Instalando VMWare Server en Ubuntu

En artículos anteriores explicábamos cómo instalar la distribución de Ubuntu.

Bien, el objetivo es construir nuestra máquina para realizar auditorías, pentests y demás gaitas de seguridad, por lo que inicialmente parece buena idea instalar un servidor VMWare (o VirtualBox según vaya en gustos) para correr nuestras máquinas virtuales según necesidad (dijesé Backtrack u otras).

Personalmente prefiero VMWare, y dado que soy un clásico y que la versión 2 incluye la consola sólo accesible vía web, me he decidido por la versión 1.0.8 del servidor.

A continuación os dejo una serie de sencillos pasos para instalar el servidor VMWare en Ubuntu 8.10:

1- Obtener la licencia VMware desde la página oficial aqui

2- Instalar los paquetes siguientes:
apt-get install linux-source-2.6.27 linux-libc-dev xinetd

3- Despues,descargar VMware
wget http://download3.vmware.com/software/vmserver/VMware-server-1.0.8-126538.tar.gz
Untar
tar -xvzf VMware-server-1.0.8-126538.tar.gz
cd vmware-server-distrib/

4- Ejecutar el instalador
./vmware-install.pl

-> Responder yes a cada pregunta hasta que llegue (run the configured script),a la cual responderemos no

5- Ahora,es necesario descargar el parche con el fin de construir el módulo del kernel (Probado con 2.6.27-7-generic)
wget http://www.insecure.ws/warehouse/vmware-update-2.6.27-5.5.7-2.tar.gz

tar -xvzf vmware-update-2.6.27-5.5.7-2.tar.gz
cd vmware-update-2.6.27-5.5.7-2
./runme.pl
-> Respondemos yes a todas las preguntas,ejecutamos el script de configuración y pulsamos ENTER para utilizar la configuración predeterminada.

-> Agregar la licencia.
-> Verificar la existencia del icono en Applications/Other.

6- Por ultimo, bajaremos un parche para solucionar un bug de la versión 1.0.8. Este parche no es oficial porque nuestros amigos de VMWare pasan y estan centrados en la versión 2:

http://www.monarialx.it/en/vmwareserver

Hacer clic en la versión 1.0.8_2 del parche el cual está hecho tanto para VMWare Server (interfaz gráfica) y para VMWare Server Console.

.. y ejecutamos ./install server

7- Verificar si el servicio està corriendo
/etc/init.d/vmware status

Bridged networking on /dev/vmnet0 is running
Host-only networking on /dev/vmnet1 is running
Host-only networking on /dev/vmnet8 is running
NAT networking on /dev/vmnet8 is running
Module vmmon loaded
Module vmnet loaded


¡Y ya está!

Extraído de http://unlugarsinfin.blogspot.es

Podcasts de seguridad informática

Os dejo un artículo buenísimo, extraído de nuestros amigos de la jodida mierda (http://www.thefuckingshit.org/?p=500) sobre los mejores podcasts de seguridad informática:



Pauldotcom Security Weekly.
Es sin duda el mejor de todos. Está dirigido por Paul Asadoorian y Larry Pesce, unos freaks de la seguridad informática que se juntan todas las semanas para beber cerveza y hablar sobre las ultimas novedades en el sector. El tono es totalmente informal, risas, chistes y tonterías, con las que yo personalmente me rio bastante.

Se publica un nuevo podcast aproximadamente cada semana y puede escucharse como un streaming en directo o bajándose el correspondiente fichero mp3. Altamente recomendado.

Web: http://www.pauldotcom.com/
RSS: http://pauldotcom.com/podcast/psw.xml

CyberSpeak Podcast
Bret Padres y Ovie Carroll, dos agentes de la Oficina de Operaciones Especiales de las Fuerzas Aéreas estodounidenses, dirigen este podcast sobre seguridad e informática forense. El tono es desenfadado pero riguroso y regularmente entrevistan a profesionales del sector. Los contenidos son bastante variados: herramientas de análisis forense, exploits, noticias recientes, nuevas tecnologías, linux, windows, software libre, etc. Se publica 3 o 4 veces al mes.

Web: http://cyberspeak.libsyn.com/
RSS: http://feeds.feedburner.com/Cyberspeak

Binary Revolution Radio
Lo llevan 4 o 5 tios diferentes y sería un podcast bastante interesante si no me chirriasen tanto los oidos al escuchar mp3 con tan poca calidad de sonido. Si a alguno de vosotros os sobra el dinero, por favor, mandadles un donativo para que compren un micrófono nuevo. Por lo demás, el podcast está bien, trata de todo un poco pero cada episodio se centra en un tema en concreto. Los últimos episodios hablaban sobre botnets, Mono&.NET, Malware, evaluación de la seguridad física, virtualización, IPv4 vs IPv6, etc. Se publica un nuevo episodio aproximadamente cada semana.

Web: http://www.binrev.com/radio/archive.php
RSS: http://www.binrev.com/radio/podcast/

SploitCast
Este es otro de los podcasts más importantes sobre seguridad informática. No se centra en un único locutor sino que lo lleva todo un grupo de gente interesada en la seguridad y la tecnología que se va turnando para hacer el podcast. No está mal pero en mi opinión, siempre se hace aburrido. Le falta algo de dinamismo o algun toque más alegre porque en ocasiones parece que los propios presentadores se quedan dormidos escuchando sus palabras. Lo recomiendo solo si despues de escuchar el resto de podcasts os quedais sedientos de más información en mp3.

Web: http://www.sploitcast.com/
RSS:
http://sploitcast.libsyn.com/rss

Security Now!
No esta del todo mal. Está dirigido por Leo Laporte, conocido presentador de la antigua TechTV americana, pero la carga principal la lleva Steve Gibson, un veterano de la informática y especialista en seguridad. Este podcast tiene un tono bastante formal pero es increiblemente didactico. Cada episodio tiene un tema distinto que se analiza en profundidad explicando todo casi desde el principio. Ideal para aprender sobre proxys, maquinas virtuales, puertos, routers, criptografía, buffers overflows, ISPs, etc.

Cada viernes se cuelga un nuevo episodio que puede descargarse en alta calidad (64Kbps), en baja (16Kbps) o en un fichero PDF que contiene la transcripción exacta.

Web: http://www.grc.com/SecurityNow.htm o bien en http://www.twit.tv/SN
RSS: http://leoville.tv/podcasts/sn.xml

FLOSS: Free Libre Open Source Software.
Este podcast no está relacionado directamente con la seguridad sino con herramientas de software libre de todo tipo. Lo he incluido en la lista porque suelen hacer interesantes entrevistas a personajes importantes del mundo del software libre como Rasmus Lerdorf, creador de PHP o Guido van Rossum , creador del lenguaje Python. Al igual que Security Now, está dirigido por Leo Laporte, pero es Chris DiBona, jefe de la seccion de Software Libre de Google, quien realmente lleva las riendas del programa. Se publica una vez al mes y lo recomiendo a todo aquel que esté interesado en el mundo del software libre.

Web: http://www.twit.tv/FLOSS
RSS:
http://leoville.tv/podcasts/floss.xml

Off The Hook

Este podcast es todo un clásico. Es una leyenda viva para la comunidad de hackers y phreakers porque lleva emitiendose por radio más de 20 años. Lo lleva Eric Gorden Corley (alias Emmanuel Goldstein), toda una celebridad dentro del mundillo, y está asociado a su famosa revista 2600 The Hacker Quarterly, fundada en 1984. Su importancia es más bien histórica porque en mi opinion, este podcast es menos interesante que los que he citado anteriormente.

Web: http://www.2600.com/offthehook/
RSS: http://www.2600.com/rss.xml

Hasta aquí lo que yo os puedo comentar personalmente. A continuación cito los podcasts que Chris Brunner pone en su lista, haciendo una traducción directamente de sus comentarios ya que yo todavía no he escuchado ninguno:

PLA Radio - Phone Losers of America
Tema principal: Phreaking
Tono: muy informal
Episodios/Mes: 1 o 2
Temas cubiertos recientemente: Lamadas gratis, IP Relay, Ingeniería Social
Justificación: Cubre temas relacionados con el phreaking telefónico. Aunque el formato es algo extraño, algunos episodios antiguos son muy graciosos y merece la pena escucharlos.episodes had

Web: http://www.phonelosers.org
RSS: http://www.phonelosers.org/rss.xml

Blue Box: The VoIP Security Podcast
Tema principal: Seguridad VoIP
Tono: semi-informal
Episodios/Mes: de 3 a 6
Temas cubiertos recientemente: Novedad en la seguridad de Skype, fraude VoIP, vulnerabilidades…
Justificación: Proporciona mucha información sobre la seguridad de las comunicaciones a través de VoIP.

Web: http://www.blueboxpodcast.com/
RSS: http://feeds.feedburner.com/BlueBox

TWAT Radio
Tema principal: Tecnología con algo de atención a la seguridad.
Tono: Informal
Episodios/Mes: 10
Temas cubiertos recientemente: Newsgroups, ataques wireless para torpes, Wake On Lan, VPNs, The Gimp…
Justificación: Cubre una gran variedad de tecnologías distintas.
Web: http://twatech.org/
RSS: http://www.twatech.org/wp-feed.php

Basenet Radio
Tono: Informal
Episodios/Mes: de 2 a 4
Justificación: Temática underground
Web: http://www.basenetradio.net/
RSS: http://www.basenetradio.net/rss2.xml

LugRadio
Tema principal: Linux y Software Libre
Tono: Informal
Episodios/Mes: de 0 a 2
Temas cubiertos recientemente: El proyecto Portland, trusted computing, comparativa entre diferentes distrubiciones GNU/Linux, Software Freedom Day…
Justificación: Posiblemente el podcast sobre Linux más popular
Web: http://www.lugradio.org/
RSS: http://www.lugradio.org/episodes.rss

The Linux Link Tech Show
Tema principal: Lo más reciente relacionado con Linux
Tono: Informal
Episodios/Mes: 4
Temas cubiertos recientemente: OpenWRT, Asterisk, Debian vs Mozilla, DRM
Justificación: Información completa relacionada con Linux
Web: http://www.tllts.org/
RSS: http://www.thelinuxlink.net/tllts/tllts.rss

StillSecure, After all these years
Tema principal: Todo lo relacionado con la seguridad, centrandose en entornos empresariales.
Tono: Formal
Episodios/Mes: de 2 a 5
Temas cubiertos recientemente: Entrevista a Steve Hanna de Juniper Networks, TCG/TNC, el IETF, Parches de terceros…
Justificación: Incluye algunas entrevistas muy interesantes e información acerca de la seguridad en la empresa.
Web: http://www.stillsecureafteralltheseyears.com/
RSS: http://clickcaster.com/clickcast/rss/1653

Symantec Security Response Podcast
Tema principal: Parches de seguridad
Tono: Formal
Episodios/Mes: de 2 a 4
Justificación: Es una fuente se actualizaciones de seguridad consistente. De gran interés para los encargados de la seguridad de una red.
Web: http://www.podtech.net/home/search/Symantec+Security+Response
RSS: http://www.symantec.com/content/en/us/about/rss/sr/sr.xml

Network Security Blog
Tema principal: Seguridad de redes.
Tono: Formal
Episodios/Mes: ?
Web: http://www.mckeay.net/
RSS: http://www.mckeay.net/secure/index.xml

:::::::::::::::::::::::::::::::::::

El Guardián
Tema principal: Seguridad en general.
Episodios/Mes: 4
Web: http://elguardian.euskadigital.net/
RSS: http://www.euskadigital.net/rss/el_guardian.xml
Aun no lo he podido escuchar pero no tiene mala pinta. Este podcast forma parte del proyecto Euskadi Digital y ya tiene bastante rodaje, llevan casi 100 programas. Por lo que he podido ver en su página web tratan temas diversos, agrupando los contenidos en secciones: Noticias, Cursos, A fondo, Alerta de virus, Seguridad fácil, Concursos, Pequeña historia, Seguridad software libre y Seguridad práctica.

Podcast Eset NOD32
Tema principal: Virus, troyanos, spyware.
Episodios/Mes: Sin definir.
Web: http://www.eset-la.com/threat-center/podcast.php
RSS: http://www.eset-la.com/rss/podcast2.xml
Al contrario que el anterior este podcast está dando aún sus primeros pasos. Lo publica la empresa de seguridad informática Eset, desarrolladora del Antivirus Eset NOD32. La temática se centra en el mundo de la seguridad frente a virus, troyanos y spyware. Tambien tienen un algo dedicado a la ingeniería social. Lo estoy bajando ahora mismo porque tiene buena pinta.


Extraído de http://unlugarsinfin.blogspot.es

Ubuntu en el pendrive

A continuación una serie de pasos muy sencillos para hacernos con una versión de Ubuntu auto-arrancable desde nuestro pendrive USB.


1. En primer lugar debemos descargarnos la imagen ISO de Ubuntu, por supuesto, la podemos obtener en el sitio web oficial de Ubuntu.

2. Después nos descargamos la última versión de Syslinux para Windows.

3. A continuación, descomprimimos la ISO y copiamos el contenido a nuestra memoria o disco USB (no es necesario que estén vacíos, sólo que haya espacio suficiente).

4. Descomprimimos Syslinux.zip y lo ejecutamos (desde una ventana de MSDOS) contra nuestro dispositivo USB desde el directorio donde está el ejecutable Syslinux (si nuestro dispositivo USB es D: la instrucción sería syslinux.exe –ma d:)

5. Copiamos los siguientes archivos al directorio raíz de nuestro dispositivo USB:

vmlinuz (lo encontraremos en el directorio casper\vmlinuz)
initrd.gz (lo encontraremos en el directorio casper\initrd.gz)
syslinux.cfg (renombraremos el archivo isolinux\isolinux.cfg a syslinux.cfg y lo copiaremos al raiz del USB)

6. Editamos syslinux.cfg de manera que vmlinuz e initrd.gz apunten al directorio root del dispositivo USB, ejemplo:

DEFAULT /casper/vmlinuz
GFXBOOT bootlogo
GFXBOOT-BACKGROUND 0xB6875A
APPEND boot=casper initrd=/casper/initrd.gz ramdisk_size=1048576 root=/dev/ram
rw quiet splash –

Lo cambiaríamos por:

DEFAULT vmlinuz
GFXBOOT bootlogo
GFXBOOT-BACKGROUND 0xB6875A
APPEND boot=casper initrd=initrd.gz ramdisk_size=1048576 root=/dev/ram
rw quiet splash –

7. Expulsamos el dispositivo USB y lo conectamos al portátil. Lo arrancamos y pulsamos F2, del, esc… (o la tecla para acceder a tu bios), para acceder a la BIOS y poder establecer nuestro dispositivo USB como predeterminado en el arranque.

8. ¡Listo!, ya tenemos ubuntu en nuestro dispositivo USB funcionando a la perfección. Podemos dejarlo así, o instalarlo en el disco duro de nuestro equipo.


Extraído de http://unlugarsinfin.blogspot.es

Conficker.C: la tercera variante

Esta obra de arte va camino de convertirse en una auténtica plaga y ya podemos dar por seguro que su nombre (también Downadup o Kido) será recordado durante los próximos años.



Esta tercera versión amenaza con activarse el próximo 1 de Abril, el famoso ‘april fool's day’ o día de los inocentes para nuestros vecinos anglosajones. Ese día, Conficker.C tratará de conectarse a una lista de 500 dominios de un conjunto de 50.000 candidatos. Recordemos que la versión anterior tenía sólo una lista de 32 dominios de 250, y fue fácilmente neutralizado con ingeniería inversa. ´

Está vez será mucho más complicado detener la infección, más aún si tenemos en cuenta que el código del gusano aparece aún más ofuscado y es más ‘agresivo’ ya que es capaz de defenderse.

Así, entre otras características, es capaz de esquivar la mayoría de los antivirus comerciales, apagar las actualizaciones automáticas de Microsoft, bloquear también las actualizaciones de los antivirus e incluso crear 'agujeros' en los servidores de seguridad para mejorar su comunicación con otros equipos infectados.

Se cree que uno de sus principales objetivos es crear una especie de gigantesca red P2P, por el que los equipos infectados pueden ser clientes y servidores, y pueden compartir archivos en ambos sentidos. Esto supone nuevas vías de infección.

Os dejo información interesante extraída de CA, comenzamos la cuenta atrás hacia el 1 de abril…

Description
Win32/Conficker.C is a worm capable of blocking security related websites, terminating system security services and downloading component files using time-based generated URLs.

Method of Infection
When executed, Win32/Conficker.C drops a copy of itself using a random filename in the %System% directory. It may also drop copies of itself in the following directories:

%Program Files%\Windows NT
%Program Files%\Windows Media Player
%Program Files%\Internet Explorer
%Program Files%\Movie Maker

For these and other dropped files, Win32/Conficker.C:

Sets Read Only, Hidden and System file attributes
Generates a file creation/access time-stamp based on that of "kernel32.dll"
Creates access control entries
Exclusively locks the file, thus restricting access and privileges
Note: %System% and %Program Files% are variable locations. The malware determines the locations of these folders by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; for XP and Vista is C:\Windows\System32. A typical location for the Program Files folder would be C:\Program Files.

In order to automatically execute at each startup, it adds the registry entry below:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ = "rundll32.exe , "

Conficker also registers a service with a random name created by combining a word from this list:

App
Audio
DM
ER
Event
help
Ias
Ir
Lanman
Net
Ntms
Ras
Remote
Sec
SR
Tapi
Trk
W32
win
Wmdm
Wmi
wsc
wuau
xml

with another word from this list:

access
agent
auto
logon
man
mgmt
mon
prov
serv
Server
Service
Srv
srv
svc
Svc
System
Time

The worm also derives a display name for the service by combining two words from the list below:

Audit
Backup
Boot
Browser
Center
Component
Config
Control
Discovery
Driver
Framework
Hardware
Helper
Image
Installer
Logon
Machine
Management
Manager
Microsoft
Monitor
Network
Notify
Policy
Power
Security
Shell
Storage
Support
System
Task
Time
Trusted
Universal
Update
Windows

For example, the worm may register a service with these registry entries:

HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\DisplayName = "Component Task"
HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Type = 00000020
HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Start = 00000002
HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ErrorControl = 00000000
HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ImagePath = "%Root%\system32\svchost.exe -k netsvcs"
HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ObjectName = "LocalSystem"
HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Description = ""
HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Parameters\ServiceDll = "%System%\"

Note: %Root% is a variable location. The malware determines the location of the current root drive by querying the operating system. A typical location for the root drive would be C:\.

Additionally, Win32/Conficker.C checks for and tries to inject code into any processes executed with the commandline parameters "svchost.exe -k NetworkService".

Payload
Modifies Registry / Lowers Security Settings
Win32/Conficker.C deletes the following registry entry to deactivate Windows Security Center notifications:

HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjects\{FD6905CE-952F-41F1-9A6F-135D9C6622CC}

It deletes the registry entry below to prevent the operating system from starting in Safe Mode:

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot

Additionally, Win32/Conficker.C deletes the below registry entry to prevent "Windows Defender" from executing on system start:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender

Deletes Restore Points
Conficker resets all system restore points and deletes any saved system restore points on the affected system.

Disables Services
Win32/Conficker.C looks for and disables the following services if running:

wscsvc - Security Center
WinDefend – Windows Defender (available in Vista)
wuauserv - Automatic Updates
BITS - Background Intelligent Transfer Service
ERSvc - Error Reporting Service
WerSvc - Windows Error Reporting Service (available in Vista)

Terminates Processes
Win32/Conficker.C terminates the following security-related processes in an attempt to prevent its removal from the system:

autoruns
avenger
confick
downad
filemon
gmer
hotfix
kb890
kb958
kido
klwk
mbsa.
mrt.
mrtstub
ms08-06
procexp
procmon
regmon
scct_
sysclean
tcpview
unlocker
wireshark

Blocks Websites
Win32/Conficker.C hooks the following APIs to monitor and restrict access to security websites:

Query_Main
DnsQuery_W
DnsQuery_UTF8
DnsQuery_A
sendto

In its attempt to prevent access to security-related sites for information, help or software updates, the worm attempts to block running applications from accessing URLs containing any of the following strings:

avg.
avp.
bit9.
ca.
cert.
gmer.
kav.
llnw.
llnwd.
msdn.
msft.
nai.
sans.
vet.
agnitum
ahnlab
anti-
antivir
arcabit
avast
avgate
avira
bothunter
castlecops
ccollomb
centralcommand
clamav
comodo
computerassociates
conficker
cpsecure
cyber-ta
db networkassociates
defender
drweb
dslreports
emsisoft
esafe
eset
etrust
ewido
f-prot
f-secure
fortinet
free-av
freeav
gdata
grisoft
hackerwatch
hacksoft
hauri
ikarus
jotti
k7computing
kaspersky
malware
mcafee
microsoft
mirage
msftncsi
msmvps
mtc.sri
nod32
norman
norton
onecare
panda
pctools
prevx
ptsecurity
quickheal
removal
rising
rootkit
safety.live
securecomputing
secureworks
sophos
spamhaus
spyware
sunbelt
symantec
technet
threat
threatexpert
trendmicro
trojan
virscan
virus
wilderssecurity
windowsupdate

Downloads and Executes Arbitrary Files
If the current system date is on or after 1 April 2009, the worm attempts to access pre-computed domain names to either download an updated copy of itself or download other malware. Below is a list of URL extensions used for pre-computed/generated URLs:

vn
vc
us
tw
to
tn
tl
tj
tc
su
sk
sh
sg
sc
ru
ro
ps
pl
pk
pe
no
nl
nf
my
mw
mu
ms
mn
me
md
ly
lv
lu
li
lc
la
kz
kn
is
ir
in
im
ie
hu
ht
hn
hk
gy
gs
gr
gd
fr
fm
es
ec
dm
dk
dj
cz
cx
com.ve
com.uy
com.ua
com.tw
com.tt
com.tr
com.sv
com.py
com.pt
com.pr
com.pe
com.pa
com.ni
com.ng
com.mx
com.mt
com.lc
com.ki
com.jm
com.hn
com.gt
com.gl
com.gh
com.fj
com.do
com.co
com.bs
com.br
com.bo
com.ar
com.ai
com.ag
co.za
co.vi
co.uk
co.ug
co.nz
co.kr
co.ke
co.il
co.id
co.cr
cn
cl
ch
cd
ca
bz
bo
be
at
as
am
ag
ae
ac

Additional Information
So that only one copy of itself runs at a time, Conficker creates a mutex in the format "Global\%u-%u", where "%u" is a decimal number.

The worm accesses the following websites to test Internet connectivity:

ask.com
baidu.com
facebook.com
google.com
imageshack.us
rapidshare.com
w3.org
yahoo.com

Extraído de http://unlugarsinfin.blogspot.es

Avkiller - making of (I)

Os paso un interesante artículo para realizar nuestro avkiller:

-------------------------------Articulo----------------------------------
#GEDZAC Mitosis eZine Issue 4
#MITOSIS ARTICLE#
#Identificando y eliminando Antivirus mas conocidos
#Autor: eCORE[GEDZAC]

En este articulo lo que voy a exponer es una super lista que confeccione para eliminar los antivirus mas comunes en casi todas la versiones. Esta bastante bien cuando se quieren eliminar versiones especificas de familias de antivirus concretos o en general. La mayoria de esta claves devuelven un Path donde esta instalado el producto bastaria con hacerle un dir y empezar a ejecutar el comando SC a todos los exes para empezar a detener el antivirus. A mi no me dio tiempo pero si lo montan bien pueden hacerse un gran AV Killer.


**************************************************************
*
* Familia Symantec
*
* Norton Internet Security 2009 PreRelease
* Norton Antivirus 2009 PreRelease
* Norton 360 (Vista)
* Symantec Corporate Edition 10.2.224 for Windows Vista 32 bits
* Symantec Corporate Edition versiones 10.1,10.0 *
* Symantec Corporate Edition versiones 9,8.x,7.5(9x,NT),7.0(9x,NT)
* Norton SystemWorks 2006 Premier
* Norton SystemWorks 2006,2005,2004,2003,2002
* Norton Internet Security 2008,2007,2006,2005,2004,2003,2002
* Norton Antivirus 2008,2007,2006,2005,2004,2003,2002,2001,2000,5.x
***************************************************************

[#]CLAVES DEL REGISTRO
[1]HKLM\SOFTWARE\Symantec\
[2]HKLM\SYSTEM\CurrentControlSet\Services\
[3]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
[4]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\
[5]HKLM\SYSTEM\CurrentControlSet\Services\
[6]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\
[1]InstalledApps\N360
[1]Symantec AntiVirus\Install\7.50\InstallDir
[1]InstalledApps\AVENGEDEFS
[1]InstalledApps\NAV
[1]InstalledApps\NAVNT
[1]Norton AntiVirus\version
[2]Services\NAVAP\ImagePath
[2]VxD\NAVAP\StaticVxD
[2]VxD\SAVRT\StaticVxD
[3]NIS\UninstallString
[3]NAV\UninstallString
[3]UninstallString
[3]SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777}\UninstallString
[3]SymSetupTemp.{2D617065-1C52-4240-B5BC-C0AE12157777}\UninstallString
[3]{6C28BDA4-6D99-4DD0-9F22-6A90A445E982}\UninstallString
[3]SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}\UninstallString
[3]SymSetup.{830D8CBD-C668-49e2-A969-C2C2106332E0}\UninstallString
[3]{3248E093-5288-4CA9-B3AB-11A675FEA1F9}\UninstallString
[3]{2CFECCAA-8CB0-459B-9636-40430DBC8951}\UninstallString
[3]{7D2B86CA-2D5D-469E-92ED-E56B62BD1D3C}\UninstallString
[3]{BD12EB47-DBDF-11D3-BEEA-00A0CC272509}\UninstallString
[3]{D6C64C68-F9F5-11D3-BEEA-00A0CC272509}\UninstallString
[3]Norton AntiVirus Corporate Edition 7.0 for Windows NT\UninstallString
[3]Norton AntiVirus Corporate Edition for Windows 7.0\UninstallString
[3]Norton AntiVirus Corporate Edition\UninstallString
[3]SymSetup.{71E7B3F5-CFAF-4C1E-B494-528E28707937}\UninstallString
[3]SymSetup.{B9807C3D-B3DD-41b7-8321-53DDB3A3A888}\UninstallString
[3]{43C3D832-AC96-463A-2003-1B8D1BFA252F}\UninstallString
[3]SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}\UninstallString
[3]SymSetup.{AED74EFF-83ED-4ed6-8413-285C24BCEB6E}\UninstallString
[3]{AFD2C5B5-BF78-47B6-9569-755448C0D0EE}\UninstallString
[3]SymSetup.{AED74EFF-83ED-4ed6-8413-285C24BCEB6E}\UninstallString
[3]{B7C61755-DB48-4003-948F-3D34DB8EAF69}\UninstallString
[3]{E36E8951-3C0E-4615-A912-948C1609D659}\UninstallString
[3]{91AA4B1F-B918-4e0b-A304-F8D4EC5D7726}\UninstallString
[3]{E47EE8FB-ACC0-4608-859C-4E2851B18A6A}\UninstallString
[3]{71D03DD3-C6D9-4503-A1CC-FBA576F6CFE3}\UninstallString
[3]SymSetup.{C6F5B6CF-609C-428E-876F-CA83176C021B}\UninstallString
[3]SymSetup.{C6B28661-7910-442E-ADDD-72EAA8395380}\UninstallString
[3]SymSetup.{47D5D869-FE57-4F2F-A358-83CFAA7B4968}\UninstallString
[3]{4CFD624C-B66C-42AA-A47E-21A78D91E06C}\UninstallString
[3]{47D5D869-FE57-4F2F-A358-83CFAA7B4968}\UninstallString
[3]{F4C9398F-B6C6-4A4B-8B6D-795CD86F915D}\UninstallString
[3]{84555E03-F08E-4B9C-BE83-9D5E77190E89}\UninstallString
[3]{EDCD4CE3-DE92-49A9-87F9-FE09B2FBA16C}\UninstallString
[3]{68AE158E-38F9-4027-A757-A82B00E45D5C}\UninstallString
[3]{93DF5BBA-2992-482F-B11D-91027EC8AC7D}\UninstallString
[3]{3075C5C3-0807-4924-AF8F-FF27052C12AE}\UninstallString
[3]Norton AntiVirus\UninstallString
[3]{0698CECB-9072-47B1-AEA1-94CA350989B8}\UninstallString
[3]{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}\UninstallString
[3]{33CFCF98-F8D6-4549-B469-6F4295676D83}\UninstallString
[3]{473af7d0-b864-4699-9974-df570c5b6dce}\UninstallString
[3]{50e125d1-88e5-48ce-80ae-98ec9698e639}\UninstallString
[3]{5a633ed0-e5d7-4d65-ab8d-53ed43510284}\UninstallString
[3]{848AC794-8B81-440A-81AE-6474337DB527}\UninstallString
[3]{a011a1dc-7f1d-4ea8-bd11-0c5f9718e428}\UninstallString
[3]{BA4B71D1-898E-4306-AE87-8BA7A596F0ED}\UninstallString
[3]{BD12EB47-DBDF-11D3-BEEA-00A0CC272509}\UninstallString
[3]{D75D48AF-E2D5-49EF-9571-EE7AFB6565B4}\UninstallString
[3]{E9FA3047-0b15-4e19-85ce-ee7fc6e60f99}\UninstallString
[3]NIS\DisplayName
[3]NAV\DisplayName
[3]NAV-16-0-0\DisplayName
[3]SymSetup.{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}\DisplayName
[3]SymSetup.{C1C185CA-C531-49F5-A6FA-B838405A049D}\DisplayName
[3]SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777}\DisplayName
[3]SymSetupTemp.{2D617065-1C52-4240-B5BC-C0AE12157777}\DisplayName
[3]{6C28BDA4-6D99-4DD0-9F22-6A90A445E982}\DisplayName
[3]SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}\DisplayName
[3]SymSetup.{830D8CBD-C668-49e2-A969-C2C2106332E0}\DisplayName
[3]{3248E093-5288-4CA9-B3AB-11A675FEA1F9}\DisplayName
[3]{2CFECCAA-8CB0-459B-9636-40430DBC8951}\DisplayName
[3]{7D2B86CA-2D5D-469E-92ED-E56B62BD1D3C}\DisplayName
[3]{BD12EB47-DBDF-11D3-BEEA-00A0CC272509}\DisplayName
[3]{D6C64C68-F9F5-11D3-BEEA-00A0CC272509}\DisplayName
[3]Norton AntiVirus Corporate Edition 7.0 for Windows NT\DisplayName
[3]Norton AntiVirus Corporate Edition for Windows 7.0\DisplayName
[3]Norton AntiVirus Corporate Edition\DisplayName
[3]SymSetup.{71E7B3F5-CFAF-4C1E-B494-528E28707937}\DisplayName
[3]SymSetup.{B9807C3D-B3DD-41b7-8321-53DDB3A3A888}\DisplayName
[3]{43C3D832-AC96-463A-2003-1B8D1BFA252F}\DisplayName
[3]SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}\DisplayName
[3]SymSetup.{AED74EFF-83ED-4ed6-8413-285C24BCEB6E}\DisplayName
[3]{AFD2C5B5-BF78-47B6-9569-755448C0D0EE}\DisplayName
[3]SymSetup.{AED74EFF-83ED-4ed6-8413-285C24BCEB6E}\DisplayName
[3]{B7C61755-DB48-4003-948F-3D34DB8EAF69}\DisplayName
[3]{E36E8951-3C0E-4615-A912-948C1609D659}\DisplayName
[3]{91AA4B1F-B918-4e0b-A304-F8D4EC5D7726}\DisplayName
[3]{E47EE8FB-ACC0-4608-859C-4E2851B18A6A}\DisplayName
[3]{71D03DD3-C6D9-4503-A1CC-FBA576F6CFE3}\DisplayName
[3]SymSetup.{C6F5B6CF-609C-428E-876F-CA83176C021B}\DisplayName
[3]SymSetup.{C6B28661-7910-442E-ADDD-72EAA8395380}\DisplayName
[3]SymSetup.{47D5D869-FE57-4F2F-A358-83CFAA7B4968}\DisplayName
[3]{4CFD624C-B66C-42AA-A47E-21A78D91E06C}\DisplayName
[3]{47D5D869-FE57-4F2F-A358-83CFAA7B4968}\DisplayName
[3]{F4C9398F-B6C6-4A4B-8B6D-795CD86F915D}\DisplayName
[3]{84555E03-F08E-4B9C-BE83-9D5E77190E89}\DisplayName
[3]{EDCD4CE3-DE92-49A9-87F9-FE09B2FBA16C}\DisplayName
[3]{68AE158E-38F9-4027-A757-A82B00E45D5C}\DisplayName
[3]{93DF5BBA-2992-482F-B11D-91027EC8AC7D}\DisplayName
[3]{3075C5C3-0807-4924-AF8F-FF27052C12AE}\DisplayName
[3]Norton AntiVirus\DisplayName
[3]{0698CECB-9072-47B1-AEA1-94CA350989B8}\DisplayName
[3]{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}\DisplayName
[3]{33CFCF98-F8D6-4549-B469-6F4295676D83}\DisplayName
[3]{473af7d0-b864-4699-9974-df570c5b6dce}\DisplayName
[3]{50e125d1-88e5-48ce-80ae-98ec9698e639}\DisplayName
[3]{5a633ed0-e5d7-4d65-ab8d-53ed43510284}\DisplayName
[3]{848AC794-8B81-440A-81AE-6474337DB527}\DisplayName
[3]{a011a1dc-7f1d-4ea8-bd11-0c5f9718e428}\DisplayName
[3]{BA4B71D1-898E-4306-AE87-8BA7A596F0ED}\DisplayName
[3]{BD12EB47-DBDF-11D3-BEEA-00A0CC272509}\DisplayName
[3]{D75D48AF-E2D5-49EF-9571-EE7AFB6565B4}\DisplayName
[3]{E9FA3047-0b15-4e19-85ce-ee7fc6e60f99}\DisplayName:
[3]{3E071930-C254-482A-B79B-722703FFAA9E}\DisplayName
[3]NIS\UninstallString
[3]NAV\UninstallString
[3]NAV-16-0-0\UninstallString
[3]SymSetup.{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}\UninstallString
[3]SymSetup.{C1C185CA-C531-49F5-A6FA-B838405A049D}\UninstallString
[3]SymSetup.{707D28BF-E145-4a9b-B97E-94FA586D05F3}\UninstallString
[3]SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777}\UninstallString
[3]SymSetupTemp.{2D617065-1C52-4240-B5BC-C0AE12157777}\UninstallString
[3]{6C28BDA4-6D99-4DD0-9F22-6A90A445E982}\UninstallString
[3]SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}\UninstallString
[3]SymSetup.{830D8CBD-C668-49e2-A969-C2C2106332E0}\UninstallString
[3]{3248E093-5288-4CA9-B3AB-11A675FEA1F9}\UninstallString
[3]{2CFECCAA-8CB0-459B-9636-40430DBC8951}\UninstallString
[3]{7D2B86CA-2D5D-469E-92ED-E56B62BD1D3C}\UninstallString
[3]{BD12EB47-DBDF-11D3-BEEA-00A0CC272509}\UninstallString
[3]{D6C64C68-F9F5-11D3-BEEA-00A0CC272509}\UninstallString
[3]Norton AntiVirus Corporate Edition 7.0 for Windows NT\UninstallString
[3]Norton AntiVirus Corporate Edition for Windows 7.0\UninstallString
[3]Norton AntiVirus Corporate Edition\UninstallString
[3]SymSetup.{71E7B3F5-CFAF-4C1E-B494-528E28707937}\UninstallString
[3]SymSetup.{B9807C3D-B3DD-41b7-8321-53DDB3A3A888}\UninstallString
[3]{43C3D832-AC96-463A-2003-1B8D1BFA252F}\UninstallString
[3]SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}\UninstallString
[3]SymSetup.{AED74EFF-83ED-4ed6-8413-285C24BCEB6E}\UninstallString
[3]{AFD2C5B5-BF78-47B6-9569-755448C0D0EE}\UninstallString
[3]SymSetup.{AED74EFF-83ED-4ed6-8413-285C24BCEB6E}\UninstallString
[3]{B7C61755-DB48-4003-948F-3D34DB8EAF69}\UninstallString
[3]{E36E8951-3C0E-4615-A912-948C1609D659}\UninstallString
[3]{91AA4B1F-B918-4e0b-A304-F8D4EC5D7726}\UninstallString
[3]{E47EE8FB-ACC0-4608-859C-4E2851B18A6A}\UninstallString
[3]{71D03DD3-C6D9-4503-A1CC-FBA576F6CFE3}\UninstallString
[3]SymSetup.{C6F5B6CF-609C-428E-876F-CA83176C021B}\UninstallString
[3]SymSetup.{C6B28661-7910-442E-ADDD-72EAA8395380}\UninstallString
[3]SymSetup.{47D5D869-FE57-4F2F-A358-83CFAA7B4968}\UninstallString
[3]{4CFD624C-B66C-42AA-A47E-21A78D91E06C}\UninstallString
[3]{47D5D869-FE57-4F2F-A358-83CFAA7B4968}\UninstallString
[3]{F4C9398F-B6C6-4A4B-8B6D-795CD86F915D}\UninstallString
[3]{84555E03-F08E-4B9C-BE83-9D5E77190E89}\UninstallString
[3]{EDCD4CE3-DE92-49A9-87F9-FE09B2FBA16C}\UninstallString
[3]{68AE158E-38F9-4027-A757-A82B00E45D5C}\UninstallString
[3]{93DF5BBA-2992-482F-B11D-91027EC8AC7D}\UninstallString
[3]{3075C5C3-0807-4924-AF8F-FF27052C12AE}\UninstallString
[3]Norton AntiVirus\UninstallString
[3]{0698CECB-9072-47B1-AEA1-94CA350989B8}\UninstallString
[3]{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}\UninstallString
[3]{33CFCF98-F8D6-4549-B469-6F4295676D83}\UninstallString
[3]{473af7d0-b864-4699-9974-df570c5b6dce}\UninstallString
[3]{50e125d1-88e5-48ce-80ae-98ec9698e639}\UninstallString
[3]{5a633ed0-e5d7-4d65-ab8d-53ed43510284}\UninstallString
[3]{848AC794-8B81-440A-81AE-6474337DB527}\UninstallString
[3]{a011a1dc-7f1d-4ea8-bd11-0c5f9718e428}\UninstallString
[3]{BA4B71D1-898E-4306-AE87-8BA7A596F0ED}\UninstallString
[3]{BD12EB47-DBDF-11D3-BEEA-00A0CC272509}\UninstallString
[3]{D75D48AF-E2D5-49EF-9571-EE7AFB6565B4}\UninstallString
[3]{E9FA3047-0b15-4e19-85ce-ee7fc6e60f99}\UninstallString
[3]{3E071930-C254-482A-B79B-722703FFAA9E}\UninstallString
[4]S-1-5-18\Products\AC581C1C135C5F946AAF8B8304A540D9\InstallProperties\UninstallString
[5]Symantec AntiVirus\ImagePath
[6]1D521E055E88EC8408EA89CE69896E93\InstallProperties\DisplayName
[6]0DE336A57D5E56D4BAD835DE34152048\InstallProperties\DisplayName


**************************************************************
* Fin Familia Symantec
**************************************************************


**************************************************************
*
* Familia McAfee
*
* McAfee VirusScan 8.5.0i Enterprise Edition
* McAfee VirusScan 8.0i Enterprise Edition
* McAfee VirusScan 7.X Enterprise Edition
*
* McAfee Managed VirusScan
*
* McAfee AntiSpyware v 2.x 2006
* McAfee Antispyware v 1.x 2005
* McAfee AntiSpam v 7.x 2006
* McAfee AntiSpam v 6.x 2005
* McAfee Personal Firewall Plus 2006 v.7.0
* McAfee Personal Firewall Plus 2005 v 6.x
* McAfee SpamKiller 6.x 2005
* McAfee Quickclean 5.x 2005
* McAfee Privacy Service 6.0
*
* McAfee Internet Security 2007 9.0 (por el McAfee Security Center)
* McAfee Internet Security 2006 8.0
* McAfee Internet Security 2004 6.0
* McAfee Internet Security 2003 5.0
* McAfee Internet Security 2002 4.0
*
* McAfee Security Center de McAfee Total Protection (Beta producto 2007)*
*
* McAfee VirusScan 12.x 2008 (por el Mcafee Security Center)
* McAfee VirusScan 11.X 2007 (por el McAfee Security Center)
* McAfee VirusScan 10.X 2006
* McAfee VirusScan 9.X 2005
* McAfee VirusScan 8.X 2004 Home & Professional editions
* McAfee VirusScan 7.X 2003 Home & Professional editions
* McAfee VirusScan 6.X 2002 Home & Professional editions
* McAfee VirusScan 5.2.0
* McAfee VirusScan 5.1.0
* McAfee VirusScan 5.0.0
* McAfee VirusScan 4.0.3
* McAfee VirusScan 4.0.2
* McAfee VirusScan 4.0.1
* McAfee VirusScan 4.5.1
* McAfee VirusScan 3.x
* McAfee VirusScan for w98-95 version
* McAfee NetShield v4.5.0
* McAfee NetShield v4.0.2
* McAfee NetShield v4.0.3
* Dr Solomon's NetShield v4.0.3
* Dr Solomon's Antivirus 8.5.0
* Dr Solomon's Antivirus 7.77.7 95,NT
* Dr Solomon's Antivirus 4.0.3 NT
* Dr Solomon´s Antivirus 4.0.2
* Dr Solomon´s Antivirus 4.0.1
* Dr Solomon's Anti-Virus Toolkit version 7.84
* Dr Solomon's Anti-Virus Toolkit version 7.94
* Dr Solomon's Anti-Virus Toolkit version 8.0.4
*
* VirusProtect 1.8.1 de Content Watch
***************************************************************

[#]CLAVES DEL REGISTRO MCAFEE VIRUS SCAN
[1]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
[2]HKLM\SYSTEM\CurrentControlSet\Services\
[3]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
[4]HKLM\SOFTWARE\
[1]NetShield NT\DisplayName\UninstallString
[1]{DBDCAA19-597C-11D3-89BB-006008C7D0F2}\UninstallString
[1]{63CB7620-B423-4BF1-A7E4-75BB8B64740E}\UninstallString
[1]{0E17F984-880D-11D3-82CA-00C04F656306}\UninstallString
[1]McAfee VirusScan\UninstallString
[1]VirusScan NT\UninstallString
[1]McAfee VirusScan\UninstallString
[1]VirusScan\UninstallString
[1]Dr Solomon's NetShield NT\UninstallString
[1]Dr Solomon's AVTK\UninstallString
[1]Dr Solomon's VirusScan NT\UninstallString
[1]Dr Solomon's VirusScan\UninstallString
[1]{63CB7620-B423-4BF1-A7E4-75BB8B64740E}\UninstallString
[1]NetShield NT\DisplayName
[1]{DBDCAA19-597C-11D3-89BB-006008C7D0F2}\DisplayName
[1]{0E17F984-880D-11D3-82CA-00C04F656306}\DisplayName
[1]McAfee VirusScan\DisplayName
[1]VirusScan NT\DisplayName
[1]McAfee VirusScan\DisplayName
[1]VirusScan\DisplayName
[1]Dr Solomon's NetShield NT\DisplayName
[1]Dr Solomon's AVTK\DisplayName
[1]Dr Solomon's VirusScan NT\DisplayName
[1]Dr Solomon's VirusScan\DisplayName
[1]{63CB7620-B423-4BF1-A7E4-75BB8B64740E}\DisplayName
[1]NetShield NT\DisplayName\UninstallString
[1]{DBDCAA19-597C-11D3-89BB-006008C7D0F2}\UninstallString
[1]{63CB7620-B423-4BF1-A7E4-75BB8B64740E}\UninstallString
[1]{0E17F984-880D-11D3-82CA-00C04F656306}\UninstallString
[1]McAfee VirusScan\UninstallString
[1]VirusScan NT\UninstallString
[1]McAfee VirusScan\UninstallString
[1]VirusScan\UninstallString
[1]Dr Solomon's NetShield NT\UninstallString
[1]Dr Solomon's AVTK\UninstallString
[1]Dr Solomon's VirusScan NT\UninstallString
[1]Dr Solomon's VirusScan\UninstallString
[1]{63CB7620-B423-4BF1-A7E4-75BB8B64740E}\UninstallString
[1]{35C03C04-3F1F-42C2-A989-A757EE691F65}\UninstallString
[1]McAfee Uninstall Utility\UninstallString
[1]{56D45213-8AD9-46C5-A393-EB21A760DD43}\UninstallString
[1]{99F690A2-158D-11D1-A116-444553540000}\UninstallString
[1]{5DF3D1BB-894E-4DCD-8275-159AC9829B43}\UninstallString
[1]{59224777-298D-4E9C-9AEB-4A91BDA01B27}\UninstallString
[1]{56D45213-8AD9-46C5-A393-EB21A760DD43}\UninstallString
[1]{DCB2928E-61F6-11D6-B259-00C04FF4B435}\UninstallString
[1]{E4DC62CE-5F95-11D6-B254-00C04FF4B435}\UninstallString
[1]{87AEFD84-BC0D-11D4-B885-00508B022A51}\UninstallString
[1]{39C30C0D-01B0-4AF8-8FB9-18B749CD3542}\UninstallString
[1]{46F56E0F-7AFE-4743-95D4-52E395C656D2}\UninstallString
[1]{EB754707-7263-4E79-999E-76DF1B61AAEE}\UninstallString
[1]{8DBA3AE7-784D-4EAA-A3FC-337FFB680711}\UninstallString
[1]{9252D0A9-AA37-4D11-BF43-BFE9160DBA28}\UninstallString
[1]{90F9A584-0D19-495C-9001-ABE2B103AAE9}\UninstallString
[1]{D79878A5-B7B9-411F-BF35-3EE10A752A2A}\UninstallString
[1]{8F7CDD24-8E6D-4962-8238-C2CFA3E792DA}\UninstallString
[1]{C41316A0-CE46-420A-8954-E8D8F1A7DDF1}\UninstallString
[1]{BCFDAAB8-6556-430F-A61E-B30A3FD4A597}\UninstallString
[1]{FFC3D741-2DC7-4EB0-896B-BCE6ED43F5F5}\UninstallString
[1]{0E17F984-880D-11D3-82CA-00C04F656306}\UninstallString
[1]{63CB7620-B423-4BF1-A7E4-75BB8B64740E}\UninstallString
[1]{5B01817B-53B2-420D-8EF8-FD5AB339E300}\UninstallString
[1]{1912F734-6580-4620-8AFD-ECCCEA19CDE2}\UninstallString
[1]{FF2F250F-472B-464B-977D-BD364E86D7C3}\UninstallString
[1]{DBB73BF2-ED76-4877-9DE0-349213AA1786}\UninstallString
[1]{EA7A4164-B32E-44B9-B4D0-5D2B3C4ADCB0}\UninstallString
[1]{3A740576-787F-490C-B1FE-9FCF52BCE39C}\UninstallString
[1]{B653B7F4-1DD6-4BB0-AC1F-CB257031BEC6}\UninstallString
[1]{3D0E8C72-BD7F-4E14-A064-8FE4558D2B07}\UninstallString
[1]{833F4F43-8E5D-489A-B343-FE135B686F21}\UninstallString
[1]{96BEF910-ECAF-475C-83FA-2BC2ABFAD866}\UninstallString
[1]{628E82DB-2376-4A2C-A319-77A3FD202D01}\UninstallString
[1]{C3739D9D-1D68-4C0A-BABB-CDB33BAD0536}\UninstallString
[1]{FD13B4EF-01DC-45BE-8C7B-64721FA0A381}\UninstallString
[1]{D8D44CA1-026E-49A2-9B25-20BE30CBC55C}\UninstallString
[1]VirusScan Online\UninstallString
[1]{35C03C04-3F1F-42C2-A989-A757EE691F65}\DisplayName
[1]{56D45213-8AD9-46C5-A393-EB21A760DD43}\DisplayName
[1]{99F690A2-158D-11D1-A116-444553540000}\DisplayName
[1]{5DF3D1BB-894E-4DCD-8275-159AC9829B43}\DisplayName
[1]{59224777-298D-4E9C-9AEB-4A91BDA01B27}\DisplayName
[1]{56D45213-8AD9-46C5-A393-EB21A760DD43}\DisplayName
[1]{DCB2928E-61F6-11D6-B259-00C04FF4B435}\DisplayName
[1]{E4DC62CE-5F95-11D6-B254-00C04FF4B435}\DisplayName
[1]{87AEFD84-BC0D-11D4-B885-00508B022A51}\DisplayName
[1]{39C30C0D-01B0-4AF8-8FB9-18B749CD3542}\DisplayName
[1]{46F56E0F-7AFE-4743-95D4-52E395C656D2}\DisplayName
[1]{EB754707-7263-4E79-999E-76DF1B61AAEE}\DisplayName
[1]{8DBA3AE7-784D-4EAA-A3FC-337FFB680711}\DisplayName
[1]{9252D0A9-AA37-4D11-BF43-BFE9160DBA28}\DisplayName
[1]{90F9A584-0D19-495C-9001-ABE2B103AAE9}\DisplayName
[1]{D79878A5-B7B9-411F-BF35-3EE10A752A2A}\DisplayName
[1]{8F7CDD24-8E6D-4962-8238-C2CFA3E792DA}\DisplayName
[1]{C41316A0-CE46-420A-8954-E8D8F1A7DDF1}\DisplayName
[1]{BCFDAAB8-6556-430F-A61E-B30A3FD4A597}\DisplayName
[1]{FFC3D741-2DC7-4EB0-896B-BCE6ED43F5F5}\DisplayName
[1]{0E17F984-880D-11D3-82CA-00C04F656306}\DisplayName
[1]{63CB7620-B423-4BF1-A7E4-75BB8B64740E}\DisplayName
[1]{5B01817B-53B2-420D-8EF8-FD5AB339E300}\DisplayName
[1]{1912F734-6580-4620-8AFD-ECCCEA19CDE2}\DisplayName
[1]{FF2F250F-472B-464B-977D-BD364E86D7C3}\DisplayName
[1]{DBB73BF2-ED76-4877-9DE0-349213AA1786}\DisplayName
[1]{EA7A4164-B32E-44B9-B4D0-5D2B3C4ADCB0}\DisplayName
[1]{3A740576-787F-490C-B1FE-9FCF52BCE39C}\DisplayName
[1]{B653B7F4-1DD6-4BB0-AC1F-CB257031BEC6}\DisplayName
[1]{3D0E8C72-BD7F-4E14-A064-8FE4558D2B07}\DisplayName
[1]{833F4F43-8E5D-489A-B343-FE135B686F21}\DisplayName
[1]{96BEF910-ECAF-475C-83FA-2BC2ABFAD866}\DisplayName
[1]{628E82DB-2376-4A2C-A319-77A3FD202D01}\DisplayName
[1]{C3739D9D-1D68-4C0A-BABB-CDB33BAD0536}\DisplayName
[1]{FD13B4EF-01DC-45BE-8C7B-64721FA0A381}\DisplayName
[1]{D8D44CA1-026E-49A2-9B25-20BE30CBC55C}\DisplayName
[1]VirusScan Online\DisplayName
[1]{35C03C04-3F1F-42C2-A989-A757EE691F65}\UninstallString
[1]McAfee Uninstall Utility\UninstallString
[1]{56D45213-8AD9-46C5-A393-EB21A760DD43}\UninstallString
[1]{99F690A2-158D-11D1-A116-444553540000}\UninstallString
[1]{5DF3D1BB-894E-4DCD-8275-159AC9829B43}\UninstallString
[1]{59224777-298D-4E9C-9AEB-4A91BDA01B27}\UninstallString
[1]{56D45213-8AD9-46C5-A393-EB21A760DD43}\UninstallString
[1]{DCB2928E-61F6-11D6-B259-00C04FF4B435}\UninstallString
[1]{E4DC62CE-5F95-11D6-B254-00C04FF4B435}\UninstallString
[1]{87AEFD84-BC0D-11D4-B885-00508B022A51}\UninstallString
[1]{39C30C0D-01B0-4AF8-8FB9-18B749CD3542}\UninstallString
[1]{46F56E0F-7AFE-4743-95D4-52E395C656D2}\UninstallString
[1]{EB754707-7263-4E79-999E-76DF1B61AAEE}\UninstallString
[1]{8DBA3AE7-784D-4EAA-A3FC-337FFB680711}\UninstallString
[1]{9252D0A9-AA37-4D11-BF43-BFE9160DBA28}\UninstallString
[1]{90F9A584-0D19-495C-9001-ABE2B103AAE9}\UninstallString
[1]{D79878A5-B7B9-411F-BF35-3EE10A752A2A}\UninstallString
[1]{8F7CDD24-8E6D-4962-8238-C2CFA3E792DA}\UninstallString
[1]{C41316A0-CE46-420A-8954-E8D8F1A7DDF1}\UninstallString
[1]{BCFDAAB8-6556-430F-A61E-B30A3FD4A597}\UninstallString
[1]{FFC3D741-2DC7-4EB0-896B-BCE6ED43F5F5}\UninstallString
[1]{0E17F984-880D-11D3-82CA-00C04F656306}\UninstallString
[1]{63CB7620-B423-4BF1-A7E4-75BB8B64740E}\UninstallString
[1]{5B01817B-53B2-420D-8EF8-FD5AB339E300}\UninstallString
[1]{1912F734-6580-4620-8AFD-ECCCEA19CDE2}\UninstallString
[1]{FF2F250F-472B-464B-977D-BD364E86D7C3}\UninstallString
[1]{DBB73BF2-ED76-4877-9DE0-349213AA1786}\UninstallString
[1]{EA7A4164-B32E-44B9-B4D0-5D2B3C4ADCB0}\UninstallString
[1]{3A740576-787F-490C-B1FE-9FCF52BCE39C}\UninstallString
[1]{B653B7F4-1DD6-4BB0-AC1F-CB257031BEC6}\UninstallString
[1]{3D0E8C72-BD7F-4E14-A064-8FE4558D2B07}\UninstallString
[1]{833F4F43-8E5D-489A-B343-FE135B686F21}\UninstallString
[1]{96BEF910-ECAF-475C-83FA-2BC2ABFAD866}\UninstallString
[1]{628E82DB-2376-4A2C-A319-77A3FD202D01}\UninstallString
[1]{C3739D9D-1D68-4C0A-BABB-CDB33BAD0536}\UninstallString
[1]{FD13B4EF-01DC-45BE-8C7B-64721FA0A381}\UninstallString
[1]{D8D44CA1-026E-49A2-9B25-20BE30CBC55C}\UninstallString
[1]VirusScan Online\UninstallString
[2]mfeavfk\ImagePath
[2]mfeapfk\ImagePath
[2]mfebopk\ImagePath
[2]NaiFiltr\ImagePath
[2]NaiAvFilter1\ImagePath
[2]VxD\VshInit\StaticVxd
[3]VirusScan Online
[4]Dr Solomon's Software\Anti-Virus\UninstallString
[4]Microsoft\Windows\CurrentVersion\RunServices\McAfeeVirusScanService
[4]Microsoft\Windows\CurrentVersion\RunServices\McShld9x
[4]McAfee.com\Virusscan Online\Install Dir
[4]McAfee\VirusScan\CurrentVersion\Location
[4]Network Associates\TVD\VirusScan Enterprise\CurrentVersion\szInstallDir

[#]CLAVES DEL REGISTRO DE MCAFEE PRIVACY SERVICE

[1]McAfee Privacy Service\UninstallString
[1]{983DD781-10DA-4C25-8706-9E152DFCEF90\UninstallString
[1]McAfee Privacy Service\DisplayName
[1]{983DD781-10DA-4C25-8706-9E152DFCEF90\DisplayName
[1]McAfee Uninstall Utility\UninstallString
[1]McAfee Privacy Service\UninstallString
[1]{983DD781-10DA-4C25-8706-9E152DFCEF90\UninstallString

[#]CLAVES DEL REGISTRO DE MCAFEE ANTISPAM
[1]McAfee SpamKiller\UninstallString
[1]McAfee SpamKiller\DisplayName
[1]McAfee Uninstall Utility\UninstallString
[1]McAfee SpamKiller\UninstallString

[#]CLAVES DEL REGISTRO DE MCAFEE FIREWALL
[1]McAfee Personal Firewall Plus\UninstallString
[1]{4471FF45-62BD-11D6-B259-00C04FF4B435}\UninstallString
[1]{9E0FB790-5971-41F3-A1C3-1CF9E153FF2A}\UninstallString
[1]McAfee Personal Firewall Plus\DisplayName
[1]{4471FF45-62BD-11D6-B259-00C04FF4B435}\DisplayName
[1]{718CF0D3-DCDF-428E-9F6C-258F065C8D6D}\DisplayName
[1]{9E0FB790-5971-41F3-A1C3-1CF9E153FF2A}\DisplayName
[1]McAfee Uninstall Utility\UninstallString
[1]McAfee Personal Firewall Plus\UninstallString
[1]{4471FF45-62BD-11D6-B259-00C04FF4B435}\UninstallString
[1]{718CF0D3-DCDF-428E-9F6C-258F065C8D6D}\UninstallString
[1]{9E0FB790-5971-41F3-A1C3-1CF9E153FF2A}\UninstallString
[1]McAfee Personal Firewall Plus\DisplayName
[1]{4471FF45-62BD-11D6-B259-00C04FF4B435}\DisplayName
[1]{718CF0D3-DCDF-428E-9F6C-258F065C8D6D}\DisplayName
[1]McAfee Uninstall Utility\UninstallString
[1]McAfee Personal Firewall Plus\UninstallString
[1]{4471FF45-62BD-11D6-B259-00C04FF4B435}\UninstallString
[1]{718CF0D3-DCDF-428E-9F6C-258F065C8D6D}\UninstallString
[2]FireSvc\ImagePath

[#]CLAVES DEL REGISTRO DE MCAFEE ANTISPYWARE
[1]McAfee AntiSpyware\UninstallString
[1]{6E234F6E-0828-405B-8776-2777EA315945}\UninstallString
[1]McAfee AntiSpyware\DisplayName
[1]{6E234F6E-0828-405B-8776-2777EA315945}\DisplayName
[1]McAfee Uninstall Utility\UninstallString
[1]McAfee AntiSpyware\UninstallString
[1]{6E234F6E-0828-405B-8776-2777EA315945}\UninstallString

[#]CLAVES DEL REGISTRO DE MCAFEE QUICKCLEAN
[1]{60BA4569-596D-45BE-97E7-15C340273B7A}\UninstallString
[1]{124E82AF-314C-49D7-853A-5D0C77AC44A9}\UninstallString
[1]{124E82AF-314C-49D7-853A-5D0C77AC44A9}\DisplayName
[1]{60BA4569-596D-45BE-97E7-15C340273B7A}\DisplayName
[1]{124E82AF-314C-49D7-853A-5D0C77AC44A9}\UninstallString
[1]{60BA4569-596D-45BE-97E7-15C340273B7A}\UninstallString

[#]CLAVES DEL REGISTRO DE MCAFEE SECURITY CENTER
[1]Mcafee SecurityCenter\UninstallString
[1]MSC\UninstallString
[1]Mcafee SecurityCenter\DisplayName
[1]MSC\DisplayName
[1]McAfee Uninstall Utility\UninstallString
[1]Mcafee SecurityCenter\UninstallString
[1]MSC\UninstallString

[#]CLAVES DEL REGISTRO DE MCAFEE MANAGED VIRUSSCAN
[1]MVS
[1]MVS\DisplayName
[1]MVS\UninstallString

[#]CLAVES DEL REGISTRO DE VIRUS PROTECT(CONTENT WATCH)
[2]Mcshield\ImagePath
[1]VP99988_is1\UninstallString
[1]VP99988_is1\DisplayName
[1]VP99988_is1\UninstallString

[#]SERVICIOS MAS COMUNES DE MCAFEE ANTIVIRUS
McAfeeFramework, McShield, McTaskManager

[#]PROCESOS MAS COMUNES DE MCAFEE ANTIVIRUS
UpdaterUI.exe, TBMon.exe, shstat.exe.



**************************************************************
*
* Familia Kaspersky
*
* Kaspersky Internet Security 2009 - 8.0.0.357
* Kaspersky Antivirus 2009 - 8.0.0.357
* Kaspersky Internet Security 7.0.0.85 Beta
* Kaspersky Antivirus 7.0.0.85 Beta
* Kaspersky Internet Security 6.0.2.509 Beta (Windows Vista)
* Kaspersky Antivirus 6.0.2.509 Beta (windows Vista)
* Kaspersky Antivirus 2006 6.0.12.167 Beta
* Kaspersky Internet Security 6.0 (6.0.1.335)
* Kaspersky Antivirus 6.0 (6.0.1.335)
* Kaspersky Security Suite 1.53 (detec y desinst. sólo el antivirus)
* Kaspersky Anti-Virus for Windows Workstation 5.0
* Kaspersky Anti-Virus Personal Pro 5.0
* Kaspersky Anti-Virus Personal 5.0
* Kaspersky Anti-Virus Lite 4.5 (4.5.0090)
* Kaspersky Anti-Virus 4.5 Wks
* Kaspersky Anti-Virus 4.5 Pers
* Kaspersky Anti-Virus 4.5 Pers Pro
* Kaspersky Anti-Virus 4.0 Wks
*
* CyberScrub Antivirus (usa el motor de kaspersky )
*
* MIcroworld eScan Corporate Edition 9.0.722.1
* MIcroworld eScan Internet Security Suite 9.0.718.1
* MIcroworld eScan Professional 9.0.722.1
* MIcroworld eScan Anti-Virus 9.0.716.1
* Microworld eScan Internet Security Suite 8.0 (usa motor Kaspersky)
* Microworld eScan 2006 Professional Edition
* Microworld eScan 2006 Internet Security Suite
* Microworld eScan 2003 Professional Edition
* Microworld eScan 2003 Virus Control
* Microworld eScan 2003 Corporate Edition
*
* AoL Active Virus Shield (usa el motor de Kaspersky)
*
* Zone Alarm Security Suite 7.0 (Antivirus usa motor Kaspersky)
* Zone Alarm Antivirus 7.0
*
* Segurmatica antivirus
***************************************************************

[#]CLAVES DEL REGISTRO DE KASPERSKY AV
[1]HKLM\SYSTEM\CurrentControlSet\Services\
[2]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
[3]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
[4]HKLM\SOFTWARE\
[1]Klif\ImagePath
[1]kl1\ImagePath
[1]AVKService\ImagePath
[1]AVP\ImagePath
[X]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\AVP
[1]Klmc\ImagePath
[2]KAVMonitorService\ImagePath
[2]AVPCC\ImagePath
[2]{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}\UninstallString
[2]{6580C5A3-2336-4EC5-85F1-3448C5F6208A}\UninstallString
[2]ZoneAlarm Anti-virus\UninstallString
[2]ZoneAlarm Security Suite\UninstallString
[X]HKLM\SOFTWARE\MicroWorld\eScan for Windows\Path
[2]InstallWIX_{C774410D-3EF9-4DE7-AC01-332613163ECF}\UninstallString
[2]InstallWIX_{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}\UninstallString
[2]InstallWIX_{75193929-9A52-4CA4-98DE-8C7296940920}\UninstallString
[2]eScan Corporate for Windows_is1\UninstallString
[2]eScan Corporate para Windows_is1\UninstallString
[2]eScan Internet Security for Windows_is1\UninstallString
[2]eScan Internet Security para Windows_is1\UninstallString
[2]eScan Professional para Windows_is1\UninstallString
[2]eScan Professional for Windows_is1\UninstallString
[2]eScan Pro for Windows_is1\UninstallString
[2]eScan Pro para Windows_is1\UninstallString
[2]eScan Virus Control (VC) for Windows_is1\UninstallString
[2]eScan Virus Control (VC) para Windows_is1\UninstallString
[2]eScan Anti-Virus (AV) for Windows_is1\UninstallString
[2]eScan Anti-Virus (AV) para Windows_is1\UninstallString
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\UninstallString
[2]InstallWIX_{D0DCD54F-C829-41A5-AF32-71E632BB0E2C}\UninstallString
[2]InstallWIX_{75193929-9A52-4CA4-98DE-8C7296940920}\UninstallString
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\UninstallString
[2]InstallShield_{79EC1ACB-FBB2-4E32-B8EC-CF8CC14F0785}\UninstallString
[2]InstallShield_{90467142-F6B5-48B5-9A46-AFE61C4598CA}\UninstallString
[2]Kaspersky Anti-Virus 2006 Beta_is1\UninstallString
[2]Kaspersky Anti-Virus Personal\UninstallString
[2]Kaspersky Anti-Virus Personal Pro\UninstallString
[2]{7F5E2A5A-92C5-4DF1-808D-1688C50CBFEE}\UninstallString
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\UninstallString
[2]{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}\DisplayName
[2]{6580C5A3-2336-4EC5-85F1-3448C5F6208A}\DisplayName
[2]ZoneAlarm Anti-virus\DisplayName
[2]ZoneAlarm Security Suite\DisplayName
[2]InstallWIX_{C774410D-3EF9-4DE7-AC01-332613163ECF}\DisplayName
[2]InstallWIX_{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}\DisplayName
[2]InstallWIX_{75193929-9A52-4CA4-98DE-8C7296940920}\DisplayName
[2]eScan Corporate for Windows_is1\DisplayName
[2]eScan Corporate para Windows_is1\DisplayName
[2]eScan Internet Security for Windows_is1\DisplayName
[2]eScan Internet Security para Windows_is1\DisplayName
[2]eScan Professional para Windows_is1\DisplayName
[2]eScan Professional for Windows_is1\DisplayName
[2]eScan Pro for Windows_is1\DisplayName
[2]eScan Pro para Windows_is1\DisplayName
[2]eScan Virus Control (VC) for Windows_is1\DisplayName
[2]eScan Virus Control (VC) para Windows_is1\DisplayName
[2]eScan Anti-Virus (AV) for Windows_is1\DisplayName
[2]eScan Anti-Virus (AV) para Windows_is1\DisplayName
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\DisplayName
[2]InstallWIX_{D0DCD54F-C829-41A5-AF32-71E632BB0E2C}\DisplayName
[2]InstallWIX_{75193929-9A52-4CA4-98DE-8C7296940920}\DisplayName
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\DisplayName
[2]InstallShield_{79EC1ACB-FBB2-4E32-B8EC-CF8CC14F0785}\DisplayName
[2]InstallShield_{90467142-F6B5-48B5-9A46-AFE61C4598CA}\DisplayName
[2]Kaspersky Anti-Virus 2006 Beta_is1\DisplayName
[2]Kaspersky Anti-Virus Personal\DisplayName
[2]Kaspersky Anti-Virus Personal Pro\DisplayName
[2]{7F5E2A5A-92C5-4DF1-808D-1688C50CBFEE}\DisplayName
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\DisplayName
[2]{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}\UninstallString
[2]{6580C5A3-2336-4EC5-85F1-3448C5F6208A}\UninstallString
[2]ZoneAlarm Anti-virus\UninstallString
[2]ZoneAlarm Security Suite\UninstallString
[2]InstallWIX_{C774410D-3EF9-4DE7-AC01-332613163ECF}\UninstallString
[2]InstallWIX_{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}\UninstallString
[2]InstallWIX_{75193929-9A52-4CA4-98DE-8C7296940920}\UninstallString
[2]eScan Corporate for Windows_is1\UninstallString
[2]eScan Corporate para Windows_is1\UninstallString
[2]eScan Internet Security for Windows_is1\UninstallString
[2]eScan Internet Security para Windows_is1\UninstallString
[2]eScan Professional para Windows_is1\UninstallString
[2]eScan Professional for Windows_is1\UninstallString
[2]eScan Pro for Windows_is1\UninstallString
[2]eScan Pro para Windows_is1\UninstallString
[2]eScan Virus Control (VC) for Windows_is1\UninstallString
[2]eScan Virus Control (VC) para Windows_is1\UninstallString
[2]eScan Anti-Virus (AV) for Windows_is1\UninstallString
[2]eScan Anti-Virus (AV) para Windows_is1\UninstallString
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\UninstallString
[2]InstallWIX_{D0DCD54F-C829-41A5-AF32-71E632BB0E2C}\UninstallString
[2]InstallWIX_{75193929-9A52-4CA4-98DE-8C7296940920}\UninstallString
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\UninstallString
[2]InstallShield_{79EC1ACB-FBB2-4E32-B8EC-CF8CC14F0785}\UninstallString
[2]InstallShield_{90467142-F6B5-48B5-9A46-AFE61C4598CA}\UninstallString
[2]Kaspersky Anti-Virus 2006 Beta_is1\UninstallString
[2]Kaspersky Anti-Virus Personal\UninstallString
[2]Kaspersky Anti-Virus Personal Pro\UninstallString
[2]{7F5E2A5A-92C5-4DF1-808D-1688C50CBFEE}\UninstallString
[2]InstallShield_{0906B442-D0EC-4FE2-B666-95C82EF8B8A6}\UninstallString
[2]SegAVSvc\imagePath
[X]HKLM\SOFTWARE\SEGURMATICA\Segurmatica Antivirus\Client\DirInstall
[2]{638B6394-5EC3-40F5-984D-663D0DF7184A}\DisplayName
[2]{638B6394-5EC3-40F5-984D-663D0DF7184A}\UninstallString

[#]SERVICIOS MAS COMUNES DE AVAST ANTIVIRUS
AVP

[#]PROCESOS MAS COMUNES DE AVAST ANTIVIRUS
Avp.exe



**************************************************************
*
* Familia NOD32
*
* Eset Virus Scan Home Edition 3.0
* Eset Smart Security Home Edition 3.0
* Eset Virus Scan Business Edition 3.0
* Eset Smart Security Business Edition 3.0
* Eset NOD32 3.0 RC1
* Eset NOD32 2.70.16 (Windows Vista)
* Eset NOD32 2.X - Ultima NOD32 2.51.26 - 32 y 64 bits
***************************************************************

[#]CLAVES DEL REGISTRO DE NOD32
HKLM\SYSTEM\CurrentControlSet\Services\eamon\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\NOD32krn\ImagePath
HKLM\System\CurrentControlSet\Services\VxD\AMON\StaticVxD
HKLM\SOFTWARE\Eset\Eset Security\CurrentVersion\Info\InstallDir
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NOD32\UninstallString
HKLM\SOFTWARE\Eset\Eset Security\CurrentVersion\Info\ProductName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NOD32\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{73DD62F9-7B11-4431-B38A-DFAD02FCB5F3}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{944BFDEB-868F-4943-A37C-2852C7D9824A}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83187D34-F9E0-42F0-BFB5-452A3DDC5A70}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BB703122-AF65-4AD9-BCA0-273E165DABEE}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A1350B64-1AF8-497B-AC07-307DF67FB8D4}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C23C7DB5-9598-495C-A44A-175ED4927528}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D31C2E0D-239C-4E9F-A938-117AFDBA1218}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NOD32\UninstallString

[#]SERVICIOS MAS COMUNES DE NOD32 ANTIVIRUS
Nod32Krn

[#]PROCESOS MAS COMUNES DE NOD32 ANTIVIRUS
Nod32Krn.exe, Nod32kui.exe



**************************************************************
*
* Familia Microsoft
*
* Windows OneCare Live
***************************************************************

[#]CLAVES DEL REGISTRO DE WINDOWS ONECARELIVE
HKLM\SOFTWARE\Microsoft\OneCare Protection\InstallLocation
HKLM\SYSTEM\CurrentControlSet\Services\winss\ImagePath
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinSS\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D07A8E7E-D324-4945-BA8C-E532AD008FF3}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinSS\UninstallString


**************************************************************
*
* Familia PCCillin
*
* Trend Micro Internet Security Pro 2008
* Trend Micro Internet Security 2008
* Trend Micro Antivirus plus Antispyware 2008
* PCCillin 16, 2008 Beta
* PCCillin 15, 2007
* PCCillin 14, 2006
* PCCillin 12, 2005
* PCCillin 11, 2004
* PCCillin 10, 2003
* PCCillin 9, 2002
* PCCillin 8, 2001
* PCCillin 7,7.5, 2000
* Trend Micro AntiSpyware 3.0
* Trend Micro OfficeScan Client 7.x 8.x
***************************************************************

[#]CLAVES DEL REGISTRO DE PCCILLING
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{319D9385-EEC1-4ae5-BFD1-C5DE1E063F30}
HKLM\SYSTEM\CurrentControlSet\Services\Tmntsrv
HKLM\SYSTEM\CurrentControlSet\Services\Tmfilter
HKLM\SYSTEM\CurrentControlSet\Services\Tmpreflt
HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Trend Realtime Service
HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TMNTSRV
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\PCCIOMON.EXE
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A621B45A-D138-4A95-BE10-7CABA05EF94E}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{23D6060D-8746-4c8e-B62E-4B63931AF4DD}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{71E4D679-20AB-41E9-A350-D5BF92088FFE}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BB4B6355-D38A-492C-873B-A1B2CF6C3832}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{319D9385-EEC1-4ae5-BFD1-C5DE1E063F30}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA8C73AA-3D75-44C9-87A2-8E945FC5FEE6}\Displayname
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3943C4CF-AC42-4E00-8824-25159B8478F1}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3ACF3AF1-8DBC-4EFB-AF03-37E212DDA83C}\Displayname
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7698EDA5-A90F-4205-99CB-8FF6F9048ED9}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA7FDA46-DFA8-4748-8F2E-8864E545735B}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C90F3E44-3BF6-11D4-A110-00500405613A}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trend PC-cillin 7\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trend PC-cillin 7.5\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trend PC-cillin 2000\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\³²Ù½ÊÞ½À°2000\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Æ®·»µ�EPC-½Ç¸° 2000\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A861F26-E6A5-4ABE-A590-8EE405C1B612}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A839294B-70A9-11D5-9F5A-0050DAD742CD}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trend PC-cillin 98\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OfficeScanNT\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OfficeScan95\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A621B45A-D138-4A95-BE10-7CABA05EF94E}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{23D6060D-8746-4c8e-B62E-4B63931AF4DD}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{71E4D679-20AB-41E9-A350-D5BF92088FFE}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BB4B6355-D38A-492C-873B-A1B2CF6C3832}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{319D9385-EEC1-4ae5-BFD1-C5DE1E063F30}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA8C73AA-3D75-44C9-87A2-8E945FC5FEE6}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3943C4CF-AC42-4E00-8824-25159B8478F1}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3ACF3AF1-8DBC-4EFB-AF03-37E212DDA83C}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7698EDA5-A90F-4205-99CB-8FF6F9048ED9}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA7FDA46-DFA8-4748-8F2E-8864E545735B}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C90F3E44-3BF6-11D4-A110-00500405613A}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trend PC-cillin 7\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trend PC-cillin 7.5\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trend PC-cillin 2000\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\³²Ù½ÊÞ½À°2000\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Æ®·»µ�EPC-½Ç¸° 2000\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A861F26-E6A5-4ABE-A590-8EE405C1B612}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A839294B-70A9-11D5-9F5A-0050DAD742CD}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trend PC-cillin 98\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OfficeScanNT\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OfficeScan95\UninstallString

[#]SERVICIOS MAS COMUNES DE TRENDMICRO ANTIVIRUS
pcctlcom, tmpfw, pcscnsrv, tmproxy, tmntsrv.



**************************************************************
*
* Familia eTrust Antivirus (eTrust, antes InoculateIT y Zone Alarm)
*
* CA eTrust Internet Security Suite Plus 2008
* CA eTrust Antivirus plus AntiSpyware 2008 v 9.0
* CA eTrust Antivirus 2008 v 9.0
* CA eTrust Internet Security 2007 Suite 3.0
* CA eTrust Antivirus 2007 v 8.x
* eTrust Internet Security Suite 2.0.1.0
* eTrust Antivirus 2006 v 7.1.9.1
* eTrust Antivirus 2005 v 7.1.0912
* eTrust Antivirus 7.X - Deteccin 9x por vetmon9x y en NT por Inort
* eTrust Antivirus 7.0.6.7 - Desinstalación VETWIN32Vp5
* EZ ARMOUR antivirus 6.2.1 - Detección 9x vetmon9x y en NT por CAISafe
* ZoneAlarm with antivirus - Detección 9x vetmon9x
* ZoneAlarm Security Suite - Detección 9x vetmon9x
* CA eTrust InoculateIT 6.0
* CA InocuLAN 5
* CA InocuLAN_NT 4.53 (son versiones antiguas de CA)
* CA InocuLAN_9.x 4.53
***************************************************************

[#]CLAVES DEL REGISTRO DE eTRUST ANTIVIRUS
HKLM\SYSTEM\CurrentControlSet\Services\InoRT
HKLM\SYSTEM\CurrentControlSet\Services\CAISafe
HKLM\Software\ComputerAssociates\CA-InstalledITProducts\InoculateIT
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust InoculateIT
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InoculateIT for Windows NT
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InoculateIT
HKLM\System\CurrentControlSet\Services\VxD\VETMON9X
HKLM\System\CurrentControlSet\Services\VxD\Wimmun32
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Suite Personal\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cciss_av\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A73227F9-C4B0-4018-B0B0-4DCAF791A29E}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm Anti-virus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm Security Suite\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust EZ Armor\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust EZ Armor\eTrust EZ Antivirus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CA eTrust Antivirus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Antivirus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VETWIN32Vp5\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Antivirus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99747F0D-D4F8-4877-9CA0-4AE96D963633}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FE184E30-8586-43B0-B2E3-5FE2B157BC7D}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{653FDA85-1ED5-4F12-9237-E750A28289A6}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CC55BD24-C1A6-4397-8EA3-2F30E74BDA2B}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6A120E99-3123-4CB2-9A02-D24784F4BC8C}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A5E011C-8479-4A2A-896C-C7C86CAF59DA}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99FE8443-D63A-469A-B280-0D34744FCACC}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust InoculateIT\UnsintallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InoculateIT for Windows NT\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InoculateIT\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Suite Personal\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cciss_av\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A73227F9-C4B0-4018-B0B0-4DCAF791A29E}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm Anti-virus\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm Security Suite\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust EZ Armor\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust EZ Armor\eTrust EZ Antivirus\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CA eTrust Antivirus\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Antivirus\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VETWIN32Vp5\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Antivirus\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99747F0D-D4F8-4877-9CA0-4AE96D963633}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FE184E30-8586-43B0-B2E3-5FE2B157BC7D}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{653FDA85-1ED5-4F12-9237-E750A28289A6}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CC55BD24-C1A6-4397-8EA3-2F30E74BDA2B}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6A120E99-3123-4CB2-9A02-D24784F4BC8C}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A5E011C-8479-4A2A-896C-C7C86CAF59DA}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99FE8443-D63A-469A-B280-0D34744FCACC}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust InoculateIT\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InoculateIT for Windows NT\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InoculateIT\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Suite Personal\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cciss_av\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A73227F9-C4B0-4018-B0B0-4DCAF791A29E}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm Anti-virus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm Security Suite\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust EZ Armor\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust EZ Armor\eTrust EZ Antivirus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CA eTrust Antivirus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Antivirus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VETWIN32Vp5\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Antivirus\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99747F0D-D4F8-4877-9CA0-4AE96D963633}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FE184E30-8586-43B0-B2E3-5FE2B157BC7D}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{653FDA85-1ED5-4F12-9237-E750A28289A6}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CC55BD24-C1A6-4397-8EA3-2F30E74BDA2B}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6A120E99-3123-4CB2-9A02-D24784F4BC8C}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A5E011C-8479-4A2A-896C-C7C86CAF59DA}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99FE8443-D63A-469A-B280-0D34744FCACC}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust InoculateIT\UnsintallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InoculateIT for Windows NT\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InoculateIT\UninstallString


**************************************************************
* Panda Antivirus
*
* Ruta compatible con todos los antivirus incluso con el cambio de nombre
* corporativo de Panda Software a Panda Security
***************************************************************

[#]CLAVES DEL REGISTRO DE PANDA ANTIVIRUS
HKLM\SOFTWARE\Panda Security\PavShld
HKLM\SOFTWARE\Panda Software\SETUP\Path

[#]SERVICIOS MAS COMUNES DE PANDA ANTIVIRUS
PAVSRV, PAVFNSVR, PSHost, PSIMSVC, PavPrSrv, TPsrv.

[#]PROCESOS MAS COMUNES DE PANDA ANTIVIRUS
ApVxdWin.exe, AvLtMain.exe, Pavprsrv.exe, PsCtrlS.exe,WebProxy.exe,Upgrader.exe,PavFnSrv.exe


**************************************************************
*
* Familia Bitdefender (softwin)
*
* Bit Defender TotalSecurity 2009 Beta 2
* Bit Defender TotalScan 2008
* Bit Defender Internet Security 2008
* Bit Defender Antivirus 2008
* Bit Defender Total Security 2008 11.0.4 Beta 2
* Bit Defender 10.x IS Beta 1 (Windows Vista)
* Bit Defender 10.x Internet Security
* Bit Defender 10.x
* Bit Defender 10.x free
* Bit Defender 9.x Internet Security
* Bit Defender 9.x Professional Plus
* Bit Defender 9.x Standard
* Bit Defender 8.x Professional
* Bit Defender 8.x Standard
* Bit Defender 8.x free
* Bit Defender 7.x Professional
* Bit Defender 7.x Standard
* Bit Defender 7.x free
* Bit Defender 6.x Professional
* Bit Defender 6.x Standard
*
* Antivirus eXpert 2000 Desktop (antiguas versiones)
* eXpert Station
*
* SteelSecurity 1.0
* BullGuard Gamers 8.x
* BullGuard 8.x
* BullGuard 7.x NT,Vista
* BullGuard 6.x NT
* BullGuard 5.x NT
* BullGuard 4.x 9x-NT (tiene los servicios de BitDefender)
***************************************************************

[#]CLAVES DEL REGISTRO DE BITDEFENDER
HKLM\Software\SOFTWIN\AntiVirus eXpert 2000 Desktop
HKLM\Software\SOFTWIN\AVX enterprise\Station
HKLM\SYSTEM\CurrentControlSet\Services\bdss\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\FILESpy\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\REGSpy\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\VSSERV\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\LIVESRV\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\XCOMM\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\Bdfndisf\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\bdftdif\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\BDFsDrv\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\bdfdll\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\BDRsDrv\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\BDfsfltr\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\bdpredir\ImagePath
HKLM\SOFTWARE\BitDefender\BitDefender Threat Scanner\EnginesFolder
HKLM\SOFTWARE\BitDefender\BitDefender Desktop\Maintenance\Install\InstallDir
HKLM\SOFTWARE\BitDefender\BitDefender Desktop\Maintenance\Antivirus\ProductVersion
HKLM\SOFTWARE\Softwin\BitDefender Desktop\Maintenance\Install\InstallDir
HKLM\SOFTWARE\Softwin\BitDefender Desktop 7\QuarantineDir
HKLM\SOFTWARE\Softwin\BitDefender Professional\QuarantineDir
HKLM\SOFTWARE\Softwin\AVXEnterprise\station\UNINSTALL
HKLM\SOFTWARE\BullGuard\Maintenance\ProductName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D434965CDB2737F4E917658A43E82575\InstallProperties\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9FF69EBC1FBC4B247978919069C915B8\InstallProperties\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CBE96FF9-CBF1-42B4-9787-1909969C518B}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C4CC775869726AF4DB313FDC4B42BDA3\InstallProperties\DisplayName:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8577CC4C-2796-4FA6-BD13-F3CDB424DB3A}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B41ACE5DBC338FB468DE2ACD0AB4D8C4\InstallProperties\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5ECA14B-33CB-4BF8-86ED-A2DCA04B8D4C}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5CB59A36-2EAD-43E5-9EBC-9A54BE0CD8E1}\DisplayName
HKLM\SOFTWARE\Softwin\BitDefender Desktop\Maintenance\Standard\ProductName
HKLM\SOFTWARE\Softwin\BitDefender Desktop\Maintenance\Professional\ProductName
HKLM\SOFTWARE\Softwin\BitDefender Desktop\Maintenance\ISecurity\ProductName
HKLM\SOFTWARE\BullGuard\Maintenance\ProductName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{369E32B4-947B-4FBD-9AE7-DA01596203B9}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99E8DC90-F010-4352-8337-F97ECA347200}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6ADEF80F-AD3F-4036-ABF3-4FE30BC68E70}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8BFFDBAB-FD81-4137-A98E-A769C828080C}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D54DD1E-5D4E-4A2B-A55E-6B74426227B0}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F7F74EE-0EB4-4133-A9C4-C242C6EFD087}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{644F9948-FD5F-4921-9AB5-59EA837DEE45}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F2E05AB6-9ED1-40D8-AC7C-0E94EA2808CA}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BullGuard\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{764944C8-D250-40A2-90C9-8D1813AAB312}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D434965CDB2737F4E917658A43E82575\InstallProperties\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9FF69EBC1FBC4B247978919069C915B8\InstallProperties\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CBE96FF9-CBF1-42B4-9787-1909969C518B}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C4CC775869726AF4DB313FDC4B42BDA3\InstallProperties\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8577CC4C-2796-4FA6-BD13-F3CDB424DB3A}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B41ACE5DBC338FB468DE2ACD0AB4D8C4\InstallProperties\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5ECA14B-33CB-4BF8-86ED-A2DCA04B8D4C}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5CB59A36-2EAD-43E5-9EBC-9A54BE0CD8E1}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6ADEF80F-AD3F-4036-ABF3-4FE30BC68E70}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8BFFDBAB-FD81-4137-A98E-A769C828080C}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D54DD1E-5D4E-4A2B-A55E-6B74426227B0}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F7F74EE-0EB4-4133-A9C4-C242C6EFD087}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{644F9948-FD5F-4921-9AB5-59EA837DEE45}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F2E05AB6-9ED1-40D8-AC7C-0E94EA2808CA}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BullGuard\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{764944C8-D250-40A2-90C9-8D1813AAB312}\UninstallString


[#]CLAVES DEL REGISTRO DE BIT DEFENDER ANTIVIRUS
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\BitDefender Scan Server
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F7F74EE-0EB4-4133-A9C4-C242C6EFD087}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F7F74EE-0EB4-4133-A9C4-C242C6EFD087}\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F7F74EE-0EB4-4133-A9C4-C242C6EFD087}\UninstallString

[#]CLAVES DEL REGISTRO DE BIT DEFENDER ANTIVIRUS VERSIONES DE 64 BITS
HKLM\SYSTEM\CurrentControlSet\Services\bdfsfltr\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\scan\ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\VSSERV\ImagePath
HKEY_CURRENT_USER\Software\BitDefender\BitDefender Desktop\Maintenance\Antivirus\ProductCode
HKEY_CURRENT_USER\Software\BitDefender\BitDefender Desktop\Maintenance\InternetSecurity\ProductCode
HKEY_CURRENT_USER\Software\BitDefender\BitDefender Desktop\Maintenance\TotalSecurity\ProductCode
HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wow64 Emulation Layer\EventMessageFile
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteelSecurity\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BullGuard\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{764944C8-D250-40A2-90C9-8D1813AAB312}\UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteelSecurity\displayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BullGuard\DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SteelSecurity\Uninst


Extraído de http://unlugarsinfin.blogspot.es