Smitfraud-C.Toolbar888

  1. #1
    Wizard is offline Newbie

    Smitfraud-C.Toolbar888

    Spybot keeps finding "Smitfraud-C.Toolbar888 " everytime i reboot i have tryed all the anti-spyware programs going and cant seem to get rid of it! i have also downloaded vundofix.exe and Smitfraud.cmd but it wont go anyway, Please Help!
    This is what Spybot's Descriptionis:-

    Smitfraud-C.Toolbar888 is connecting to malicious website without giving the user a possibility to cancel that process.
    It also adds a randomly named dll to the Winlogon Notify, which will make it very resistable to removal.



    Logfile of HijackThis v1.99.1
    Scan saved at 1624, on 22/03/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Maxthon2\Maxthon.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Documents and Settings\Wizard\Desktop\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\TSI32\tsircusr.exe
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {2C58AADB-ED25-4266-859C-89E506FF45F8} - (no file)
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\vnkoshlo.dll",setvm
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [LapLink Server Proxy] "C:\PROGRA~1\LAPLIN~1\WProxy.exe" -l
    O4 - HKLM\..\Run: [Winwall] C:\PROGRA~1\Winwall\Loader.exe
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Disk Cleaner.lnk = C:\Program Files\Disk Cleaner\dclean.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1167354957765
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: opnliii - opnliii.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
    Last edited by Wizard; 22-03-2007 at 05:39 PM.


  2. #2
    VopThis is offline Senior Member (Canada)
    Can you rename Hijackthis.exe to Analyse.exe

    Then scan with Analyse.exe and post the log in your next reply (which will be a HijackThis LOG, of course)

  3. #3
    Wizard is offline Newbie
    As requested!

    Logfile of HijackThis v1.99.1
    Scan saved at 20:13:34, on 22/03/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Maxthon2\Maxthon.exe
    C:\Program Files\BitComet\BitComet.exe
    C:\Documents and Settings\Wizard\Desktop\Analyse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\TSI32\tsircusr.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {2C58AADB-ED25-4266-859C-89E506FF45F8} - (no file)
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\vnkoshlo.dll",setvm
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [LapLink Server Proxy] "C:\PROGRA~1\LAPLIN~1\WProxy.exe" -l
    O4 - HKLM\..\Run: [Winwall] C:\PROGRA~1\Winwall\Loader.exe
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\RunOnce: [a_usdll] cmd /C "del C:\WINDOWS\system32\Macromed\Download\Download.dll "
    O4 - HKLM\..\RunOnce: [b_usexe] cmd /C "del C:\WINDOWS\system32\Macromed\Download\Download.exe "
    O4 - HKLM\..\RunOnce: [c_usdir] cmd /C "rmdir /Q C:\WINDOWS\system32\Macromed\Download"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Disk Cleaner.lnk = C:\Program Files\Disk Cleaner\dclean.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1167354957765
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: opnliii - opnliii.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

  4. #4
    VopThis is offline Senior Member (Canada)
    Do not allow 'BitComet' to load and run while you attempt to fix this PC. Many infections are often a result of using such a P2P application and will continue to put your PC at higher risk.

    You said that you ran 'smitfraudfix' but your HJT LOG does not reflect that a complete recommended fix process was run. Such an infection could interfere with successful vundofix procedures.


    STEP # 2 - Cleaning

    Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.



    Download and install AVG Anti-Spyware 7.5 (AVG AS - previously known as Ewido anti-spyware 4.0) (uninstall any previous version first).
    • Click the Download BUTTON. On the next page click the Download now BUTTON.
    • Save and then install (Run) from the save location.
    • Open/Run AVG Anti-Spyware
    • Wait a few moments and AVG Anti-Spyware should Auto update itself (note date of last update). If it doesn't update, click the update ICON at top of screen:

    • Click on the Update now LINK at the top of the window
      • Click on the Start update button
      • Wait for the update to download and install
  5. This is very important to get the LATEST updates
  6. Click on the Status ICON
    • Under "Your computers Security"
      Click change status on Resident shield to inactive (ONLY consider activation of that feature once you are clean)
  7. Click on the Scanner ICON at the top of the window
  8. Click on the Settings tab then select Recommended Actions and choose Quarantine
  9. When updating has finished. Close AVG Anti-Spyware.



  10. We will be using this tool in a later step.




    Reboot your computer in Safe Mode.
    • If the computer is running, shut down Windows, and then turn off the power.
    • Wait 30 seconds, and then turn the computer on.
    • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
    • Ensure that the Safe Mode option is selected.
    • Press Enter. The computer then begins to start in Safe mode.
    • Login on your usual account.
    ______________________________


    Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
    The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
    ______________________________

    Clean out your Temporary Internet files. Proceed like this:
    • Quit Internet Explorer and quit any instances of Windows Explorer.
    • Click Start, click Control Panel, and then double-click Internet Options.
    • On the General tab, click Delete Files under Temporary Internet Files.
    • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
    • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
    • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
    • Click OK.
    Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

    Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.


    ______________________________

    Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware , and run a full scan:
    • Click on the default Status ICON and select the Scan now LINK.

      OR

    • Click on the Scanner ICON . Select the Scan TAB.

      • Select Complete System Scan. AVG Anti-Spyware will now begin to scan your system.

    • If AVG Anti-Spyware finds anything it will list them in the Preview WINDOW:
      • Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
      • Select Apply all actions at the bottom of the window (and the items found will be quarantined – and recoverable, if any items are needed back).

    • When the scan has completed, click on the Save Scan Report button and save the scan to your Desktop where it can be easily found.
    • Copy and paste the AVG Anti-Spyware scan results into your next post.
    • Close AVG Anti-Spyware.


    ______________________________
    SELECT HijackThis FIX ITEMS: Scan with HijackThis and place a check next to these items:

    ----------No items specified

    Make sure that all browser windows and internet links are closed, even this one!
    CLICK ’FIX CHECKED’ with HijackThis.
    ______________________________

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #3 - Delete Trusted zone by typing 3 and press Enter
    Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.

    Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.


    ______________________________
    Reboot in Normal Mode.

    Please post (preferably not file attachments, please):
    1. c:\rapport.txt
    2. AVG Anti-Spyware log
    3. A new HijackThis log (see note below)




    You are not running HijackThis (HJT) from a desired location. You really need to setup a dedicated folder for HJT items – to avoid horrible clutter and/or potential lost backup issues.

    It's best that the HijackThis tool NOT be located in its current location (particularly on your Desktop or in a TEMP folder). This way you can more easily undo any changes if something goes wrong.
    • Create a new folder in your C: Drive.
    • Name the FOLDER HijackThis (or HJT) such as C:\Program Files\HijackThis or C:\HJT and
    • Move the HijackThis.exe (or similar) file into the newly created FOLDER.
    • Run HJT from there (and revise your shortcut accordingly).

  • #5
    Wizard is offline Newbie
    rapport.txt:-
    SmitFraudFix v2.152

    Scan done at 20:59:31.68, 22/03/2007
    Run from C:\Documents and Settings\Wizard\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End

    Avg Log:-
    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 22:13:01 22/03/2007

    + Scan result:



    C:\Documents and Settings\Wizard\Desktop\SmitfraudFix\SmiUpdate.exe -> Adware.SmiUpdate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{A20A3D1A-36E7-41F4-A740-714A9B361400}\RP4\A0006971.exe -> Adware.SmiUpdate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{A20A3D1A-36E7-41F4-A740-714A9B361400}\RP6\A0007533.exe -> Adware.SmiUpdate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{A20A3D1A-36E7-41F4-A740-714A9B361400}\RP6\A0007689.exe -> Adware.SmiUpdate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{A20A3D1A-36E7-41F4-A740-714A9B361400}\RP9\A0008533.exe -> Adware.SmiUpdate : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\SmitfraudFix\SmiUpdate.exe -> Adware.SmiUpdate : Cleaned with backup (quarantined).
    :mozilla.56:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\384kyxn0.default\coo kies.txt -> TrackingCookie.Paypal : Cleaned.
    :mozilla.6:C:\Documents and Settings\Wizard\Application Data\Mozilla\Firefox\Profiles\ubpai24a.default\coo kies.txt -> TrackingCookie.Real : Cleaned.
    :mozilla.7:C:\Documents and Settings\Wizard\Application Data\Mozilla\Firefox\Profiles\ubpai24a.default\coo kies.txt -> TrackingCookie.Real : Cleaned.


    ::Report end


    Logfile of HijackThis v1.99.1
    Scan saved at 22:29:39, on 22/03/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\Winwall\Winwall.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\Maxthon2\Maxthon.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Highjackthis\Analyse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\TSI32\tsircusr.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {2C58AADB-ED25-4266-859C-89E506FF45F8} - (no file)
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\vnkoshlo.dll",setvm
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [LapLink Server Proxy] "C:\PROGRA~1\LAPLIN~1\WProxy.exe" -l
    O4 - HKLM\..\Run: [Winwall] C:\PROGRA~1\Winwall\Loader.exe
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Disk Cleaner.lnk = C:\Program Files\Disk Cleaner\dclean.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1167354957765
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: opnliii - opnliii.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

  • #6
    VopThis is offline Senior Member (Canada)
    Read over the following directions. Ask if anything appears unclear to you.



    Clean out TEMPORARY FILES procedures:
    To clean your temp folder, recycle bin, etc..please download this free tool:

    CCleaner http://www.ccleaner.com/downloadbuilds.asp

    Install Options:
    • Don't install any Toolbars, or other programs, should it ask you!
    • Just uncheck the option of installing the Yahoo toolbar.

    It will put a shortcut on your Desktop.

    Do not run CCleaner until requested later.





    We will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet. Accordingly, it is probably a good idea to print out the following directions or copy them to a text file on your desktop using NOTEPAD. Read these instructions carefully and feel free to ask if you're unsure about anything.

    SELECT HijackThis FIX ITEMS: Scan with HijackThis and place a check next to these items:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    O2 - BHO: (no name) - {2C58AADB-ED25-4266-859C-89E506FF45F8} - (no file)
    O20 - Winlogon Notify: opnliii - opnliii.dll (file missing)

    Make sure that all browser windows and internet links are closed, even this one!
    CLICK ’FIX CHECKED’ with HijackThis.



    HIDDEN FILES: To make sure you can see all hidden files, please follow the directions here

    SAFEMODE: Boot into safe mode by tapping the F8 key at restart and choosing 'safe mode' menu option (explained here if needed).



    Delete TEMPORARY FILES: Now, use CCleaner to hunt down the most common temporary file locations and the temporary file clutter contained therein (and of possible malware hiding places):

    Run CCleaner .

    FIRST-TIME USE:
    Select the ‘Options’ BUTTON option (top LEFT), ‘Advanced’ BUTTON, and then UNCHECK the ‘Only delete files in Windows Temp Folders older than 48 hours’.

    Select the ‘Cleaner’ BUTTON option (top LEFT), if not already selected. Use the ’Windows’ TAB up front by default.
    • Uncheck ‘Cookies’ option (advisable)
    • Optionally, Uncheck ‘Recently Typed URLs’ option (potentially still useful)
    • Click the ‘Analyse’ button.
    • Thereafter, click ‘Run Cleaner’ after you have reviewed what it proposes to clean.





    POST A REVISED HIJACKTHIS LOG for review:
    Reboot and post a new HijackThis log with any feedback as appropriate - how things are now behaving: any new or remaining apparent issues.

  • #7
    Wizard is offline Newbie
    Thank you for your help but its still there, here is the results from SpyBot
    --- Search result list ---
    Smitfraud-C.Toolbar888: Settings (Registry key, nothing done)
    HKEY_USERS\S-1-5-21-1275210071-162531612-725345543-1003\Software\Microsoft\aldd

    Smitfraud-C.Toolbar888: Settings (Registry key, nothing done)
    HKEY_LOCAL_MACHINE\SOFTWARE\Araf15

    User abort!: Scan was not completed successfully. ()



    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2007-02-14 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2007-01-15 advcheck.dll (1.2.1.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2005-05-31 SDHelper.dll (1.4.0.0)
    2007-01-02 Tools.dll (2.0.1.0)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2007-03-21 Includes\Cookies.sbi (*)
    2006-12-08 Includes\Dialer.sbi (*)
    2007-03-21 Includes\DialerC.sbi (*)
    2007-03-21 Includes\Hijackers.sbi (*)
    2007-03-21 Includes\HijackersC.sbi (*)
    2006-10-27 Includes\Keyloggers.sbi (*)
    2007-03-21 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2007-03-21 Includes\Malware.sbi (*)
    2007-03-21 Includes\MalwareC.sbi (*)
    2007-03-21 Includes\PUPS.sbi (*)
    2007-03-21 Includes\PUPSC.sbi (*)
    2007-03-21 Includes\Revision.sbi (*)
    2006-12-08 Includes\Security.sbi (*)
    2007-03-21 Includes\SecurityC.sbi (*)
    2007-03-21 Includes\Spybots.sbi (*)
    2007-03-21 Includes\SpybotsC.sbi (*)
    2005-02-17 Includes\Tracks.uti
    2007-03-21 Includes\Trojans.sbi (*)
    2007-03-21 Includes\TrojansC.sbi (*)



    --- System information ---
    Windows XP (Build: 2600) Service Pack 2
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB886903)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
    / Microsoft .NET Framework 2.0: This Security Update is for Microsoft .NET Framework 2.0. \n
    If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
    For more information, visit http://support.microsoft.com/kb/917283
    / Microsoft .NET Framework 2.0: This Security Update is for Microsoft .NET Framework 2.0. \n
    If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
    For more information, visit http://support.microsoft.com/kb/922770
    / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
    / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
    / Windows / SP1: Microsoft National Language Support Downlevel APIs
    / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
    / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
    / Windows Media Player 9: Security Update for Windows Media Player 9 (KB917734)
    / Windows XP: Security Update for Windows XP (KB923689)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB929969)
    / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
    / Windows XP / SP2: Windows XP Service Pack 2
    / Windows XP / SP3: Windows XP Hotfix - KB873339
    / Windows XP / SP3: Windows XP Hotfix - KB885835
    / Windows XP / SP3: Windows XP Hotfix - KB885836
    / Windows XP / SP3: Windows XP Hotfix - KB885884
    / Windows XP / SP3: Windows XP Hotfix - KB886185
    / Windows XP / SP3: Windows XP Hotfix - KB887472
    / Windows XP / SP3: Windows XP Hotfix - KB888302
    / Windows XP / SP3: Windows XP Hotfix - KB890859
    / Windows XP / SP3: Windows XP Hotfix - KB891781
    / Windows XP / SP3: Security Update for Windows XP (KB893756)
    / Windows XP / SP3: Windows Installer 3.1 (KB893803)
    / Windows XP / SP3: Update for Windows XP (KB894391)
    / Windows XP / SP3: Hotfix for Windows XP (KB896344)
    / Windows XP / SP3: Security Update for Windows XP (KB896358)
    / Windows XP / SP3: Security Update for Windows XP (KB896423)
    / Windows XP / SP3: Security Update for Windows XP (KB896424)
    / Windows XP / SP3: Security Update for Windows XP (KB896428)
    / Windows XP / SP3: Update for Windows XP (KB898461)
    / Windows XP / SP3: Security Update for Windows XP (KB899587)
    / Windows XP / SP3: Security Update for Windows XP (KB899591)
    / Windows XP / SP3: Update for Windows XP (KB900485)
    / Windows XP / SP3: Security Update for Windows XP (KB900725)
    / Windows XP / SP3: Security Update for Windows XP (KB901017)
    / Windows XP / SP3: Security Update for Windows XP (KB901214)
    / Windows XP / SP3: Security Update for Windows XP (KB902400)
    / Windows XP / SP3: Security Update for Windows XP (KB904706)
    / Windows XP / SP3: Update for Windows XP (KB904942)
    / Windows XP / SP3: Security Update for Windows XP (KB905414)
    / Windows XP / SP3: Security Update for Windows XP (KB905749)
    / Windows XP / SP3: Security Update for Windows XP (KB908519)
    / Windows XP / SP3: Update for Windows XP (KB908531)
    / Windows XP / SP3: Update for Windows XP (KB910437)
    / Windows XP / SP3: Update for Windows XP (KB911280)
    / Windows XP / SP3: Security Update for Windows XP (KB911562)
    / Windows XP / SP3: Security Update for Windows XP (KB911567)
    / Windows XP / SP3: Security Update for Windows XP (KB911927)
    / Windows XP / SP3: Security Update for Windows XP (KB912919)
    / Windows XP / SP3: Security Update for Windows XP (KB913580)
    / Windows XP / SP3: Security Update for Windows XP (KB914388)
    / Windows XP / SP3: Security Update for Windows XP (KB914389)
    / Windows XP / SP3: Hotfix for Windows XP (KB914440)
    / Windows XP / SP3: Hotfix for Windows XP (KB915865)
    / Windows XP / SP3: Update for Windows XP (KB916595)
    / Windows XP / SP3: Security Update for Windows XP (KB917344)
    / Windows XP / SP3: Security Update for Windows XP (KB917422)
    / Windows XP / SP3: Security Update for Windows XP (KB917953)
    / Windows XP / SP3: Security Update for Windows XP (KB918118)
    / Windows XP / SP3: Security Update for Windows XP (KB918439)
    / Windows XP / SP3: Security Update for Windows XP (KB919007)
    / Windows XP / SP3: Security Update for Windows XP (KB920213)
    / Windows XP / SP3: Security Update for Windows XP (KB920214)
    / Windows XP / SP3: Update for Windows XP (KB920342)
    / Windows XP / SP3: Security Update for Windows XP (KB920670)
    / Windows XP / SP3: Security Update for Windows XP (KB920683)
    / Windows XP / SP3: Security Update for Windows XP (KB920685)
    / Windows XP / SP3: Update for Windows XP (KB920872)
    / Windows XP / SP3: Security Update for Windows XP (KB921398)
    / Windows XP / SP3: Update for Windows XP (KB922582)
    / Windows XP / SP3: Security Update for Windows XP (KB922616)
    / Windows XP / SP3: Security Update for Windows XP (KB922760)
    / Windows XP / SP3: Security Update for Windows XP (KB922819)
    / Windows XP / SP3: Security Update for Windows XP (KB923191)
    / Windows XP / SP3: Security Update for Windows XP (KB923414)
    / Windows XP / SP3: Security Update for Windows XP (KB923694)
    / Windows XP / SP3: Security Update for Windows XP (KB923980)
    / Windows XP / SP3: Security Update for Windows XP (KB924191)
    / Windows XP / SP3: Security Update for Windows XP (KB924270)
    / Windows XP / SP3: Security Update for Windows XP (KB924496)
    / Windows XP / SP3: Security Update for Windows XP (KB924667)
    / Windows XP / SP3: Security Update for Windows XP (KB925486)
    / Windows XP / SP3: Update for Windows XP (KB925720)
    / Windows XP / SP3: Update for Windows XP (KB925876)
    / Windows XP / SP3: Hotfix for Windows XP (KB926239)
    / Windows XP / SP3: Security Update for Windows XP (KB926255)
    / Windows XP / SP3: Security Update for Windows XP (KB926436)
    / Windows XP / SP3: Security Update for Windows XP (KB927779)
    / Windows XP / SP3: Security Update for Windows XP (KB927802)
    / Windows XP / SP3: Security Update for Windows XP (KB928255)
    / Windows XP / SP3: Hotfix for Windows XP (KB928388)
    / Windows XP / SP3: Security Update for Windows XP (KB928843)
    / Windows XP / SP3: Hotfix for Windows XP (KB929120)
    / Windows XP / SP3: Update for Windows XP (KB929338)
    / Windows XP / SP3: Security Update for Windows XP (KB929969)
    / Windows XP / SP3: Update for Windows XP (KB931836)
    / XML Paper Specification Shared Components Pack 1.0: XML Paper Specification Shared Components Pack 1.0


    --- Startup entries list ---
    Located: HK_LM:Run, !AVG Anti-Spyware
    command: "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    file: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    size: 6266880
    MD5: 01d90ae5dccbce0c7b52874fec35a608

    Located: HK_LM:Run, {0228e555-4f9c-4e35-a3ec-b109a192b4c2}
    command: C:\Program Files\Google\Gmail Notifier\gnotify.exe
    file: C:\Program Files\Google\Gmail Notifier\gnotify.exe
    size: 479232
    MD5: 3df7ac30a381c57d0c70eaefee3c4ef2

    Located: HK_LM:Run, 2chkdsk
    command: rundll32.exe "C:\WINDOWS\system32\vnkoshlo.dll",setvm
    file: C:\WINDOWS\system32\rundll32.exe
    size: 33280
    MD5: da285490bbd8a1d0ce6623577d5ba1ff

    Located: HK_LM:Run, AVG7_CC
    command: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    file: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    size: 411648
    MD5: 2a62570d13f14f49218ce7b03caa9cb2

    Located: HK_LM:Run, iTunesHelper
    command: "C:\Program Files\iTunes\iTunesHelper.exe"
    file: C:\Program Files\iTunes\iTunesHelper.exe
    size: 257088
    MD5: b0e9efadf04e9e25c0001b48757f3e71

    Located: HK_LM:Run, LapLink Server Proxy
    command: "C:\PROGRA~1\LAPLIN~1\WProxy.exe" -l
    file:

    Located: HK_LM:Run, QuickTime Task
    command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
    file: C:\Program Files\QuickTime\qttask.exe
    size: 282624
    MD5: 30e1f03dcc8825988528d9058312ede2

    Located: HK_LM:Run, RegistryMechanic
    command:
    file:

    Located: HK_LM:Run, TkBellExe
    command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    size: 180269
    MD5: 1ac2c58b587c70de64582ad41ee79fba

    Located: HK_LM:Run, Winwall
    command: C:\PROGRA~1\Winwall\Loader.exe
    file: C:\PROGRA~1\Winwall\Loader.exe
    size: 20480
    MD5: cc078ba499324715080313d0dd6eabdc

    Located: HK_LM:Run, ZoneAlarm Client
    command: "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    size: 919280
    MD5: f6d4d4068aec371df8f89cdf11fc321d

    Located: HK_CU:Run, ctfmon.exe
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 24232996a38c0b0cf151c2140ae29fc8

    Located: Startup (user), Disk Cleaner.lnk
    command: C:\Program Files\Disk Cleaner\dclean.exe
    file: C:\Program Files\Disk Cleaner\dclean.exe
    size: 209920
    MD5: 2dd03e4184eb39fc97a6a78a75546cc3

    Located: System.ini, crypt32chain
    command: crypt32.dll
    file: crypt32.dll

    Located: System.ini, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll

    Located: System.ini, cscdll
    command: cscdll.dll
    file: cscdll.dll

    Located: System.ini, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, Schedule
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll

    Located: System.ini, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll

    Located: System.ini, termsrv
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, WgaLogon
    command: WgaLogon.dll
    file: WgaLogon.dll

    Located: System.ini, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll



    --- Browser helper object list ---
    {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (BitComet ClickCapture)
    BHO name: BitComet ClickCapture
    CLSID name: BitComet Helper
    Path: C:\Program Files\BitComet\tools\
    Long name: BitCometBHO_1.1.2.7.dll
    Short name: BITCOM~4.DLL
    Date (created): 08/02/2007 05:04:02
    Date (last access): 28/02/2007 00:39:26
    Date (last write): 08/02/2007 05:04:02
    Filesize: 158272
    Attributes: archive
    MD5: F6FB4263C593BF2F795061895C99EC9F
    CRC32: 382DB2D0
    Version: 1.1.2.7

    {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
    BHO name:
    CLSID name: Windows Live Sign-in Helper
    Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
    Long name: WindowsLiveLogin.dll
    Short name: WINDOW~1.DLL
    Date (created): 07/07/2006 12:29:52
    Date (last access): 27/01/2007 12:10:52
    Date (last write): 07/07/2006 12:29:52
    Filesize: 324416
    Attributes: archive
    MD5: 52A70C80A446FA3BBCDAF59A9AB26AF4
    CRC32: B1456034
    Version: 4.0.249.1



    --- ActiveX list ---


    --- Process list ---
    PID: 0 ( 0) [System]
    PID: 600 ( 4) \SystemRoot\System32\smss.exe
    PID: 660 ( 600) \??\C:\WINDOWS\system32\csrss.exe
    PID: 684 ( 600) \??\C:\WINDOWS\system32\winlogon.exe
    PID: 728 ( 684) C:\WINDOWS\system32\services.exe
    size: 108032
    MD5: C6CE6EEC82F187615D1002BB3BB50ED4
    PID: 740 ( 684) C:\WINDOWS\system32\lsass.exe
    size: 13312
    MD5: 84885F9B82F4D55C6146EBF6065D75D2
    PID: 912 ( 728) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 960 ( 728) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1060 ( 728) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1176 ( 728) C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    size: 75568
    MD5: C570C4239323EB4E08AB0C0D99ED62F1
    PID: 1812 (1780) C:\WINDOWS\Explorer.EXE
    size: 1032192
    MD5: A0732187050030AE399B241436565E64
    PID: 1892 ( 728) C:\WINDOWS\system32\spoolsv.exe
    size: 57856
    MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
    PID: 352 (1812) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    size: 180269
    MD5: 1AC2C58B587C70DE64582AD41EE79FBA
    PID: 360 (1812) C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    size: 919280
    MD5: F6D4D4068AEC371DF8F89CDF11FC321D
    PID: 380 (1812) C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    size: 411648
    MD5: 2A62570D13F14F49218CE7B03CAA9CB2
    PID: 440 (1812) C:\Program Files\Google\Gmail Notifier\gnotify.exe
    size: 479232
    MD5: 3DF7AC30A381C57D0C70EAEFEE3C4EF2
    PID: 492 ( 728) C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    size: 353792
    MD5: 708D06E4285B5DB85876329ED672423B
    PID: 500 ( 420) C:\PROGRA~1\Winwall\Winwall.exe
    size: 299008
    MD5: D1F3A5FC167A9931488FE8624921D29E
    PID: 508 (1812) C:\Program Files\iTunes\iTunesHelper.exe
    size: 257088
    MD5: B0E9EFADF04E9E25C0001B48757F3E71
    PID: 592 ( 728) C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    size: 49664
    MD5: 30A14F65DB477DC00A64A5A24E96919C
    PID: 656 ( 728) C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    size: 49152
    MD5: EE684C735B6D1D07498A1EC2EA1AE483
    PID: 944 ( 656) C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    size: 798720
    MD5: 16A004C841CB520F980CFE158E01ADFA
    PID: 1008 ( 728) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    size: 322120
    MD5: 11F714F85530A2BD134074DC30E99FCA
    PID: 1128 (1812) C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    size: 6266880
    MD5: 01D90AE5DCCBCE0C7B52874FEC35A608
    PID: 1148 ( 728) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    size: 45056
    MD5: 3978F082274F723AD5A0A8058C2417DD
    PID: 1180 (1812) C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 24232996A38C0B0CF151C2140AE29FC8
    PID: 1728 ( 728) C:\Program Files\iPod\bin\iPodService.exe
    size: 500800
    MD5: 661194608009B558DE1925C7EBE1A4BA
    PID: 2236 ( 728) C:\WINDOWS\System32\alg.exe
    size: 44544
    MD5: F1958FBF86D5C004CF19A5951A9514B7
    PID: 3640 (1812) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 4393096
    MD5: 09CA174A605B480318731E691DC98539
    PID: 2284 ( 440) C:\Program Files\Maxthon2\Maxthon.exe
    size: 1323008
    MD5: F8889CB176A5A445C60B22B21643AD14
    PID: 4 ( 0) System


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 22/03/2007 23:24:54

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
    http://home.microsoft.com/access/autosearch.asp?p=%s
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    %SystemRoot%\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    about:blank
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://go.microsoft.com/fwlink/?LinkId=54896


    --- Winsock Layered Service Provider list ---


    --- Uninstall list ---
    Ad-Aware SE Personal 1.06 (Ad-Aware SE Personal)
    uninstall cmd: C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
    publisher: Lavasoft
    help link: http://www.lavasoft.com

    (AddressBook)

    Adobe Shockwave Player 10.1.4.20 (Adobe Shockwave Player)
    uninstall cmd: C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
    publisher: Adobe Systems, Inc.
    help link: http://www.adobe.com/support/shockwave

    Advanced WindowsCare 2.21 Professional (Advanced WindowsCare V2 Pro_is1)
    install date: 20070127
    install location: C:\Program Files\IObit\Advanced WindowsCare V2 Pro\
    uninstall cmd: "C:\Program Files\IObit\Advanced WindowsCare V2 Pro\unins000.exe"
    publisher: IObit
    help link: http://www.iobit.com

    Ashampoo WinOptimizer Platinum 3 (Ashampoo WinOptimizer Platinum 3)
    uninstall cmd: "C:\Program Files\Ashampoo\Ashampoo WinOptimizer Platinum 3\Uninstall\WOP3_Uninstall.exe"
    publisher: ashampoo GmbH & Co. KG

    AVG 7.5 (AVG7Uninstall)
    uninstall cmd: C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL

    AVG Anti-Spyware 7.5 (AVGAntiSpyware75)
    install location: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5
    uninstall cmd: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
    publisher: Grisoft Ltd.
    help link: http://www.grisoft.com

    AviSynth 2.5 (AviSynth)
    uninstall cmd: "C:\Program Files\AviSynth 2.5\Uninstall.exe"

    AVS Video Tools 5.1 (AVS Video Tools 5.1_is1)
    install location: C:\Program Files\AVSMedia\VideoTools\
    uninstall cmd: "C:\Program Files\AVSMedia\VideoTools\unins000.exe"
    publisher: Online Media Technologies Ltd.
    help link: http://www.avsmedia.com/support/index.aspx

    AVS Disc Creator version 2.1 (AVSDiscCreator_is1)
    install location: C:\Program Files\AVSMedia\DiscCreator\
    uninstall cmd: "C:\Program Files\AVSMedia\DiscCreator\unins000.exe"
    publisher: Online Media Technologies Ltd.
    help link: http://www.avsmedia.com/support/index.aspx

    BitComet 0.84 0.84 (BitComet)
    uninstall cmd: C:\Program Files\BitComet\uninst.exe
    publisher: ~RnySmile~

    (Branding)

    CCleaner (remove only) (CCleaner)
    uninstall cmd: "C:\Program Files\CCleaner\uninst.exe"

    (Connection Manager)

    CopyPod (remove only) (CopyPod)
    uninstall cmd: "C:\Program Files\CopyPod\uninstall.exe"

    (DirectAnimation)

    (DirectDrawEx)

    Disk Cleaner (remove only) (DiskCleaner)
    uninstall cmd: "C:\Program Files\Disk Cleaner\uninstall.exe"

    DivX Content Uploader 1.1.0 (DivX Content Uploader)
    install location: C:\Program Files\DivX
    uninstall cmd: C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
    publisher: DivX, Inc.

    (DXM_Runtime)

    (Fontcore)

    HijackThis 1.99.1 1.99.1 (HijackThis)
    uninstall cmd: C:\Documents and Settings\Wizard\Local Settings\Temporary Internet Files\Content.IE5\S10921BF\HijackThis.exe /uninstall
    publisher: Soeperman Enterprises Ltd.

    (ICW)

    Microsoft Internationalized Domain Names Mitigation APIs (IDNMitigationAPIs)
    install date: 20061214
    uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAP Is$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation

    (IE40)

    (IE4Data)

    (IE5BAKEX)

    Windows Internet Explorer 7 20061107.210142 (ie7)
    install date: 20070125
    uninstall cmd: "C:\WINDOWS\ie7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://www.microsoft.com/ie

    (IEData)

    (InstallShield Uninstall Information)

    IObit SmartDefrag Beta 2.01 (IObit SmartDefrag Beta 2.01_is1)
    install date: 20070127
    install location: C:\Program Files\IObit\IObit SmartDefrag\
    uninstall cmd: "C:\Program Files\IObit\IObit SmartDefrag\unins000.exe"
    publisher: IObit
    help link: http://www.iobit.com

    Windows XP Hotfix - KB873339 20041117.092459 (KB873339)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst .exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=873339

    (KB884016)

    (KB884267)

    (KB885353)

    Windows XP Hotfix - KB885835 20041027.181713 (KB885835)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst .exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=885835

    Windows XP Hotfix - KB885836 20041028.173203 (KB885836)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst .exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=885836

    Windows XP Hotfix - KB885884 20040924.025457 (KB885884)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst .exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=885884

    Windows XP Hotfix - KB886185 20041021.090540 (KB886185)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst .exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=886185

    (KB886612)

    (KB887078)

    Windows XP Hotfix - KB887472 20041014.162858 (KB887472)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst .exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=887472

    (KB887626)

    Windows XP Hotfix - KB888302 20041207.111426 (KB888302)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst .exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=888302

    (KB888656)

    (KB889858)

    Windows XP Hotfix - KB890859 1 (KB890859)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=890859

    Windows Media Format SDK Hotfix - KB891122 (KB891122)
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB891122$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=891122

    Windows XP Hotfix - KB891781 20050110.165439 (KB891781)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst .exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=891781

    (KB892313)

    (KB893240)

    (KB893241)

    Security Update for Windows XP (KB893756) 1 (KB893756)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=893756

    (KB893803)

    Windows Installer 3.1 (KB893803) 3.1 (KB893803v2)
    uninstall cmd: "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\s puninst.exe"
    publisher: Microsoft Corporation
    help link: http://go.microsoft.com/fwlink/?LinkId=42467

    Update for Windows XP (KB894391) 1 (KB894391)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=894391

    (KB895181)

    (KB895316)

    (KB895572)

    Hotfix for Windows XP (KB896344) 2 (KB896344)
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896344$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896344

    Security Update for Windows XP (KB896358) 1 (KB896358)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896358

    Security Update for Windows XP (KB896423) 1 (KB896423)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896423

    Security Update for Windows XP (KB896424) 1 (KB896424)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896424$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896424

    Security Update for Windows XP (KB896428) 1 (KB896428)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896428

    (KB897586)

    Update for Windows XP (KB898461) 1 (KB898461)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=898461

    (KB898549)

    Security Update for Windows XP (KB899587) 1 (KB899587)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=899587

    Security Update for Windows XP (KB899591) 1 (KB899591)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=899591

    (KB900399)

    Update for Windows XP (KB900485) 2 (KB900485)
    install date: 20061210
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=900485

    Security Update for Windows XP (KB900725) 1 (KB900725)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=900725

    Security Update for Windows XP (KB901017) 1 (KB901017)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=901017

    Security Update for Windows XP (KB901214) 1 (KB901214)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=901214

    (KB902344)

    Security Update for Windows XP (KB902400) 1 (KB902400)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=902400

    Security Update for Windows XP (KB904706) 2 (KB904706)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=904706

    Update for Windows XP (KB904942) 2 (KB904942)
    install date: 20061210
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB904942$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=904942

    Security Update for Windows XP (KB905414) 1 (KB905414)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=905414

    Security Update for Windows XP (KB905749) 1 (KB905749)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=905749

    (KB907658)

    Security Update for Windows XP (KB908519) 1 (KB908519)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=908519

    Update for Windows XP (KB908531) 2 (KB908531)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=908531

    Microsoft Base Smart Card Cryptographic Service Provider Package (KB909520)
    uninstall cmd: "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst .exe"
    publisher: Microsoft Corporation

    Update for Windows XP (KB910437) 1 (KB910437)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=910437

    Update for Windows XP (KB911280) 2 (KB911280)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=911280

    Security Update for Windows XP (KB911562) 1 (KB911562)
    install date: 20061209
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=911562

    (KB911565)

    (KB911854)

    (KB915865)

    Security Update for Microsoft .NET Framework 2.0 (KB917283) 1 (KB917283.T1_1ToU93_1)
    uninstall cmd: C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {967B098A-042D-4367-BAC9-8BC11684174F} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/kb/917283

    Security Update for Windows XP (KB918118) 1 (KB918118)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=918118

    Security Update for Windows XP (KB920213) 1 (KB920213)
    install date: 20061210
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=920213

    Update for Windows XP (KB920342) 1 (KB920342)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB920342$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=920342

    Security Update for Microsoft .NET Framework 2.0 (KB922770) 1 (KB922770.T1_1ToU168_1)
    uninstall cmd: C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {0E92DD42-76F5-4EF2-B381-F9C1D72BE23D} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/kb/922770

    Security Update for Windows XP (KB923689) (KB923689)
    install date: 20061217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB923689$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=923689

    Security Update for Windows XP (KB923694) 1 (KB923694)
    install date: 20061217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB923694$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=923694

    Security Update for Windows XP (KB924667) 1 (KB924667)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=924667

    Security Update for Windows Media Player 6.4 (KB925398) (KB925398_WMP64)
    install date: 20061217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\s puninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=925398

    Update for Windows XP (KB925720) 1 (KB925720)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB925720$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=925720

    Update for Windows XP (KB925876) 1 (KB925876)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB925876$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=925876

    Hotfix for Windows XP (KB926239) 2 (KB926239)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB926239$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=926239

    Security Update for Windows XP (KB926255) 1 (KB926255)
    install date: 20061217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=926255

    Security Update for Windows XP (KB926436) 1 (KB926436)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=926436

    Security Update for Windows XP (KB927779) 1 (KB927779)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=927779

    Security Update for Windows XP (KB927802) 1 (KB927802)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=927802

    Security Update for Windows Internet Explorer 7 (KB928090) 20070117.120000 (KB928090-IE7)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=928090

    Security Update for Windows XP (KB928255) 1 (KB928255)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=928255

    Hotfix for Windows XP (KB928388) 1 (KB928388)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB928388$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=928388

    Security Update for Windows XP (KB928843) 1 (KB928843)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=928843

    Hotfix for Windows XP (KB929120) 1 (KB929120)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB929120$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=929120

    Update for Windows XP (KB929338) 1 (KB929338)
    install date: 20070314
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB929338$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=929338

    Hotfix for Windows Media Format 11 SDK (KB929399) (KB929399)
    install date: 20070314
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=929399

    Security Update for Windows Internet Explorer 7 (KB929969) 20061222.120000 (KB929969)
    install date: 20070125
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=929969

    Update for Windows XP (KB931836) 1 (KB931836)
    install date: 20070217
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB931836$\spuninst\spunins t.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=931836

    Microsoft .NET Framework 1.1 Hotfix (KB886903) (M886903)
    uninstall cmd: "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Upda tes\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Upda tes\M886903\M886903Uninstall.msp"

    MailFrontier Desktop 4.9.1.8203 (MailFrontier Desktop)
    uninstall cmd: C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\UNWISE.EXE C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\INSTMLF.LOG
    publisher: MailFrontier

    Maxthon2 Browser (remove only) (Maxthon2)
    uninstall cmd: C:\Program Files\Maxthon2\MaxthonUINST.exe

    Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033))
    uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\ RepairRedist.htm

    Microsoft .NET Framework 2.0 (Microsoft .NET Framework 2.0)
    install location: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\
    uninstall cmd: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Micr osoft .NET Framework 2.0\install.exe
    publisher: Microsoft Corporation
    help link: http://go.microsoft.com/fwlink/?LinkId=45396

    Microsoft .NET Framework 3.0 (Microsoft .NET Framework 3.0)
    install location: c:\WINDOWS\Microsoft.NET\Framework\v3.0\
    uninstall cmd: c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
    publisher: Microsoft Corporation
    help link: http://go.microsoft.com/fwlink/?LinkId=51019

    (Microsoft NetShow Player 2.0)

    mIRC 6.21 (mIRC)
    uninstall cmd: "C:\Program Files\mIRC\mirc.exe" -uninstall
    publisher: mIRC Co. Ltd.

    (MobileOptionPack)

    Mozilla Firefox (2.0.0.2) 2.0.0.2 (en-US) (Mozilla Firefox (2.0.0.2))
    install location: C:\Program Files\Mozilla Firefox
    uninstall cmd: C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    publisher: Mozilla
    comments: Mozilla Firefox

    (MPlayer2)

    Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spu ninst.exe"
    publisher: Microsoft Corporation
    help link: http://go.microsoft.com/fwlink/?LinkId=74087

    (MSI30-Beta1)

    (MSI30-Beta2)

    (MSI30-KB884016)

    (MSI30-RC1)

    (MSI30-RC2)

    (MSI30a-KB884016)

    (MSI31-Beta)

    (MSI31-RC1)

    (MsJavaVM)

    MySpaceIM (MySpaceIM)
    uninstall cmd: C:\Program Files\MySpace\IM\Uninstall.exe

    Nero 6 Ultra Edition (Nero - Burning Rom!UninstallKey)
    uninstall cmd: C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL

    Nero Digital (NeroVision!UninstallKey)
    uninstall cmd: C:\WINDOWS\UNNeroVision.exe /UNINSTALL

    (NetMeeting)

    (NLSDownlevelMapping)

    (OutlookExpress)

    Panda ActiveScan (Panda ActiveScan)
    uninstall cmd: C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
    publisher: Panda Software S.L.

    (PCHealth)
    uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf

    PSP Video 9 1.74 1.74 (PSP Video 9)
    uninstall cmd: C:\Program Files\pspvideo9\uninst.exe
    publisher: Videora Holdings

    (RealJukebox 1.0)
    uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

    RealPlayer (RealPlayer 6.0)
    uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

    Registry Mechanic 5.1 5.1 (Registry Mechanic_is1)
    install location: C:\Program Files\Registry Mechanic\
    uninstall cmd: "C:\Program Files\Registry Mechanic\unins000.exe"
    publisher: PC Tools Pty. Ltd.
    help link: http://www.pctools.com/registry-mechanic/support/

    SAMSUNG CDMA Modem Driver Set (SAMSUNG CDMA Modem)
    uninstall cmd: C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUnin stall.exe

    SAMSUNG Mobile USB Modem Software (SAMSUNG Mobile USB Modem)
    uninstall cmd: C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Unin stall.exe

    SAMSUNG Mobile USB Modem 1.0 Software (SAMSUNG Mobile USB Modem 1.0)
    uninstall cmd: C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Unins tall.exe

    (SchedulingAgent)

    (Shockwave)

    (ShockwaveFlash)

    Spybot - Search & Destroy 1.4 1.4 (Spybot - Search & Destroy_is1)
    install location: C:\Program Files\Spybot - Search & Destroy\
    uninstall cmd: "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    publisher: Safer Networking Limited

    µTorrent 1.6.1 (uTorrent)
    install location: C:\Program Files\uTorrent
    uninstall cmd: "C:\Program Files\uTorrent\uninstall.exe"

    SAMSUNG Mobile USB Modem ^^ (Vodafone 804SS USB driver)
    uninstall cmd: C:\WINDOWS\system32\Samsung_USB_Drivers\4\SSVDUnin stall.exe

    Windows Genuine Advantage Notifications (KB905474) 1.7.0017.0 (WgaNotify)
    install date: 20070310
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=905474

    Windows Imaging Component 3.0.0.0 (WIC)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe "
    publisher: Microsoft Corporation

    Windows Media Format 11 runtime (Windows Media Format Runtime)
    uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    help link: http://go.microsoft.com/fwlink/?LinkId=62768

    Windows Media Player 11 (Windows Media Player)
    uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall

    Windows XP Service Pack 2 20040803.231319 (Windows XP Service Pack)
    uninstall cmd: C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuni nst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=811113

    WinRAR archiver (WinRAR archiver)
    uninstall cmd: C:\Program Files\WinRAR\uninstall.exe

    Winwall (Winwall)
    uninstall cmd: C:\Program Files\Winwall\Uninstall.exe

    WinZip (WinZip)
    uninstall cmd: C:\PROGRA~1\WinZip\winzip32.exe /uninstall

    (WMCSetup)

    Windows Media Format 11 runtime (WMFDist11)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spunin st.exe"
    publisher: Microsoft Corporation
    help link: http:

    Windows Media Player 11 (wmp11)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.e xe"
    publisher: Microsoft Corporation
    help link: http:

    Microsoft User-Mode Driver Framework Feature Pack 1.0 (Wudf01000)
    install date: 20070207
    uninstall cmd: "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spunin st.exe"
    publisher: Microsoft Corporation
    comments: Build Number 5716

    XML Paper Specification Shared Components Pack 1.0 (XpsEPSC)
    install date: 20070207
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=test

    Yahoo! Toolbar (Yahoo! Companion)
    uninstall cmd: C:\PROGRA~1\Yahoo!\Common\unyt.exe

    Yahoo! Toolbar (Yahoo! Toolbar)

    ZoneAlarm 7.0.302.000 (ZoneAlarm)
    uninstall cmd: C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe
    publisher: Check Point, Inc
    help link: C:\Program Files\Zone Labs\ZoneAlarm\Help\zaclients.chm

    Zoom Player (remove only) (ZoomPlayer)
    uninstall cmd: "C:\Program Files\Zoom Player\uninstall.exe"

    Google Gmail Notifier ({0228e555-4f9c-4e35-a3ec-b109a192b4c2})
    uninstall cmd: "C:\Program Files\Google\Gmail Notifier\UninstallGmail.exe"
    publisher: Google Inc.
    help link: http://mail.google.com/support

    iLike 1.0.85 ({0C8A05E1-271B-49D3-AC55-37739048C658})
    version: 16777301
    version (major): 1
    estimated size: 2036
    install date: 20070225
    install source: C:\DOCUME~1\Wizard\LOCALS~1\Temp\
    uninstall cmd: MsiExec.exe /I{0C8A05E1-271B-49D3-AC55-37739048C658}
    publisher: iLike
    comments: iLike
    contact: iLike Inc.

    Microsoft .NET Framework 3.0 3.0.04506.30 ({15095BF3-A3D7-4DDF-B193-3A496881E003})
    version: 50336154
    version (major): 3
    estimated size: 16102
    install date: 20070207
    install location: c:\WINDOWS\Microsoft.NET\Framework\v3.0\
    uninstall cmd: MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
    publisher: Microsoft Corporation

    AutoUpdate 1.1 ({18D10072035C4515918F7E37EAFAACFC})
    install location: C:\Program Files\DivX

    Samsung PC Studio 3.0.0.60404 ({1967D67C-6F3F-4001-9644-BAC704F7EE84})
    version: 50331648
    version (major): 3
    estimated size: 2589
    install date: 20061217
    install location: C:\Program Files\Samsung\Samsung PC Studio 3\
    publisher: Samsung Electronics Co., Ltd.
    contact: Customer Support Department
    help link: http://www.samsungmobile.co.kr
    help telephone: 1-555-555-4505

    Google Talk (remove only) ({226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk)
    uninstall cmd: "C:\Program Files\Google\Google Talk\uninstall.exe"

    Windows Live Sign-in Assistant 4.000.249.1 ({22B3CC30-77B8-419C-AA4B-F571FDF5D66D})
    version: 67109113
    version (major): 4
    estimated size: 1112
    install date: 20061217
    uninstall cmd: MsiExec.exe /I{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}
    publisher: Microsoft Corporation

    Ahead Nero Burning Rom PlugIn Pack 2.0.2 by MadHacker2k4 2.0.2 ({2715D1D6-2B81-4DD5-A9DC-6EFF4D5E0993})
    version: 33554434
    install date: 20061217
    install location: C:\Program Files\GoldEsel\Ahead Nero Burning Rom PlugIn Pack 2.0.2 by MadHacker2k4
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\ 50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2715D1D6-2B81-4DD5-A9DC-6EFF4D5E0993}\setup.exe" -l0x7 -removeonly
    publisher: GoldEsel

    2.1.20060807 ({2CCBABCB-6427-4A55-B091-49864623C43F})
    version: 20060807
    version (major): 2
    version (minor): 1

    J2SE Runtime Environment 5.0 Update 9 1.5.0.90 ({3248F0A8-6813-11D6-A77B-00B0D0150090})
    version: 17104896
    version (major): 1
    version (minor): 5
    estimated size: 122833
    install date: 20061225
    install source: http://javadl.sun.com/webapps/downlo...windows-i586//
    uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
    publisher: Sun Microsystems, Inc.
    contact: http://java.com
    help link: http://java.com
    readme: C:\Program Files\Java\jre1.5.0_09\README.txt

    J2SE Runtime Environment 5.0 Update 10 1.5.0.100 ({3248F0A8-6813-11D6-A77B-00B0D0150100})
    version: 17104896
    version (major): 1
    version (minor): 5
    estimated size: 122989
    install date: 20061226
    install source: http://javadl.sun.com/webapps/downlo...windows-i586//
    uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
    publisher: Sun Microsystems, Inc.
    contact: http://java.com
    help link: http://java.com
    readme: C:\Program Files\Java\jre1.5.0_10\README.txt

    J2SE Runtime Environment 5.0 Update 11 1.5.0.110 ({3248F0A8-6813-11D6-A77B-00B0D0150110})
    version: 17104896
    version (major): 1
    version (minor): 5
    estimated size: 123326
    install date: 20070304
    install source: http://javadl.sun.com/webapps/downlo...windows-i586//
    uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
    publisher: Sun Microsystems, Inc.
    contact: http://java.com
    help link: http://java.com
    readme: C:\Program Files\Java\jre1.5.0_11\README.txt

    WebFldrs XP 9.50.6513 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227})
    version: 154278257
    version (major): 9
    version (minor): 50
    estimated size: 2492
    install date: 20061209
    install source: C:\WINDOWS\System32\
    publisher: Microsoft Corporation
    help link: http://www.microsoft.com/windows

    MSXML 4.0 SP2 (KB927978) 4.20.9841.0 ({37477865-A3F1-4772-AD43-AAFC6BCFF99F})
    version: 68429425
    version (major): 4
    version (minor): 20
    estimated size: 2625
    install date: 20061218
    uninstall cmd: MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/kb/927978

    Windows Communication Foundation 3.0.04506.30 ({491DD792-AD81-429C-9EB4-86DD3D22E333})
    version: 50336154
    version (major): 3
    estimated size: 90556
    install date: 20070207
    uninstall cmd: MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
    publisher: Microsoft Corporation

    MSXML 6.0 Parser (KB927977) 6.00.3890.0 ({5A710547-B58E-488B-828D-CA9A25A0533C})
    version: 100667186
    version (major): 6
    estimated size: 1332
    install date: 20070207
    uninstall cmd: MsiExec.exe /I{5A710547-B58E-488B-828D-CA9A25A0533C}
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/kb/927977

    QuickTime 7.1.5.120 ({5E863175-E85D-44A6-8968-82507D34AE7F})
    version: 117506053
    version (major): 7
    version (minor): 1
    estimated size: 72139
    install date: 20070307
    install location: C:\Program Files\QuickTime\
    install source: C:\DOCUME~1\Wizard\LOCALS~1\Temp\IXP290.TMP\
    uninstall cmd: MsiExec.exe /I{5E863175-E85D-44A6-8968-82507D34AE7F}
    publisher: Apple Computer, Inc.
    contact: AppleCare Support
    help link: http://www.apple.com/support/
    help telephone: 1-800-275-2273

    ({62369F2F77534556AEF4C58152E3BDE5})

    Adobe Flash Player 9 ActiveX 9.0.28.0 ({685A56F8-75B6-44AD-B3DA-FB0A3266B47C})
    version: 150994972
    version (major): 9
    estimated size: 2382
    install date: 20070322
    install location: C:\WINDOWS\system32\Macromed\Flash\
    install source: C:\Documents and Settings\Wizard\Desktop\
    uninstall cmd: MsiExec.exe /X{685A56F8-75B6-44AD-B3DA-FB0A3266B47C}
    publisher: Adobe Systems, Inc.
    help link: http://www.adobe.com/go/flashplayer_support/

    Microsoft .NET Framework 2.0 2.0.50727 ({7131646D-CD3C-40F4-97B9-CD9E4E6262EF})
    version: 33605159
    version (major): 2
    estimated size: 218792
    install date: 20070207
    publisher: Microsoft Corporation

    6.2.1 ({7585478E9D9B42108671C12F8714CEFE})
    install location: C:\Program Files\DivX
    uninstall cmd: C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
    publisher: DivX, Inc.

    DivX Codec 6.5.1 ({7B63B2922B174135AFC0E1377DD81EC2})
    install location: C:\Program Files\DivX
    uninstall cmd: C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
    publisher: DivX, Inc.

    Windows Workflow Foundation 3.0.4203.2 ({7D1B85BD-AA07-48B8-808D-67A4067FC6BD})
    version: 50335851
    version (major): 3
    estimated size: 18672
    install date: 20070207
    install location: c:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\
    uninstall cmd: MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
    publisher: Microsoft Corporation

    DivX Player 6.4.2 ({8ADFC4160D694100B5B8A22DE9DCABD9})
    install location: C:\Program Files\DivX
    uninstall cmd: C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
    publisher: DivXNetworks, Inc.

    Microsoft Office PowerPoint Viewer 2003 11.0.6458.0 ({90AF0409-6000-11D3-8CFE-0150048383C9})
    version: 184555834
    version (major): 11
    estimated size: 4107
    install date: 20061223
    install location: C:\Program Files\Microsoft Office\
    uninstall cmd: MsiExec.exe /X{90AF0409-6000-11D3-8CFE-0150048383C9}
    publisher: Microsoft Corporation
    help link: http://www.microsoft.com/support

    Microsoft Office XP Professional 10.0.6626.0 ({91110409-6000-11D3-8CFE-0050048383C9})
    version: 167778786
    version (major): 10
    estimated size: 661263
    install date: 20070217
    uninstall cmd: MsiExec.exe /I{91110409-6000-11D3-8CFE-0050048383C9}
    publisher: Microsoft Corporation
    help link: http://www.microsoft.com/support
    readme: C:\Program Files\Microsoft Office\Office10\1033\OFREAD10.HTM

    Apple Software Update 1.1.0.3 ({A260B422-70E1-41E2-957D-F76FA21266D5})
    version: 16842752
    version (major): 1
    version (minor): 1
    estimated size: 2472
    install date: 20070307
    install location: C:\Program Files\Apple Software Update\
    install source: C:\DOCUME~1\Wizard\LOCALS~1\Temp\IXP290.TMP\
    uninstall cmd: MsiExec.exe /I{A260B422-70E1-41E2-957D-F76FA21266D5}
    publisher: Apple Computer, Inc.
    contact: AppleCare Support
    help link: http://www.apple.com/support/
    help telephone: 1-800-275-2273

    iTunes 7.1.1.5 ({AB90749C-7422-4580-8A7A-66CC5E9E5F98})
    version: 117506049
    version (major): 7
    version (minor): 1
    estimated size: 51658
    install date: 20070318
    install location: C:\Program Files\iTunes\
    install source: C:\DOCUME~1\Wizard\LOCALS~1\Temp\IXP662.TMP\
    uninstall cmd: MsiExec.exe /I{AB90749C-7422-4580-8A7A-66CC5E9E5F98}
    publisher: Apple Inc.
    contact: AppleCare Support
    help link: http://www.apple.com/support/
    help telephone: 1-800-275-2273

    Adobe Reader 7.0.9 7.0.9 ({AC76BA86-7AD7-1033-7B44-A70900000002})
    version: 117440521
    version (major): 7
    estimated size: 66695
    install date: 20070219
    install source: C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig709\ENU\
    uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
    publisher: Adobe Systems Incorporated
    comments:
    contact:
    help link: http://www.adobe.com/support/main.html
    help telephone:
    readme: C:\Program Files\Adobe\Acrobat 7.0\Reader\Readme.htm

    DivX Converter 6.2.1 ({B13A7C41581B411290FBC0395694E2A9})
    install location: C:\Program Files\DivX
    uninstall cmd: C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
    publisher: DivX, Inc.

    Polar WebLink 2.3.4 02.34.0000 ({B23A4F08-8355-42BA-B0CA-C5F22FE470A6})
    version: 35782656
    version (major): 2
    version (minor): 34
    estimated size: 6917
    install date: 20070124
    install source: C:\WINDOWS\Downloaded Installations\{7B722B83-5B80-4F7B-8CFC-57B2839A67BA}\
    uninstall cmd: MsiExec.exe /X{B23A4F08-8355-42BA-B0CA-C5F22FE470A6}
    publisher: Polar Electro Oy
    contact: Customer Support Department
    help link: http://support.polar.fi/
    help telephone: 358 - 8 - 5202 100

    DivX Web Player 1.3.0 ({B7050CBDB2504B34BC2A9CA0A692CC29})
    install location: C:\Program Files\DivX
    uninstall cmd: C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    publisher: DivX,Inc.

    Windows Presentation Foundation 3.0.6920.0 ({BAF78226-3200-4DB4-BE33-4D922A799840})
    version: 50338568
    version (major): 3
    estimated size: 117877
    install date: 20070207
    uninstall cmd: MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
    publisher: Microsoft Corporation

    Samsung PC Studio 3.1.0.60706 ({C4A4722E-79F9-417C-BD72-8D359A090C97})
    version: 50331648
    install date: 20061217
    install location: C:\Program Files\Samsung\Samsung PC Studio 3\
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\ 50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x9 -removeonly
    publisher: Samsung Electronics Co., Ltd.
    comments: Samsung PC Studio 3 Maintenance
    contact: Samsung Electronics Co., Ltd.
    help link: http://www.samsungmobile.co.kr
    help telephone: +82 2051 4151

    Microsoft .NET Framework 1.1 1.1.4322 ({CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1})
    version: 16847074
    version (major): 1
    version (minor): 1
    estimated size: 59893
    install date: 20070301
    uninstall cmd: MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    publisher: Microsoft
    readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\ RepairRedist.htm

    TomTom HOME 1.5.032 ({CE325D55-FCAF-4273-BB79-069BB8747270})
    version: 17104928
    install date: 20070206
    install location: C:\Program Files\TomTom HOME
    uninstall cmd: C:\Program Files\InstallShield Installation Information\{CE325D55-FCAF-4273-BB79-069BB8747270}\setup.exe -runfromtemp -l0x0009 -removeonly -removeonly
    publisher: TomTom
    help link: http://www.tomtom.com/support/

    V-Gear TalkCam Pro ({D7B0A31D-4F69-497E-8210-CF71A3BC1BF2})
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D7B0A31D-4F69-497E-8210-CF71A3BC1BF2}\Setup.exe"

    Samsung PC Studio 3 USB Driver Installer 1.00.0000 ({EBA29752-DDD2-4B62-B2E3-9841F92A3E3A})
    version: 16777216
    install date: 20061217
    install location: C:\Program Files\Samsung\Samsung PC Studio 3
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\ 50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x9 -removeonly
    publisher: Samsung Electronics Co., Ltd.
    comments: Samsung PC Studio 3 Maintenance
    contact: Samsung Electronics Co., Ltd.
    help link: http://www.samsungmobile.co.kr
    help telephone: +82 2051 4151

    Sony PSP Media Manager 1.0 1.0.172 ({ECB74828-944D-473A-BF6E-FBF596166815})
    version: 16777388
    version (major): 1
    estimated size: 47143
    install date: 20070228
    install source: C:\Program Files\Sony Setup\PSP Media Manager 1.0\
    uninstall cmd: MsiExec.exe /X{ECB74828-944D-473A-BF6E-FBF596166815}
    publisher: Sony
    help link: http://mediasoftware.sonypictures.com/support

    SoundMAX ({F0A37341-D692-11D4-A984-009027EC0A9C})
    install location: C:\Program Files\Analog Devices\SoundMAX
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"

    Polar UpLink Tool 1.60.0 ({F996DEB7-4AD7-4F15-84AA-114B8BE45911})
    version: 20709376
    version (major): 1
    version (minor): 60
    estimated size: 2940
    install date: 20070124
    install location: C:\Program Files\Polar\Polar UpLink Tool\
    install source: C:\WINDOWS\Downloaded Installations\{AF3A4721-1086-489E-8CF2-B57CF0AFA201}\
    uninstall cmd: MsiExec.exe /X{F996DEB7-4AD7-4F15-84AA-114B8BE45911}
    publisher: Polar Electro Oy

    Windows Live Messenger 8.0.0812.00 ({FCE50DB8-C610-4C42-BE5C-193F46C6F812})
    version: 134218540
    version (major): 8
    estimated size: 28205
    install date: 20061217
    uninstall cmd: MsiExec.exe /I{FCE50DB8-C610-4C42-BE5C-193F46C6F812}
    publisher: Microsoft Corporation

    Belkin 54g USB Network Adapter ({FF20F6D2-28E0-43FF-8A49-E69D07B12224})
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\Belkin\Belkin Wireless Network Utility\setup.exe" -l0x9



    --- System Services ---
    Service (registry key): .NET CLR Data
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): .NET CLR Networking
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): .NET Data Provider for Oracle
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): .NET Data Provider for SqlServer
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): .NETFramework
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Abiosdsk
    Start: 4
    Type: 1
    Error Control: 0

    Service (registry key): abp480n5
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ACPI
    Display name: Microsoft ACPI Driver
    Image path: System32\DRIVERS\ACPI.sys
    Image size: 187776
    Image MD5: A10C7534F7223F4A73A948967D00E69B
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): ACPIEC
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): adpu160m
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): aeaudio
    Image path: system32\drivers\aeaudio.sys
    Image size: 100224
    Image MD5: E696E749BEDCDA8B23757B8B5EA93780
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): aec
    Display name: Microsoft Kernel Acoustic Echo Canceller
    Image path: system32\drivers\aec.sys
    Image size: 142464
    Image MD5: 1EE7B434BA961EF845DE136224C30FEC
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): AegisP
    Display name: AEGIS Protocol (IEEE 802.1x) v3.0.0.5
    Description: AEGIS Protocol (IEEE 802.1x) v3.0.0.5
    Image path: system32\DRIVERS\AegisP.sys
    Image size: 15939
    Image MD5: 4B66E250C94C92522C33A759D5D273CB
    Start: 2
    Type: 1
    Error Control: 1

    Service (registry key): AFD
    Display name: AFD Networking Support Environment
    Description: AFD Networking Support Environment
    Image path: \SystemRoot\System32\drivers\afd.sys
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): agp440
    Display name: Intel AGP Bus Filter
    Image path: System32\DRIVERS\agp440.sys
    Image size: 42368
    Image MD5: 2C428FA0C3E3A01ED93C9B2A27D8D4BB
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): Aha154x
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): aic78u2
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): aic78xx
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Alerter
    Display name: Alerter
    Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: LanmanWorkstation

    Service (registry key): ALG
    Display name: Application Layer Gateway Service
    Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\alg.exe
    Image size: 44544
    Image MD5: F1958FBF86D5C004CF19A5951A9514B7
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): AliIde
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): amsint
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): AppMgmt
    Display name: Application Management
    Description: Provides software installation services such as Assign, Publish, and Remove.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1

    Service (registry key): asc
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): asc3350p
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): asc3550
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ASP.NET
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): ASP.NET_1.1.4322
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): ASP.NET_2.0.50727
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): aspnet_state
    Display name: ASP.NET State Service
    Description: Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\as pnet_state.exe
    Image size: 29896
    Image MD5: D33C507942299753868204CC7642FA27
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): AsyncMac
    Display name: RAS Asynchronous Media Driver
    Description: RAS Asynchronous Media Driver
    Image path: System32\DRIVERS\asyncmac.sys
    Image size: 14336
    Image MD5: 02000ABF34AF4C218C35D257024807D6
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): atapi
    Display name: Standard IDE/ESDI Hard Disk Controller
    Image path: System32\DRIVERS\atapi.sys
    Image size: 95360
    Image MD5: CDFE4411A69C224BD1D11B2DA92DAC51
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): Atdisk
    Start: 4
    Type: 1
    Error Control: 0

    Service (registry key): Atmarpc
    Display name: ATM ARP Client Protocol
    Description: ATM ARP Client Protocol
    Image path: System32\DRIVERS\atmarpc.sys
    Image size: 59904
    Image MD5: EC88DA854AB7D7752EC8BE11A741BB7F
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): AudioSrv
    Display name: Windows Audio
    Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: PlugPlay,RpcSs

    Service (registry key): audstub
    Display name: Audio Stub Driver
    Image path: System32\DRIVERS\audstub.sys
    Image size: 3072
    Image MD5: D9F724AA26C010A217C97606B160ED68
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): AVG Anti-Spyware Driver
    Display name: AVG Anti-Spyware Driver
    Image path: \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
    Image size: 4096
    Image MD5: 7D78B7FD0EBE00F177B053A08C78E35B
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): AVG Anti-Spyware Guard
    Display name: AVG Anti-Spyware Guard
    Object name: LocalSystem
    Image path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    Image size: 204800
    Image MD5: E8FBDCC8D618D1BB84B828F247A6244B
    Start: 2
    Type: 16
    Error Control: 1

    Service (registry key): Avg7Alrt
    Display name: AVG7 Alert Manager Server
    Object name: LocalSystem
    Image path: C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    Image size: 353792
    Image MD5: 708D06E4285B5DB85876329ED672423B
    Start: 2
    Type: 272
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): Avg7Core
    Display name: AVG7 Kernel
    Image path: \SystemRoot\System32\Drivers\avg7core.sys
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Avg7RsW
    Display name: AVG7 Wrap Driver
    Image path: \SystemRoot\System32\Drivers\avg7rsw.sys
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Avg7RsXP
    Display name: AVG7 Resident Driver XP
    Image path: \SystemRoot\System32\Drivers\avg7rsxp.sys
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Avg7UpdSvc
    Display name: AVG7 Update Service
    Object name: LocalSystem
    Image path: C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    Image size: 49664
    Image MD5: 30A14F65DB477DC00A64A5A24E96919C
    Start: 2
    Type: 16
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): AvgAsCln
    Display name: AVG Anti-Spyware Clean Driver
    Image path: System32\DRIVERS\AvgAsCln.sys
    Image size: 3968
    Image MD5: 6D4A1DA6E6D522B3EBBCBFF4A3589EC5
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): AvgClean
    Display name: AVG7 Clean Driver
    Image path: \SystemRoot\System32\Drivers\avgclean.sys
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): BattC
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Beep
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Belkin 54g Wireless USB Network Adapter Service
    Display name: Belkin 54g Wireless USB Network Adapter
    Description: Wireless LAN Service
    Object name: LocalSystem
    Image path: C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    Image size: 49152
    Image MD5: EE684C735B6D1D07498A1EC2EA1AE483
    Start: 2
    Type: 272
    Error Control: 1

    Service (registry key): BITS
    Display name: Background Intelligent Transfer Service
    Description: Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: Rpcss

    Service (registry key): bkn50USB
    Display name: Belkin 54Mbps Wireless USB Network Adapter
    Image path: system32\DRIVERS\rt2500usb.sys
    Image size: 140416
    Image MD5: 6D39682A1051A5BE7437EC99F1BF9921
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Browser
    Display name: Computer Browser
    Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: LanmanWorkstation,LanmanServer

    Service (registry key): cbidf2k
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): CCDECODE
    Display name: Closed Caption Decoder
    Image path: system32\DRIVERS\CCDECODE.sys
    Image size: 17024
    Image MD5: 6163ED60B684BAB19D3352AB22FC48B2
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): cd20xrnt
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Cdaudio
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): Cdfs
    Start: 4
    Type: 2
    Error Control: 1
    Depends On group: "SCSI CDROM Class"

    Service (registry key): Cdrom
    Display name: CD-ROM Driver
    Image path: System32\DRIVERS\cdrom.sys
    Image size: 49536
    Image MD5: AF9C19B3100FE010496B1A27181FBF72
    Start: 1
    Type: 1
    Error Control: 1
    Depends On group: "SCSI miniport"

    Service (registry key): Changer
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): CiSvc
    Display name: Indexing Service
    Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\cisvc.exe
    Image size: 5632
    Image MD5: 3192BD04D032A9C4A85A3278C268A13A
    Start: 3
    Type: 288
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): ClipSrv
    Display name: ClipBook
    Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\clipsrv.exe
    Image size: 33280
    Image MD5: C8DEC22C4137D7A90F8BDF41CA4B82AE
    Start: 4
    Type: 16
    Error Control: 1
    Depends On services: NetDDE

    Service (registry key): clr_optimization_v2.0.50727_32
    Display name: .NET Runtime Optimization Service v2.0.50727_X86
    Description: Microsoft .NET Framework NGEN
    Object name: LocalSystem
    Image path: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe
    Image size: 66240
    Image MD5: 3C4D595E7F9B747325AEF28B4ADCAAE5
    Start: 3
    Type: 16
    Error Control: 0

    Service (registry key): CmdIde
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): COMSysApp
    Display name: COM+ System Application
    Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    Image size: 5120
    Image MD5: DD87DB7387B9EB441C5674888A0D840C
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: rpcss

    Service (registry key): ContentFilter
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): ContentIndex
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Cpqarray
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): CryptSvc
    Display name: Cryptographic Services
    Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): CscService
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): dac2w2k
    Start: 4
    Type: 1
    Error Control: 0

    Service (registry key): dac960nt
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): DCamUSBEMPIA
    Display name: V-Gear TalkCam Pro
    Image path: system32\DRIVERS\emDevice.sys
    Image size: 110653
    Image MD5: 4273955F3AA1EAF22351417A238DB095
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): DcomLaunch
    Display name: DCOM Server Process Launcher
    Description: Provides launch functionality for DCOM services.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost -k DcomLaunch
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): Dhcp
    Display name: DHCP Client
    Description: Manages network configuration by registering and updating IP addresses and DNS names.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: Tcpip,Afd,NetBT

    Service (registry key): Disk
    Display name: Disk Driver
    Image path: System32\DRIVERS\disk.sys
    Image size: 36352
    Image MD5: 00CA44E4534865F8A3B64F7C0984BFF0
    Start: 0
    Type: 1
    Error Control: 1
    Depends On group: "SCSI miniport"

    Service (registry key): dmadmin
    Display name: Logical Disk Manager Administrative Service
    Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\dmadmin.exe /com
    Image size: 224768
    Image MD5: 554C7CB178FE3BD12450B81AD63ADBC3
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs,PlugPlay,DmServer

    Service (registry key): dmboot
    Image path: System32\drivers\dmboot.sys
    Image size: 799744
    Image MD5: C0FBB516E06E243F0CF31F597E7EBF7D
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): dmio
    Display name: Logical Disk Manager Driver
    Image path: System32\drivers\dmio.sys
    Image size: 153344
    Image MD5: F5E7B358A732D09F4BCF2824B88B9E28
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): dmload
    Image path: System32\drivers\dmload.sys
    Image size: 5888
    Image MD5: E9317282A63CA4D188C0DF5E09C6AC5F
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): dmserver
    Display name: Logical Disk Manager
    Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs,PlugPlay

    Service (registry key): DMusic
    Display name: Microsoft Kernel DLS Syntheiszer
    Image path: system32\drivers\DMusic.sys
    Image size: 52864
    Image MD5: A6F881284AC1150E37D9AE47FF601267
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Dnscache
    Display name: DNS Client
    Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\System32\svchost.exe -k NetworkService
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): dpti2o
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): drmkaud
    Display name: Microsoft Kernel DRM Audio Descrambler
    Image path: system32\drivers\drmkaud.sys
    Image size: 2944
    Image MD5: 1ED4DBBAE9F5D558DBBA4CC450E3EB2E
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): emAudio
    Display name: USB Audio Device
    Image path: system32\drivers\emAudio.sys
    Image size: 20608
    Image MD5: 8BFF3EF6F480B2BA00C0AF75B2C8FCE1
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): ERSvc
    Display name: Error Reporting Service
    Description: Allows error reporting for services and applictions running in non-standard environments.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 4
    Type: 32
    Error Control: 0
    Depends On services: RpcSs

    Service (registry key): Eventlog
    Display name: Event Log
    Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\services.exe
    Image size: 108032
    Image MD5: C6CE6EEC82F187615D1002BB3BB50ED4
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): EventSystem
    Display name: COM+ Event System
    Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): Fastfat
    Start: 4
    Type: 2
    Error Control: 1

    Service (registry key): FastUserSwitchingCompatibility
    Display name: Fast User Switching Compatibility
    Description: Provides management for applications that require assistance in a multiple user environment.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: TermService

    Service (registry key): Fdc
    Display name: Floppy Disk Controller Driver
    Image path: System32\DRIVERS\fdc.sys
    Image size: 27392
    Image MD5: CED2E8396A8838E59D8FD529C680E02C
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): FiltUSBEMPIA
    Display name: USB Device Lower Filter
    Image path: system32\DRIVERS\emFilter.sys
    Image size: 79339
    Image MD5: B1A4E679F6D5AEC1ECD8A9FCE789A1E3
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Fips
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): Flpydisk
    Display name: Floppy Disk Driver
    Image path: System32\DRIVERS\flpydisk.sys
    Image size: 20480
    Image MD5: 0DD1DE43115B93F4D85E889D7A86F548
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): FltMgr
    Display name: FltMgr
    Description: File System Filter Manager Driver
    Image path: system32\drivers\fltmgr.sys
    Image size: 128896
    Image MD5: 3D234FB6D6EE875EB009864A299BEA29
    Start: 0
    Type: 2
    Error Control: 1

    Service (registry key): FontCache3.0.0.0
    Display name: Windows Presentation Foundation Font Cache 3.0.0.0
    Description: Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.
    Object name: NT AUTHORITY\LocalService
    Image path: c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\Presen tationFontCache.exe
    Image size: 36864
    Image MD5: FACECF3F75BAF3775A879D1168402270
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): Fs_Rec
    Start: 1
    Type: 8
    Error Control: 0

    Service (registry key): Ftdisk
    Display name: Volume Manager Driver
    Image path: System32\DRIVERS\ftdisk.sys
    Image size: 125056
    Image MD5: 6AC26732762483366C3969C9E4D2259D
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): GEARAspiWDM
    Display name: GEARAspiWDM
    Image path: System32\Drivers\GEARAspiWDM.sys
    Image size: 15664
    Image MD5: 4AC51459805264AFFD5F6FDFB9D9235F
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Gpc
    Display name: Generic Packet Classifier
    Description: Generic Packet Classifier
    Image path: System32\DRIVERS\msgpc.sys
    Image size: 35072
    Image MD5: C0F1D4A21DE5A415DF8170616703DEBF
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): GTNDIS5
    Display name: GTNDIS5 NDIS Protocol Driver
    Image path: \??\C:\WINDOWS\system32\GTNDIS5.SYS
    Image size: 15872
    Image MD5: FC80052194D5708254A346568F0E77C0
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): helpsvc
    Display name: Help and Support
    Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): HidServ
    Display name: HID Input Service
    Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): hidusb
    Display name: Microsoft HID Class Driver
    Image path: System32\DRIVERS\hidusb.sys
    Image size: 9600
    Image MD5: 1DE6783B918F540149AA69943BDFEBA8
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): hpn
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): HTTP
    Display name: HTTP
    Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start.
    Image path: System32\Drivers\HTTP.sys
    Image size: 262784
    Image MD5: CB77BB47E67E84DEB17BA29632501730
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): HTTPFilter
    Display name: HTTP SSL
    Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: HTTP

    Service (registry key): i2omgmt
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): i2omp
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): i8042prt
    Display name: i8042 Keyboard and PS/2 Mouse Port Driver
    Image path: System32\DRIVERS\i8042prt.sys
    Image size: 52736
    Image MD5: 5502B58EEF7486EE6F93F3F164DCB808
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): idsvc
    Display name: Windows CardSpace
    Description: Securely enables the creation, management, and disclosure of digital identities.
    Object name: LocalSystem
    Image path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windo ws Communication Foundation\infocard.exe"
    Image size: 741376
    Image MD5: EA7267505149B3A10DF32506A4E4E412
    Start: 3
    Type: 32
    Error Control: 1

    Service (registry key): IKEEXT
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Imapi
    Display name: CD-Burning Filter Driver
    Image path: System32\DRIVERS\imapi.sys
    Image size: 41856
    Image MD5: F8AA320C6A0409C0380E5D8A99D76EC6
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): ImapiService
    Display name: IMAPI CD-Burning COM Service
    Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\System32\imapi.exe
    Image size: 150016
    Image MD5: FA788520BCAC0F5D9D5CDE5615C0D931
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): inetaccs
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): ini910u
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Inport
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): IntelIde
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): intelppm
    Display name: Intel Processor Driver
    Image path: System32\DRIVERS\intelppm.sys
    Image size: 36096
    Image MD5: 279FB78702454DFF2BB445F238C048D2
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): ip6fw
    Display name: IPv6 Windows Firewall Driver
    Description: Provides intrusion prevention service for a home or small office network.
    Image path: system32\drivers\ip6fw.sys
    Image size: 29056
    Image MD5: 4448006B6BC60E6C027932CFC38D6855
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): IpFilterDriver
    Display name: IP Traffic Filter Driver
    Description: IP Traffic Filter Driver
    Image path: System32\DRIVERS\ipfltdrv.sys
    Image size: 32896
    Image MD5: 731F22BA402EE4B62748ADAF6363C182
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): IpInIp
    Display name: IP in IP Tunnel Driver
    Description: IP in IP Tunnel Driver
    Image path: System32\DRIVERS\ipinip.sys
    Image size: 20992
    Image MD5: E1EC7F5DA720B640CD8FB8424F1B14BB
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): IpNat
    Display name: IP Network Address Translator
    Description: IP Network Address Translator
    Image path: System32\DRIVERS\ipnat.sys
    Image size: 134912
    Image MD5: E2168CBC7098FFE963C6F23F472A3593
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): iPod Service
    Display name: iPod Service
    Description: iPod hardware management services
    Object name: LocalSystem
    Image path: "C:\Program Files\iPod\bin\iPodService.exe"
    Image size: 500800
    Image MD5: 661194608009B558DE1925C7EBE1A4BA
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): IPSec
    Display name: IPSEC driver
    Description: IPSEC driver
    Image path: System32\DRIVERS\ipsec.sys
    Image size: 74752
    Image MD5: 64537AA5C003A6AFEEE1DF819062D0D1
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): IRENUM
    Display name: IR Enumerator Service
    Image path: System32\DRIVERS\irenum.sys
    Image size: 11264
    Image MD5: 50708DAA1B1CBB7D6AC1CF8F56A24410
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): ISAPISearch
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): isapnp
    Display name: PnP ISA/EISA Bus Driver
    Image path: System32\DRIVERS\isapnp.sys
    Image size: 35840
    Image MD5: E504F706CCB699C2596E9A3DA1596E87
    Start: 0
    Type: 1
    Error Control: 3

    Service (registry key): Kbdclass
    Display name: Keyboard Class Driver
    Image path: System32\DRIVERS\kbdclass.sys
    Image size: 24576
    Image MD5: EBDEE8A2EE5393890A1ACEE971C4C246
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): kbdhid
    Display name: Keyboard HID Driver
    Image path: System32\DRIVERS\kbdhid.sys
    Image size: 14848
    Image MD5: E182FA8E49E8EE41B4ADC53093F3C7E6
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): kl1
    Display name: kl1
    Image path: System32\Drivers\kl1.sys
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): kmixer
    Display name: Microsoft Kernel Wave Audio Mixer
    Image path: system32\drivers\kmixer.sys
    Image size: 172416
    Image MD5: BA5DEDA4D934E6288C2F66CAF58D2562
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): KSecDD
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): lanmanserver
    Display name: Server
    Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): lanmanworkstation
    Display name: Workstation
    Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): lbrtfdc
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): ldap
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): LicenseService
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): LmHosts
    Display name: TCP/IP NetBIOS Helper
    Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: NetBT,Afd

    Service (registry key): Mcx2Svc
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): MDM
    Display name: Machine Debug Manager
    Description: Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly.
    Object name: LocalSystem
    Image path: "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
    Image size: 322120
    Image MD5: 11F714F85530A2BD134074DC30E99FCA
    Start: 2
    Type: 272
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): Messenger
    Display name: Messenger
    Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS

    Service (registry key): mnmdd
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): mnmsrvc
    Display name: NetMeeting Remote Desktop Sharing
    Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\System32\mnmsrvc.exe
    Image size: 32768
    Image MD5: F6415361201915B9FE3896B0E4E724FF
    Start: 4
    Type: 272
    Error Control: 1

    Service (registry key): Modem
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): Mouclass
    Display name: Mouse Class Driver
    Image path: System32\DRIVERS\mouclass.sys
    Image size: 23040
    Image MD5: 34E1F0031153E491910E12551400192C
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): mouhid
    Display name: Mouse HID Driver
    Image path: System32\DRIVERS\mouhid.sys
    Image size: 12160
    Image MD5: B1C303E17FB9D46E87A98E4BA6769685
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): MountMgr
    Display name: Mount Point Manager
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): mraid35x
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): MRxDAV
    Display name: WebDav Client Redirector
    Description: WebDav Client Redirector
    Image path: System32\DRIVERS\mrxdav.sys
    Image size: 181248
    Image MD5: 46EDCC8F2DB2F322C24F48785CB46366
    Start: 3
    Type: 2
    Error Control: 1

    Service (registry key): MRxSmb
    Display name: MRXSMB
    Description: MRXSMB
    Image path: System32\DRIVERS\mrxsmb.sys
    Image size: 453120
    Image MD5: 025AF03CE51645C62F3B6907A7E2BE5E
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): MSDTC
    Display name: Distributed Transaction Coordinator
    Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\NetworkService
    Image path: C:\WINDOWS\System32\msdtc.exe
    Image size: 6144
    Image MD5: C7C3D89EB0A6F3DBA622EA737FA335B1
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RPCSS,SamSS

    Service (registry key): MSDTC Bridge 3.0.0.0
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Msfs
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): MSIServer
    Display name: Windows Installer
    Description: Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\msiexec.exe /V
    Image size: 78848
    Image MD5: F5F0146580E7023ADB963879840777F8
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): MSKSSRV
    Display name: Microsoft Streaming Service Proxy
    Image path: system32\drivers\MSKSSRV.sys
    Image size: 7552
    Image MD5: AE431A8DD3C1D0D0610CDBAC16057AD0
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): MSPCLOCK
    Display name: Microsoft Streaming Clock Proxy
    Image path: system32\drivers\MSPCLOCK.sys
    Image size: 5376
    Image MD5: 13E75FEF9DFEB08EEDED9D0246E1F448
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): MSPQM
    Display name: Microsoft Streaming Quality Manager Proxy
    Image path: system32\drivers\MSPQM.sys
    Image size: 4992
    Image MD5: 1988A33FF19242576C3D0EF9CE785DA7
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): mssmbios
    Display name: Microsoft System Management BIOS Driver
    Image path: System32\DRIVERS\mssmbios.sys
    Image size: 15488
    Image MD5: 469541F8BFD2B32659D5D463A6714BCE
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): MSTEE
    Display name: Microsoft Streaming Tee/Sink-to-Sink Converter
    Image path: system32\drivers\MSTEE.sys
    Image size: 5504
    Image MD5: BF13612142995096AB084F2DB7F40F77
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Mup
    Display name: Mup
    Start: 0
    Type: 2
    Error Control: 1

    Service (registry key): NABTSFEC
    Display name: NABTS/FEC VBI Codec
    Image path: System32\DRIVERS\NABTSFEC.sys
    Image size: 85376
    Image MD5: 5C8DC6429C43DC6177C1FA5B76290D1A
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NDIS
    Display name: NDIS System Driver
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): NdisIP
    Display name: Microsoft TV/Video Connection
    Image path: System32\DRIVERS\NdisIP.sys
    Image size: 10880
    Image MD5: 520CE427A8B298F54112857BCF6BDE15
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NdisTapi
    Display name: Remote Access NDIS TAPI Driver
    Description: Remote Access NDIS TAPI Driver
    Image path: System32\DRIVERS\ndistapi.sys
    Image size: 9600
    Image MD5: 08D43BBDACDF23F34D79E44ED35C1B4C
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Ndisuio
    Display name: NDIS Usermode I/O Protocol
    Description: NDIS Usermode I/O Protocol
    Image path: System32\DRIVERS\ndisuio.sys
    Image size: 12928
    Image MD5: 34D6CD56409DA9A7ED573E1C90A308BF
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NdisWan
    Display name: Remote Access NDIS WAN Driver
    Description: Remote Access NDIS WAN Driver
    Image path: System32\DRIVERS\ndiswan.sys
    Image size: 91776
    Image MD5: 0B90E255A9490166AB368CD55A529893
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NDProxy
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): NetBIOS
    Display name: NetBIOS Interface
    Description: NetBIOS Interface
    Image path: System32\DRIVERS\netbios.sys
    Image size: 34560
    Image MD5: 3A2ACA8FC1D7786902CA434998D7CEB4
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): NetBT
    Display name: NetBios over Tcpip
    Description: NetBios over Tcpip
    Image path: System32\DRIVERS\netbt.sys
    Image size: 162816
    Image MD5: 0C80E410CD2F47134407EE7DD19CC86B
    Start: 1
    Type: 1
    Error Control: 1
    Depends On services: Tcpip

    Service (registry key): NetDDE
    Display name: Network DDE
    Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\netdde.exe
    Image size: 111104
    Image MD5: 05AFB5AD06462257BEA7495283C86D50
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: NetDDEDSDM

    Service (registry key): NetDDEdsdm
    Display name: Network DDE DSDM
    Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\netdde.exe
    Image size: 111104
    Image MD5: 05AFB5AD06462257BEA7495283C86D50
    Start: 4
    Type: 32
    Error Control: 1

    Service (registry key): Netlogon
    Display name: Net Logon
    Description: Supports pass-through authentication of account logon events for computers in a domain.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\lsass.exe
    Image size: 13312
    Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: LanmanWorkstation

    Service (registry key): Netman
    Display name: Network Connections
    Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 288
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): NetTcpPortSharing
    Display name: Net.Tcp Port Sharing Service
    Description: Provides ability to share TCP ports over the net.tcp protocol.
    Object name: NT AUTHORITY\LocalService
    Image path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windo ws Communication Foundation\SMSvcHost.exe"
    Image size: 122880
    Image MD5: 8070BB07FE06DE8B9ACB29B07016A273
    Start: 4
    Type: 32
    Error Control: 1

    Service (registry key): Nla
    Display name: Network Location Awareness (NLA)
    Description: Collects and stores network configuration and location information, and notifies applications when this information changes.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: Tcpip,Afd

    Service (registry key): Npfs
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): Ntfs
    Start: 4
    Type: 2
    Error Control: 1

    Service (registry key): NtLmSsp
    Display name: NT LM Security Support Provider
    Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\lsass.exe
    Image size: 13312
    Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
    Start: 4
    Type: 32
    Error Control: 1

    Service (registry key): NtmsSvc
    Display name: Removable Storage
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): Null
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): nv
    Image path: System32\DRIVERS\nv4_mini.sys
    Image size: 1897408
    Image MD5: 2B298519EDBFCF451D43E0F1E8F1006D
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): NwlnkFlt
    Display name: IPX Traffic Filter Driver
    Description: IPX Traffic Filter Driver
    Image path: System32\DRIVERS\nwlnkflt.sys
    Image size: 12416
    Image MD5: B305F3FAD35083837EF46A0BBCE2FC57
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: NwlnkFwd

    Service (registry key): NwlnkFwd
    Display name: IPX Traffic Forwarder Driver
    Description: IPX Traffic Forwarder Driver
    Image path: System32\DRIVERS\nwlnkfwd.sys
    Image size: 32512
    Image MD5: C99B3415198D1AAB7227F2C88FD664B9
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): P3
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Parport
    Display name: Parallel port driver
    Image path: System32\DRIVERS\parport.sys
    Image size: 80128
    Image MD5: 29744EB4CE659DFE3B4122DEB45BC478
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): PartMgr
    Display name: Partition Manager
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): ParVdm
    Start: 2
    Type: 1
    Error Control: 0
    Depends On services: Parport
    Depends On group: "Parallel arbitrator"

    Service (registry key): PCI
    Display name: PCI Bus Driver
    Image path: System32\DRIVERS\pci.sys
    Image size: 68224
    Image MD5: 8086D9979234B603AD5BC2F5D890B234
    Start: 0
    Type: 1
    Error Control: 3

    Service (registry key): PCIDump
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): PCIIde
    Image path: System32\DRIVERS\pciide.sys
    Image size: 3328
    Image MD5: CCF5F451BB1A5A2A522A76E670000FF0
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): Pcmcia
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): PDCOMP
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): PDFRAME
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): PDRELI
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): PDRFRAME
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): perc2
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): perc2hib
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): PerfDisk
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): PerfNet
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): PerfOS
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): PerfProc
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): PlugPlay
    Display name: Plug and Play
    Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\services.exe
    Image size: 108032
    Image MD5: C6CE6EEC82F187615D1002BB3BB50ED4
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): PolicyAgent
    Display name: IPSEC Services
    Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\lsass.exe
    Image size: 13312
    Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RPCSS,Tcpip,IPSec

    Service (registry key): PptpMiniport
    Display name: WAN Miniport (PPTP)
    Description: WAN Miniport (PPTP)
    Image path: System32\DRIVERS\raspptp.sys
    Image size: 48384
    Image MD5: 1C5CC65AAC0783C344F16353E60B72AC
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Processor
    Display name: Processor Driver
    Image path: System32\DRIVERS\processr.sys
    Image size: 35328
    Image MD5: 0D97D88720A4087EC93AF7DBB303B30A
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): ProtectedStorage
    Display name: Protected Storage
    Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 13312
    Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
    Start: 2
    Type: 288
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): PSched
    Display name: QoS Packet Scheduler
    Description: QoS Packet Scheduler
    Image path: System32\DRIVERS\psched.sys
    Image size: 69120
    Image MD5: 48671F327553DCF1D27F6197F622A668
    Start: 3
    Type: 1
    Error Control: 1
    Depends On services: Gpc

    Service (registry key): Ptilink
    Display name: Direct Parallel Link Driver
    Description: Direct Parallel Link Driver
    Image path: System32\DRIVERS\ptilink.sys
    Image size: 17792
    Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): PxHelp20
    Image path: system32\DRIVERS\PxHelp20.sys
    Image size: 36624
    Image MD5: 1962166E0CEB740704F30FA55AD3D509
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): ql1080
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Ql10wnt
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ql12160
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ql1240
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): ql1280
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): RasAcd
    Display name: Remote Access Auto Connection Driver
    Description: Remote Access Auto Connection Driver
    Image path: System32\DRIVERS\rasacd.sys
    Image size: 8832
    Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): RasAuto
    Display name: Remote Access Auto Connection Manager
    Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RasMan,Tapisrv

    Service (registry key): Rasl2tp
    Display name: WAN Miniport (L2TP)
    Description: WAN Miniport (L2TP)
    Image path: System32\DRIVERS\rasl2tp.sys
    Image size: 51328
    Image MD5: 98FAEB4A4DCF812BA1C6FCA4AA3E115C
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): RasMan
    Display name: Remote Access Connection Manager
    Description: Creates a network connection.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: Tapisrv

    Service (registry key): RasPppoe
    Display name: Remote Access PPPOE Driver
    Description: Remote Access PPPOE Driver
    Image path: System32\DRIVERS\raspppoe.sys
    Image size: 41472
    Image MD5: 7306EEED8895454CBED4669BE9F79FAA
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Raspti
    Display name: Direct Parallel
    Description: Direct Parallel
    Image path: System32\DRIVERS\raspti.sys
    Image size: 16512
    Image MD5: FDBB1D60066FCFBB7452FD8F9829B242
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Rdbss
    Display name: Rdbss
    Description: Rdbss
    Image path: System32\DRIVERS\rdbss.sys
    Image size: 174592
    Image MD5: 03B965B1CA47F6EF60EB5E51CB50E0AF
    Start: 1
    Type: 2
    Error Control: 1

    Service (registry key): RDPCDD
    Image path: System32\DRIVERS\RDPCDD.sys
    Image size: 4224
    Image MD5: 4912D5B403614CE99C28420F75353332
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): RDPDD
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): rdpdr
    Display name: Terminal Server Device Redirector Driver
    Image path: System32\DRIVERS\rdpdr.sys
    Image size: 196864
    Image MD5: A2CAE2C60BC37E0751EF9DDA7CEAF4AD
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): RDPNP
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): RDPWD
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): RDSessMgr
    Display name: Remote Desktop Help Session Manager
    Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\sessmgr.exe
    Image size: 140800
    Image MD5: 729798E0933076B8FCFCD9934698F164
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): redbook
    Display name: Digital CD Audio Playback Filter Driver
    Image path: System32\DRIVERS\redbook.sys
    Image size: 57472
    Image MD5: B31B4588E4086D8D84ADBF9845C2402B
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): RemoteAccess
    Display name: Routing and Remote Access
    Description: Offers routing services to businesses in local area and wide area network environments.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSS
    Depends On group: NetBIOSGroup

    Service (registry key): RemoteRegistry
    Display name: Remote Registry
    Description: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): RpcLocator
    Display name: Remote Procedure Call (RPC) Locator
    Description: Manages the RPC name service database.
    Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\System32\locator.exe
    Image size: 75264
    Image MD5: 793F04A09B15E7C6C11DBDFFAF06C0AB
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: LanmanWorkstation

    Service (registry key): RpcSs
    Display name: Remote Procedure Call (RPC)
    Description: Provides the endpoint mapper and other miscellaneous RPC services.
    Object name: NT Authority\NetworkService
    Image path: %SystemRoot%\system32\svchost -k rpcss
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): RSVP
    Display name: QoS RSVP
    Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\rsvp.exe
    Image size: 132608
    Image MD5: 471B3F9741D762ABE75E9DEEA4787E47
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: TcpIp,Afd,RpcSs

    Service (registry key): SamSs
    Display name: Security Accounts Manager
    Description: Stores security information for local user accounts.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 13312
    Image MD5: 84885F9B82F4D55C6146EBF6065D75D2
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): ScanUSBEMPIA
    Display name: USB Still Image Capture Device
    Image path: system32\DRIVERS\emScan.sys
    Image size: 4857
    Image MD5: F3CD3709919A453AC84C290DCEEB767C
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): SCardDrv
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): SCardSvr
    Display name: Smart Card
    Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\SCardSvr.exe
    Image size: 95744
    Image MD5: 25D8DE134DF108E3DBC8D7D23B1AA58E
    Start: 3
    Type: 32
    Error Control: 0
    Depends On services: PlugPlay

    Service (registry key): Schedule
    Display name: Task Scheduler
    Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 288
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): ScsiPort
    Image path: %SystemRoot%\system32\drivers\scsiport.sys
    Image size: 96256
    Image MD5: D7FD0FF761E28AC0EA35AD71E0CD67E9
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Secdrv
    Display name: Secdrv
    Description: SafeDisc driver
    Image path: System32\DRIVERS\secdrv.sys
    Image size: 27440
    Image MD5: D26E26EA516450AF9D072635C60387F4
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): seclogon
    Display name: Secondary Logon
    Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 288
    Error Control: 0

    Service (registry key): SENS
    Display name: System Event Notification
    Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: EventSystem

    Service (registry key): serenum
    Display name: Serenum Filter Driver
    Image path: System32\DRIVERS\serenum.sys
    Image size: 15488
    Image MD5: A2D868AEEFF612E70E213C451A70CAFB
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Serial
    Display name: Serial port driver
    Image path: System32\DRIVERS\serial.sys
    Image size: 64896
    Image MD5: CD9404D115A00D249F70A371B46D5A26
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): ServiceModelEndpoint 3.0.0.0
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): ServiceModelOperation 3.0.0.0
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): ServiceModelService 3.0.0.0
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Sfloppy
    Start: 1
    Type: 1
    Error Control: 0
    Depends On group: "SCSI miniport"

    Service (registry key): SharedAccess
    Display name: Windows Firewall/Internet Connection Sharing (ICS)
    Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: Netman,WinMgmt

    Service (registry key): ShellHWDetection
    Display name: Shell Hardware Detection
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 0
    Depends On services: RpcSs

    Service (registry key): Simbad
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): SLIP
    Display name: BDA Slip De-Framer
    Image path: System32\DRIVERS\SLIP.sys
    Image size: 11136
    Image MD5: 5CAEED86821FA2C6139E32E9E05CCDC9
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): SMSvcHost 3.0.0.0
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): smwdm
    Image path: system32\drivers\smwdm.sys
    Image size: 578304
    Image MD5: FA3368A7039F5ABAA4B933703AC34763
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): SoundMAX Agent Service (default)
    Display name: SoundMAX Agent Service
    Object name: LocalSystem
    Image path: C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    Image size: 45056
    Image MD5: 3978F082274F723AD5A0A8058C2417DD
    Start: 2
    Type: 16
    Error Control: 1

    Service (registry key): Sparrow
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): splitter
    Display name: Microsoft Kernel Audio Splitter
    Image path: system32\drivers\splitter.sys
    Image size: 6400
    Image MD5: 0CE218578FFF5F4F7E4201539C45C78F
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Spooler
    Display name: Print Spooler
    Description: Loads files to memory for later printing.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\spoolsv.exe
    Image size: 57856
    Image MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
    Start: 2
    Type: 272
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): sr
    Display name: System Restore Filter Driver
    Image path: System32\DRIVERS\sr.sys
    Image size: 73472
    Image MD5: E41B6D037D6CD08461470AF04500DC24
    Start: 0
    Type: 2
    Error Control: 1

    Service (registry key): srescan
    Image path: system32\ZoneLabs\srescan.sys
    Image size: 50416
    Image MD5: D2370F80130AF1044220344AAEAD912A
    Start: 0
    Type: 1
    Error Control: 0

    Service (registry key): srservice
    Display name: System Restore Service
    Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): Srv
    Display name: Srv
    Description: Srv
    Image path: System32\DRIVERS\srv.sys
    Image size: 332928
    Image MD5: EA554A3FFC3F536FE8320EB38F5E4843
    Start: 3
    Type: 2
    Error Control: 1

    Service (registry key): SSDPSRV
    Display name: SSDP Discovery Service
    Description: Enables discovery of UPnP devices on your home network.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 4
    Type: 32
    Error Control: 1
    Depends On services: HTTP

    Service (registry key): ssm_bus
    Display name: SAMSUNG Mobile USB Device II 1.0 driver (WDM)
    Image path: system32\DRIVERS\ssm_bus.sys
    Image size: 58320
    Image MD5: DF5C19F053EFF7F8BA25D73AEA899656
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): ssm_mdfl
    Display name: SAMSUNG Mobile USB Modem II 1.0 Filter
    Description: SAMSUNG Mobile USB Modem II 1.0 Filter
    Image path: system32\DRIVERS\ssm_mdfl.sys
    Image size: 8336
    Image MD5: 5347169FA449EABC4D0728AE39FAB926
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): ssm_mdm
    Display name: SAMSUNG Mobile USB Modem II 1.0 Drivers
    Description: SAMSUNG Mobile USB Modem II 1.0 Drivers
    Image path: system32\DRIVERS\ssm_mdm.sys
    Image size: 94000
    Image MD5: 7AAE23DD105EED15C4F45FC269FA42A9
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): stisvc
    Display name: Windows Image Acquisition (WIA)
    Description: Provides image acquisition services for scanners and cameras.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k imgsvc
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): streamip
    Display name: BDA IPSink
    Image path: System32\DRIVERS\StreamIP.sys
    Image size: 15360
    Image MD5: 284C57DF5DC7ABCA656BC2B96A667AFB
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): swenum
    Display name: Software Bus Driver
    Image path: System32\DRIVERS\swenum.sys
    Image size: 4352
    Image MD5: 03C1BAE4766E2450219D20B993D6E046
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): swmidi
    Display name: Microsoft Kernel GS Wavetable Synthesizer
    Image path: system32\drivers\swmidi.sys
    Image size: 54272
    Image MD5: 94ABC808FC4B6D7D2BBF42B85E25BB4D
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): SwPrv
    Display name: MS Software Shadow Copy Provider
    Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\System32\dllhost.exe /Processid:{CFCEC1FD-E46A-4421-87E6-247CF046CE49}
    Image size: 5120
    Image MD5: DD87DB7387B9EB441C5674888A0D840C
    Start: 3
    Type: 16
    Error Control: 0
    Depends On services: rpcss

    Service (registry key): swwd
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): symc810
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): symc8xx
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): sym_hi
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): sym_u3
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): sysaudio
    Display name: Microsoft Kernel System Audio Device
    Image path: system32\drivers\sysaudio.sys
    Image size: 60800
    Image MD5: 650AD082D46BAC0E64C9C0E0928492FD
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): SysmonLog
    Display name: Performance Logs and Alerts
    Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT Authority\NetworkService
    Image path: %SystemRoot%\system32\smlogsvc.exe
    Image size: 89600
    Image MD5: 8B54AA346D1B1B113FFAA75501B8B1B2
    Start: 4
    Type: 16
    Error Control: 1

    Service (registry key): TabletInputService
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): TapiSrv
    Display name: Telephony
    Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: PlugPlay,RpcSs

    Service (registry key): Tcpip
    Display name: TCP/IP Protocol Driver
    Description: TCP/IP Protocol Driver
    Image path: System32\DRIVERS\tcpip.sys
    Image size: 359808
    Image MD5: 1DBF125862891817F374F407626967F4
    Start: 1
    Type: 1
    Error Control: 1
    Depends On services: IPSec

    Service (registry key): TDPIPE
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): TDTCP
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): TermDD
    Display name: Terminal Device Driver
    Image path: System32\DRIVERS\termdd.sys
    Image size: 40840
    Image MD5: A540A99C281D933F3D69D55E48727F47
    Start: 1
    Type: 1
    Error Control: 1

    Service (registry key): TermService
    Display name: Terminal Services
    Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost -k DComLaunch
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): Themes
    Display name: Themes
    Description: Provides user experience theme management.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): TlntSvr
    Display name: Telnet
    Description: Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: C:\WINDOWS\System32\tlntsvr.exe
    Image size: 73216
    Image MD5: 37DB0A7D097310E8B4DE803FC3119C78
    Start: 4
    Type: 16
    Error Control: 1
    Depends On services: RPCSS,TCPIP,NTLMSSP

    Service (registry key): tmcomm
    Display name: tmcomm
    Image path: \??\C:\WINDOWS\system32\drivers\tmcomm.sys
    Image size: 76560
    Image MD5: 4DC436421C9D745D7E8C37F956701C78
    Start: 2
    Type: 1
    Error Control: 1

    Service (registry key): TosIde
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): TrkWks
    Display name: Distributed Link Tracking Client
    Description: Maintains links between NTFS files within a computer or across computers in a network domain.
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): TSDDD
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): tsircmir
    Display name: LapLink Mirror Driver Miniport
    Image path: System32\Drivers\tsircmir.sys
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): TSISER
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): TSP
    Display name: TSP
    Image path: \??\C:\WINDOWS\system32\drivers\klif.sys
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): Udfs
    Start: 4
    Type: 2
    Error Control: 1

    Service (registry key): ultra
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): Update
    Display name: Microcode Update Driver
    Image path: System32\DRIVERS\update.sys
    Image size: 209408
    Image MD5: AFF2E5045961BBC0A602BB6F95EB1345
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): uploadmgr
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): upnphost
    Display name: Universal Plug and Play Device Host
    Description: Provides support to host Universal Plug and Play devices.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: SSDPSRV,HTTP

    Service (registry key): UPS
    Display name: Uninterruptible Power Supply
    Description: Manages an uninterruptible power supply (UPS) connected to the computer.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\ups.exe
    Image size: 18432
    Image MD5: 3F5DF65B0758675F95A2D43918A740A3
    Start: 3
    Type: 16
    Error Control: 1

    Service (registry key): usbccgp
    Display name: Microsoft USB Generic Parent Driver
    Image path: System32\DRIVERS\usbccgp.sys
    Image size: 31616
    Image MD5: BFFD9F120CC63BCBAA3D840F3EEF9F79
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbehci
    Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
    Image path: System32\DRIVERS\usbehci.sys
    Image size: 26624
    Image MD5: 15E993BA2F6946B2BFBBFCD30398621E
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbhub
    Display name: Microsoft USB Standard Hub Driver
    Image path: System32\DRIVERS\usbhub.sys
    Image size: 57600
    Image MD5: C72F40947F92CEA56A8FB532EDF025F1
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbprint
    Display name: Microsoft USB PRINTER Class
    Image path: System32\DRIVERS\usbprint.sys
    Image size: 25856
    Image MD5: A42369B7CD8886CD7C70F33DA6FCBCF5
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): USBSTOR
    Display name: USB Mass Storage Driver
    Image path: System32\DRIVERS\USBSTOR.SYS
    Image size: 26496
    Image MD5: 6CD7B22193718F1D17A47A1CD6D37E75
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usbuhci
    Display name: Microsoft USB Universal Host Controller Miniport Driver
    Image path: System32\DRIVERS\usbuhci.sys
    Image size: 20480
    Image MD5: F8FD1400092E23C8F2F31406EF06167B
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): usnsvc
    Display name: Messenger Sharing USN Journal Reader service
    Description: Service installed by Messenger to enable sharing scenarios
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\svchost.exe -k usnsvc
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: rpcss,eventlog

    Service (registry key): VgaSave
    Display name: VGA Display Controller.
    Description: Controls the VGA display adapter to provide basic display capabilities.
    Image path: \SystemRoot\System32\drivers\vga.sys
    Start: 1
    Type: 1
    Error Control: 0

    Service (registry key): ViaIde
    Start: 4
    Type: 1
    Error Control: 1

    Service (registry key): VolSnap
    Start: 0
    Type: 1
    Error Control: 1

    Service (registry key): vsdatant
    Display name: vsdatant
    Image path: System32\vsdatant.sys
    Image size: 394160
    Image MD5: FA05489771DB33572A79316942163388
    Start: 1
    Type: 1
    Error Control: 1
    Depends On services: TCPIP

    Service (registry key): vsmon
    Display name: TrueVector Internet Monitor
    Description: Monitors internet traffic and generates alerts for disallowed access.
    Object name: LocalSystem
    Image path: C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service
    Image size: 75568
    Image MD5: C570C4239323EB4E08AB0C0D99ED62F1
    Start: 2
    Type: 272
    Error Control: 1
    Depends On services: Afd,RpcSs,vsdatant

    Service (registry key): VSS
    Display name: Volume Shadow Copy
    Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\vssvc.exe
    Image size: 289792
    Image MD5: 3EE00364AE0FD8D604F46CBAF512838A
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): VXD
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): W32Time
    Display name: Windows Time
    Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): W3SVC
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Wanarp
    Display name: Remote Access IP ARP Driver
    Description: Remote Access IP ARP Driver
    Image path: System32\DRIVERS\wanarp.sys
    Image size: 34560
    Image MD5: 984EF0B9788ABF89974CFED4BFBAACBC
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): WDICA
    Start: 3
    Type: 1
    Error Control: 0

    Service (registry key): wdmaud
    Display name: Microsoft WINMM WDM Audio Compatibility Driver
    Image path: system32\drivers\wdmaud.sys
    Image size: 82944
    Image MD5: EFD235CA22B57C81118C1AEB4798F1C1
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): WebClient
    Display name: WebClient
    Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: MRxDAV

    Service (registry key): WerSvc
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): Windows Workflow Foundation 3.0.0.0
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): winmgmt
    Display name: Windows Management Instrumentation
    Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
    Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 0
    Depends On services: RPCSS,Eventlog

    Service (registry key): Winsock
    Start: 3
    Type: 4
    Error Control: 1

    Service (registry key): WinSock2
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): WinTrust
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): WinVNC4
    Display name: VNC Server Version 4
    Object name: LocalSystem
    Image path: "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service
    Image size: 685048
    Image MD5: 45F3B7C1D46ADCCD7D40286C69518E48
    Start: 2
    Type: 272
    Error Control: 0

    Service (registry key): WmdmPmSN
    Display name: Portable Media Serial Number Service
    Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 4
    Type: 32
    Error Control: 1

    Service (registry key): Wmi
    Display name: Windows Management Instrumentation Driver Extensions
    Description: Provides systems management information to and from drivers.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1

    Service (registry key): WmiApRpl
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): WmiApSrv
    Display name: WMI Performance Adapter
    Description: Provides performance library information from WMI HiPerf providers.
    Object name: LocalSystem
    Image path: C:\WINDOWS\System32\wbem\wmiapsrv.exe
    Image size: 126464
    Image MD5: BA8CECC3E813E1F7C441B20393D4F86C
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: RPCSS

    Service (registry key): WMPNetworkSvc
    Display name: Windows Media Player Network Sharing Service
    Description: Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
    Object name: NT AUTHORITY\NetworkService
    Image path: "C:\Program Files\Windows Media Player\WMPNetwk.exe"
    Image size: 913408
    Image MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B
    Start: 3
    Type: 16
    Error Control: 1
    Depends On services: upnphost,http,HTTPFilter

    Service (registry key): wscsvc
    Display name: Security Center
    Description: Monitors system security settings and configurations.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs,winmgmt

    Service (registry key): WSearch
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): WSTCODEC
    Display name: World Standard Teletext Codec
    Image path: System32\DRIVERS\WSTCODEC.SYS
    Image size: 19328
    Image MD5: D5842484F05E12121C511AA93F6439EC
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): wuauserv
    Display name: Automatic Updates
    Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.
    Object name: LocalSystem
    Image path: %systemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1

    Service (registry key): WudfPf
    Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver
    Description: Provide communciation services for UMDF components.
    Image path: system32\DRIVERS\WudfPf.sys
    Image size: 77568
    Image MD5: F15FEAFFFBB3644CCC80C5DA584E6311
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): WudfRd
    Display name: Windows Driver Foundation - User-mode Driver Framework Reflector
    Description: Reflect device requests to user-mode driver drivers
    Image path: system32\DRIVERS\wudfrd.sys
    Image size: 82944
    Image MD5: 28B524262BCE6DE1F7EF9F510BA3985B
    Start: 3
    Type: 1
    Error Control: 1

    Service (registry key): WudfSvc
    Display name: Windows Driver Foundation - User-mode Driver Framework
    Description: Manages user-mode driver host processes
    Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: PlugPlay

    Service (registry key): WZCSVC
    Display name: Wireless Zero Configuration
    Description: Provides automatic configuration for the 802.11 adapters
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 2
    Type: 32
    Error Control: 1
    Depends On services: RpcSs,Ndisuio

    Service (registry key): xmlprov
    Display name: Network Provisioning Service
    Description: Manages XML configuration files on a domain basis for automatic network provisioning.
    Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 14336
    Image MD5: 8F078AE4ED187AAABC0A305146DE6716
    Start: 3
    Type: 32
    Error Control: 1
    Depends On services: RpcSs

    Service (registry key): {0A10CB4B-B2CD-4239-AFE1-140E40ED2DC0}
    Start: 0
    Type: 0
    Error Control: 0

    Service (registry key): {4C302841-318B-4A63-8D46-EBADD995D694}
    Start: 0
    Type: 0
    Error Control: 0


    Logfile of HijackThis v1.99.1
    Scan saved at 23:27:30, on 22/03/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Winwall\Winwall.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Maxthon2\Maxthon.exe
    C:\Highjackthis\Analyse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\TSI32\tsircusr.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\vnkoshlo.dll",setvm
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [LapLink Server Proxy] "C:\PROGRA~1\LAPLIN~1\WProxy.exe" -l
    O4 - HKLM\..\Run: [Winwall] C:\PROGRA~1\Winwall\Loader.exe
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Disk Cleaner.lnk = C:\Program Files\Disk Cleaner\dclean.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1167354957765
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

  • #8
    VopThis is offline Senior Member (Canada)
    Save 20% on AVG Internet Security 2012 Suite!
    Lets try an additional scan - see if another tool finds and/or addresses the SpyBot issue:


    Using Internet Explorer run Panda's ActiveScan from here and perform a full system scan.

    1. Once you are on the Panda site click the "Scan your PC" button
    2. A new window will open...click the big "Check Now" button
    3. Enter your Country
    4. Enter your State/Province
    5. Enter your e-mail address and click send
    6. Select either Home User or Company
    7. Click the big Scan Now button
    8. If it wants to install an ActiveX component allow it
    9. It will start downloading the files it requires for the scan (Note: It will take a couple minutes). You may need to click the ‘Retry again’ BUTTON or you may need to exit and retry at the ‘Scan Now’ BUTTON.
    10. Click on "Local Disks" to start the scan
    11. Post Panda scan results in your next reply

  • + Reply to Thread

    Similar Threads