O15 - Trusted Zone: http://icm-km.erlm.siemens.de
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de
O15 - Trusted Zone: http://ikuddq.icn.siemens.it
O15 - Trusted Zone: virtualtrainingroom.vodafone.com
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: *.placeware.com (HKLM)
O15 - Trusted Zone: *.sap-ag.de (HKLM)
O15 - Trusted Zone: *.sap.com (HKLM)
O15 - Trusted Zone: http://communication-market1.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://ikuddq.icn.siemens.it (HKLM)
O15 - Trusted Zone: virtualtrainingroom.vodafone.com (HKLM)
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webattend.com/components/wt0523.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218817069823
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components) - https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
O16 - DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} (Xerox_Services_Portal.XrxPrinter_Inst) - https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\Software\..\Telephony: DomainName = nsn-intra.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nsn-intra.net
O20 - AppInit_DLLs: cdmcvw.dll
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: eBOSS Helper (eBOSS) - Nortel Networks - (no file)
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\IP VPN Remote Services\Extranet_serv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: HTTP Poster Service (HTTP Poster) - Nokia - C:\WINNT\system32\HTTP_Poster.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Managed Client Service (MCsvc) - © 2005 - 2008 Siemens AG - C:\WINNT\System32\MCSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Service Launcher - SIS GO GIO DS PSU6 - C:\WINNT\system32\SvcLncher.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScanNT Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmProxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINNT\System32\WLTRYSVC.EXE
–
End of file - 16457 bytes
Spybot Log (after reboot)
— Search result list —
Hint of the Day: Click the bar at the right of this to see more information! ()
Smitfraud-C.: [SBI $99619F8C] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\instkey
Microsoft.Windows.ActiveDesktop: [SBI $B6472C30] User settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoAddingComponents
Microsoft.Windows.ActiveDesktop: [SBI $B6472C30] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoAddingComponents
Microsoft.Windows.ActiveDesktop: [SBI $B6472C30] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoAddingComponents
Microsoft.Windows.ActiveDesktop: [SBI $76BCFD1C] User settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoDeletingComponents
Microsoft.Windows.ActiveDesktop: [SBI $76BCFD1C] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoDeletingComponents
Microsoft.Windows.ActiveDesktop: [SBI $76BCFD1C] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoDeletingComponents
Microsoft.Windows.ActiveDesktop: [SBI $5C7BE05C] User settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoEditingComponents
Microsoft.Windows.ActiveDesktop: [SBI $5C7BE05C] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoEditingComponents
Microsoft.Windows.ActiveDesktop: [SBI $5C7BE05C] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoEditingComponents
Microsoft.Windows.ActiveDesktop: [SBI $C565A534] User settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoClosingComponents
Microsoft.Windows.ActiveDesktop: [SBI $C565A534] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoClosingComponents
Microsoft.Windows.ActiveDesktop: [SBI $C565A534] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoClosingComponents
Microsoft.Windows.Explorer: [SBI $1931FF4D] Settings (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges
Microsoft.Windows.Explorer: [SBI $1931FF4D] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges
Microsoft.Windows.Explorer: [SBI $1931FF4D] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges
Microsoft.Windows.disableSystemRestore: [SBI $1645D19C] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig
Microsoft.Windows.disableSystemRestore: [SBI $6296EC95] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableSR
Virtumonde: [SBI $8F2A4A7E] Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Virtumonde.generic: [SBI $1BB1339D] Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Virtumonde.generic: [SBI $2F10E03B] Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Virtumonde: [SBI $4D2BC948] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim
Virtumonde: [SBI $779C9C0D] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP
Virtumonde: [SBI $FD08B4B7] Configuration file (File, nothing done)
C:\WINNT\system32\VGfLmnpo.ini2
Virtumonde: [SBI $2A2DCEAC] Configuration file (File, nothing done)
C:\WINNT\system32\VGfLmnpo.ini
Virtumonde.prx: [SBI $3F5CA9DA] Autorun settings (d0dcc578) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d0dcc578
Virtumonde.prx: [SBI $3F5CA9DA] Program file (File, nothing done)
C:\WINNT\system32\ytflnqpf.dll
Win32.Agent.amyy: [SBI $DC8955FA] Program directory (Directory, nothing done)
C:\Documents and Settings\vm092543\Application Data\gadcom\
— Spybot - Search & Destroy version: 1.6.0 (build: 20080707) —
2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe ([removed])
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe ([removed])
2008-07-07 SDUpdate.exe ([removed])
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe ([removed])
2008-09-16 TeaTimer.exe ([removed])
2008-09-25 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-10-22 advcheck.dll ([removed])
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2008-11-04 Includes\Adware.sbi (*)
2008-11-25 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-09-02 Includes\Dialer.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-11-18 Includes\Hijackers.sbi (*)
2008-11-18 Includes\HijackersC.sbi (*)
2008-09-09 Includes\Keyloggers.sbi (*)
2008-11-18 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-11-18 Includes\Malware.sbi (*)
2008-12-03 Includes\MalwareC.sbi (*)
2008-11-03 Includes\PUPS.sbi (*)
2008-12-02 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-12-02 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-11-04 Includes\Spyware.sbi (*)
2008-12-02 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-11-04 Includes\Trojans.sbi (*)
2008-12-02 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
— System information —
Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB928367)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Service Pack 3 (KB867461)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ Microsoft .NET Framework 2.0: This Security Update is for Microsoft .NET Framework 2.0. \n
If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
For more information, visit http://support.microsoft.com/kb/917283
/ Microsoft .NET Framework 2.0: This Security Update is for Microsoft .NET Framework 2.0. \n
If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
For more information, visit http://support.microsoft.com/kb/922770
/ Microsoft .NET Framework 2.0: This Security Update is for Microsoft .NET Framework 2.0. \n
If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
For more information, visit http://support.microsoft.com/kb/928365
/ MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
/ Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB890937
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Windows XP Hotfix - KB892050
/ Windows XP / SP3: Hotfix for Windows XP (KB893357)
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Hotfix for Windows XP (KB896256)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Update for Windows XP (KB896427)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Update for Windows XP (KB897663)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901190)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Update for Windows XP (KB908531)
/ Windows XP / SP3: Hotfix for Windows XP (KB909095)
/ Windows XP / SP3: Update for Windows XP (KB911280)
/ Windows XP / SP3: Security Update for Windows XP (KB911562)
/ Windows XP / SP3: Security Update for Windows XP (KB911927)
/ Windows XP / SP3: Hotfix for Windows XP (KB912761)
/ Windows XP / SP3: Security Update for Windows XP (KB913580)
/ Windows XP / SP3: Security Update for Windows XP (KB914388)
/ Windows XP / SP3: Security Update for Windows XP (KB914389)
/ Windows XP / SP3: Hotfix for Windows XP (KB916191)
/ Windows XP / SP3: Hotfix for Windows XP (KB917021)
/ Windows XP / SP3: Security Update for Windows XP (KB917344)
/ Windows XP / SP3: Security Update for Windows XP (KB917953)
/ Windows XP / SP3: Security Update for Windows XP (KB918118)
/ Windows XP / SP3: Security Update for Windows XP (KB918439)
/ Windows XP / SP3: Security Update for Windows XP (KB919007)
/ Windows XP / SP3: Security Update for Windows XP (KB920213)
/ Windows XP / SP3: Security Update for Windows XP (KB920670)
/ Windows XP / SP3: Security Update for Windows XP (KB920683)
/ Windows XP / SP3: Security Update for Windows XP (KB920685)
/ Windows XP / SP3: Security Update for Windows XP (KB921503)
/ Windows XP / SP3: Security Update for Windows XP (KB922819)
/ Windows XP / SP3: Security Update for Windows XP (KB923191)
/ Windows XP / SP3: Security Update for Windows XP (KB923414)
/ Windows XP / SP3: Security Update for Windows XP (KB923980)
/ Windows XP / SP3: Security Update for Windows XP (KB924191)
/ Windows XP / SP3: Security Update for Windows XP (KB924270)
/ Windows XP / SP3: Security Update for Windows XP (KB924496)
/ Windows XP / SP3: Security Update for Windows XP (KB924667)
/ Windows XP / SP3: Security Update for Windows XP (KB925902)
/ Windows XP / SP3: Hotfix for Windows XP (KB926239)
/ Windows XP / SP3: Security Update for Windows XP (KB926255)
/ Windows XP / SP3: Security Update for Windows XP (KB926436)
/ Windows XP / SP3: Security Update for Windows XP (KB927779)
/ Windows XP / SP3: Security Update for Windows XP (KB927802)
/ Windows XP / SP3: Security Update for Windows XP (KB928255)
/ Windows XP / SP3: Security Update for Windows XP (KB928843)
/ Windows XP / SP3: Security Update for Windows XP (KB929123)
/ Windows XP / SP3: Security Update for Windows XP (KB929969)
/ Windows XP / SP3: Security Update for Windows XP (KB930178)
/ Windows XP / SP3: Security Update for Windows XP (KB931261)
/ Windows XP / SP3: Security Update for Windows XP (KB931784)
/ Windows XP / SP3: Update for Windows XP (KB931836)
/ Windows XP / SP3: Security Update for Windows XP (KB932168)
/ Windows XP / SP3: Hotfix for Windows XP (KB933062)
/ Windows XP / SP3: Update for Windows XP (KB933360)
/ Windows XP / SP3: Security Update for Windows XP (KB933566)
/ Windows XP / SP3: Security Update for Windows XP (KB933729)
/ Windows XP / SP3: Hotfix for Windows XP (KB935448)
/ Windows XP / SP3: Security Update for Windows XP (KB935839)
/ Windows XP / SP3: Security Update for Windows XP (KB935840)
/ Windows XP / SP3: Security Update for Windows XP (KB936021)
/ Windows XP / SP3: Security Update for Windows XP (KB937894)
/ Windows XP / SP3: Security Update for Windows XP (KB938127)
/ Windows XP / SP3: Security Update for Windows XP (KB938829)
/ Windows XP / SP3: Hotfix for Windows XP (KB939273)
/ Windows XP / SP3: Security Update for Windows XP (KB941202)
/ Windows XP / SP3: Security Update for Windows XP (KB941568)
/ Windows XP / SP3: Security Update for Windows XP (KB941693)
/ Windows XP / SP3: Security Update for Windows XP (KB942615)
/ Windows XP / SP3: Security Update for Windows XP (KB943055)
/ Windows XP / SP3: Security Update for Windows XP (KB943460)
/ Windows XP / SP3: Security Update for Windows XP (KB943485)
/ Windows XP / SP3: Security Update for Windows XP (KB944338-v2)
/ Windows XP / SP3: Security Update for Windows XP (KB944653)
/ Windows XP / SP3: Security Update for Windows XP (KB945553)
/ Windows XP / SP3: Security Update for Windows XP (KB946026)
/ Windows XP / SP3: Security Update for Windows XP (KB948590)
/ Windows XP / SP3: Security Update for Windows XP (KB950749)
/ Windows XP / SP4: Security Update for Windows XP (KB938464)
/ Windows XP / SP4: Security Update for Windows XP (KB946648)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Update for Windows XP (KB951072-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951698)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB953838)
/ Windows XP / SP4: Security Update for Windows XP (KB954211)
/ Windows XP / SP4: Security Update for Windows XP (KB955069)
/ Windows XP / SP4: Security Update for Windows XP (KB956390)
/ Windows XP / SP4: Security Update for Windows XP (KB956391)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB956841)
/ Windows XP / SP4: Security Update for Windows XP (KB957095)
/ Windows XP / SP4: Security Update for Windows XP (KB957097)
/ Windows XP / SP4: Security Update for Windows XP (KB958644)
— Startup entries list —
Located: HK_LM:Run, AccessManager
command: C:\Program Files\AccessManager\Client\AccessMgr.exe
file: C:\Program Files\AccessManager\Client\AccessMgr.exe
size: 786432
MD5: E00A56C2B8ABF31C433EBE9EAD54EEAE
Located: HK_LM:Run, Acrobat Assistant 8.0
command: "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
file: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
size: 620152
MD5: A21E70B4F972CA396A80013D0D436350
Located: HK_LM:Run, Apoint
command: C:\Program Files\DellTPad\Apoint.exe
file: C:\Program Files\DellTPad\Apoint.exe
size: 159744
MD5: 5EF24621ABCE6965E32A365CA613A544
Located: HK_LM:Run, Broadcom Wireless Manager UI
command: C:\WINNT\system32\WLTRAY.exe
file: C:\WINNT\system32\WLTRAY.exe
size: 1392640
MD5: 17CEC1CB41C5580DBE20984FC73BC4F4
Located: HK_LM:Run, CoolSwitch
command: C:\WINNT\system32\taskswitch.exe
file: C:\WINNT\system32\taskswitch.exe
size: 45632
MD5: EBD2EA535FC47D426D0C2FC7C7293534
Located: HK_LM:Run, d0dcc578
command: rundll32.exe "C:\WINNT\system32\ytflnqpf.dll",b
file: C:\WINNT\system32\ytflnqpf.dll
size: 72704
MD5: 1FC555C50D0092F36D76636A0F84D1FE
Located: HK_LM:Run, HotKeysCmds
command: C:\WINNT\system32\hkcmd.exe
file: C:\WINNT\system32\hkcmd.exe
size: 162584
MD5: 48ED49A40D09A6CF258E8BF398B9CF79
Located: HK_LM:Run, IgfxTray
command: C:\WINNT\system32\igfxtray.exe
file: C:\WINNT\system32\igfxtray.exe
size: 138008
MD5: 16219958FA5A3948C983D821C669F7A6
Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 267048
MD5: 04A9F0C58B170F30445BCC0683EF9FFC
Located: HK_LM:Run, KernelFaultCheck
command: %systemroot%\system32\dumprep 0 -k
file: C:\WINNT\system32\dumprep 0 -k
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, MCDesk
command: %MgmtFolder%\MCDesk.exe %MgmtFolder%\MCDesk.ini
file: C:\WINNT\Managed\MCDesk.exe
size: 53248
MD5: 89DA9CF9227744A7A6C0D582AED94EA5
Located: HK_LM:Run, OfficeScanNT Monitor
command: "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
file: C:\Program Files\OfficeScan NT\pccntmon.exe
size: 714024
MD5: 71056AD9643BA2DCEBB1A5E49A2F4070
Located: HK_LM:Run, Persistence
command: C:\WINNT\system32\igfxpers.exe
file: C:\WINNT\system32\igfxpers.exe
size: 138008
MD5: B922482FA05828762EA1FD8D24D3AD62
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\QTTask.exe" -atboottime
file: C:\Program Files\QuickTime\QTTask.exe
size: 413696
MD5: 6DF76965A0FB8237E9C3B3CAB9815EC2
Located: HK_LM:Run, ServicesSynchronizationUtility
command: "C:\Program Files\Siemens\Services Synchronization Utility\vbs.exe" SyncServices.vbe r "C:\" "C:\WINNT\" "C:\WINNT\system32\" "\\nsn-intra.net\dfsres\s_lw\global\etc\"
file: C:\Program Files\Siemens\Services Synchronization Utility\vbs.exe
size: 20480
MD5: 2E807FF6F78DA11CEDBC4916BF70CFCA
Located: HK_LM:Run, SigmatelSysTrayApp
command: stsystra.exe
file: C:\WINNT\stsystra.exe
size: 303104
MD5: 34F44FE583D16815AD848855E7618E0D
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre6\bin\jusched.exe"
file: C:\Program Files\Java\jre6\bin\jusched.exe
size: 136600
MD5: AB68B7C232293F6B09E5C29CB31AE76D
Located: HK_LM:Run, Synchronization Manager
command: mobsync.exe /logon
file: C:\WINNT\system32\mobsync.exe
size: 143360
MD5: 5531C63F05C7D041F7DA9F8B7D88F00E
Located: HK_LM:Run, WinZip Quick Pick
command: C:\Program Files\WinZip\WZQKPICK.EXE
file: C:\Program Files\WinZip\WZQKPICK.EXE
size: 106560
MD5: 2FE253973433442C2CB234FB2BC4BF29
Located: HK_CU:Run, Nokia.PCSync
where: .DEFAULT…
command: "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog
file: C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, AdobeUpdater
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
file: C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
size: 2321600
MD5: CEBB4703FE0A875947E5F0A3A95FE577
Located: HK_CU:Run, Copernic Desktop Search - Home
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
file: C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
size: 1698816
MD5: 950F6A67AE3FBB1DA12842D0927F6035
Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: C:\WINNT\system32\ctfmon.exe
file: C:\WINNT\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8
Located: HK_CU:Run, Google Update
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
file: C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
size: 133104
MD5: 626A24ED1228580B9518C01930936DF9
Located: HK_CU:Run, Nokia.PCSync
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
file: C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
size: 1249280
MD5: 457C3DD5F4655EB0F1A564110319B9D0
Located: HK_CU:Run, PC Suite Tray
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: "C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe" -onlytray
file: C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe
size: 1124352
MD5: 67576EBBAD86E5F92B327A9F83443628
Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-1593251271-2640304127-1825641215-227304…
command: C:\Program Files\Spybot\TeaTimer.exe
file: C:\Program Files\Spybot\TeaTimer.exe
size: 1833296
MD5: 63B3FF83B87AFCEBA89CED54695DA0F6
Located: HK_CU:Run, Nokia.PCSync
where: S-1-5-18…
command: "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog
file: C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: Startup (common), Adobe Acrobat Speed Launcher.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\WINNT\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe
file: C:\WINNT\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe
size: 295606
MD5: 21638D0E7F02D6CB855B76243521F409
Located: Startup (common), Adobe Acrobat Synchronizer.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
file: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
size: 734872
MD5: 169C293CE9460A05646D17DC6AA2FB2C
Located: Startup (common), Adobe Reader - Schnellstart.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
size: 29696
MD5: 43362B96870CE8649F4F2EC893DA93F0
Located: Startup (common), Bluetooth Manager.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
file: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
size: 2150400
MD5: E8DD777F7AA93648894574CC418B0624
Located: Startup (common), Digital Line Detect.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\Digital Line Detect\DLG.exe
file: C:\Program Files\Digital Line Detect\DLG.exe
size: 50688
MD5: F03FFC962E18F36A922E61F96BE09925
Located: Startup (common), HP Digital Imaging Monitor.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
file: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
size: 288472
MD5: 4543367E50BD35E7D1269D42841B156E
Located: Startup (common), Push Client.LNK
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup…
command: C:\Program Files\interwise\Participant\pull.exe
file: C:\Program Files\interwise\Participant\pull.exe
size: 886000
MD5: 21B7263CFB2360727B2CE61866FF1B86
Located: Startup (disabled), Infotriever (DISABLED)
command: C:\PROGRA~1\INFOTR~1\Agent\INFOCL~1.EXE -startup
file: C:\PROGRA~1\INFOTR~1\Agent\INFOCL~1.EXE
size: 111976
MD5: 30A04467118710C03750D093853B86AC
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, igfxcui
command: igfxdev.dll
file: igfxdev.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, urqRLfCr
command: urqRLfCr.dll
file: urqRLfCr.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
— Browser helper object list —
{53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D; IE Protection)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Spybot-S&D; IE Protection
description: Spybot-S&D; IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\Spybot\
Long name: SDHelper.dll
Short name:
Date (created): 9/25/2008 10:22:20 PM
Date (last access): 12/7/2008 8:06:14 PM
Date (last write): 9/15/2008 1:25:44 PM
Filesize: 1562960
Attributes: readonly hidden sysfile archive
MD5: 35F73F1936BDE91F1B6995510A61E7A8
CRC32: BE6A5D15
Version: 1.6.2.14
{57AF5BDF-F2F5-42CC-AB33-CD39B6DD6DC0} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\WINNT\system32\
Long name: opnmLfGV.dll
Short name:
Date (created): 12/7/2008 4:46:28 PM
Date (last access): 12/7/2008 6:41:14 PM
Date (last write): 12/7/2008 4:46:30 PM
Filesize: 302592
Attributes:
MD5: 84FBB985EEBF04AA18540D86B2791E13
CRC32: CE6440AC
{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\WINNT\system32\
Long name: urqRLfCr.dll
Short name:
Date (created): 12/7/2008 4:41:22 PM
Date (last access): 12/7/2008 6:55:20 PM
Date (last write): 12/7/2008 4:41:22 PM
Filesize: 34816
Attributes: archive
MD5: 1201DB328B213337DA604FA636D6FBF8
CRC32: F8BB58B2
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Java™ Plug-In SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java™ Plug-In SSV Helper
Path: C:\Program Files\Java\jre6\bin\
Long name: ssv.dll
Short name:
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 4:59:24 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 320920
Attributes: archive
MD5: DC090E320775F1B1FE896F6E1D393D7F
CRC32: 068B5AFC
Version: 6.0.100.33
{7CAB59B4-55A3-4737-9FD5-B93C6430BF78} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\WINNT\system32\
Long name: pohxirds.dll
Short name:
Date (created): 12/7/2008 4:47:20 PM
Date (last access): 12/7/2008 6:55:20 PM
Date (last write): 12/7/2008 4:47:20 PM
Filesize: 116224
Attributes: archive
MD5: 451CD6EFFE6E4454BF0226CAB847CEA3
CRC32: 17D40512
{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java™ Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java™ Plug-In 2 SSV Helper
Path: C:\Program Files\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 4:59:24 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 34816
Attributes: archive
MD5: 27771CDC5D464818C8F92356AE840A6F
CRC32: B0BC1BD4
Version: 6.0.100.33
{fc0299ec-3e9a-4425-8697-219e2fc5e21f} ({f12e5cf2-e912-7968-5244-a9e3ce9920cf})
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: {f12e5cf2-e912-7968-5244-a9e3ce9920cf}
CLSID name:
Path: C:\WINNT\system32\
Long name: yxqdgw.dll
Short name:
Date (created): 12/7/2008 5:14:24 PM
Date (last access): 12/7/2008 6:40:12 PM
Date (last write): 12/7/2008 5:14:24 PM
Filesize: 129024
Attributes: archive
MD5: 4BA37AFDF4AEC72C0E47F87E8FC3601B
CRC32: DE571456
— ActiveX list —
{21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain)
DPF name:
CLSID name: WebTrain.ctlWebTrain
Installer: C:\WINNT\Downloaded Program Files\WEB_TRAIN.INF
Codebase: http://www.webattend.com/components/wt0523.cab
Path: C:\WINNT\system32\
Long name: WEBTRAIN.OCX
Short name:
Date (created): 6/1/2006 9:30:06 AM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 6/1/2006 9:30:06 AM
Filesize: 5023232
Attributes: archive
MD5: 29F676053EBF97DD31BDADA03D701E5B
CRC32: 76B3920F
Version: 3.5.0.10
{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Installer: C:\WINNT\Downloaded Program Files\wuweb.inf
Codebase: http://www.update.microsoft.com/windowsupd…b?1218817069823
description:
classification: Legitimate
known filename: wuweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINNT\system32\
Long name: wuweb.dll
Short name:
Date (created): 9/26/2007 1:48:38 PM
Date (last access): 12/7/2008 6:01:58 PM
Date (last write): 7/18/2008 9:09:44 PM
Filesize: 205000
Attributes: archive
MD5: 4889720E56E85E1FE4659039BB5F6E3F
CRC32: EE278BD5
Version: 7.2.6001.784
{7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control)
DPF name:
CLSID name: JNILoader Control
Installer: C:\WINNT\Downloaded Program Files\STJNILoader.inf
Codebase: https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
description:
classification: Open for discussion
known filename: STJNIL~1.OCX
info link:
info source: Safer Networking Ltd.
Path: C:\WINNT\DOWNLO~1\
Long name: STJNILoader.ocx
Short name: STJNIL~1.OCX
Date (created): 6/2/2005 10:41:50 AM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 6/2/2005 10:41:50 AM
Filesize: 274432
Attributes: archive
MD5: 7CF21AEC4A39199EE44C10415A97A5E3
CRC32: FE340101
Version: 3.1.1.104
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_10
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_10.dll
Short name: NPJPI1~1.DLL
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 132504
Attributes: archive
MD5: 3CEF7A7DE0D5141E016A862B1D86B1CD
CRC32: CC232AC8
Version: 6.0.100.33
{8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components)
DPF name:
CLSID name: Whale Client Components
Installer: C:\WINNT\Downloaded Program Files\WhlCompMgr.inf
Codebase: https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
description:
classification: Legitimate
known filename: WhlMgr.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINNT\Downloaded Program Files\
Long name: WhlMgr.dll
Short name:
Date (created): 1/17/2008 12:53:56 PM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 1/17/2008 12:53:56 PM
Filesize: 945816
Attributes: archive
MD5: 493035BD9564C65DE8FCE1C0EB2F7A3F
CRC32: E08FA9DB
Version: 3.7.196.0
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name:
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_04
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Path: C:\Program Files\Java\jre1.6.0_04\bin\
Long name: npjpi160_04.dll
Short name: NPJPI1~1.DLL
Date (created): 12/14/2007 1:59:16 AM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 12/14/2007 3:42:38 AM
Filesize: 132496
Attributes: archive
MD5: 58A1C3B13CC79E76F66CA6F8FED3B36A
CRC32: A4EACB48
Version: 6.0.40.12
{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_10
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_10.dll
Short name: NPJPI1~1.DLL
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 8:06:18 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 132504
Attributes: archive
MD5: 3CEF7A7DE0D5141E016A862B1D86B1CD
CRC32: CC232AC8
Version: 6.0.100.33
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_10
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_10.dll
Short name: NPJPI1~1.DLL
Date (created): 11/26/2008 12:35:52 PM
Date (last access): 12/7/2008 8:06:18 PM
Date (last write): 11/26/2008 12:35:52 PM
Filesize: 132504
Attributes: archive
MD5: 3CEF7A7DE0D5141E016A862B1D86B1CD
CRC32: CC232AC8
Version: 6.0.100.33
{D3E01836-60CD-480D-BBDB-19D5A7D23128} (Xerox_Services_Portal.XrxPrinter_Inst)
DPF name:
CLSID name: Xerox_Services_Portal.XrxPrinter_Inst
Installer: C:\WINNT\Downloaded Program Files\Xerox_Services_Portal_Pref.INF
Codebase: https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
Path: C:\WINNT\Downloaded Program Files\
Long name: Xerox_Services_Portal_Pref.ocx
Short name: XEROX_~1.OCX
Date (created): 1/28/2008 3:27:56 PM
Date (last access): 12/7/2008 5:12:36 PM
Date (last write): 1/28/2008 3:27:56 PM
Filesize: 73728
Attributes: archive
MD5: D065C5D8051318F3EFA53AC61D3D772B
CRC32: CB3E80CD
Version: 3.8.0.22
— Process list —
PID: 0 ( 0) [System]
PID: 1168 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 1412 (1168) \??\C:\WINNT\system32\csrss.exe
size: 6144
PID: 1696 (1168) \??\C:\WINNT\system32\winlogon.exe
size: 502272
PID: 1740 (1696) C:\WINNT\system32\services.exe
size: 108032
MD5: C6CE6EEC82F187615D1002BB3BB50ED4
PID: 1752 (1696) C:\WINNT\system32\lsass.exe
size: 13312
MD5: 84885F9B82F4D55C6146EBF6065D75D2
PID: 1988 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 128 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 368 (1740) C:\WINNT\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 400 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 468 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 776 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1020 (1740) C:\WINNT\System32\WLTRYSVC.EXE
size: 20480
MD5: 60714B1C15F815F55798C0B3D4819BEB
PID: 1032 (1020) C:\WINNT\System32\bcmwltry.exe
size: 1253376
MD5: 7C19764A2EC7AC4AE8DB4BBF0B7F20C5
PID: 1104 (1740) C:\WINNT\system32\spoolsv.exe
size: 57856
MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
PID: 1160 (1740) C:\WINNT\System32\SCardSvr.exe
size: 95744
MD5: 25D8DE134DF108E3DBC8D7D23B1AA58E
PID: 1272 (1740) C:\Program Files\AccessManager\Client\AMBroker.exe
size: 77824
MD5: 0A8446FEA210A30C07B8DD879858ED35
PID: 1340 (1740) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
size: 110592
MD5: 1961CB10BB48EB4D97E37DB6373E9E63
PID: 1436 (1740) C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
size: 86016
MD5: 52A4ED0D41DD3652B1DB311FC0765BC4
PID: 1448 (1740) C:\Program Files\Java\jre6\bin\jqs.exe
size: 152984
MD5: 5FD5865DC1A2100F8D4CF000EE5409A3
PID: 1544 (1740) C:\WINNT\System32\MCSvc.exe
size: 69632
MD5: 86EC5A1FAEEE67FCE1287150E635A64C
PID: 1596 (1740) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
size: 322120
MD5: 11F714F85530A2BD134074DC30E99FCA
PID: 1644 (1740) C:\Program Files\OfficeScan NT\ntrtscan.exe
size: 906536
MD5: EC539F17431F5FA73DD4F44FF64E9C0B
PID: 1672 (1740) C:\WINNT\system32\HPZipm12.exe
size: 69632
MD5: D31F88C5F19EEFA366A415D6BC5F2ABC
PID: 1824 (1740) C:\WINNT\system32\SvcLncher.exe
size: 229376
MD5: 8E21F9A309FDA5BA391682527E48A6AF
PID: 2004 (1740) C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
size: 118784
MD5: EF1F7335F0285599438A2E713CE8772A
PID: 2020 (1740) C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
size: 90112
MD5: 686FA4ACFDCB4E16B7F0230B88F6D17E
PID: 516 (1740) C:\WINNT\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 528 (1740) C:\WINNT\system32\Suss.exe
size: 12048
MD5: 7A375DBDAC196606E0CA92F4580B87D2
PID: 580 (1740) C:\Program Files\AccessManager\Client\sygman.exe
size: 126976
MD5: B3B3ABC9FCD0720587F12F7649DC664F
PID: 696 (1740) C:\Program Files\OfficeScan NT\tmlisten.exe
size: 984360
MD5: 89D686F4656CDEAEC3936ABCCE9DF11D
PID: 964 (1740) C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
size: 251256
MD5: E5F1614AE616C9C1B00E92031867F48F
PID: 992 (1740) C:\WINNT\system32\CCM\CcmExec.exe
size: 590712
MD5: E4B94F8EDB3540D43A473D552C30D395
PID: 1480 (1644) C:\WINNT\TEMP\XZ8E65.EXE
size: 296224
MD5: B8BEE3B4802F23FCC809082DFB5A663B
PID: 2312 (1740) C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
size: 135168
MD5: BEDE742D051F3F848C10F59FC85C0DEB
PID: 2664 (1740) C:\WINNT\System32\alg.exe
size: 44544
MD5: F1958FBF86D5C004CF19A5951A9514B7
PID: 2836 (1740) C:\Program Files\OfficeScan NT\TmPfw.exe
size: 488768
MD5: 3341EDF8769BC1967E2CA097792C370C
PID: 3188 (1988) C:\WINNT\system32\wbem\wmiprvse.exe
size: 218112
MD5: 075EA6C849AB0FE416A3D6DD65C3CF41
PID: 3588 (1988) C:\WINNT\system32\wbem\wmiprvse.exe
size: 218112
MD5: 075EA6C849AB0FE416A3D6DD65C3CF41
PID: 3860 ( 696) C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
size: 435576
MD5: 42F903C87ABDC68176A1A436470D4B0F
PID: 828 (3992) C:\WINNT\Explorer.EXE
size: 1032192
MD5: A0732187050030AE399B241436565E64
PID: 2068 ( 828) C:\Program Files\Spybot\SpybotSD.exe
size: 4891472
MD5: 3B1B5D09D3C9C4CD39D4DB06ED7A0855
PID: 3476 (1740) C:\WINNT\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 3380 ( 368) C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
size: 133104
MD5: 626A24ED1228580B9518C01930936DF9
PID: 4 ( 0) System
— Browser start & search pages list —
Spybot - Search & Destroy browser pages report, 12/7/2008 8:06:19 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINNT\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
https://inside.nokiasiemensnetworks.com/global/search.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
https://inside.nokiasiemensnetworks.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
https://inside.nokiasiemensnetworks.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
— Winsock Layered Service Provider list —
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{82050D99-E21F-4151-BB2B-BDFB81A15DB1}] SEQPACKET 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{82050D99-E21F-4151-BB2B-BDFB81A15DB1}] DATAGRAM 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{67C55556-3A19-425C-AE9D-6F311F24CF5B}] SEQPACKET 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{67C55556-3A19-425C-AE9D-6F311F24CF5B}] DATAGRAM 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{5E8875FA-BF7D-4B93-8D00-F179F4FEF81F}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{5E8875FA-BF7D-4B93-8D00-F179F4FEF81F}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FAFCE09D-8A2E-4F21-A092-B020C58316EB}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FAFCE09D-8A2E-4F21-A092-B020C58316EB}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{31129AF3-2CDF-4692-8126-6AEED5019D8A}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{31129AF3-2CDF-4692-8126-6AEED5019D8A}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CF321070-626F-48AE-B65A-3105209C4985}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CF321070-626F-48AE-B65A-3105209C4985}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{126BA951-FA38-47DE-9561-C5BE92FE0776}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{126BA951-FA38-47DE-9561-C5BE92FE0776}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F20EE0C8-D5BD-413F-844F-D76262EE0E81}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F20EE0C8-D5BD-413F-844F-D76262EE0E81}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EC26FC9D-9BB7-4038-839E-642242A7CF10}] SEQPACKET 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EC26FC9D-9BB7-4038-839E-642242A7CF10}] DATAGRAM 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 23: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BDE3CAD2-30AD-4E60-982B-A8FCFBAE8ECC}] SEQPACKET 9
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 24: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BDE3CAD2-30AD-4E60-982B-A8FCFBAE8ECC}] DATAGRAM 9
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
Namespace Provider 3: mdnsNSP
GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
Filename: C:\Program Files\Bonjour\mdnsNSP.dll
Description: Apple Rendezvous protocol
DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
DB protocol: mdnsNSP
— Uninstall list —
Windows Driver Package - Nokia Modem (02/15/2007 3.1) 02/15/2007 3.1 (0C5EDC3653FED5B121F464339EAC12534D253B25)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\pccs_bluet_8B37DC72918CCD58A6EC20373AF6242B037A293B\pccs_bluetooth.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (08/08/2007 3.3) 08/08/2007 3.3 (24894EA20BE8E62AA4FC3DD3AA85785356B52BF5)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\pccs_bluet_32E2E448B53EE5B28E074D88802D0BAF984038DA\pccs_bluetooth.inf
publisher: Nokia
Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) 10/12/2007 6.85.4.0 (3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (10/12/2007 3.6) 10/12/2007 3.6 (6A630DCEC5EEC912115F2FF59D8C2C769798D930)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokia_blue_0A5D98F754C6588B2E3DDE89DDEF097075ADFFB7\nokia_bluetooth.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2) 08/03/2007 6.84.0.2 (819D45A9F73817F5B6D7C71A33ADAB88C5DA1765)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokbtmdm_1EB5F2E6F54A6BEDE9F436D1BA5D830FC71739BE\nokbtmdm.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1) 05/22/2008 7.00.0.1 (9CD348AE9C64C4B939B624E8E24F3903EFDFC82B)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9\nokbtmdm.inf
publisher: Nokia
WebEx (ActiveTouchMeetingClient)
uninstall cmd: C:\PROGRA~1\MOZILL~1\plugins\atcliun.exe
publisher: WebEx Communications, Inc
contact: Customer Support
help link: http://support.webex.com/
(AddressBook)
Adobe Acrobat 8 Professional - English, Français, Deutsch 8.0.0 (Adobe Acrobat 8 Professional - English, Français, Deutsch)
version (major): 8
install date: 10/6/2007
install location: C:\Program Files\Adobe\Acrobat 8.0\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\Adobe Acrobat 8.0\
uninstall cmd: msiexec /I {AC76BA86-1033-F400-7760-000000000003}
publisher: Adobe Systems
contact: Customer Support
help link: http://www.adobe.com/support/main.html
help telephone:
readme: C:\Program Files\Adobe\Acrobat 8.0\Readme.htm
Adobe Flash Player 10 Plugin 10.0.12.36 (Adobe Flash Player Plugin)
uninstall cmd: C:\WINNT\system32\Macromed\Flash\uninstall_plugin.exe
publisher: Adobe Systems Incorporated
Adobe Shockwave Player 11 11 (Adobe Shockwave Player)
version (major): 11
install location: C:\WINNT\system32\Adobe\
uninstall cmd: C:\WINNT\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINNT\system32\Adobe\SHOCKW~1\Install.log
publisher: Adobe Systems, Inc.
help link: http://www.adobe.com/support/shockwave
AT&T; Connect Participant (AT&T; Connect Participant)
install location: C:\Program Files\Interwise\Participant
uninstall cmd: C:\Program Files\Interwise\Participant\iwuninst.exe
Windows Driver Package - Nokia Modem (02/15/2007 3.1) 02/15/2007 3.1 (B726756F5B5A5AA9D798B399386FC6205A45F19E)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\pccs_bluet_F12A08B6F776984A95553486F64C541356F86E38\pccs_bluetooth.inf
publisher: Nokia
(Branding)
Dell Wireless WLAN Card 4.100.15.8 (Broadcom 802.11b Network Adapter)
uninstall cmd: "C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
publisher: Dell Inc.
Windows Driver Package - Nokia Modem (05/22/2008 3.8) 05/22/2008 3.8 (C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181E\nokia_bluetooth.inf
publisher: Nokia
Windows Driver Package - Nokia Modem (03/05/2008 3.7) 03/05/2008 3.7 (CBF192A85B624E32B8D19ADEEF2DCFC5BC3AA73A)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokia_blue_635B28EFCFA9395123BB1C251595CB16129E2560\nokia_bluetooth.inf
publisher: Nokia
CCleaner (remove only) (CCleaner)
uninstall cmd: "C:\Program Files\CCleaner\uninst.exe"
Windows Driver Package - Nokia Modem (05/24/2007 6.84.0.1) 05/24/2007 6.84.0.1 (CD8424B9400BFF7D34AA18F816C71322AC4BDAA7)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokbtmdm_5E1541AFF1E1EA3554CE566743CCAD323ED1C108\nokbtmdm.inf
publisher: Nokia
Conexant HDA D330 MDC V.92 Modem (CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F)
uninstall cmd: C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F\HXFSETUP.EXE -U -Idel000f5.inf
(Connection Manager)
Copernic Desktop Search - Home (CopernicDesktopSearch2)
uninstall cmd: C:\Program Files\Copernic Desktop Search 2\uninst.exe
publisher: Copernic Inc.
(DirectAnimation)
(DirectDrawEx)
DVD Decrypter (Remove Only) (DVD Decrypter)
uninstall cmd: "C:\Program Files\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2 (DVD Shrink_is1)
install location: C:\Program Files\DVD Shrink\
uninstall cmd: "C:\Program Files\DVD Shrink\unins000.exe"
publisher: DVD Shrink
help link: http://www.dvdshrink.org
(DXM_Runtime)
Windows Driver Package - Nokia Modem (03/13/2008 6.86.0.1) 03/13/2008 6.86.0.1 (E092B2EBF2FFE83E896F8F7F829A7B5D7D1B2F9D)
uninstall cmd: C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINNT\system32\DRVSTORE\nokbtmdm_28F2EAC406838DA65AFF6C6886FE9FE96AEF5186\nokbtmdm.inf
publisher: Nokia
Firefly Media Server svn-1359 (Firefly Media Server)
uninstall cmd: C:\Program Files\Firefly Media Server\uninst.exe
publisher: Ron Pedde
(Fontcore)
GSplit 2.0 2.0.0.2 (GSplit20S)
uninstall cmd: C:\Program Files\GSplit\Uninst.exe
publisher: The G.D.G. Software Team
Intel® Graphics Media Accelerator Driver (HDMI)
uninstall cmd: C:\WINNT\system32\igxpun.exe -uninstall
HijackThis 2.0.0 2.0.0 (HijackThis)
uninstall cmd: "D:\Data\Downloads\HijackThis.exe" /uninstall
publisher: TrendMicro
HP Imaging Device Functions 7.0 7.0 (HP Imaging Device Functions)
uninstall cmd: C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
publisher: HP
help link: http://www.hp.com/support
HP Solution Center 7.0 7.0 (HP Solution Center & Imaging Support Tools)
uninstall cmd: C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
publisher: HP
help link: http://www.hp.com/support
OCR Software by I.R.I.S 7.0 7.0 (HPOCR)
uninstall cmd: C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
publisher: HP
help link: http://www.hp.com/support
(ICW)
(IE40)
(IE4Data)
(IE5BAKEX)
(IEData)
(InstallShield Uninstall Information)
BlackBerry Connect Desktop for Nokia 4.0.0 (InstallShield_{5238A932-32B7-4F62-B384-869A23DEA4BE})
version: 67108864
version (major): 4
estimated size: 3624
install date: 20080103
install source: C:\Documents and Settings\vm092543\Local Settings\Application Data\{D76BC089-A308-4D85-AF2F-5CBBF3E3ACC5}\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{5238A932-32B7-4F62-B384-869A23DEA4BE} /l1033
publisher: Research In Motion, Ltd.
20040929.110854 (KB834707)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=834707
20041117.092459 (KB873339)
uninstall cmd: C:\WINNT\$NtUninstallKB873339$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=873339
(KB884016)
(KB884267)
(KB885353)
20041027.181713 (KB885835)
uninstall cmd: C:\WINNT\$NtUninstallKB885835$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=885835
20041028.173203 (KB885836)
uninstall cmd: C:\WINNT\$NtUninstallKB885836$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=885836
20041021.090540 (KB886185)
uninstall cmd: C:\WINNT\$NtUninstallKB886185$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=886185
(KB886612)
(KB887078)
20041014.162858 (KB887472)
uninstall cmd: C:\WINNT\$NtUninstallKB887472$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=887472
(KB887626)
High Definition Audio Driver Package - KB888111 20040219.000000 (KB888111WXPSP2)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=KB888111
20041207.111426 (KB888302)
uninstall cmd: C:\WINNT\$NtUninstallKB888302$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=888302
(KB888656)
(KB889858)
Security Update for Windows XP (KB890046) 1 (KB890046)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB890046$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=890046
1 (KB890859)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB890859$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=890859
20041229.171115 (KB890937)
uninstall cmd: C:\WINNT\$NtUninstallKB890937$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=890937
(KB891122)
20050110.165439 (KB891781)
uninstall cmd: C:\WINNT\$NtUninstallKB891781$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=891781
3 (KB892050)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB892050$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=892050
(KB892313)
(KB893240)
(KB893241)
2 (KB893357)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB893357$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=893357
1 (KB893756)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB893756$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=893756
3.1 (KB893803)
help link: http://go.microsoft.com/fwlink/?LinkId=42467
(KB893803v2)
uninstall cmd: "C:\WINNT\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=42467
(KB895181)
(KB895316)
(KB895572)
Hotfix for Windows XP (KB896256) 3 (KB896256)
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896256
1 (KB896358)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB896358$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896358
1 (KB896423)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB896423$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896423
3 (KB896427)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB896427$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896427
1 (KB896428)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB896428$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=896428
(KB897586)
1 (KB897663)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB897663$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=897663
(KB898549)
1 (KB899587)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB899587$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=899587
1 (KB899591)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB899591$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=899591
(KB900399)
1 (KB900725)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB900725$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=900725
1 (KB901017)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB901017$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=901017
1 (KB901190)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB901190$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=901190
1 (KB901214)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB901214$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=901214
(KB902344)
1 (KB902400)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB902400$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=902400
1 (KB904706)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB904706$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=904706
1 (KB905414)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB905414$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=905414
1 (KB905749)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB905749$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=905749
(KB907658)
1 (KB908519)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB908519$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=908519
2 (KB908531)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB908531$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=908531
1 (KB909095)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB909095$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=909095
2 (KB911280)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB911280$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911280
1 (KB911562)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB911562$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911562
(KB911565)
(KB911854)
1 (KB911927)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB911927$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=911927
1 (KB912761)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB912761$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=912761
1 (KB913580)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB913580$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=913580
1 (KB914388)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB914388$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=914388
1 (KB914389)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB914389$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=914389
Hotfix for Windows XP (KB916191) 1 (KB916191)
install date: 20080915
uninstall cmd: "C:\WINNT\$NtUninstallKB916191$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=916191
3 (KB917021)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB917021$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=917021
1 (KB917344)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB917344$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=917344
1 (KB917953)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB917953$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=917953
1 (KB918118)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB918118$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=918118
1 (KB918439)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB918439$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=918439
1 (KB919007)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB919007$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=919007
1 (KB920213)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB920213$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920213
1 (KB920670)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB920670$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920670
1 (KB920683)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB920683$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920683
1 (KB920685)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB920685$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=920685
1 (KB921503)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB921503$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=921503
1 (KB922819)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB922819$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=922819
1 (KB923191)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB923191$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923191
1 (KB923414)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB923414$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923414
1 (KB923980)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB923980$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=923980
1 (KB924191)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB924191$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924191
1 (KB924270)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB924270$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924270
1 (KB924496)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB924496$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924496
1 (KB924667)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB924667$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=924667
(KB925398_WMP64)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=925398
1 (KB925902)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB925902$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=925902
Hotfix for Windows XP (KB926239) 2 (KB926239)
install date: 20080707
uninstall cmd: "C:\WINNT\$NtUninstallKB926239$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926239
1 (KB926255)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB926255$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926255
1 (KB926436)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB926436$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=926436
1 (KB927779)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB927779$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=927779
1 (KB927802)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB927802$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=927802
1 (KB928255)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB928255$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=928255
2 (KB928365.T1_1ToU569_1)
uninstall cmd: C:\WINNT\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/928365
1 (KB928843)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB928843$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=928843
1 (KB929123)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB929123$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=929123
1 (KB929969)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB929969$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=929969
1 (KB930178)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB930178$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=930178
1 (KB931261)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB931261$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931261
1 (KB931784)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB931784$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931784
1 (KB931836)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB931836$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=931836
1 (KB932168)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB932168$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=932168
Hotfix for Windows XP (KB933062) 1 (KB933062)
install date: 20080915
uninstall cmd: "C:\WINNT\$NtUninstallKB933062$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933062
1 (KB933360)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB933360$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933360
1 (KB933566)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB933566$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933566
1 (KB933729)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB933729$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=933729
1 (KB935448)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB935448$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=935448
1 (KB935839)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB935839$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=935839
1 (KB935840)
install date: 20070926
uninstall cmd: "C:\WINNT\$NtUninstallKB935840$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=935840
1 (KB936021)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB936021$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=936021
Security Update for Windows Media Player 11 (KB936782) (KB936782_WMP11)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com/?kbid=936782
1 (KB937894)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB937894$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=937894
1 (KB938127)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB938127$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938127
Security Update for Windows XP (KB938464) 1 (KB938464)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB938464$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938464
1 (KB938829)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB938829$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=938829
Hotfix for Windows XP (KB939273) 1 (KB939273)
install date: 20080916
uninstall cmd: "C:\WINNT\$NtUninstallKB939273$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=939273
1 (KB941202)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB941202$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941202
1 (KB941568)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB941568$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941568
Security Update for Windows XP (KB941569) (KB941569)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB941569$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941569
Security Update for Windows XP (KB941693) 1 (KB941693)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB941693$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=941693
1 (KB942615)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB942615$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=942615
Security Update for Windows XP (KB943055) 1 (KB943055)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB943055$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943055
1 (KB943460)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB943460$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943460
Security Update for Windows XP (KB943485) 1 (KB943485)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB943485$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=943485
Security Update for Windows XP (KB944338-v2) 2 (KB944338-v2)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=944338
1 (KB944653)
install date: 20080126
uninstall cmd: "C:\WINNT\$NtUninstallKB944653$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=944653
Security Update for Windows XP (KB945553) 1 (KB945553)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB945553$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=945553
Security Update for Windows XP (KB946026) 1 (KB946026)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB946026$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=946026
Security Update for Windows XP (KB946648) 1 (KB946648)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB946648$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=946648
Security Update for Windows XP (KB948590) 1 (KB948590)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB948590$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=948590
Security Update for Windows XP (KB950749) 1 (KB950749)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB950749$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950749
Security Update for Windows XP (KB950762) 1 (KB950762)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB950762$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950762
Security Update for Windows XP (KB950974) 1 (KB950974)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB950974$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=950974
Security Update for Windows XP (KB951066) 1 (KB951066)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB951066$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951066
Update for Windows XP (KB951072-v2) 2 (KB951072-v2)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951072
Security Update for Windows XP (KB951376-v2) 2 (KB951376-v2)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951376
Security Update for Windows XP (KB951698) 1 (KB951698)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB951698$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951698
Security Update for Windows XP (KB951748) 1 (KB951748)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB951748$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=951748
Security Update for Windows XP (KB952954) 1 (KB952954)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB952954$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=952954
Security Update for Windows XP (KB953838) 1 (KB953838)
install date: 20080917
uninstall cmd: "C:\WINNT\$NtUninstallKB953838$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=953838
Security Update for Windows XP (KB954211) 1 (KB954211)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB954211$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=954211
Security Update for Windows XP (KB955069) 1 (KB955069)
install date: 20081124
uninstall cmd: "C:\WINNT\$NtUninstallKB955069$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=955069
Security Update for Windows XP (KB956390) 1 (KB956390)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB956390$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956390
Security Update for Windows XP (KB956391) 1 (KB956391)
install date: 20081201
uninstall cmd: "C:\WINNT\$NtUninstallKB956391$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956391
Security Update for Windows XP (KB956803) 1 (KB956803)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB956803$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956803
Security Update for Windows XP (KB956841) 1 (KB956841)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB956841$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=956841
Security Update for Windows XP (KB957095) 1 (KB957095)
install date: 20081020
uninstall cmd: "C:\WINNT\$NtUninstallKB957095$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=957095
Security Update for Windows XP (KB957097) 1 (KB957097)
install date: 20081124
uninstall cmd: "C:\WINNT\$NtUninstallKB957097$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=957097
Security Update for Windows XP (KB958644) 1 (KB958644)
install date: 20081024
uninstall cmd: "C:\WINNT\$NtUninstallKB958644$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.microsoft.com?kbid=958644
(M928366)
uninstall cmd: "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
(M928367)
uninstall cmd: "C:\WINNT\Microsoft.NET\Framework\v1.0.3705\Updates\hotfix.exe" "C:\WINNT\Microsoft.NET\Framework\v1.0.3705\Updates\M928367\M928367Uninstall.msp"
Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033))
uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
readme: file://C:\WINNT\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm
(Microsoft .NET Framework Full v1.0.3705 (1033))
readme: file://C:\WINNT\Microsoft.NET\Framework\v1.0.3705\repair.htm
(MobileOptionPack)
Mozilla Firefox (3.0.4) 3.0.4 (en-US) (Mozilla Firefox (3.0.4))
install location: C:\Program Files\Mozilla Firefox
uninstall cmd: C:\Program Files\Mozilla Firefox\uninstall\helper.exe
publisher: Mozilla
comments: Mozilla Firefox
(MPlayer2)
Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1)
install date: 20080707
uninstall cmd: "C:\WINNT\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkId=74087
(MSI30-Beta1)
(MSI30-Beta2)
(MSI30-KB884016)
(MSI30-RC1)
(MSI30-RC2)
(MSI30a-KB884016)
(MSI31-Beta)
(MSI31-RC1)
(Nero - Burning Rom!UninstallKey)
uninstall cmd: C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
(NeroRecode!UninstallKey)
uninstall cmd: C:\WINNT\UNRecode.exe /UNINSTALL
(NetMeeting)
Nokia Multimedia Factory 1.3 (Nokia Multimedia Factory{4CFB3821-1582-4F3B-BF8D-30986923B36B})
estimated size: 25000
install location: C:\Program Files\Nokia\Nokia PC Suite 6\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{4CFB3821-1582-4f3b-BF8D-30986923B36B}\Installations\Nokia Multimedia Factory\
uninstall cmd: "C:\Documents and Settings\All Users\Application Data\Installations\{4CFB3821-1582-4f3b-BF8D-30986923B36B}\Nokia_Multimedia_Factory_2_0.exe" /MAINTENANCE /SILENT="SWLPCER" /LANG="2057" /MSI_COMMON_OPTIONS="PCSLANG= MMFLANG=eng"
publisher: Nokia
Nokia PC Suite 7.0.9.2 (Nokia PC Suite)
install location: C:\Program Files\Nokia\Nokia PC Suite 7\
uninstall cmd: C:\Documents and Settings\All Users\Application Data\Installations\{D5577624-0626-4C4B-87AA-D966DA1739D6}\Nokia_PC_Suite_rel_7_0_9_2_eng.exe
publisher: Nokia
NVIDIA Drivers (NVIDIA Drivers)
Trend Micro OfficeScan Client (OfficeScanNT)
uninstall cmd: "C:\Program Files\OfficeScan NT\ntrmv.exe"
(OutlookExpress)
Password Safe (Password Safe)
uninstall cmd: "C:\Program Files\Password Safe\Uninstall.exe"
(PCHealth)
uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINNT\INF\PCHealth.inf
(SchedulingAgent)
(Shockwave)
Tweak UI (Tweak UI 2.10)
uninstall cmd: "C:\WINNT\system32\mshta.exe" "res://C:\WINNT\system32\TweakUI.exe/uninstall.hta"
DVD Video Player 0.8.6e (VideoLAN)
estimated size: 25344
install location: %systemroot%\AddOns\VLCPlayer
uninstall cmd: %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 128 %systemroot%\AddOns\VLCPlayer\vlc.inf
publisher: VideoLAN Team
help link: http://mchp9vga.gmo.siemens.com/WSBP
VideoLAN VLC media player 0.8.6h 0.8.6h (VLC media player)
uninstall cmd: C:\Program Files\VideoLAN\VLC\uninstall.exe
publisher: VideoLAN Team
(Wdf01000)
(Wdf01001)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 (Wdf01005)
install date: 20080302
uninstall cmd: "C:\WINNT\$NtUninstallWdf01005$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 (Wdf01007)
install date: 20081204
uninstall cmd: "C:\WINNT\$NtUninstallWdf01007$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
Whale Communications' Client Components v3.7.1 (Whale Communications' Client Components 3.1.0)
uninstall cmd: rundll32.exe C:\WINNT\DOWNLO~1\WhlMgr.dll,UnInstall 3.1.0 63 0 1 3.7.1
Windows Media Format 11 runtime (Windows Media Format Runtime)
uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
help link: http://go.microsoft.com/fwlink/?LinkId=62768
Windows Media Player 11 (Windows Media Player)
uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
WinPcap 4.0.1 4.0.0.901 (WinPcapInst)
uninstall cmd: C:\Program Files\WinPcap\uninstall.exe
publisher: CACE Technologies
WinRAR archiver (WinRAR archiver)
uninstall cmd: C:\Program Files\WinRAR\uninstall.exe
WinSCP 4.1.7 4.1.7 (winscp3_is1)
install date: 20081013
install location: C:\Program Files\WinSCP\
uninstall cmd: "C:\Program Files\WinSCP\unins000.exe"
publisher: Martin Prikryl
help link: http://winscp.net/forum/
Wireshark 0.99.6a 0.99.6a (Wireshark)
uninstall cmd: "C:\Program Files\Ethereal\uninstall.exe"
publisher: The Wireshark developer community, http://www.wireshark.org
help link: mailto:[removed]
(WMCSetup)
Windows Media Format 11 runtime (WMFDist11)
install date: 20080707
uninstall cmd: "C:\WINNT\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:
Windows Media Player 11 (wmp11)
install date: 20080707
uninstall cmd: "C:\WINNT\$NtUninstallwmp11$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http:
Microsoft User-Mode Driver Framework Feature Pack 1.5 (Wudf01005)
install date: 20080713
uninstall cmd: "C:\WINNT\$NtUninstallWudf01005$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
comments: Build Number 5730
Yahoo! Messenger (Yahoo! Messenger)
uninstall cmd: C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Apple Software Update 2.1.0.110 ({02DFF6B1-1654-411C-8D7B-FD6052EF016F})
version: 33619968
version (major): 2
version (minor): 1
estimated size: 2196
install date: 20080606
install location: C:\Program Files\Apple Software Update\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
Nokia Software Updater 01.04.064.36264 ({0332234E-09D1-4B74-A5F3-73E34BA29F5B})
version: 17039424
version (major): 1
version (minor): 4
estimated size: 39306
install date: 20081203
install location: C:\Program Files\Nokia\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{0332234E-09D1-4B74-A5F3-73E34BA29F5B}\Packages\NokiaSoftwareUpdater\Setup\
uninstall cmd: MsiExec.exe /X{0332234E-09D1-4B74-A5F3-73E34BA29F5B}
publisher: Nokia Corporation
NokiaFonts 1.0.0.0 ({039D9222-849C-497D-86D4-1E082825334C})
version: 16777216
version (major): 1
estimated size: 1427
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0300139\
uninstall cmd: MsiExec.exe /I{039D9222-849C-497D-86D4-1E082825334C}
publisher: Nokia
comments: Software package provided by Siemens AG
contact: For support call your local help desk
IBM Lotus Sametime Connect 8.0 for NSN v8.0080205 (NSWP) 8.0.080205 ({051AB369-C32F-4643-87E0-06685E20577A})
version: 134297933
version (major): 8
estimated size: 31289
install date: 20081021
install location: C:\Program Files\IBM\Lotus\Sametime Connect\
install source: C:\Temp\ST8\
uninstall cmd: C:\WINNT\Unwise.exe /S /Z C:\PROGRA~1\IBM\Lotus\SAMETI~1\NSN80.log
publisher: IT Service Desk
contact: Service Desk
help telephone: Call your local Service Desk
Services Synchronization Utility 1.0 1.0.0.0 ({08D41F8C-6495-40C7-B502-5BD6EC625FC7})
version: 16777216
version (major): 1
estimated size: 18
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\AP0000135\
uninstall cmd: MsiExec.exe /I{08D41F8C-6495-40C7-B502-5BD6EC625FC7}
publisher: Siemens AG
comments: Software package provided by Siemens AG
contact: For support call your local help desk
Altova XMLSpy® 2008 rel. 2 sp1 Enterprise Edition 2008.02.01 ({1418A0A6-D816-4537-AE4F-6F97E418387A})
version (major): 2008
version (minor): 2
estimated size: 118075
install date: 20081031
install location: C:\Program Files\Altova\
install source: C:\WINNT\Downloaded Installations\{B69BB392-1645-4A01-8A29-C7CD595F97D8}\
uninstall cmd: MsiExec.exe /I{1418A0A6-D816-4537-AE4F-6F97E418387A}
publisher: Altova
comments: Please use the Support URL unless you have a telephone support contract
contact: Customer Support Department
help link: http://www.altova.com/support
help telephone: [removed]
QuickTime 7.4.5.67 ({1838C5A2-AB32-4145-85C1-BB9B8DFA24CD})
version: 117702661
version (major): 7
version (minor): 4
estimated size: 80580
install date: 20080606
install location: C:\Program Files\QuickTime\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
PC Connectivity Solution 8.22.4.0 ({1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C})
version: 135659524
version (major): 8
version (minor): 22
estimated size: 10783
install date: 20080907
install location: C:\Program Files\PC Connectivity Solution\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Packages\PCCS\Setup\
uninstall cmd: MsiExec.exe /I{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}
publisher: Nokia
MSXML 6 Service Pack 2 (KB954459) 6.20.1099.0 ({1A528690-6A2D-4BC5-B143-8C4AE8D19D96})
version: 101975115
version (major): 6
version (minor): 20
estimated size: 1369
install date: 20081124
install source: d:\ebe4829cbf29e27f7176cc8f\
uninstall cmd: MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/954459
Access Manager 1.24.0000 ({1A748F80-F0D9-4E0E-AA17-DA940E355864})
version: 18350080
version (major): 1
version (minor): 24
estimated size: 37870
install date: 20070927
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\
uninstall cmd: MsiExec.exe /I{1A748F80-F0D9-4E0E-AA17-DA940E355864}
publisher: MCI, Inc.
comments: Software package provided by Siemens AG
contact: For support contact your local Help Desk
help link:
help telephone:
Image Resizer Powertoy for Windows XP 1.00.0001 ({1CB92574-96F2-467B-B793-5CEB35C40C29})
version: 16777217
version (major): 1
estimated size: 17
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{1CB92574-96F2-467B-B793-5CEB35C40C29}
publisher: Microsoft Corporation
comments: Image Resizer Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
GUI 4.11.0000 ({209617C6-3666-40B0-A708-C8B027A1534E})
version: 67829760
version (major): 4
version (minor): 11
estimated size: 18305
install date: 20070927
install location: C:\Program Files\AccessManager\Client\
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\
publisher: MCI, Inc.
comments:
contact:
help link:
help telephone:
readme:
MSVC80_x86 1.0.1.0 ({212748BB-0DA5-46DE-82A1-403736DC9F27})
version: 16777217
version (major): 1
estimated size: 4095
install date: 20080103
install source: C:\Documents and Settings\All Users\Application Data\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Packages\VC80_x86\Setup\
uninstall cmd: MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
publisher: Nokia
HPPhotoSmartExpress 70.0.170.000 ({2376813B-2E5A-4641-B7B3-A0D5ADB55229})
version: 1174405290
version (major): 70
estimated size: 10150
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\HPPhotoSmartExpress\
publisher: Hewlett-Packard
Java™ 6 Update 10 6.0.100 ({26A24AE4-039D-4CA4-87B4-2F83216010FF})
version: 100663396
version (major): 6
estimated size: 92664
install date: 20081126
install location: C:\Program Files\Java\jre6\
install source: C:\Documents and Settings\vm092543\Application Data\Sun\Java\jre1.6.0_10\
uninstall cmd: MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
publisher: Sun Microsystems, Inc.
contact: http://java.com
help link: http://java.com
readme: C:\Program Files\Java\jre6\README.txt
Nokia Flashing Cable Driver 8.23.0.0 ({2A0A6470-FD0F-4F45-9B11-85F3167DB943})
version: 135725056
version (major): 8
version (minor): 23
estimated size: 580
install date: 20080901
install location: C:\Program Files\Nokia\Flashing Cable Driver\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{48110A46-A3A4-481E-8230-7873B7F4C696}\Packages\FCD\Setup\
uninstall cmd: MsiExec.exe /X{2A0A6470-FD0F-4F45-9B11-85F3167DB943}
publisher: Nokia
Adobe SVG Viewer 3.0.3 3.0.3 ({2DA60A68-199E-4D51-A7C7-EFF5F912D751})
version: 50331651
version (major): 3
estimated size: 4741
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\BR0100199\
uninstall cmd: MsiExec.exe /I{2DA60A68-199E-4D51-A7C7-EFF5F912D751}
publisher: Adobe Inc.
comments: Software Package authored based on system capture by Siemens AG,CAT@Siemens
contact: For support call your local HelpDesk
Microsoft RAW Image Thumbnailer and Viewer for Windows XP Version 1.0 (Build 50) 01.1.0050.00 ({2E5A5B57-57FC-4C79-A239-9DB280ADEC2A})
version: 16842802
version (major): 1
version (minor): 1
estimated size: 20333
install date: 20071006
install location: C:\Program Files\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\
install source: C:\WINNT\Downloaded Installations\{3C270D9D-E9B3-4B32-9CEE-011D8DE7F2E3}\
uninstall cmd: MsiExec.exe /X{2E5A5B57-57FC-4C79-A239-9DB280ADEC2A}
publisher: Microsoft
help link: www.microsoft.com/prophoto
readme: C:\Program Files\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\readme.htm
Magnifier Powertoy for Windows XP 1.00.0001 ({2FBF04DC-404C-4FA4-BA28-99903080D2B9})
version: 16777217
version (major): 1
estimated size: 5
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{2FBF04DC-404C-4FA4-BA28-99903080D2B9}
publisher: Microsoft Corporation
comments: Powertoys for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
PMAC 1.3.57.0 ({30EA517D-2BEB-4E2E-BB85-49AC61D25B3E})
version: 16973881
version (major): 1
version (minor): 3
estimated size: 567
install date: 20070927
install location: C:\Program Files\AccessManager\PMAC\
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\
publisher:
help link:
help telephone:
Java™ 6 Update 3 1.6.0.30 ({3248F0A8-6813-11D6-A77B-00B0D0160030})
version: 17170432
version (major): 1
version (minor): 6
estimated size: 138186
install date: 20080226
install source: C:\Documents and Settings\vm092543\Application Data\Sun\Java\jre1.6.0_03\
uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
publisher: Sun Microsystems, Inc.
contact: http://java.com
help link: http://java.com
readme: C:\Program Files\Java\jre1.6.0_03\README.txt
Java™ 6 Update 4 1.6.0.40 ({3248F0A8-6813-11D6-A77B-00B0D0160040})
version: 17170432
version (major): 1
version (minor): 6
estimated size: 141042
install date: 20080226
install source: C:\Documents and Settings\vm092543\Application Data\Sun\Java\jre1.6.0_04\
uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
publisher: Sun Microsystems, Inc.
contact: http://java.com
help link: http://java.com
readme: C:\Program Files\Java\jre1.6.0_04\README.txt
WebFldrs XP 9.50.7523 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227})
version: 154279267
version (major): 9
version (minor): 50
estimated size: 2472
install date: 20070926
install source: C:\WINNT\system32\
publisher: Microsoft Corporation
help link: http://www.microsoft.com/windows
PanoStandAlone 70.0.170.000 ({363790D2-DA98-41DD-9C9F-69FA36B169DE})
version: 1174405290
version (major): 70
estimated size: 1775
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\PanoStandAlone\
publisher: Hewlett-Packard
Macromedia Shockwave 8.5.1 8.5.1.106 ({3694346F-8370-4CAC-B0F8-68AA1F9EC9C3})
version: 134545409
version (major): 8
version (minor): 5
estimated size: 7098
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\BR0100092\
uninstall cmd: MsiExec.exe /I{3694346F-8370-4CAC-B0F8-68AA1F9EC9C3}
publisher: Macromedia
comments: Software Package authored based on system capture by Siemens AG,CAT@Siemens
contact: For support call your local HelpDesk
help link: " "
help telephone: " "
readme: " "
Xerox Walk-Up Printing Driver 2.0 2.0 ({39D03604-22DA-48A4-A8EB-E9691C1F9556})
version: 33554432
version (major): 2
estimated size: 818
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\RarSFX0\
uninstall cmd: MsiExec.exe /X{39D03604-22DA-48A4-A8EB-E9691C1F9556}
publisher: Xerox
help link: http://www.xerox.com
({3E70509C-A2D6-4C55-915D-50CD11155FBF})
PKI2 Basis Client V2.0.0.8 2.0.0.8 ({3FFCF6D9-157B-4F2F-93E2-DDC68059B1A3})
version: 33554432
version (major): 2
estimated size: 11637
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\ST0000119\
uninstall cmd: MsiExec.exe /I{3FFCF6D9-157B-4F2F-93E2-DDC68059B1A3}
publisher: ICN, iC ComPass, SBS SOL, SBS SEC3
comments: Software Package provided by Siemens AG
contact: For support call your local help desk
Apple Mobile Device Support [removed] ({44734179-8A79-4DEE-BB08-73037F065543})
version: 16842756
version (major): 1
version (minor): 1
estimated size: 34842
install date: 20080606
install location: C:\Program Files\Common Files\Apple\Mobile Device Support\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
BufferChm 70.0.170.000 ({45B8A76B-57EC-4242-B019-066400CD8428})
version: 1174405290
version (major): 70
estimated size: 1657
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\BufferChm\
publisher: Hewlett-Packard
Bonjour 1.0.104 ({47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3})
version: 16777320
version (major): 1
estimated size: 3317
install date: 20080405
install location: C:\Program Files\Bonjour\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\IXP759.TMP\
uninstall cmd: MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
Flash Player 9 9.0.115.0 ({4841D7F0-C0EE-485E-8F34-FD6CFF854FF1})
version: 150995059
version (major): 9
estimated size: 2897
install date: 20080125
install source: C:\WINNT\CatPC\LIA\LSDP\BR0100263\
uninstall cmd: MsiExec.exe /I{4841D7F0-C0EE-485E-8F34-FD6CFF854FF1}
publisher: Adobe Inc.
comments: Software Package authored based on system capture by Siemens AG,CAT@Siemens
contact: For support call your local HelpDesk
help link: ""
help telephone: ""
readme: ""
SMS Advanced Client 2.50.4253.3000 ({4A39A27F-005B-407E-8CF5-F4D8065658E4})
version: 36835485
version (major): 2
version (minor): 50
estimated size: 11074
install date: 20080915
install source: C:\WINNT\system32\ccmsetup\{2FBB7E06-7665-442B-98E3-189CB634C5CC}\
publisher: Microsoft Corporation
Nokia Multimedia Factory 1.3.2.0 ({4CFB3821-1582-4F3B-BF8D-30986923B36B})
version: 16973826
version (major): 1
version (minor): 3
estimated size: 9299
install date: 20080216
install location: C:\Program Files\Nokia\Nokia PC Suite 6\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{4CFB3821-1582-4f3b-BF8D-30986923B36B}\Installations\NokiaMultimediaFactoryMSI\
uninstall cmd: MsiExec.exe /I{4CFB3821-1582-4F3B-BF8D-30986923B36B}
publisher: Nokia
help link: http://www.nokia.com/pcsuite
HTML Slideshow Powertoy for Windows XP 1.0.2.0 ({4E475FD4-4513-4B1D-8DDA-43912B068C99})
version: 16777218
version (major): 1
estimated size: 600
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{4E475FD4-4513-4B1D-8DDA-43912B068C99}
publisher: Microsoft Corporation
comments: HTML Slideshow Powertoy for Windows XP
contact: Microsoft Corporation>
help link: http://www.microsoft.com/windowsxp
readme: http://www.microsoft.com/windowsxp
HPProductAssistant 70.0.170.000 ({4EA684E9-5C81-4033-A696-3019EC57AC3A})
version: 1174405290
version (major): 70
estimated size: 4531
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\hpproductassistant\
publisher: Hewlett-Packard
ICM PowerPoint Templates 1.0 1.0.0.0 ({4ED3CBA6-8984-41BF-BE3E-116476140436})
version: 16777216
version (major): 1
estimated size: 18537
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0300082\
uninstall cmd: MsiExec.exe /I{4ED3CBA6-8984-41BF-BE3E-116476140436}
publisher: Siemens AG
comments: Software package provided by Siemens AG
contact: For support call your local help desk
BlackBerry Connect Desktop for Nokia 4.0.0 ({5238A932-32B7-4F62-B384-869A23DEA4BE})
version: 67108864
version (major): 4
estimated size: 3632
install date: 20080103
install source: C:\Documents and Settings\vm092543\Local Settings\Application Data\{D76BC089-A308-4D85-AF2F-5CBBF3E3ACC5}\
publisher: Research In Motion, Ltd.
DirXdiscover 5.0C English 5.0.5.5 ({55603446-2604-4B67-973F-152588683D8B})
version: 83886085
version (major): 5
estimated size: 10118
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\MC0100027\
uninstall cmd: MsiExec.exe /I{55603446-2604-4B67-973F-152588683D8B}
publisher: Siemens AG
comments: Software Package authored based on system capture by Siemens AG, CAT@Siemens
contact: For support call your local HelpDesk
help link: " "
help telephone: " "
readme: " "
TriggerPointEditor 6.1.0 ({556E7F99-8A88-49C5-BA3D-47C2A1430DC5})
version: 100728832
version (major): 6
version (minor): 1
estimated size: 1068
install date: 20081118
install source: D:\Data\Documents\IMS\6.0\HSSd\Trigger Point Editor\
uninstall cmd: MsiExec.exe /I{556E7F99-8A88-49C5-BA3D-47C2A1430DC5}
publisher: Nokia Siemens Networks
contact: Paul Kubitscheck
help telephone: +49 89 72263706
neroxml 1.0.0 ({56C049BE-79E9-4502-BEA7-9754A3E60F9B})
version: 16777216
version (major): 1
estimated size: 48
install date: 20071021
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\NERO13390\Redist\
uninstall cmd: MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
publisher: Nero AG
contact: Nero AG
SMOC 1.3.54.0 ({580343FF-B12B-49A6-BAB7-D1CF407FA9FB})
version: 16973878
version (major): 1
version (minor): 3
estimated size: 1176
install date: 20070927
install location: C:\Program Files\AccessManager\SMOC\
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\
publisher:
help link:
help telephone:
iTunes 7.6.2.9 ({585776BC-4BD6-4BD2-A19A-1D6CB44A403B})
version: 117833730
version (major): 7
version (minor): 6
estimated size: 75108
install date: 20080606
install location: C:\Program Files\iTunes\
install source: C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple\Apple Software Update\
uninstall cmd: MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
publisher: Apple Inc.
contact: AppleCare Support
help link: http://www.apple.com/support/
help telephone: [removed]
ServiceLauncher 1.0.1.36 ({5AFAA589-F446-4D9E-AAD6-B8C9B43BEB08})
version: 16777217
version (major): 1
estimated size: 265
install date: 20080513
install source: \\nsn-intra.net\dfsres\nsndp\P-\N-CP0005001\
publisher: SIS GO GIO DS PSU3
comments: Software Package authored based on system capture by Siemens AG.
contact: For support call your local help desk
Shockwave Player 10.1.1 10.1.1.16 ({5C4CA537-82B3-48EF-B5F8-ABA673107567})
version: 167837697
version (major): 10
version (minor): 1
estimated size: 4298
install date: 20070926
install location: C:\WINNT\system32\Macromed\
install source: \\nsn-intra.net\dfsres\nsndp\P-\BR0100179\
uninstall cmd: MsiExec.exe /I{5C4CA537-82B3-48EF-B5F8-ABA673107567}
publisher: Macromedia
comments: ""
contact: ""
IP VPN RS Nortel 4.00.0020 ({5D1DEA4B-1BC3-438B-B75A-01827209B916})
version: 67108884
version (major): 4
estimated size: 4384
install date: 20070927
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licenced\MCI VPN Access Mgr\ra0000118\software\vpnclnt\
uninstall cmd: MsiExec.exe /X{5D1DEA4B-1BC3-438B-B75A-01827209B916}
publisher: MCI
comments: .
contact: .
help link: .
help telephone:
Internet Explorer 6.0 SP2 6.0.2900.2180 ({5DD0FD76-DFA1-4274-BF35-09D2B4386E31})
version: 100666196
version (major): 6
estimated size: 143
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\br0000042\
uninstall cmd: MsiExec.exe /I{5DD0FD76-DFA1-4274-BF35-09D2B4386E31}
publisher: Microsoft Corp.
comments: Software Package authored based on system capture by Siemens AG, CAT@Siemens
contact: For support call your local HelpDesk
help link: " "
help telephone: " "
readme: " "
WebReg 70.0.170.000 ({66910000-8B30-4973-A159-6371345AFFA5})
version: 1174405290
version (major): 70
estimated size: 525
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\WebReg\
publisher: Hewlett-Packard
eSupportQFolder 1.00.0000 ({66E6CE0C-5A1E-430C-B40A-0C90FF1804A8})
version: 16777216
version (major): 1
estimated size: 124
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\QFolder\
publisher: Hewlett-Packard
CmdHere Powertoy For Windows XP 1.00.0001 ({6855CCDD-BDF9-48E4-B80A-80DFB96FE36C})
version: 16777217
version (major): 1
estimated size: 5
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}
publisher: Microsoft Corporation
comments: CmdHere Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
AiOSoftwareNPI 70.0.231.000 ({68763C27-235D-4165-A961-FDEA228CE504})
version: 1174405351
version (major): 70
estimated size: 3366
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\AiOSoftwarenpi\
publisher: Hewlett-Packard
Toolbox 70.0.170.000 ({6909F917-5499-482e-9AA1-FAD06A99F231})
version: 1174405290
version (major): 70
estimated size: 5709
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\Toolbox\
publisher: Hewlett-Packard
iPassConnect English 3.55.0.0 ({6E6547D1-34A8-4105-857B-BC21FC70DAD3})
version: 53936128
version (major): 3
version (minor): 55
estimated size: 157158
install date: 20081202
install location: C:\Program Files\iPass\iPassConnect\
install source: C:\ccmcache\Z0100319.9.System\
uninstall cmd: MsiExec.exe /I{6E6547D1-34A8-4105-857B-BC21FC70DAD3}
publisher: iPass Inc.
comments: Software package provided by NSN
contact: For support call the NSN Service Desk
Microsoft .NET Framework 2.0 2.0.50727 ({7131646D-CD3C-40F4-97B9-CD9E4E6262EF})
version: 33605159
version (major): 2
estimated size: 234943
install date: 20070926
install source: C:\WINNT\CatPC\temp\OS0200031\
publisher: Microsoft Corporation
Microsoft Visual C++ 2005 Redistributable 8.0.56336 ({7299052b-02a4-4627-81f2-1818da5d550d})
version: 134274064
version (major): 8
estimated size: 5330
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\IXP001.TMP\
uninstall cmd: MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
publisher: Microsoft Corporation
Readme 70.0.231.000 ({736C803C-DD3B-4015-BC51-AFB9E67B9076})
version: 1174405351
version (major): 70
estimated size: 44
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\readme\
publisher: Hewlett-Packard
({7A926FF0-3E6E-4BA0-9EBD-4D03448FA769})
ProductContextNPI 70.0.231.000 ({7E7B7865-6C80-4373-8BC1-C2EB9431F9DE})
version: 1174405351
version (major): 70
estimated size: 1
install date: 20071006
install source: C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\
publisher: Hewlett-Packard
Status 70.0.170.000 ({8331C3EA-0C91-43AA-A4D4-27221C631139})
version: 1174405290
version (major): 70
estimated size: 3260
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\Status\
publisher: Hewlett-Packard
MSXML 4.0 SP2 (KB954430) 4.20.9870.0 ({86493ADD-824D-4B8E-BD72-8C5DCDC52A71})
version: 68429454
version (major): 4
version (minor): 20
estimated size: 2729
install date: 20081124
install source: d:\38f00d96e5ab374948\
uninstall cmd: MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/954430
DocProcQFolder 1.00.0000 ({87E2B986-07E8-477a-93DC-AF0B6758B192})
version: 16777216
version (major): 1
estimated size: 120
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\QFolder\
publisher: Hewlett-Packard
Microsoft Silverlight 2.0.30523.8 ({89F4137D-6C26-4A84-BDB8-2E5A4BB71E00})
version: 33584955
version (major): 2
estimated size: 4704
install date: 20080815
install source: d:\5763206a7b40bc5e09f0b954ac5de0b8\
uninstall cmd: MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
publisher: Microsoft Corporation
help link: http://go.microsoft.com/fwlink/?LinkID=91955
DocProc 7.0.0.0 ({8A4CE7FD-9657-4B06-9943-E1819F3D5D67})
version: 117440512
version (major): 7
estimated size: 77615
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\DocProc\
publisher: Hewlett-Packard
comments: 0
contact: 0
help link: 0
help telephone: 0
readme: 0
3.0.7.009 ({8ADC27DB-E2C8-446C-A576-166C05C2DD24})
version: 50331655
version (major): 3
estimated size: 184
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\HPSoftwareUpdate\
publisher: Hewlett-Packard
Unload 7.0.0 ({8CE4E6E9-9D55-43FB-9DDB-688C976BFC05})
version: 117440512
version (major): 7
estimated size: 8361
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\UnloadIntent\
publisher: Hewlett-Packard
comments: 0
contact: 0
help link: 0
help telephone: 0
readme: 0
Microsoft Office Professional Edition 2003 11.0.7969.0 ({90110409-6000-11D3-8CFE-0150048383C9})
version: 184557345
version (major): 11
estimated size: 518782
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0000116\
uninstall cmd: MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Office\OFFICE11\1033\OFREADME.HTM
Compatibility Pack for the 2007 Office system 12.0.4518.1014 ({90120000-0020-0409-0000-0000000FF1CE})
version: 201331110
version (major): 12
estimated size: 63775
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0200532\
uninstall cmd: MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
publisher: Microsoft Corporation
comments: Software Package provided by Siemens AG; CAT@Siemens
contact: For support call your local help desk
Microsoft Office 2003 German User Interface Pack 11.0.7969.0 ({901E0407-6000-11D3-8CFE-0150048383C9})
version: 184557345
version (major): 11
estimated size: 205423
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\LP0000071\
uninstall cmd: MsiExec.exe /I{901E0407-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Office\OFFICE11\MUIREAD.HTM
Microsoft Office Visio Professional 2003 11.0.3216.5614 ({90510409-6000-11D3-8CFE-0150048383C9})
version: 184552592
version (major): 11
estimated size: 195109
install date: 20071006
install location: C:\Program Files\Microsoft Office\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\pftDE.tmp\
uninstall cmd: MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Office\Visio11\1033\VIREADME.HTM
Microsoft Organization Chart 2.0 11.0.5614.0 ({90AE0409-6000-11D3-8CFE-0150048383C9})
version: 184554990
version (major): 11
estimated size: 1889
install date: 20070926
install location: C:\Program Files\Microsoft Office\
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0600032\
uninstall cmd: MsiExec.exe /I{90AE0409-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
help link: http://www.microsoft.com/support
Remove Hidden Data Tool 11.0.6361.0 ({90F80409-6000-11D3-8CFE-0150048383C9})
version: 184555737
version (major): 11
estimated size: 365
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{90F80409-6000-11D3-8CFE-0150048383C9}
publisher: Microsoft Corporation
InterVideo WinDVD ({98E8A2EF-4EAE-43B8-A172-74842B764777})
version (major): 4
install location: C:\Program Files\InterVideo\WinDVD
uninstall cmd: "C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALL
publisher: InterVideo Inc.
ScannerCopy 7.0.0.0 ({996512CF-F35B-48DE-9291-557FA5316967})
version: 117440512
version (major): 7
estimated size: 3202
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\ScannerCopy\
publisher: Hewlett-Packard
comments: 0
contact: 0
help link: 0
help telephone: 0
readme: 0
Dell Touchpad 7.1.102.7 ({9F72EF8B-AEC9-4CA5-B483-143980AFD6FD})
uninstall cmd: C:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
publisher: Alps Electric
SigmaTel Audio 5.10.4820.0 ({A462213D-EED4-42C2-9A60-7BDD4D4B0B17})
version: 84546260
install date: 20070927
install location: C:\Program Files\SigmaTel\C-Major Audio
install source: C:\dell\drivers\R153908\
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
publisher: SigmaTel
Microsoft Visual C++ 2005 Redistributable 8.0.50727.42 ({A49F249F-0C91-497F-86DF-B2585E8E76B7})
version: 134268455
version (major): 8
estimated size: 4584
install date: 20081021
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\IXP000.TMP\
uninstall cmd: MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
publisher: Microsoft Corporation
MATLAB Component Runtime 7.4 ({A5A65472-F1BD-4EB3-B244-0A8007365FBA})
version: 117702656
version (major): 7
version (minor): 4
estimated size: 268976
install date: 20071112
install location: C:\Program Files\MATLAB\MATLAB Component Runtime\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\_is49\
uninstall cmd: MsiExec.exe /I{A5A65472-F1BD-4EB3-B244-0A8007365FBA}
publisher: The MathWorks
comments: MATLAB Component Runtime Installer
contact: The MathWorks, Inc.
help link: www.mathworks.com
help telephone: [removed]
Alt-Tab Task Switcher Powertoy for Windows XP 1.00.0001 ({A7050037-F0EA-4BAB-BCD5-FC05507D6147})
version: 16777217
version (major): 1
estimated size: 41
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{A7050037-F0EA-4BAB-BCD5-FC05507D6147}
publisher: Microsoft Corporation
comments: Alt-Tab Task Switcher Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
Timershot Powertoy for Windows XP 1.00.0001 ({A743BBCC-3438-4BB3-8397-6C9D9AC125A6})
version: 16777217
version (major): 1
estimated size: 184
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{A743BBCC-3438-4BB3-8397-6C9D9AC125A6}
publisher: Microsoft Corporation
comments: Timershot Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
Lotus Notes 5.0.12.0 ({A7D69D97-BD43-4708-BC68-245E5B7B6C1E})
version: 83886092
version (major): 5
estimated size: 109476
install date: 20070927
install source: \\nsn-intra.net\dfsres\us005\packages$\Site Licensed\Notes\
uninstall cmd: MsiExec.exe /I{A7D69D97-BD43-4708-BC68-245E5B7B6C1E}
publisher: Lotus Development GmbH
comments: Software package provided by Siemens AG
contact: For support contact you local Help Desk
OSCE_MSI_NT_CLIENT 7.3 ({A97792EC-E172-4B38-85DD-0F853599D5EF})
version: 117637120
version (major): 7
version (minor): 3
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\AV0000062\
publisher: Trend Micro
help link: http://www.trendmicro.com
DeviceManagementQFolder 1.00.0000 ({AB5D51AE-EBC3-438D-872C-705C7C2084B0})
version: 16777216
version (major): 1
estimated size: 124
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\QFolder\
publisher: Hewlett-Packard
Adobe Acrobat 8 Professional - English, Français, Deutsch 8.0.0 ({AC76BA86-1033-F400-7760-000000000003})
version: 134217728
version (major): 8
estimated size: 1322821
install date: 20071006
install location: C:\Program Files\Adobe\Acrobat 8.0\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\Adobe Acrobat 8.0\
publisher: Adobe Systems
comments:
contact: Customer Support
help link: http://www.adobe.com/support/main.html
help telephone:
readme: C:\Program Files\Adobe\Acrobat 8.0\Readme.htm
Adobe Reader 7.0.9 German 7.0.9 ({AC76BA86-7AD7-1031-7B44-A70000000000})
version: 117440521
version (major): 7
estimated size: 78108
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\WT0000144\
uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A70000000000}
publisher: Adobe Systems Incorporated
comments:
contact: Customer Support Department
help link: http://www.adobe.de/support/main.html
help telephone:
readme: C:\Program Files\Adobe\Acrobat 7.0\Reader\Readme.htm
Adobe Reader Japanese Fonts 7.00.000 ({AC76BA86-7AD7-5A76-5A64-7E8A45000001})
version: 117440512
version (major): 7
estimated size: 21462
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0600062\
uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-5A76-5A64-7E8A45000001}
publisher: Adobe Systems
comments: ""
contact: Customer Support
help link: http://www.adobe.com/support/main.html
help telephone: [removed]
WebTrain Communicator 3.5.0.10 ({AF833083-331F-4EC2-8FAA-FE0B8BF12C0E})
version: 50659328
version (major): 3
version (minor): 5
estimated size: 13270
install date: 20071115
install source: C:\Documents and Settings\vm092543\Local Settings\Temporary Internet Files\Content.IE5\QN5FZ02X\
uninstall cmd: MsiExec.exe /I{AF833083-331F-4EC2-8FAA-FE0B8BF12C0E}
publisher: WebTrain Communications
comments: Zip / Authenticode CAB versions also available on website
contact: WebTrain Technical Support
help link: http://www.microsoft.com/management
help telephone: [removed]
Calculator Powertoy for Windows XP 1.00.0001 ({B37C842A-B624-46B8-A727-654E72F1C91A})
version: 16777217
version (major): 1
estimated size: 224
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{B37C842A-B624-46B8-A727-654E72F1C91A}
publisher: Microsoft Corporation
comments: Calculator Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
Spybot - Search & Destroy 1.6.0 ({B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1)
install date: 20080925
install location: C:\Program Files\Spybot\
uninstall cmd: "C:\Program Files\Spybot\unins000.exe"
publisher: Safer Networking Limited
help link: http://www.safer-networking.org/index.php?page=support
Microsoft .NET Framework (English) 1.0.3705 ({B43357AA-3A6D-4D94-B56E-43C44D09E548})
version: 16780921
version (major): 1
estimated size: 48744
install date: 20070926
install source: C:\WINNT\CatPC\temp\OS0200007\
uninstall cmd: MsiExec.exe /X{B43357AA-3A6D-4D94-B56E-43C44D09E548}
publisher: Microsoft
SyncToy 1.4 ({B5688129-7595-4E5B-9990-CEF981A31264})
version: 17039360
version (major): 1
version (minor): 4
estimated size: 2656
install date: 20080626
install source: D:\Data\Downloads\
uninstall cmd: MsiExec.exe /I{B5688129-7595-4E5B-9990-CEF981A31264}
publisher: Microsoft
comments: Synchronization Powertoy
contact: Microsoft
TextPad 5 5.2.0 ({B6EC7388-E277-4A5B-8C8F-71067A41BA64})
version: 84017152
version (major): 5
version (minor): 2
estimated size: 4780
install date: 20080810
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\{B7F69EDA-28A2-41A5-B411-2EEDB1008E7C}\
uninstall cmd: MsiExec.exe /X{B6EC7388-E277-4A5B-8C8F-71067A41BA64}
publisher: Helios
comments: Your Comments
contact: Customer Support Department
help link: http://www.textpad.com/support/
help telephone: http://www.textpad.com/support/
DivX Web Player 1.3.1 ({B7050CBDB2504B34BC2A9CA0A692CC29})
install location: C:\Program Files\DivX
uninstall cmd: C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
publisher: DivX,Inc.
HP Software Update 3.0.7.014 ({BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E})
version: 50331655
version (major): 3
estimated size: 3506
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\HPSoftwareUpdate\
uninstall cmd: MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
publisher: HEWLET~1|Hewlett-Packard
contact: http://www.hp.com/support
Netflix Movie Viewer 1.2.211 ({BCE72AED-3332-4863-9567-C5DCB9052CA2})
version: 16908499
version (major): 1
version (minor): 2
estimated size: 1564
install date: 20081201
install location: C:\Program Files\Netflix\Netflix Movie Viewer\
install source: C:\Documents and Settings\vm092543\Local Settings\Temporary Internet Files\Content.IE5\VHRMMI1K\
uninstall cmd: MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}
publisher: Netflix
comments: Netflix Movie Viewer
contact: Netflix Customer Service
help link: www.netflix.com/Help
HP Photosmart, Officejet and Deskjet 7.0.A ({BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C})
uninstall cmd: C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
publisher: HP
help link: http://www.hp.com/support
4.20.9848.0 ({C04E32E0-0416-434D-AFB9-6969D703A9EF})
version: 68429432
version (major): 4
version (minor): 20
estimated size: 2681
install date: 20080125
install source: C:\WINNT\CatPC\LIA\LSDP\BR0100248\
uninstall cmd: MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
publisher: Microsoft Corporation
help link: http://support.microsoft.com/kb/936181
Slideshow Generator Powertoy for Windows XP 1.00.0001 ({C39DE425-6CCF-4B12-A101-3CB5CF3AF3AD})
version: 16777217
version (major): 1
estimated size: 81
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{C39DE425-6CCF-4B12-A101-3CB5CF3AF3AD}
publisher: Microsoft Corporation
comments: Slideshow Generator Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
German Menus and Dialogs for Internet Explorer 6.0 6.0.2800.1106 ({C69EF57A-2F95-4188-8B22-1D03D2673C62})
version: 100666096
version (major): 6
estimated size: 5175
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\LP0000041\
uninstall cmd: MsiExec.exe /I{C69EF57A-2F95-4188-8B22-1D03D2673C62}
publisher: Microsoft Corp.
comments: Software Package authored based on system capture by Siemens AG, CAT@Siemens
contact: For support call your local HelpDesk
help link: " "
help telephone: " "
readme: " "
SolutionCenter 70.0.170.000 ({C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476})
version: 1174405290
version (major): 70
estimated size: 7940
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\SolutionCenter\
publisher: Hewlett-Packard
AiO_Scan_CDA 70.0.231.000 ({C8753E28-2680-49BF-BD48-DD38FD086EFE})
version: 1174405351
version (major): 70
estimated size: 701
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\AiO_Scan\
publisher: Hewlett-Packard
ClearType Tuning Control Panel Applet 1.01.0000 ({C9E4932C-8417-4E4C-A0E3-EE534810AB4D})
version: 16842752
version (major): 1
version (minor): 1
estimated size: 253
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\_is41\
uninstall cmd: MsiExec.exe /I{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}
publisher: Microsoft Corporation
comments: Your Comments
contact: Customer Support Department
help link: http://www.microsoft.com
help telephone:
Microsoft .NET Framework 1.1 1.1.4322 ({CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1})
version: 16847074
version (major): 1
version (minor): 1
estimated size: 69906
install date: 20070926
install source: C:\WINNT\CatPC\temp\OS0200009\
uninstall cmd: MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
publisher: Microsoft
Nokia Connectivity Cable Driver 7.1.6.0 ({CBDE9C7D-CF52-4558-B23E-B66359CB586A})
version: 117506054
version (major): 7
version (minor): 1
estimated size: 2730
install date: 20081203
install location: C:\Program Files\Nokia\Connectivity Cable Driver\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{0332234E-09D1-4B74-A5F3-73E34BA29F5B}\Packages\CCD\Setup\
uninstall cmd: MsiExec.exe /X{CBDE9C7D-CF52-4558-B23E-B66359CB586A}
publisher: Nokia
help link: http://www.nokia.com/nokia/0,8764,75877,00.html
Bluetooth Stack for Windows by Toshiba v4.31.02.6(D) ({CEBB6BFB-D708-4F99-A633-BC2600E01EF6})
version: 67108864
version (major): 4
version (minor): 31
estimated size: 31267
install date: 20071008
install location: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
install source: C:\dell\drivers\R155172\2kxp\
uninstall cmd: MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
3100_3200_3300_Help 70.0.231.000 ({D002159B-91CD-48E5-96D1-C476BA3DECB3})
version: 1174405351
version (major): 70
estimated size: 6545
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\Setup\AiOHelp\
publisher: Hewlett-Packard
DivX Content Uploader 1.2.1 ({D050D7362D214723AD585B541FFB6C11})
install location: C:\Program Files\DivX
uninstall cmd: C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
publisher: DivX, Inc.
3100_3200_3300trb 70.0.231.000 ({D3227BD6-7D66-4B96-BA01-C21FB1F2224D})
version: 1174405351
version (major): 70
estimated size: 233
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\Setup\AiOHelp\
publisher: Hewlett-Packard
Broadcom Gigabit Integrated Controller 10.15.08 ({D3B3B9B2-FE73-44CB-8C0A-F737D92F991B})
version: 168755208
version (major): 10
version (minor): 15
estimated size: 480
install date: 20070927
install location: C:\Program Files\Broadcom\
install source: C:\dell\drivers\R151327\
uninstall cmd: MsiExec.exe /X{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}
publisher: Broadcom Corporation
contact: Dell Customer Support
help link: http://www.support.dell.com
Altova AltovaXML™ 2008 rel. 2 sp2 2008.02.02 ({D49BC58E-7680-4101-A511-6603C8A3B2DB})
version (major): 2008
version (minor): 2
estimated size: 28286
install date: 20081030
install location: C:\Program Files\Altova\
install source: C:\WINNT\Downloaded Installations\{AB927108-21D7-4197-B5F4-1198BE0F157E}\
uninstall cmd: MsiExec.exe /I{D49BC58E-7680-4101-A511-6603C8A3B2DB}
publisher: Altova
comments: Please use the Support URL unless you have a telephone support contract
contact: Customer Support Department
help link: http://www.altova.com/support
help telephone: [removed]
Nokia PC Suite 7.0.9.2 ({D5577624-0626-4C4B-87AA-D966DA1739D6})
version: 117440521
version (major): 7
estimated size: 53886
install date: 20081109
install location: C:\Program Files\Nokia\Nokia PC Suite 7\
install source: C:\Documents and Settings\All Users\Application Data\Installations\{D5577624-0626-4C4B-87AA-D966DA1739D6}\Packages\Nokia_PC_Suite\Setup\
uninstall cmd: MsiExec.exe /I{D5577624-0626-4C4B-87AA-D966DA1739D6}
publisher: Nokia
help link: http://www.nokia.com/nokia/0,8764,75877,00.html
Remove Hidden Data Tool 11.0.6361.0 ({D5A55E84-1C14-46F1-8718-1D91F2351FC5})
version: 184555737
version (major): 11
estimated size: 366
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\OF0600038\
uninstall cmd: MsiExec.exe /X{D5A55E84-1C14-46F1-8718-1D91F2351FC5}
publisher: Microsoft Corporation
TrayApp 70.0.170.000 ({DBC20735-34E6-4E97-A9E5-2066B66B243D})
version: 1174405290
version (major): 70
estimated size: 707
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\TrayApp\
publisher: Hewlett-Packard
Microsoft Capicom 2.1.0.2 ({DEAECFA9-FC4E-4AE5-9B1B-14A3A7EC1DE8})
version: 33619968
version (major): 2
version (minor): 1
estimated size: 969
install date: 20080125
install source: C:\WINNT\CatPC\LIA\LSDP\CP0100407\
uninstall cmd: MsiExec.exe /X{DEAECFA9-FC4E-4AE5-9B1B-14A3A7EC1DE8}
publisher: Microsoft Corp.
comments: Software package provided by Siemens AG
contact: For support call your local help desk
help link: ""
help telephone: ""
readme: ""
3300 70.0.231.000 ({E1D94FAD-CFA4-4B76-91D9-28F5AB18A431})
version: 1174405351
version (major): 70
estimated size: 66
install date: 20071006
install source: C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\Product\
publisher: Hewlett-Packard
Digital Line Detect 1.21 ({E646DCF0-5A68-11D5-B229-002078017FBF})
version: 18153472
install date: 20070927
install location: C:\Program Files\Digital Line Detect
install source: C:\dell\drivers\R148605\
uninstall cmd: C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\Setup.exe -runfromtemp -l0x0009 -removeonly
publisher: BVRP Software, Inc
WinZip 8.1 SR2 English 14.0.5791.0 ({E817FC5E-170A-493E-82F8-95C1C64A54FA})
version: 234886815
version (major): 14
estimated size: 4311
install date: 20070926
install source: \\nsn-intra.net\dfsres\nsndp\P-\PA0000025\
uninstall cmd: MsiExec.exe /I{E817FC5E-170A-493E-82F8-95C1C64A54FA}
publisher: Winzip
comments: Software package provided by Siemens AG
contact: For support call your local help desk
IP VPN Remote Services ({EF964A78-078C-11D1-B7A7-0000C0134CE6})
uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF964A78-078C-11D1-B7A7-0000C0134CE6}\setup.exe" Uninstall
Nero 7 Ultra Edition 7.02.0936 ({F14B8ECC-BDA0-4987-9201-D7B7DBE11033})
version: 117572520
version (major): 7
version (minor): 2
estimated size: 222528
install date: 20071021
install location: C:\Program Files\Nero\Nero 7\
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\NeroDemo11237\
uninstall cmd: MsiExec.exe /I{F14B8ECC-BDA0-4987-9201-D7B7DBE11033}
publisher: Nero AG
comments: Nero AG
contact: [removed]
help link: http://www.nero.com/
InstantShareDevicesMFC 70.0.170.000 ({F157460F-720E-482f-8625-AD7843891E5F})
version: 1174405290
version (major): 70
estimated size: 2580
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\InstantShareDevicesMFC\
publisher: Hewlett-Packard
({F1BC653B-BBDD-4B32-A9FD-3E709833BAF8})
Virtual Desktop Manager Powertoy for Windows XP 1.00.0001 ({F251B999-08A9-4704-999C-9962F0DFD88E})
version: 16777217
version (major): 1
estimated size: 149
install date: 20071006
install source: C:\WINNT\Downloaded Installations\
uninstall cmd: MsiExec.exe /I{F251B999-08A9-4704-999C-9962F0DFD88E}
publisher: Microsoft Corporation
comments: Virtual Desktop Manager Powertoy for XP
contact: Microsoft Corporation
help link: http://www.microsoft.com/directory
help telephone: [removed]
readme: http://www.microsoft.com/windowsxp
Scan 7.0.0.0 ({F3760724-B29D-465B-BC53-E5D72095BCC4})
version: 117440512
version (major): 7
estimated size: 9900
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\Scan\
publisher: Hewlett-Packard
comments: 0
contact: 0
help link: 0
help telephone: 0
readme: 0
Fax_CDA 70.0.231.000 ({F6076EF9-08E1-442F-B6A2-BFB61B295A14})
version: 1174405351
version (major): 70
estimated size: 22006
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\fax\
publisher: Hewlett-Packard
Destinations 70.0.170.000 ({FB15E224-67C3-491F-9F5C-F257BC418412})
version: 1174405290
version (major): 70
estimated size: 17221
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\Destinations\
publisher: Hewlett-Packard
NewCopy_CDA 70.0.231.000 ({FBB980B0-63F8-4B48-8D65-90F1D9F81D9F})
version: 1174405351
version (major): 70
estimated size: 1513
install date: 20071006
install source: C:\DOCUME~1\vm092543\LOCALS~1\Temp\hp_webrelease\setup\newcopy\
publisher: Hewlett-Packard
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 9.0.21022 ({FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4})
version: 151015966
version (major): 9
estimated size: 6844
install date: 20081201
install source: d:\37472a24a871e7d62279a55f328f6b5a\
uninstall cmd: MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
publisher: Microsoft Corporation
— System Services —
Service (registry key): .NET CLR Data
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET CLR Networking
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET Data Provider for Oracle
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET Data Provider for SqlServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NETFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Abiosdsk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0
Service (registry key): abp480n5
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ACPI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft ACPI Driver
Image path: system32\DRIVERS\ACPI.sys
Image size: 187776
Image MD5: A10C7534F7223F4A73A948967D00E69B
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): ACPIEC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): adpu160m
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): aec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Acoustic Echo Canceller
Image path: system32\drivers\aec.sys
Image size: 142464
Image MD5: 841F385C6CFAF66B58FBD898722BB4F0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): AFD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AFD
Description: AFD Networking Support Environment
Image path: \SystemRoot\System32\drivers\afd.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Aha154x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): aic78u2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): aic78xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Alerter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Alerter
Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation
Service (registry key): ALG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Layer Gateway Service
Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\alg.exe
Image size: 44544
Image MD5: F1958FBF86D5C004CF19A5951A9514B7
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): AliIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): AMBroker
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Access Manager Configuration Service
Object name: LocalSystem
Image path: "C:\Program Files\AccessManager\Client\AMBroker.exe"
Image size: 77824
Image MD5: 0A8446FEA210A30C07B8DD879858ED35
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): amsint
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ApfiltrService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Alps Touch Pad Filter Driver for Windows 2000/XP/Vista
Image path: system32\DRIVERS\Apfiltr.sys
Image size: 155136
Image MD5: 350F19EB5FE4EC37A2414DF56CDE1AA8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): Apple Mobile Device
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Apple Mobile Device
Description: Provides the interface to Apple mobile devices.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
Image size: 110592
Image MD5: 1961CB10BB48EB4D97E37DB6373E9E63
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: Tcpip
Service (registry key): AppMgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Application Management
Description: Provides software installation services such as Assign, Publish, and Remove.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): Arp1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 ARP Client Protocol
Description: 1394 ARP Client Protocol
Image path: system32\DRIVERS\arp1394.sys
Image size: 60800
Image MD5: F0D692B0BFFB46E30EB3CEA168BBC49F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): asc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): asc3350p
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): asc3550
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ASP.NET
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): ASP.NET_1.1.4322
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): ASP.NET_2.0.50727
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): aspnet_state
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ASP.NET State Service
Description: Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
Image size: 33632
Image MD5: E1633440859F9A1B3CEAF73BA85225CA
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): AsyncMac
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: RAS Asynchronous Media Driver
Description: RAS Asynchronous Media Driver
Image path: system32\DRIVERS\asyncmac.sys
Image size: 14336
Image MD5: 02000ABF34AF4C218C35D257024807D6
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): atapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Standard IDE/ESDI Hard Disk Controller
Image path: system32\DRIVERS\atapi.sys
Image size: 95360
Image MD5: CDFE4411A69C224BD1D11B2DA92DAC51
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): Atdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0
Service (registry key): Atmarpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ATM ARP Client Protocol
Description: ATM ARP Client Protocol
Image path: system32\DRIVERS\atmarpc.sys
Image size: 59904
Image MD5: EC88DA854AB7D7752EC8BE11A741BB7F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): AudioSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Audio
Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs
Service (registry key): audstub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Audio Stub Driver
Image path: system32\DRIVERS\audstub.sys
Image size: 3072
Image MD5: D9F724AA26C010A217C97606B160ED68
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): b57w2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Broadcom NetXtreme Gigabit Ethernet
Image path: system32\DRIVERS\b57xp32.sys
Image size: 160256
Image MD5: F96038AA1EC4013A93D2420FC689D1E9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BattC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): BCM43XX
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Dell Wireless WLAN Card Driver
Image path: system32\DRIVERS\bcmwl5.sys
Image size: 604928
Image MD5: B89BCF0A25AEB3B47030AC83287F894A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BCMLogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: BCMLogon
Description: Provides credential information (user name, password, domain) used by wireless management software for login to wireless networks. Optionally enables wireless login at startup for SSO environments.
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Beep
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): BITS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Background Intelligent Transfer Service
Description: Transfers data between clients and servers in the background. If BITS is disabled, features such as Windows Update will not work correctly.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): Bonjour Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bonjour Service
Description: Enables hardware devices and software services to automatically configure themselves on the network and advertise their presence, so that users can discover and use those services without any unnecessary manual setup or administration.
Object name: LocalSystem
Image path: "C:\Program Files\Bonjour\mDNSResponder.exe"
Image size: 229376
Image MD5: CFD4C3352E29A8B729536648466E8DF5
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: Tcpip
Service (registry key): Browser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Computer Browser
Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,LanmanServer
Service (registry key): cbidf2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): CcmExec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SMS Agent Host
Description: Provides change and configuration services for computer management systems.
Object name: LocalSystem
Image path: C:\WINNT\system32\CCM\CcmExec.exe
Image size: 590712
Image MD5: E4B94F8EDB3540D43A473D552C30D395
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: winmgmt
Service (registry key): CcmFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): cd20xrnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Cdaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): Cdfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Depends On group: "SCSI CDROM Class"
Service (registry key): Cdrom
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-ROM Driver
Image path: system32\DRIVERS\cdrom.sys
Image size: 49536
Image MD5: AF9C19B3100FE010496B1A27181FBF72
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"
Service (registry key): Changer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): CiSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Indexing Service
Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
Object name: LocalSystem
Image path: %SystemRoot%\system32\cisvc.exe
Image size: 5632
Image MD5: 3192BD04D032A9C4A85A3278C268A13A
Control Set: CurrentControlSet
Start: 4
Type: 288
Error Control: 1
Depends On services: RPCSS
Service (registry key): ClipSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ClipBook
Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\clipsrv.exe
Image size: 33280
Image MD5: C8DEC22C4137D7A90F8BDF41CA4B82AE
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: NetDDE
Service (registry key): clr_optimization_v2.0.50727_32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: .NET Runtime Optimization Service v2.0.50727_X86
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
Image size: 68952
Image MD5: 3D560AF01BDC50B4A1E1BFB5CDC06D63
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Service (registry key): CmBatt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft AC Adapter Driver
Image path: system32\DRIVERS\CmBatt.sys
Image size: 14080
Image MD5: 4266BE808F85826AEDF3C64C1E240203
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): CmdIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Compbatt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Composite Battery Driver
Image path: system32\DRIVERS\compbatt.sys
Image size: 9344
Image MD5: DF1B1A24BF52D0EBC01ED4ECE8979F50
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): COMSysApp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ System Application
Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Image size: 5120
Image MD5: DD87DB7387B9EB441C5674888A0D840C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: rpcss
Service (registry key): ContentFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): ContentIndex
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Cpqarray
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): CryptSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Cryptographic Services
Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): CSRBC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CSRBC.Sys CSR test driver
Image path: System32\Drivers\csrbcxp.sys
Image size: 31744
Image MD5: 8E1945984E147562F9F08E1D344A69CC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): dac2w2k
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 0
Service (registry key): dac960nt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): DAPlugin
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Visual Insight DA Plugin
Object name: LocalSystem
Image path: C:\Program Files\AccessManager\Client\DAPlugin.exe
Image size: 81920
Image MD5: 82636E971E7EAFEE84DC3A6CE7B36026
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): DcomLaunch
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DCOM Server Process Launcher
Description: Provides launch functionality for DCOM services.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost -k DcomLaunch
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): Dhcp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DHCP Client
Description: Manages network configuration by registering and updating IP addresses and DNS names.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd,NetBT
Service (registry key): Disk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Disk Driver
Image path: system32\DRIVERS\disk.sys
Image size: 36352
Image MD5: 00CA44E4534865F8A3B64F7C0984BFF0
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Depends On group: "SCSI miniport"
Service (registry key): dmadmin
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager Administrative Service
Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops.
Object name: LocalSystem
Image path: %SystemRoot%\System32\dmadmin.exe /com
Image size: 224768
Image MD5: 554C7CB178FE3BD12450B81AD63ADBC3
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay,DmServer
Service (registry key): dmboot
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmboot.sys
Image size: 799744
Image MD5: C0FBB516E06E243F0CF31F597E7EBF7D
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): dmio
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmio.sys
Image size: 153344
Image MD5: F5E7B358A732D09F4BCF2824B88B9E28
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): dmload
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\drivers\dmload.sys
Image size: 5888
Image MD5: E9317282A63CA4D188C0DF5E09C6AC5F
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): dmserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Logical Disk Manager
Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,PlugPlay
Service (registry key): DMService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Whale Component Manager
Description: Manages the Whale Client Components.
Object name: LocalSystem
Image path: C:\WINNT\DOWNLO~1\DMService.exe
Image size: 423576
Image MD5: 18637209B4F263124EAC3DB5A77B24D1
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): DMusic
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DLS Syntheiszer
Image path: system32\drivers\DMusic.sys
Image size: 52864
Image MD5: A6F881284AC1150E37D9AE47FF601267
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Dnscache
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: DNS Client
Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Tcpip
Service (registry key): dpti2o
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): drmkaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel DRM Audio Descrambler
Image path: system32\drivers\drmkaud.sys
Image size: 2944
Image MD5: 1ED4DBBAE9F5D558DBBA4CC450E3EB2E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Eacfilt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Eacfilt Miniport
Image path: system32\DRIVERS\eacfilt.sys
Image size: 9817
Image MD5: D5B58855861FB5DD21087788BD1995EA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): eBOSS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: eBOSS Helper
Object name: LocalSystem
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0
Service (registry key): el575nd5
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 3Com Megahertz 10/100 LAN CardBus PC Card Driver
Image path: system32\DRIVERS\el575nd5.sys
Image size: 69692
Image MD5: 23F6B9CF432F492EBBD8105D78CB008C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ERSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Error Reporting Service
Description: Allows error reporting for services and applictions running in non-standard environments.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs
Service (registry key): Eventlog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Event Log
Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 108032
Image MD5: C6CE6EEC82F187615D1002BB3BB50ED4
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): EventSystem
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: COM+ Event System
Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): ExtranetAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Contivity VPN Service
Object name: LocalSystem
Image path: "C:\Program Files\IP VPN Remote Services\Extranet_serv.exe"
Image size: 643072
Image MD5: D049BB8445005592967A71B7F3B089FE
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 0
Service (registry key): Fastfat
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Service (registry key): FastUserSwitchingCompatibility
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Fast User Switching Compatibility
Description: Provides management for applications that require assistance in a multiple user environment.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: TermService
Service (registry key): Fdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): Fips
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Firefly Media Server
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Firefly Media Server
Object name: LocalSystem
Image path: C:\Program Files\Firefly Media Server\firefly.exe
Image size: 499712
Image MD5: 23D720C989580B1A2CF79789BA2F8738
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: "Bonjour Service"
Service (registry key): FLEXnet Licensing Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: FLEXnet Licensing Service
Description: This service performs licensing functions on behalf of FLEXnet enabled products.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
Image size: 654848
Image MD5: 227846995AFEEFA70D328BF5334A86A5
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): Flpydisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): FltMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: FltMgr
Description: File System Filter Manager Driver
Image path: system32\DRIVERS\fltMgr.sys
Image size: 124800
Image MD5: 157754F0DF355A9E0A6F54721914F9C6
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1
Service (registry key): Fs_Rec
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 8
Error Control: 0
Service (registry key): Ftdisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Manager Driver
Image path: system32\DRIVERS\ftdisk.sys
Image size: 125056
Image MD5: 6AC26732762483366C3969C9E4D2259D
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): GEARAspiWDM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: GEARAspiWDM
Image path: System32\Drivers\GEARAspiWDM.sys
Image size: 16168
Image MD5: 5DC17164F66380CBFEFD895C18467773
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Gpc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Generic Packet Classifier
Description: Generic Packet Classifier
Image path: system32\DRIVERS\msgpc.sys
Image size: 35072
Image MD5: C0F1D4A21DE5A415DF8170616703DEBF
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): HDAudBus
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft UAA Bus Driver for High Definition Audio
Image path: system32\DRIVERS\HDAudBus.sys
Image size: 138752
Image MD5: 3FCC124B6E08EE0E9351F717DD136939
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): helpsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Help and Support
Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): HidServ
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HID Input Service
Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): HidUsb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft HID Class Driver
Image path: system32\DRIVERS\hidusb.sys
Image size: 9600
Image MD5: 1DE6783B918F540149AA69943BDFEBA8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): HP Port Resolver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HP Port Resolver
Object name: LocalSystem
Image path: C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE
Image size: 81920
Image MD5: C5F00D15AA15CB7F55A027FF75E44BB7
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): HP Status Server
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HP Status Server
Object name: LocalSystem
Image path: C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE
Image size: 73728
Image MD5: C5A288E4CEEF5A26D105117BAA3763AB
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): hpn
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): HSFHWAZL
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\HSFHWAZL.sys
Image size: 209152
Image MD5: B1526810210980BED9D22315946C919D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): HSF_DPV
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\HSF_DPV.sys
Image size: 989696
Image MD5: DDBD528E60F5961C142A490DC4EA7780
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): HTTP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP
Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start.
Image path: System32\Drivers\HTTP.sys
Image size: 263040
Image MD5: C19B522A9AE0BBC3293397F3055E80A1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): HTTP Poster
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP Poster Service
Object name: LocalSystem
Image path: C:\WINNT\system32\HTTP_Poster.exe
Image size: 45056
Image MD5: D5B0476AFB0C425180FF60B0EE4735EC
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 0
Service (registry key): HTTPFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HTTP SSL
Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP
Service (registry key): i2omgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): i2omp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): i8042prt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: i8042 Keyboard and PS/2 Mouse Port Driver
Image path: system32\DRIVERS\i8042prt.sys
Image size: 52736
Image MD5: 5502B58EEF7486EE6F93F3F164DCB808
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): ialm
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\igxpmp32.sys
Image size: 5707744
Image MD5: 200CCA76CD0E0F7EEC78FA56C29B4D67
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): idisntkm
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 0
Error Control: 0
Service (registry key): idisw2km
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\idisw2km.sys
Image size: 8992
Image MD5: E9CCE03BCE0585226DA5B2AB2A3E342E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): IDriverT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: InstallDriver Table Manager
Description: Provides support for the Running Object Table for InstallShield Drivers
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"
Image size: 69632
Image MD5: DAF66902F08796F9C694901660E5A64A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Service (registry key): Imapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD-Burning Filter Driver
Image path: system32\DRIVERS\imapi.sys
Image size: 41856
Image MD5: F8AA320C6A0409C0380E5D8A99D76EC6
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): ImapiService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IMAPI CD-Burning COM Service
Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\imapi.exe
Image size: 150016
Image MD5: FA788520BCAC0F5D9D5CDE5615C0D931
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): inetaccs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): ini910u
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Inport
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): IntelIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): intelppm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Intel Processor Driver
Image path: system32\DRIVERS\intelppm.sys
Image size: 36096
Image MD5: 279FB78702454DFF2BB445F238C048D2
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Ip6Fw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPv6 Windows Firewall Driver
Description: Provides intrusion prevention service for a home or small office network.
Image path: system32\DRIVERS\Ip6Fw.sys
Image size: 29056
Image MD5: 4448006B6BC60E6C027932CFC38D6855
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): iPassConnectEngine
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPassConnectEngine
Object name: LocalSystem
Image path: C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
Image size: 1396736
Image MD5: 1C045B834B7A852E8741B0138C682114
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): iPassP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPass Protocol (IEEE 802.1x) v3.7.4.0
Description: iPass Protocol (IEEE 802.1x) v3.7.4.0
Image path: system32\DRIVERS\iPassP.sys
Image size: 21393
Image MD5: 468422B9137C884AB8FBA05A590989D7
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): iPassPeriodicUpdateApp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPassPeriodicUpdateApp
Object name: LocalSystem
Image path: "C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe"
Image size: 135168
Image MD5: BEDE742D051F3F848C10F59FC85C0DEB
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): iPassPeriodicUpdateService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPassPeriodicUpdateService
Object name: LocalSystem
Image path: "C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe"
Image size: 86016
Image MD5: 52A4ED0D41DD3652B1DB311FC0765BC4
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): IpFilterDriver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Traffic Filter Driver
Description: IP Traffic Filter Driver
Image path: system32\DRIVERS\ipfltdrv.sys
Image size: 32896
Image MD5: 731F22BA402EE4B62748ADAF6363C182
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): IpInIp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP in IP Tunnel Driver
Description: IP in IP Tunnel Driver
Image path: system32\DRIVERS\ipinip.sys
Image size: 20992
Image MD5: E1EC7F5DA720B640CD8FB8424F1B14BB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): IpNat
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IP Network Address Translator
Description: IP Network Address Translator
Image path: system32\DRIVERS\ipnat.sys
Image size: 134912
Image MD5: E2168CBC7098FFE963C6F23F472A3593
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): iPod Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: iPod Service
Description: iPod hardware management services
Object name: LocalSystem
Image path: "C:\Program Files\iPod\bin\iPodService.exe"
Image size: 504104
Image MD5: 1CB96E83FD76EB5580451CEF29E24303
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RpcSs
Service (registry key): IPSec
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC driver
Description: IPSEC driver
Image path: system32\DRIVERS\ipsec.sys
Image size: 74752
Image MD5: 64537AA5C003A6AFEEE1DF819062D0D1
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): IPSECEXT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nortel Extranet Access Protocol
Description: Nortel Extranet Access Protocol
Image path: system32\DRIVERS\ipsecw2k.sys
Image size: 117760
Image MD5: 6DB37F829B27C0F59B840F94F9DD1122
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): IPSECSHM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nortel IPSECSHM Adapter
Description: Nortel IPSECSHM Adapter
Image path: system32\DRIVERS\ipsecw2k.sys
Image size: 117760
Image MD5: 6DB37F829B27C0F59B840F94F9DD1122
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): IRENUM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IR Enumerator Service
Image path: system32\DRIVERS\irenum.sys
Image size: 11264
Image MD5: 50708DAA1B1CBB7D6AC1CF8F56A24410
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ISAPISearch
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): isapnp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PnP ISA/EISA Bus Driver
Image path: system32\DRIVERS\isapnp.sys
Image size: 35840
Image MD5: E504F706CCB699C2596E9A3DA1596E87
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3
Service (registry key): JavaQuickStarterService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Java Quick Starter
Description: Prefetches JRE files for faster startup of Java applets and applications
Object name: LocalSystem
Image path: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
Image size: 152984
Image MD5: 5FD5865DC1A2100F8D4CF000EE5409A3
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): Kbdclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Keyboard Class Driver
Image path: system32\DRIVERS\kbdclass.sys
Image size: 24576
Image MD5: EBDEE8A2EE5393890A1ACEE971C4C246
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): kbdhid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Keyboard HID Driver
Image path: system32\DRIVERS\kbdhid.sys
Image size: 14848
Image MD5: E182FA8E49E8EE41B4ADC53093F3C7E6
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): kbstuff
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SMS Virtual Mouse
Image path: system32\DRIVERS\kbstuff5.sys
Image size: 11744
Image MD5: 5CB887962A98B4E11D62858B75D87580
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): kmixer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Wave Audio Mixer
Image path: system32\drivers\kmixer.sys
Image size: 171776
Image MD5: D93CAD07C5683DB066B0B2D2D3790EAD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): KMW_KBD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Kensington Input Devices Class filter driver
Image path: System32\DRIVERS\KMW_KBD.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): KMW_USB
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Kensington MouseWorks USB filter driver
Image path: system32\DRIVERS\KMW_USB.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): KSecDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): lanmanserver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Server
Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): lanmanworkstation
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Workstation
Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): lbrtfdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): ldap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): LicenseService
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): LmHosts
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP NetBIOS Helper
Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: NetBT,Afd
Service (registry key): MCsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Managed Client Service
Description: Performs support functions for the Managed Client including receiving notification messages.
Object name: LocalSystem
Image path: C:\WINNT\System32\MCSvc.exe
Image size: 69632
Image MD5: 86EC5A1FAEEE67FCE1287150E635A64C
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Service (registry key): MDM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Machine Debug Manager
Description: Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
Image size: 322120
Image MD5: 11F714F85530A2BD134074DC30E99FCA
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): mdmxsdk
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\mdmxsdk.sys
Image size: 12672
Image MD5: 0CEA2D0D3FA284B85ED5B68365114F76
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0
Service (registry key): Messenger
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Messenger
Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS
Service (registry key): mnmdd
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): mnmsrvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetMeeting Remote Desktop Sharing
Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\mnmsrvc.exe
Image size: 32768
Image MD5: F6415361201915B9FE3896B0E4E724FF
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Service (registry key): Modem
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): Mouclass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mouse Class Driver
Image path: system32\DRIVERS\mouclass.sys
Image size: 23040
Image MD5: 34E1F0031153E491910E12551400192C
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): mouhid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mouse HID Driver
Image path: system32\DRIVERS\mouhid.sys
Image size: 12160
Image MD5: B1C303E17FB9D46E87A98E4BA6769685
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): MountMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): mraid35x
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): MRxDAV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebDav Client Redirector
Description: WebDav Client Redirector
Image path: system32\DRIVERS\mrxdav.sys
Image size: 179584
Image MD5: 29414447EB5BDE2F8397DC965DBB3156
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1
Service (registry key): MRxSmb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MRXSMB
Description: MRXSMB
Image path: system32\DRIVERS\mrxsmb.sys
Image size: 453632
Image MD5: 6F2D483B97B395544E59749C47963C6A
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): MSDTC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Transaction Coordinator
Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\NetworkService
Image path: C:\WINNT\system32\msdtc.exe
Image size: 6144
Image MD5: C7C3D89EB0A6F3DBA622EA737FA335B1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS,SamSS
Service (registry key): MSExchangeIMC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Msfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): MSIServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Installer
Description: Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\msiexec.exe /V
Image size: 78848
Image MD5: F5F0146580E7023ADB963879840777F8
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): MSKSSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Service Proxy
Image path: system32\drivers\MSKSSRV.sys
Image size: 7552
Image MD5: AE431A8DD3C1D0D0610CDBAC16057AD0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): MSPCLOCK
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Clock Proxy
Image path: system32\drivers\MSPCLOCK.sys
Image size: 5376
Image MD5: 13E75FEF9DFEB08EEDED9D0246E1F448
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): MSPQM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Streaming Quality Manager Proxy
Image path: system32\drivers\MSPQM.sys
Image size: 4992
Image MD5: 1988A33FF19242576C3D0EF9CE785DA7
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): mssmbios
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft System Management BIOS Driver
Image path: system32\DRIVERS\mssmbios.sys
Image size: 15488
Image MD5: 469541F8BFD2B32659D5D463A6714BCE
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Mup
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Mup
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1
Service (registry key): NbtDet
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBoot PCI Detection Service
Image path: system32\DRIVERS\nbtdet.sys
Image size: 4992
Image MD5: BBC9F2882ADC411876DEC75E281471BA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): NDIS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS System Driver
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): NdisTapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS TAPI Driver
Description: Remote Access NDIS TAPI Driver
Image path: system32\DRIVERS\ndistapi.sys
Image size: 9600
Image MD5: 08D43BBDACDF23F34D79E44ED35C1B4C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Ndisuio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NDIS Usermode I/O Protocol
Description: NDIS Usermode I/O Protocol
Image path: system32\DRIVERS\ndisuio.sys
Image size: 14592
Image MD5: 5146C3D286E66C72328F6CE6E4D983A8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): NdisWan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access NDIS WAN Driver
Description: Remote Access NDIS WAN Driver
Image path: system32\DRIVERS\ndiswan.sys
Image size: 91776
Image MD5: 0B90E255A9490166AB368CD55A529893
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): NDProxy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): NetBIOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBIOS Interface
Description: NetBIOS Interface
Image path: system32\DRIVERS\netbios.sys
Image size: 34560
Image MD5: 3A2ACA8FC1D7786902CA434998D7CEB4
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): NetBT
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetBios over Tcpip
Description: NetBios over Tcpip
Image path: system32\DRIVERS\netbt.sys
Image size: 162816
Image MD5: 0C80E410CD2F47134407EE7DD19CC86B
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: Tcpip
Service (registry key): NetDDE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE
Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: 05AFB5AD06462257BEA7495283C86D50
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: NetDDEDSDM
Service (registry key): NetDDEdsdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network DDE DSDM
Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\system32\netdde.exe
Image size: 111104
Image MD5: 05AFB5AD06462257BEA7495283C86D50
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Service (registry key): Netlogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Net Logon
Description: Supports pass-through authentication of account logon events for computers in a domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation
Service (registry key): Netman
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Connections
Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 288
Error Control: 1
Depends On services: RpcSs
Service (registry key): NIC1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 Net Driver
Image path: system32\DRIVERS\nic1394.sys
Image size: 61824
Image MD5: 5C5C53DB4FEF16CF87B9911C7E8C6FBC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Nla
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Location Awareness (NLA)
Description: Collects and stores network configuration and location information, and notifies applications when this information changes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tcpip,Afd
Service (registry key): nm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Monitor Driver
Image path: system32\DRIVERS\NMnt.sys
Image size: 40320
Image MD5: 60CF8C7192B3614F240838DDBAA4A245
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): nmwcd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nokia USB Phone Parent
Image path: system32\drivers\ccdcmb.sys
Image size: 17664
Image MD5: 9A908A9BB857C2CCEB2907EB9DCAEB8B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): nmwcdc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nokia USB Generic
Image path: system32\drivers\ccdcmbo.sys
Image size: 22016
Image MD5: 68EC3EE2348E475EA62C66E6AAFCFC9B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): NPF
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NetGroup Packet Filter Driver
Image path: system32\drivers\npf.sys
Image size: 42512
Image MD5: 243126DA7BA441D7C7C3262DCF435A9C
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): Npfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): Ntfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Service (registry key): NtLmSsp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: NT LM Security Support Provider
Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): NtmsSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Removable Storage
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): ntrtscan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OfficeScanNT RealTime Scan
Description: Performs Real-time, Scheduled, and Manual scan on OfficeScan clients.
Object name: LocalSystem
Image path: "C:\Program Files\OfficeScan NT\ntrtscan.exe"
Image size: 906536
Image MD5: EC539F17431F5FA73DD4F44FF64E9C0B
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Service (registry key): Null
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): NwlnkFlt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Filter Driver
Description: IPX Traffic Filter Driver
Image path: system32\DRIVERS\nwlnkflt.sys
Image size: 12416
Image MD5: B305F3FAD35083837EF46A0BBCE2FC57
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: NwlnkFwd
Service (registry key): NwlnkFwd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPX Traffic Forwarder Driver
Description: IPX Traffic Forwarder Driver
Image path: system32\DRIVERS\nwlnkfwd.sys
Image size: 32512
Image MD5: C99B3415198D1AAB7227F2C88FD664B9
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ohci1394
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OHCI Compliant IEEE 1394 Host Controller
Image path: system32\DRIVERS\ohci1394.sys
Image size: 61056
Image MD5: 0951DB8E5823EA366B0E408D71E1BA2A
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): ose
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Office Source Engine
Description: Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.
Object name: LocalSystem
Image path: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Image size: 89136
Image MD5: 7A56CF3E3F12E8AF599963B16F50FB6A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): Outlook
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Parport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Parallel port driver
Image path: system32\DRIVERS\parport.sys
Image size: 80128
Image MD5: 29744EB4CE659DFE3B4122DEB45BC478
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): PartMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): ParVdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 0
Depends On services: Parport
Depends On group: "Parallel arbitrator"
Service (registry key): pccsmcfd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PCCS Mode Change Filter Driver
Image path: system32\DRIVERS\pccsmcfd.sys
Image size: 21632
Image MD5: 175CC28DCF819F78CAA3FBD44AD9E52A
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): PCI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: PCI Bus Driver
Image path: system32\DRIVERS\pci.sys
Image size: 68224
Image MD5: 8086D9979234B603AD5BC2F5D890B234
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3
Service (registry key): PCIDump
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): PCIIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\pciide.sys
Image size: 3328
Image MD5: CCF5F451BB1A5A2A522A76E670000FF0
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): Pcmcia
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\pcmcia.sys
Image size: 119936
Image MD5: 82A087207DECEC8456FBE8537947D579
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): PDCOMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): PDFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): PDRELI
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): PDRFRAME
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): perc2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): perc2hib
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): PerfDisk
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): PerfNet
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): PerfOS
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): PerfProc
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): PlugPlay
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Plug and Play
Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
Object name: LocalSystem
Image path: %SystemRoot%\system32\services.exe
Image size: 108032
Image MD5: C6CE6EEC82F187615D1002BB3BB50ED4
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): Pml Driver HPZ12
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Pml Driver HPZ12
Object name: LocalSystem
Image path: C:\WINNT\system32\HPZipm12.exe
Image size: 69632
Image MD5: D31F88C5F19EEFA366A415D6BC5F2ABC
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): PolicyAgent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IPSEC Services
Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RPCSS,Tcpip,IPSec
Service (registry key): PptpMiniport
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (PPTP)
Description: WAN Miniport (PPTP)
Image path: system32\DRIVERS\raspptp.sys
Image size: 48384
Image MD5: 1C5CC65AAC0783C344F16353E60B72AC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): prepdrvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SMS Process Event Driver
Image path: \??\C:\WINNT\system32\CCM\prepdrv.sys
Image size: 23416
Image MD5: 19505C4134F3181FC2203E087140C192
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ProtectedStorage
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Protected Storage
Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 1
Depends On services: RpcSs
Service (registry key): Ptilink
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel Link Driver
Description: Direct Parallel Link Driver
Image path: system32\DRIVERS\ptilink.sys
Image size: 17792
Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ql1080
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Ql10wnt
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ql12160
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ql1240
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): ql1280
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): RasAcd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Driver
Description: Remote Access Auto Connection Driver
Image path: system32\DRIVERS\rasacd.sys
Image size: 8832
Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): RasAuto
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Auto Connection Manager
Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RasMan,Tapisrv
Service (registry key): Rasl2tp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WAN Miniport (L2TP)
Description: WAN Miniport (L2TP)
Image path: system32\DRIVERS\rasl2tp.sys
Image size: 51328
Image MD5: 98FAEB4A4DCF812BA1C6FCA4AA3E115C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): RasMan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access Connection Manager
Description: Creates a network connection.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: Tapisrv
Service (registry key): RasPppoe
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access PPPOE Driver
Description: Remote Access PPPOE Driver
Image path: system32\DRIVERS\raspppoe.sys
Image size: 41472
Image MD5: 7306EEED8895454CBED4669BE9F79FAA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Raspti
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Direct Parallel
Description: Direct Parallel
Image path: system32\DRIVERS\raspti.sys
Image size: 16512
Image MD5: FDBB1D60066FCFBB7452FD8F9829B242
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): RCHelp
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 0
Error Control: 0
Service (registry key): Rdbss
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Rdbss
Description: Rdbss
Image path: system32\DRIVERS\rdbss.sys
Image size: 174592
Image MD5: 03B965B1CA47F6EF60EB5E51CB50E0AF
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): RDPCDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: System32\DRIVERS\RDPCDD.sys
Image size: 4224
Image MD5: 4912D5B403614CE99C28420F75353332
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): RDPDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): rdpdr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Server Device Redirector Driver
Image path: system32\DRIVERS\rdpdr.sys
Image size: 196864
Image MD5: A2CAE2C60BC37E0751EF9DDA7CEAF4AD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): RDPNP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): RDPWD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): RDSessMgr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Desktop Help Session Manager
Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box.
Object name: LocalSystem
Image path: C:\WINNT\system32\sessmgr.exe
Image size: 140800
Image MD5: 729798E0933076B8FCFCD9934698F164
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): redbook
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Digital CD Audio Playback Filter Driver
Image path: system32\DRIVERS\redbook.sys
Image size: 57472
Image MD5: B31B4588E4086D8D84ADBF9845C2402B
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): RemoteAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Routing and Remote Access
Description: Offers routing services to businesses in local area and wide area network environments.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Depends On services: RpcSS
Depends On group: NetBIOSGroup
Service (registry key): RemoteRegistry
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Registry
Description: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): ROOTMODEM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Legacy Modem Driver
Image path: System32\Drivers\RootMdm.sys
Image size: 5888
Image MD5: D8B0B4ADE32574B2D9C5CC34DC0DBBE7
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): rpcapd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Packet Capture Protocol v.0 (experimental)
Description: Allows to capture traffic on this machine from a remote machine.
Object name: LocalSystem
Image path: "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini"
Image size: 92792
Image MD5: 8738CAD3F5D285D544A4D6553FF61BCC
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): RpcLocator
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC) Locator
Description: Manages the RPC name service database.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\locator.exe
Image size: 75264
Image MD5: 793F04A09B15E7C6C11DBDFFAF06C0AB
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: LanmanWorkstation
Service (registry key): RpcSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Procedure Call (RPC)
Description: Provides the endpoint mapper and other miscellaneous RPC services.
Object name: NT AUTHORITY\NetworkService
Image path: %SystemRoot%\system32\svchost -k rpcss
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): RSVP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: QoS RSVP
Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
Object name: LocalSystem
Image path: %SystemRoot%\system32\rsvp.exe
Image size: 132608
Image MD5: 471B3F9741D762ABE75E9DEEA4787E47
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: TcpIp,Afd,RpcSs
Service (registry key): SamSs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Accounts Manager
Description: Stores security information for local user accounts.
Object name: LocalSystem
Image path: %SystemRoot%\system32\lsass.exe
Image size: 13312
Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): SCardSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Smart Card
Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\SCardSvr.exe
Image size: 95744
Image MD5: 25D8DE134DF108E3DBC8D7D23B1AA58E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: PlugPlay
Service (registry key): Schedule
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Task Scheduler
Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): Secdrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secdrv
Description: SafeDisc driver
Image path: system32\DRIVERS\secdrv.sys
Image size: 20480
Image MD5: 90A3935D05B494A5A39D37E71F09A677
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): seclogon
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Secondary Logon
Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 288
Error Control: 0
Service (registry key): SENS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Event Notification
Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: EventSystem
Service (registry key): serenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Serenum Filter Driver
Image path: system32\DRIVERS\serenum.sys
Image size: 15488
Image MD5: A2D868AEEFF612E70E213C451A70CAFB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Serial
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Serial port driver
Image path: system32\DRIVERS\serial.sys
Image size: 64896
Image MD5: CD9404D115A00D249F70A371B46D5A26
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): Service Launcher
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Service Launcher
Description: Service Launcher
Object name: LocalSystem
Image path: C:\WINNT\system32\SvcLncher.exe
Image size: 229376
Image MD5: 8E21F9A309FDA5BA391682527E48A6AF
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0
Service (registry key): ServiceLayer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ServiceLayer
Object name: LocalSystem
Image path: "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"
Image size: 575488
Image MD5: 277D0890E10584C216BCCFA4EF6B9B3D
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): Sfloppy
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Depends On group: "SCSI miniport"
Service (registry key): SharedAccess
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Firewall/Internet Connection Sharing (ICS)
Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: Netman,WinMgmt
Service (registry key): ShellHWDetection
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Shell Hardware Detection
Description: Provides notifications for AutoPlay hardware events.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RpcSs
Service (registry key): Simbad
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): SP Software Installer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SP Software Installer
Description: Enables software updates and installations.
Object name: LocalSystem
Image path: C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
Image size: 118784
Image MD5: EF1F7335F0285599438A2E713CE8772A
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): Sparrow
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): splitter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel Audio Splitter
Image path: system32\drivers\splitter.sys
Image size: 6400
Image MD5: 8E186B8F23295D1E42C573B82B80D548
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Spooler
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Print Spooler
Description: Loads files to memory for later printing.
Object name: LocalSystem
Image path: %SystemRoot%\system32\spoolsv.exe
Image size: 57856
Image MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Depends On services: RPCSS
Service (registry key): sp_spi_da
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Visual Insight Dial Analysis
Object name: LocalSystem
Image path: C:\Program Files\AccessManager\SMOC\spi_da.exe
Image size: 81920
Image MD5: 570861636E49AC292051D102CD1379E1
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): sr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Filter Driver
Image path: \SystemRoot\system32\DRIVERS\sr.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Service (registry key): srservice
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: System Restore Service
Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): Srv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Srv
Description: Srv
Image path: system32\DRIVERS\srv.sys
Image size: 333056
Image MD5: 7A0111577D8046633D5162A3CE15E9E1
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1
Service (registry key): SSDPSRV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SSDP Discovery Service
Description: Enables discovery of UPnP devices on your home network.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: HTTP
Service (registry key): STacSV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SigmaTel Audio Service
Description: Manages SigmaTel Audio Universal Jack configurations.
Object name: LocalSystem
Image path: C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
Image size: 90112
Image MD5: 686FA4ACFDCB4E16B7F0230B88F6D17E
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): STHDA
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SigmaTel High Definition Audio CODEC
Image path: system32\drivers\sthda.sys
Image size: 1228296
Image MD5: 31BA85E1CFF39A57F702A2A0877BB8E1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): StillCam
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Still Serial Digital Camera Driver
Image path: system32\DRIVERS\serscan.sys
Image size: 6784
Image MD5: A9573045BAA16EAB9B1085205B82F1ED
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): stisvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Image Acquisition (WIA)
Description: Provides image acquisition services for scanners and cameras.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k imgsvc
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): SU
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SU Service
Object name: LocalSystem
Image path: C:\WINNT\system32\Suss.exe
Image size: 12048
Image MD5: 7A375DBDAC196606E0CA92F4580B87D2
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RpcSs
Service (registry key): swenum
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Software Bus Driver
Image path: system32\DRIVERS\swenum.sys
Image size: 4352
Image MD5: 03C1BAE4766E2450219D20B993D6E046
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): swmidi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel GS Wavetable Synthesizer
Image path: system32\drivers\swmidi.sys
Image size: 54272
Image MD5: 94ABC808FC4B6D7D2BBF42B85E25BB4D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): SwPrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: MS Software Shadow Copy Provider
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\dllhost.exe /Processid:{2FB04F5C-5388-4800-BAAC-7D4ED1D99E25}
Image size: 5120
Image MD5: DD87DB7387B9EB441C5674888A0D840C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 0
Depends On services: rpcss
Service (registry key): Sygman
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SSA Integration Manager
Description: SSA integration management services.
Object name: LocalSystem
Image path: "C:\Program Files\AccessManager\Client\sygman.exe"
Image size: 126976
Image MD5: B3B3ABC9FCD0720587F12F7649DC664F
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): symc810
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): symc8xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): sym_hi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): sym_u3
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): sysaudio
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Kernel System Audio Device
Image path: system32\drivers\sysaudio.sys
Image size: 60800
Image MD5: 650AD082D46BAC0E64C9C0E0928492FD
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): SysmonLog
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Performance Logs and Alerts
Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT Authority\NetworkService
Image path: %SystemRoot%\system32\smlogsvc.exe
Image size: 89600
Image MD5: 8B54AA346D1B1B113FFAA75501B8B1B2
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): TapiSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telephony
Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: PlugPlay,RpcSs
Service (registry key): Tcpip
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: TCP/IP Protocol Driver
Description: TCP/IP Protocol Driver
Image path: system32\DRIVERS\tcpip.sys
Image size: 360320
Image MD5: 2A5554FC5B1E04E131230E3CE035C3F9
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Depends On services: IPSec
Service (registry key): TDPIPE
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): TDTCP
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): TermDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Device Driver
Image path: system32\DRIVERS\termdd.sys
Image size: 40840
Image MD5: A540A99C281D933F3D69D55E48727F47
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): TermService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Terminal Services
Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost -k DComLaunch
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RPCSS
Service (registry key): Themes
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Themes
Description: Provides user experience theme management.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): TlntSvr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Telnet
Description: Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: C:\WINNT\system32\tlntsvr.exe
Image size: 73216
Image MD5: 37DB0A7D097310E8B4DE803FC3119C78
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 1
Depends On services: RPCSS,TCPIP,NTLMSSP
Service (registry key): tmcfw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro Common Firewall Service
Image path: system32\DRIVERS\TM_CFW.sys
Image size: 335888
Image MD5: C353B24CCBF0227621EB0FA72C9572DB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): tmcomm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: tmcomm
Image path: \??\C:\WINNT\system32\drivers\tmcomm.sys
Image size: 142096
Image MD5: F65E545771FD922693F0EC68B2141012
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): TmFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro Filter
Image path: \??\C:\Program Files\OfficeScan NT\TmXPFlt.sys
Image size: 205328
Image MD5: F23C38F5EDEB8D0FBD512632F5421651
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Depends On services: VSApiNt,TmPreFilter
Service (registry key): tmlisten
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OfficeScan NT Listener
Description: Receives commands and notifications from the OfficeScan server and facilitates communication from the client to the server.
Object name: LocalSystem
Image path: "C:\Program Files\OfficeScan NT\tmlisten.exe"
Image size: 984360
Image MD5: 89D686F4656CDEAEC3936ABCCE9DF11D
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Service (registry key): TmPfw
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OfficeScanNT Personal Firewall
Description: Provides packet level firewall, network virus scanning and intrusion detection capabilities.
Object name: LocalSystem
Image path: "C:\Program Files\OfficeScan NT\TmPfw.exe"
Image size: 488768
Image MD5: 3341EDF8769BC1967E2CA097792C370C
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: tmcfw
Service (registry key): TmPreFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro PreFilter
Image path: \??\C:\Program Files\OfficeScan NT\TmPreFlt.sys
Image size: 36368
Image MD5: DE9E8269185A7614A5A4F39CACD266EC
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): TmProxy
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: OfficeScan NT Proxy Service
Description: Scans network traffic before passing it to the target application.
Object name: LocalSystem
Image path: "C:\Program Files\OfficeScan NT\TmProxy.exe"
Image size: 652552
Image MD5: D49903A8B0EEA75A6EC1E162CDB6D473
Control Set: CurrentControlSet
Start: 3
Type: 272
Error Control: 1
Depends On services: tmtdi
Service (registry key): tmtdi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro TDI Driver
Image path: system32\DRIVERS\tmtdi.sys
Image size: 72072
Image MD5: 1A72B37AFA1C9B05488D9871D04C7AC5
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): toshidpt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth HID Port
Image path: system32\drivers\Toshidpt.sys
Image size: 3712
Image MD5: E362D54FD394999C4178936396664E57
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): TosIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): tosporte
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth COM Port
Image path: system32\DRIVERS\tosporte.sys
Image size: 41600
Image MD5: 8D624D3BD1F2D78BD1C01A2D4E954B4E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): tosrfbd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth RFBUS
Image path: system32\DRIVERS\tosrfbd.sys
Image size: 113920
Image MD5: 435AC6CC2ABED508AC5A495658CBAF0F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): tosrfbnp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth RFBNEP
Image path: System32\Drivers\tosrfbnp.sys
Image size: 36480
Image MD5: 90C8525BC578AAFFE87C2D0ED4379E9E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Tosrfcom
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth RFCOMM
Image path: System32\Drivers\tosrfcom.sys
Image size: 64896
Image MD5: 5BA1CA3B3CDDB1DDC67DF473F05D1EC2
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Tosrfhid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth RFHID
Image path: system32\DRIVERS\Tosrfhid.sys
Image size: 73600
Image MD5: 28099A4E52148319AFA685D93A2244D0
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): tosrfnds
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth Personal Area Network
Image path: system32\DRIVERS\tosrfnds.sys
Image size: 18612
Image MD5: C52FD27B9ADF3A1F22CB90E6BCF9B0CB
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Tosrfusb
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth USB Controller
Image path: system32\DRIVERS\tosrfusb.sys
Image size: 41856
Image MD5: 6BC529C5ECA0C7654943FD6FAB21C5FA
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): TrkWks
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Distributed Link Tracking Client
Description: Maintains links between NTFS files within a computer or across computers in a network domain.
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): TSDDD
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Udfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Service (registry key): UIUSys
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Conexant Setup API
Image path: system32\DRIVERS\UIUSYS.SYS
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ultra
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): Update
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microcode Update Driver
Image path: system32\DRIVERS\update.sys
Image size: 209408
Image MD5: AFF2E5045961BBC0A602BB6F95EB1345
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): upnphost
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Universal Plug and Play Device Host
Description: Provides support to host Universal Plug and Play devices.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: SSDPSRV,HTTP
Service (registry key): upperdev
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\usbser_lowerflt.sys
Image size: 8064
Image MD5: A34560A5D516A2F5240180370866B99D
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): UPS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Uninterruptible Power Supply
Description: Manages an uninterruptible power supply (UPS) connected to the computer.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\ups.exe
Image size: 18432
Image MD5: 3F5DF65B0758675F95A2D43918A740A3
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): usbccgp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Generic Parent Driver
Image path: system32\DRIVERS\usbccgp.sys
Image size: 31616
Image MD5: BFFD9F120CC63BCBAA3D840F3EEF9F79
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): USBCCID
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Smart Card reader
Image path: system32\DRIVERS\usbccid.sys
Image size: 28672
Image MD5: 6B5E4D5E6E5ECD6ACD14AED59768CE5C
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbehci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
Image path: system32\DRIVERS\usbehci.sys
Image size: 27008
Image MD5: 7481D843E672B51039B7E8A161B746B8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbhub
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Standard Hub Driver
Image path: system32\DRIVERS\usbhub.sys
Image size: 57600
Image MD5: C72F40947F92CEA56A8FB532EDF025F1
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbprint
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB PRINTER Class
Image path: system32\DRIVERS\usbprint.sys
Image size: 25856
Image MD5: A42369B7CD8886CD7C70F33DA6FCBCF5
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbscan
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Scanner Driver
Image path: system32\DRIVERS\usbscan.sys
Image size: 15104
Image MD5: A6BC71402F4F7DD5B77FD7F4A8DDBA85
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Nokia USB Serial Port
Image path: system32\DRIVERS\usbser.sys
Image size: 25600
Image MD5: 49106EE29074E6A3D3AC9E24C6D791D8
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): UsbserFilt
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\usbser_lowerfltj.sys
Image size: 8064
Image MD5: 6410EEBD6E0427466812858EE84C8467
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): USBSTOR
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: USB Mass Storage Driver
Image path: system32\DRIVERS\USBSTOR.SYS
Image size: 26496
Image MD5: 6CD7B22193718F1D17A47A1CD6D37E75
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): usbuhci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft USB Universal Host Controller Miniport Driver
Image path: system32\DRIVERS\usbuhci.sys
Image size: 20480
Image MD5: F8FD1400092E23C8F2F31406EF06167B
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): VgaSave
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\System32\drivers\vga.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 0
Service (registry key): ViaIde
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 4
Type: 1
Error Control: 1
Service (registry key): VolSnap
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): VSApiNt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Trend Micro VSAPI NT
Image path: \??\C:\Program Files\OfficeScan NT\VSApiNt.sys
Image size: 1195448
Image MD5: EB80F44FE19E0CD7CE998CA11CD790DD
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): VSS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Volume Shadow Copy
Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\vssvc.exe
Image size: 289792
Image MD5: 3EE00364AE0FD8D604F46CBAF512838A
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): W32Time
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Time
Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Service (registry key): W3SVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): Wanarp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Remote Access IP ARP Driver
Description: Remote Access IP ARP Driver
Image path: system32\DRIVERS\wanarp.sys
Image size: 34560
Image MD5: 984EF0B9788ABF89974CFED4BFBAACBC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Wdf01000
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wdf01000
Image path: system32\DRIVERS\Wdf01000.sys
Image size: 503008
Image MD5: BBCFEAB7E871CDDAC2D397EE7FA91FDC
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): WDICA
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): wdmaud
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft WINMM WDM Audio Compatibility Driver
Image path: system32\drivers\wdmaud.sys
Image size: 82944
Image MD5: 2797F33EBF50466020C430EE4F037933
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): WebClient
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WebClient
Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalService
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: MRxDAV
Service (registry key): winachsf
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\HSF_CNXT.sys
Image size: 730112
Image MD5: 96AFF1738271755A39B52EEF7E35F98F
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): winmgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation
Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 0
Depends On services: RPCSS
Service (registry key): Winsock
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 3
Type: 4
Error Control: 1
Service (registry key): WinSock2
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): WinTrust
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): wltrysvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Dell Wireless WLAN Tray Service
Description: Provides automatic configuration for the 802.11 adapter using the Broadcom supplicant.
Object name: LocalSystem
Image path: %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe
Image size: 20480
Image MD5: 60714B1C15F815F55798C0B3D4819BEB
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 1
Service (registry key): WmdmPmSN
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Portable Media Serial Number Service
Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): Wmi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Management Instrumentation Driver Extensions
Description: Provides systems management information to and from drivers.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): WmiAcpi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft Windows Management Interface for ACPI
Image path: system32\DRIVERS\wmiacpi.sys
Image size: 8832
Image MD5: AE2C8544E747C20062DB27456EA2D67A
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): WmiApRpl
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): WmiApSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: WMI Performance Adapter
Description: Provides performance library information from WMI HiPerf providers.
Object name: LocalSystem
Image path: C:\WINNT\system32\wbem\wmiapsrv.exe
Image size: 126464
Image MD5: BA8CECC3E813E1F7C441B20393D4F86C
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: RPCSS
Service (registry key): WMPNetworkSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Media Player Network Sharing Service
Description: Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
Object name: NT AUTHORITY\NetworkService
Image path: "C:\Program Files\Windows Media Player\WMPNetwk.exe"
Image size: 913408
Image MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Depends On services: upnphost,http,HTTPFilter
Service (registry key): WS2IFSL
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 1
Type: 0
Error Control: 0
Service (registry key): wscsvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Security Center
Description: Monitors system security settings and configurations.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,winmgmt
Service (registry key): wuauserv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Automatic Updates
Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.
Object name: LocalSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 4
Type: 32
Error Control: 1
Service (registry key): WudfPf
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver
Description: Provide communciation services for UMDF components.
Image path: system32\DRIVERS\WudfPf.sys
Image size: 76544
Image MD5: 50EB9E21963B4F06FD010D007D54351B
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): WudfRd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework Reflector
Description: Reflect device requests to user-mode driver drivers
Image path: system32\DRIVERS\wudfrd.sys
Image size: 82688
Image MD5: 6E209664BDEA8A15B5E8E480D6C607C2
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): WudfSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Windows Driver Foundation - User-mode Driver Framework
Description: Manages user-mode driver host processes
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay
Service (registry key): Wuser32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: SMS Remote Control Agent
Object name: LocalSystem
Image path: C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
Image size: 251256
Image MD5: E5F1614AE616C9C1B00E92031867F48F
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 0
Service (registry key): WZCSVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Wireless Zero Configuration
Description: Provides automatic configuration for the 802.11 adapters
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,Ndisuio
Service (registry key): xmlprov
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Network Provisioning Service
Description: Manages XML configuration files on a domain basis for automatic network provisioning.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 14336
Image MD5: 8F078AE4ED187AAABC0A305146DE6716
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): {31129AF3-2CDF-4692-8126-6AEED5019D8A}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {5E8875FA-BF7D-4B93-8D00-F179F4FEF81F}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {67C55556-3A19-425C-AE9D-6F311F24CF5B}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {82050D99-E21F-4151-BB2B-BDFB81A15DB1}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {CF321070-626F-48AE-B65A-3105209C4985}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): {FAFCE09D-8A2E-4F21-A092-B020C58316EB}
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
HJT startup list
StartupList report, 12/7/2008, 8:42:59 PM
StartupList version: 1.52.2
Started from : C:\Program Files\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\MCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\SvcLncher.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Suss.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\TEMP\XZ8E65.EXE
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\Program Files\OfficeScan NT\TmPfw.exe
C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\svchost.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\stsystra.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\WINNT\system32\WLTRAY.exe
C:\WINNT\system32\taskswitch.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINNT\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINNT\Managed\MCDesk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interwise\Participant\pull.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINNT\system32\HPZinw12.exe
————————————————–
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\vm092543\Start Menu\Programs\Startup]
*No files*
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Acrobat Speed Launcher.lnk = ?
Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Bluetooth Manager.lnk = ?
Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = c:\winnt\system32\userinit.exe
[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
OfficeScanNT Monitor = "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
Synchronization Manager = mobsync.exe /logon
WinZip Quick Pick = C:\Program Files\WinZip\WZQKPICK.EXE
ServicesSynchronizationUtility = "C:\Program Files\Siemens\Services Synchronization Utility\vbs.exe" SyncServices.vbe r "C:\" "C:\WINNT\" "C:\WINNT\system32\" "\\nsn-intra.net\dfsres\s_lw\global\etc\"
SigmatelSysTrayApp = stsystra.exe
IgfxTray = C:\WINNT\system32\igfxtray.exe
HotKeysCmds = C:\WINNT\system32\hkcmd.exe
Persistence = C:\WINNT\system32\igfxpers.exe
AccessManager = C:\Program Files\AccessManager\Client\AccessMgr.exe
Broadcom Wireless Manager UI = C:\WINNT\system32\WLTRAY.exe
CoolSwitch = C:\WINNT\system32\taskswitch.exe
Acrobat Assistant 8.0 = "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
Apoint = C:\Program Files\DellTPad\Apoint.exe
QuickTime Task = "C:\Program Files\QuickTime\QTTask.exe" -atboottime
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe"
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No values found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No values found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No values found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PC Suite Tray = "C:\Program Files\NOKIA\Nokia PC Suite 7\PCSuite.exe" -onlytray
ctfmon.exe = C:\WINNT\system32\ctfmon.exe
AdobeUpdater = C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
Google Update = "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
SpybotSD TeaTimer = C:\Program Files\Spybot\TeaTimer.exe
Copernic Desktop Search - Home = "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
Nokia.PCSync = "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No values found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No values found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No values found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
*No values found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
————————————————–
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
————————————————–
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default) = "%1" %*
————————————————–
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command
(Default) = "%1" %*
————————————————–
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command
(Default) = "%1" %*
————————————————–
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command
(Default) = "%1" %*
————————————————–
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" /S
————————————————–
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
(Default) = C:\WINNT\system32\mshta.exe "%1" %*
————————————————–
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1
————————————————–
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINNT\inf\unregmp2.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf
[{5084F01D-458E-45EB-A6FD-692D4C9D2789}] *
StubPath = C:\WINNT\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}
[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msmsgs.inf,BLC.QuietInstall.PerUser
[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp11.inf,PerUserStub
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe
[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINNT\system32\Rundll32.exe C:\WINNT\system32\mscories.dll,Install
[{A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}] *
StubPath = C:\WINNT\system32\msiexec.exe /qn /fpu {A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}
————————————————–
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps
*Registry key not found*
————————————————–
Load/Run keys from C:\WINNT\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=cdmcvw.dll
————————————————–
Shell & screensaver key from C:\WINNT\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=LOGON.SCR
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Checking for EXPLORER.EXE instances:
C:\WINNT\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINNT\Explorer\Explorer.exe: not present
C:\WINNT\System\Explorer.exe: not present
C:\WINNT\System32\Explorer.exe: not present
C:\WINNT\Command\Explorer.exe: not present
C:\WINNT\Fonts\Explorer.exe: not present
————————————————–
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
————————————————–
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINNT
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
Registry check passed
————————————————–
Enumerating Browser Helper Objects:
*No BHO's found*
————————————————–
Enumerating Task Scheduler jobs:
AppleSoftwareUpdate.job
GoogleUpdateTaskUser.job
————————————————–
Enumerating Download Program Files:
[WebTrain.ctlWebTrain]
InProcServer32 = C:\WINNT\system32\WEBTRAIN.OCX
CODEBASE = http://www.webattend.com/components/wt0523.cab
[WUWebControl Class]
InProcServer32 = C:\WINNT\system32\wuweb.dll
CODEBASE = http://www.update.microsoft.com/windowsupd…b?1218817069823
[JNILoader Control]
InProcServer32 = C:\WINNT\DOWNLO~1\STJNIL~1.OCX
CODEBASE = https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
[Java Plug-in 1.6.0_10]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Whale Client Components]
InProcServer32 = C:\WINNT\Downloaded Program Files\WhlMgr.dll
CODEBASE = https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
[Java Plug-in 1.6.0_03]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Java Plug-in 1.6.0_04]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Java Plug-in 1.6.0_10]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Java Plug-in 1.6.0_10]
InProcServer32 = C:\Program Files\Java\jre6\bin\npjpi160_10.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
[Xerox_Services_Portal.XrxPrinter_Inst]
InProcServer32 = C:\WINNT\Downloaded Program Files\Xerox_Services_Portal_Pref.ocx
CODEBASE = https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
————————————————–
Enumerating Winsock LSP files:
NameSpace #1: C:\WINNT\System32\mswsock.dll
NameSpace #2: C:\WINNT\System32\winrnr.dll
NameSpace #3: C:\WINNT\System32\mswsock.dll
NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll
Protocol #1: C:\WINNT\system32\mswsock.dll
Protocol #2: C:\WINNT\system32\mswsock.dll
Protocol #3: C:\WINNT\system32\mswsock.dll
Protocol #4: C:\WINNT\system32\rsvpsp.dll
Protocol #5: C:\WINNT\system32\rsvpsp.dll
Protocol #6: C:\WINNT\system32\mswsock.dll
Protocol #7: C:\WINNT\system32\mswsock.dll
Protocol #8: C:\WINNT\system32\mswsock.dll
Protocol #9: C:\WINNT\system32\mswsock.dll
Protocol #10: C:\WINNT\system32\mswsock.dll
Protocol #11: C:\WINNT\system32\mswsock.dll
Protocol #12: C:\WINNT\system32\mswsock.dll
Protocol #13: C:\WINNT\system32\mswsock.dll
Protocol #14: C:\WINNT\system32\mswsock.dll
Protocol #15: C:\WINNT\system32\mswsock.dll
Protocol #16: C:\WINNT\system32\mswsock.dll
Protocol #17: C:\WINNT\system32\mswsock.dll
Protocol #18: C:\WINNT\system32\mswsock.dll
Protocol #19: C:\WINNT\system32\mswsock.dll
Protocol #20: C:\WINNT\system32\mswsock.dll
Protocol #21: C:\WINNT\system32\mswsock.dll
Protocol #22: C:\WINNT\system32\mswsock.dll
Protocol #23: C:\WINNT\system32\mswsock.dll
Protocol #24: C:\WINNT\system32\mswsock.dll
Protocol #25: C:\WINNT\system32\mswsock.dll
————————————————–
Enumerating Windows NT/2000/XP services
Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
Access Manager Configuration Service: "C:\Program Files\AccessManager\Client\AMBroker.exe" (autostart)
Alps Touch Pad Filter Driver for Windows 2000/XP/Vista: system32\DRIVERS\Apfiltr.sys (manual start)
Apple Mobile Device: "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" (autostart)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: system32\DRIVERS\arp1394.sys (manual start)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Broadcom NetXtreme Gigabit Ethernet: system32\DRIVERS\b57xp32.sys (manual start)
Dell Wireless WLAN Card Driver: system32\DRIVERS\bcmwl5.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Bonjour Service: "C:\Program Files\Bonjour\mDNSResponder.exe" (disabled)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
SMS Agent Host: C:\WINNT\system32\CCM\CcmExec.exe (autostart)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (disabled)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
.NET Runtime Optimization Service v2.0.50727_X86: C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (manual start)
Microsoft AC Adapter Driver: system32\DRIVERS\CmBatt.sys (manual start)
Microsoft Composite Battery Driver: system32\DRIVERS\compbatt.sys (system)
COM+ System Application: C:\WINNT\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
CSRBC.Sys CSR test driver: System32\Drivers\csrbcxp.sys (manual start)
Visual Insight DA Plugin: C:\Program Files\AccessManager\Client\DAPlugin.exe (manual start)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Whale Component Manager: C:\WINNT\DOWNLO~1\DMService.exe (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Eacfilt Miniport: system32\DRIVERS\eacfilt.sys (manual start)
3Com Megahertz 10/100 LAN CardBus PC Card Driver: system32\DRIVERS\el575nd5.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINNT\system32\svchost.exe -k netsvcs (manual start)
Contivity VPN Service: "C:\Program Files\IP VPN Remote Services\Extranet_serv.exe" (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Firefly Media Server: C:\Program Files\Firefly Media Server\firefly.exe (disabled)
FLEXnet Licensing Service: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
GEARAspiWDM: System32\Drivers\GEARAspiWDM.sys (manual start)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Microsoft UAA Bus Driver for High Definition Audio: system32\DRIVERS\HDAudBus.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
HID Input Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft HID Class Driver: system32\DRIVERS\hidusb.sys (manual start)
HP Port Resolver: C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE (manual start)
HP Status Server: C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE (manual start)
HSFHWAZL: system32\DRIVERS\HSFHWAZL.sys (manual start)
HSF_DPV: system32\DRIVERS\HSF_DPV.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP Poster Service: C:\WINNT\system32\HTTP_Poster.exe (autostart)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
ialm: system32\DRIVERS\igxpmp32.sys (manual start)
idisw2km: system32\DRIVERS\idisw2km.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINNT\system32\imapi.exe (manual start)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
iPassConnectEngine: C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe (manual start)
iPass Protocol (IEEE 802.1x) v3.7.4.0: system32\DRIVERS\iPassP.sys (autostart)
iPassPeriodicUpdateApp: "C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe" (manual start)
iPassPeriodicUpdateService: "C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe" (autostart)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
Nortel Extranet Access Protocol: system32\DRIVERS\ipsecw2k.sys (autostart)
Nortel IPSECSHM Adapter: system32\DRIVERS\ipsecw2k.sys (manual start)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
Java Quick Starter: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" (autostart)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Keyboard HID Driver: system32\DRIVERS\kbdhid.sys (system)
SMS Virtual Mouse: system32\DRIVERS\kbstuff5.sys (manual start)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Kensington Input Devices Class filter driver: System32\DRIVERS\KMW_KBD.sys (manual start)
Kensington MouseWorks USB filter driver: system32\DRIVERS\KMW_USB.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Managed Client Service: C:\WINNT\System32\MCSvc.exe (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
mdmxsdk: system32\DRIVERS\mdmxsdk.sys (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
NetMeeting Remote Desktop Sharing: C:\WINNT\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINNT\system32\msdtc.exe (manual start)
Windows Installer: C:\WINNT\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
NetBoot PCI Detection Service: system32\DRIVERS\nbtdet.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (autostart)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
1394 Net Driver: system32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Network Monitor Driver: system32\DRIVERS\NMnt.sys (manual start)
Nokia USB Phone Parent: system32\drivers\ccdcmb.sys (manual start)
Nokia USB Generic: system32\drivers\ccdcmbo.sys (manual start)
NetGroup Packet Filter Driver: system32\drivers\npf.sys (autostart)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
OfficeScanNT RealTime Scan: "C:\Program Files\OfficeScan NT\ntrtscan.exe" (autostart)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
Parallel port driver: system32\DRIVERS\parport.sys (manual start)
PCCS Mode Change Filter Driver: system32\DRIVERS\pccsmcfd.sys (manual start)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
Pcmcia: system32\DRIVERS\pcmcia.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
Pml Driver HPZ12: C:\WINNT\system32\HPZipm12.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (disabled)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
SMS Process Event Driver: \??\C:\WINNT\system32\CCM\prepdrv.sys (manual start)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINNT\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Remote Registry: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Microsoft Legacy Modem Driver: System32\Drivers\RootMdm.sys (manual start)
Remote Packet Capture Protocol v.0 (experimental): "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" (manual start)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (autostart)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: system32\DRIVERS\secdrv.sys (manual start)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: system32\DRIVERS\serenum.sys (manual start)
Serial port driver: system32\DRIVERS\serial.sys (system)
Service Launcher: C:\WINNT\system32\SvcLncher.exe (autostart)
ServiceLayer: "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe" (manual start)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SP Software Installer: C:\Program Files\AccessManager\PMAC\sp_SWIns.exe (autostart)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Visual Insight Dial Analysis: C:\Program Files\AccessManager\SMOC\spi_da.exe (manual start)
System Restore Filter Driver: \SystemRoot\system32\DRIVERS\sr.sys (disabled)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Srv: system32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
SigmaTel Audio Service: C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe (autostart)
SigmaTel High Definition Audio CODEC: system32\drivers\sthda.sys (manual start)
Still Serial Digital Camera Driver: system32\DRIVERS\serscan.sys (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart)
SU Service: C:\WINNT\system32\Suss.exe (autostart)
Software Bus Driver: system32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINNT\system32\dllhost.exe /Processid:{2FB04F5C-5388-4800-BAAC-7D4ED1D99E25} (manual start)
SSA Integration Manager: "C:\Program Files\AccessManager\Client\sygman.exe" (autostart)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: system32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (autostart)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Telnet: C:\WINNT\system32\tlntsvr.exe (disabled)
Trend Micro Common Firewall Service: system32\DRIVERS\TM_CFW.sys (manual start)
tmcomm: \??\C:\WINNT\system32\drivers\tmcomm.sys (autostart)
Trend Micro Filter: \??\C:\Program Files\OfficeScan NT\TmXPFlt.sys (autostart)
OfficeScan NT Listener: "C:\Program Files\OfficeScan NT\tmlisten.exe" (autostart)
OfficeScanNT Personal Firewall: "C:\Program Files\OfficeScan NT\TmPfw.exe" (manual start)
Trend Micro PreFilter: \??\C:\Program Files\OfficeScan NT\TmPreFlt.sys (autostart)
OfficeScan NT Proxy Service: "C:\Program Files\OfficeScan NT\TmProxy.exe" (manual start)
Trend Micro TDI Driver: system32\DRIVERS\tmtdi.sys (system)
Bluetooth HID Port: system32\drivers\Toshidpt.sys (manual start)
Bluetooth COM Port: system32\DRIVERS\tosporte.sys (manual start)
Bluetooth RFBUS: system32\DRIVERS\tosrfbd.sys (manual start)
Bluetooth RFBNEP: System32\Drivers\tosrfbnp.sys (manual start)
Bluetooth RFCOMM: System32\Drivers\tosrfcom.sys (system)
Bluetooth RFHID: system32\DRIVERS\Tosrfhid.sys (manual start)
Bluetooth Personal Area Network: system32\DRIVERS\tosrfnds.sys (manual start)
Bluetooth USB Controller: system32\DRIVERS\tosrfusb.sys (manual start)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Conexant Setup API: system32\DRIVERS\UIUSYS.SYS (manual start)
Microcode Update Driver: system32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
upperdev: system32\DRIVERS\usbser_lowerflt.sys (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
USB Smart Card reader: system32\DRIVERS\usbccid.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
Microsoft USB Standard Hub Driver: system32\DRIVERS\usbhub.sys (manual start)
Microsoft USB PRINTER Class: system32\DRIVERS\usbprint.sys (manual start)
USB Scanner Driver: system32\DRIVERS\usbscan.sys (manual start)
Nokia USB Serial Port: system32\DRIVERS\usbser.sys (manual start)
UsbserFilt: system32\DRIVERS\usbser_lowerfltj.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
Trend Micro VSAPI NT: \??\C:\Program Files\OfficeScan NT\VSApiNt.sys (autostart)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
Wdf01000: system32\DRIVERS\Wdf01000.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
winachsf: system32\DRIVERS\HSF_CNXT.sys (manual start)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Dell Wireless WLAN Tray Service: %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Windows Management Interface for ACPI: system32\DRIVERS\wmiacpi.sys (system)
WMI Performance Adapter: C:\WINNT\system32\wbem\wmiapsrv.exe (manual start)
Windows Media Player Network Sharing Service: "C:\Program Files\Windows Media Player\WMPNetwk.exe" (manual start)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (disabled)
Windows Driver Foundation - User-mode Driver Framework Platform Driver: system32\DRIVERS\WudfPf.sys (system)
Windows Driver Foundation - User-mode Driver Framework Reflector: system32\DRIVERS\wudfrd.sys (manual start)
Windows Driver Foundation - User-mode Driver Framework: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup (autostart)
SMS Remote Control Agent: C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
————————————————–
Enumerating Windows NT logon/logoff scripts:
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\WINNT\system32\ytflnqpf.dll||C:\WINNT\system32\vfpdpcfw.dll||C:\WINNT\system32\vfpdpcfw.dll||C:\DOCUME~1\vm092543\LOCALS~1\Temp\_iu14D2N.tmp|||N
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINNT\system32\SHELL32.dll
CDBurn: C:\WINNT\system32\SHELL32.dll
WebCheck: C:\WINNT\system32\webcheck.dll
SysTray: C:\WINNT\system32\stobject.dll
WPDShServiceObj: C:\WINNT\system32\WPDShServiceObj.dll
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
*Registry key not found*
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
*Registry key not found*
————————————————–
End of report, 43,588 bytes
Report generated in 0.469 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hope the provided information is sufficient :-)