Author Topic: [Inactive] malware bytes found a few rogue.errorfix & rogue.Acentive  (Read 9446 times)

0 Members and 1 Guest are viewing this topic.

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #15 on: September 21, 2009, 11:00:06 pm »
i did uninstall errorfix, yes i still get pop ups, and i cant find spybot log after saving but it was clean, are you familer with WinASO regesrty optimizer, was wondering if a good software it find a lot of stuff wondering if false finds?

  thank you for your time<

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #16 on: September 22, 2009, 11:57:43 am »
-- Search result list ---
Congratulations!: No immediate threats were found. (Status)
 


--- Spybot - Search & Destroy version: 1.6.2  (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-09-19 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-09-07 advcheck.dll (1.6.4.18)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-05-19 Includes\Adware.sbi (*)
2009-09-15 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-08-10 Includes\Dialer.sbi (*)
2009-09-15 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-09-15 Includes\HijackersC.sbi (*)
2009-06-23 Includes\Keyloggers.sbi (*)
2009-09-15 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-08-19 Includes\Malware.sbi (*)
2009-09-15 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-09-15 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-09-15 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-04-07 Includes\Spyware.sbi (*)
2009-09-15 Includes\SpywareC.sbi (*)
2009-06-08 Includes\Tracks.uti
2009-09-15 Includes\Trojans.sbi (*)
2009-09-16 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



--- System information ---
Windows Vista (Build: 6002) Service Pack 2 (6.0.6002)


--- Startup entries list ---
Located: HK_LM:Run, mcagent_exe
command: "C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe" /runkey
   file: C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
   size: 645328
    MD5: EAE3C29E6B437F970D014E59D462A66E

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
   file: C:\Program Files (x86)\Java\jre6\bin\jusched.exe
   size: 149280
    MD5: 5E4C9C25D603AE46DEDCBD9674F86E21

Located: HK_CU:Run, DelayShred
  where: .DEFAULT...
command: c:\PROGRA~2\mcafee\mshr\ShrCL.EXE /P10 /q c:\users\danielle\appdata\local\temp\TEMPOR~1\Content.SH! c:\users\danielle\appdata\local\temp\TEMPOR~1.SH! c:\users\danielle\appdata\local\temp\History\History.SH! c:\users\danielle\appdata\local\temp\History.SH! c:\users\danielle\appdata\local\temp\Cookies.SH!
   file:
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: HK_CU:Run, MySpaceIM
  where: .DEFAULT...
command: C:\Program Files (x86)\MySpace\IM\MySpaceIM.exe
   file: C:\Program Files (x86)\MySpace\IM\MySpaceIM.exe
   size: 9555968
    MD5: F7335700A80C7D296D040B963EBC9A90

Located: HK_CU:Run, ehTray.exe
  where: S-1-5-21-842586378-3866043728-2563244127-1000...
command: C:\Windows\ehome\ehTray.exe
   file: C:\Windows\ehome\ehTray.exe
   size: 138240
    MD5: 65437DAD4F238EA9549408A783002222

Located: HK_CU:Run, Sidebar
  where: S-1-5-21-842586378-3866043728-2563244127-1000...
command: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
   file: C:\Program Files\Windows Sidebar\sidebar.exe
   size: 1555968
    MD5: 9C5A0F070196B601D629F5BA9AA921F8

Located: HK_CU:Run, Speech Recognition
  where: S-1-5-21-842586378-3866043728-2563244127-1000...
command: "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
   file: C:\Windows\Speech\Common\sapisvr.exe
   size: 41984
    MD5: CE881FB400AAFE32D3DC0A7561B547C2

Located: HK_CU:Run, DelayShred
  where: S-1-5-18...
command: c:\PROGRA~2\mcafee\mshr\ShrCL.EXE /P10 /q c:\users\danielle\appdata\local\temp\TEMPOR~1\Content.SH! c:\users\danielle\appdata\local\temp\TEMPOR~1.SH! c:\users\danielle\appdata\local\temp\History\History.SH! c:\users\danielle\appdata\local\temp\History.SH! c:\users\danielle\appdata\local\temp\Cookies.SH!
   file:
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: HK_CU:Run, MySpaceIM
  where: S-1-5-18...
command: C:\Program Files (x86)\MySpace\IM\MySpaceIM.exe
   file: C:\Program Files (x86)\MySpace\IM\MySpaceIM.exe
   size: 9555968
    MD5: F7335700A80C7D296D040B963EBC9A90

Located: Startup (user), Dell Dock.lnk
  where: C:\Users\John Jr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup...
command: C:\Program Files\Dell\DellDock\DellDock.exe
   file: C:\Program Files\Dell\DellDock\DellDock.exe
   size: 1295656
    MD5: 58D9C70B01DBF2DEAEA787A1D7C869BB



--- Browser helper object list ---
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name: AcroIEHelperStub
        CLSID name: Adobe PDF Link Helper
              Path: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\
         Long name: AcroIEHelperShim.dll
        Short name:       ACROIE~2.DLL
    Date (created): 2/27/2009 12:07:26 PM
Date (last access): 7/29/2009 7:45:32 PM
 Date (last write): 2/27/2009 12:07:26 PM
          Filesize:              75128
        Attributes:           archive
               MD5: 5CF6190CD875DA6B35256FEE573E7908
             CRC32:           764BA81B
           Version:          9.1.0.163

{28AED1AF-B164-44CD-B435-CF04AA955015} (MySpace Toolbar)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: MySpace Toolbar
              Path: C:\Program Files (x86)\MySpace\Toolbar\1.0.45.0\
         Long name: MySpaceToolbar.dll
        Short name:       MYSPAC~1.DLL
    Date (created): 6/9/2009 6:02:40 PM
Date (last access): 6/22/2009 5:40:32 PM
 Date (last write): 6/9/2009 6:02:40 PM
          Filesize:             650304
        Attributes:           archive
               MD5: 806EE1749812E1E99F4D248A23AC4DB8
             CRC32:           418F6A2C
           Version:            1.0.0.1

{29456bfc-6fb2-4b36-b6a6-086a4cfc6770} (CommentsBar - Stickers and Comments Toolbar)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: CommentsBar - Stickers and Comments Toolbar
              Path: C:\Program Files (x86)\CommentsBar_-_Stickers_and_Comments\
         Long name:         tbCom1.dll
        Short name:                   
    Date (created): 7/29/2009 2:14:28 AM
Date (last access): 7/29/2009 2:14:28 AM
 Date (last write): 7/29/2009 2:14:40 AM
          Filesize:            2215960
        Attributes:           archive
               MD5: 9DFCDFB7C7E83B71E6DFF56545E4ABCD
             CRC32:           D75D5A52
           Version:            5.0.1.3

{5C255C8A-E604-49b4-9D64-90988571CECB} ()
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name:
              Path:                   
         Long name: __BHODemonDisabled

{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} (Search Helper)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name: Search Helper
        CLSID name: Search Helper
              Path: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\
         Long name: SEPsearchhelperie.dll
        Short name:       SEPSEA~1.DLL
    Date (created): 5/19/2009 11:36:18 AM
Date (last access): 5/26/2009 9:23:10 PM
 Date (last write): 5/19/2009 11:36:18 AM
          Filesize:             137600
        Attributes:           archive
               MD5: F655CDD5506FBB4C40C08C9C6A66F7C8
             CRC32:           579241EB
           Version:           1.3.59.0

{7DB2D5A0-7241-4E79-B68D-6309F01C5231} (scriptproxy)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name: scriptproxy
        CLSID name: scriptproxy
              Path: C:\Program Files (x86)\McAfee\VirusScan\
         Long name:       scriptsn.dll
        Short name:                   
    Date (created): 9/1/2009 8:52:24 PM
Date (last access): 7/8/2009 1:43:46 PM
 Date (last write): 7/8/2009 1:43:46 PM
          Filesize:              62784
        Attributes:           archive
               MD5: E7FD30A856E6BD3EAB92B9D6C76E6B1B
             CRC32:           EA160385
           Version:         14.0.0.433

{9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: Windows Live Sign-in Helper
              Path: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\
         Long name: WindowsLiveLogin.dll
        Short name:       WINDOW~1.DLL
    Date (created): 2/17/2009 4:11:04 PM
Date (last access): 3/14/2009 4:43:26 AM
 Date (last write): 2/17/2009 4:11:04 PM
          Filesize:             408440
        Attributes:           archive
               MD5: 1A82C1B9BB43385695EFC3A84F6756A2
             CRC32:           75E558CA
           Version:          5.0.818.6

{B164E929-A1B6-4A06-B104-2CD0E90A88FF} (McAfee SiteAdvisor BHO)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: McAfee SiteAdvisor BHO
              Path: c:\PROGRA~2\mcafee\SITEAD~1\
         Long name:        McIEPlg.dll
        Short name:                   
    Date (created): 9/1/2009 8:53:34 PM
Date (last access): 1/29/2009 12:27:02 PM
 Date (last write): 1/29/2009 12:27:02 PM
          Filesize:             145424
        Attributes:           archive
               MD5: 6F3D08D20BADF949390E838EAE9DE390
             CRC32:           F361B914
           Version:          1.0.1.204

{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: Java(tm) Plug-In 2 SSV Helper
              Path: C:\Program Files (x86)\Java\jre6\bin\
         Long name:         jp2ssv.dll
        Short name:                   
    Date (created): 9/11/2009 12:03:18 AM
Date (last access): 9/11/2009 12:03:18 AM
 Date (last write): 9/11/2009 12:03:18 AM
          Filesize:              41760
        Attributes:           archive
               MD5: 7AF9D3B7B88AF81D2F87AA846DC2EE70
             CRC32:           00DFC49A
           Version:          6.0.160.1

{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} (Windows Live Toolbar Helper)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: Windows Live Toolbar Helper
              Path: C:\Program Files (x86)\Windows Live\Toolbar\
         Long name:        wltcore.dll
        Short name:                   
    Date (created): 2/6/2009 6:17:46 PM
Date (last access): 4/13/2009 10:50:42 PM
 Date (last write): 2/6/2009 6:17:46 PM
          Filesize:            1068904
        Attributes:           archive
               MD5: 28455424E3C8B81661C5A40E18066BB1
             CRC32:           E5BA354B
           Version:      14.0.8064.206



--- ActiveX list ---
{5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module)
          DPF name:
        CLSID name: Windows Live Safety Center Base Module
         Installer: C:\Windows\Downloaded Program Files\wlscBase.inf
          Codebase: http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab
       description:
    classification: Legitimate
    known filename: wlscBase.dll
         info link:
       info source: Safer Networking Ltd.
              Path: C:\Windows\Downloaded Program Files\
         Long name:       wlscBase.dll
        Short name:                   
    Date (created): 9/9/2009 3:37:20 AM
Date (last access): 9/9/2009 3:37:20 AM
 Date (last write): 9/9/2009 3:37:20 AM
          Filesize:             452488
        Attributes:           archive
               MD5: 468995AC642F885F6BF3AF4C5CB255A1
             CRC32:           C82904CD
           Version:        1.11.6796.1

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
          DPF name: Java Runtime Environment 1.6.0
        CLSID name: Java Plug-in 1.6.0_16
         Installer:
          Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
       description:
    classification: Legitimate
    known filename: npjpi150_06.dll
         info link:
       info source: Safer Networking Ltd.
              Path: C:\Program Files (x86)\Java\jre6\bin\
         Long name:    npjpi160_16.dll
        Short name:       NPJPI1~1.DLL
    Date (created): 9/11/2009 12:03:18 AM
Date (last access): 9/11/2009 12:03:18 AM
 Date (last write): 9/11/2009 12:03:18 AM
          Filesize:             136992
        Attributes:           archive
               MD5: EF5C38E082CA41D7588621F3DFA09A64
             CRC32:           D4B4406B
           Version:          6.0.160.1



--- Process list ---
PID:    0 (   0) [System]
PID: 3336 (3308) C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
 size: 645328
  MD5: EAE3C29E6B437F970D014E59D462A66E
PID: 4784 (4548) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
 size: 115712
  MD5: B9E350C3EEE748E332251274DEC33829
PID: 3688 (2624) C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
 size: 5365592
  MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 3128 ( 868) C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe
 size: 224632
  MD5: 731F05B5C01B3CA9B813561C0B90E722
PID:  452 ( 868) C:\Windows\SysWow64\Macromed\Flash\FlashUtil10c.exe
 size: 257440
  MD5: AE619F242F2CE340F3B33DDEAA88248D
PID: 3876 ( 480) C:\Program Files (x86)\Internet Explorer\iexplore.exe
 size: 638216
  MD5: C33BD196A0301F9B23D9A003D30ED8B0
PID: 3580 (3876) C:\Program Files (x86)\Internet Explorer\iexplore.exe
 size: 638216
  MD5: C33BD196A0301F9B23D9A003D30ED8B0
PID:    4 (   0) System
PID:  428 (   4) smss.exe
PID:  560 ( 548) csrss.exe
PID:  596 ( 548) wininit.exe
 size: 96768
PID:  616 ( 604) csrss.exe
PID:  652 ( 596) services.exe
 size: 279552
PID:  684 ( 604) winlogon.exe
 size: 314368
PID:  700 ( 596) lsass.exe
PID:  708 ( 596) lsm.exe
 size: 229888
PID:  868 ( 652) svchost.exe
 size: 21504
PID:  928 ( 652) svchost.exe
 size: 21504
PID:  968 ( 652) svchost.exe
 size: 21504
PID:  256 ( 652) svchost.exe
 size: 21504
PID:  356 ( 652) svchost.exe
 size: 21504
PID:  444 ( 652) svchost.exe
 size: 21504
PID:  248 ( 256) audiodg.exe
 size: 88576
PID:  876 ( 652) svchost.exe
 size: 21504
PID: 1044 ( 652) SLsvc.exe
PID: 1088 ( 652) svchost.exe
 size: 21504
PID: 1192 ( 652) DockLogin.exe
PID: 1268 ( 652) svchost.exe
 size: 21504
PID: 1452 ( 652) spoolsv.exe
PID: 1484 ( 652) svchost.exe
 size: 21504
PID: 1696 ( 652) AERTSr64.exe
PID: 1748 ( 652) McSACore.exe
PID: 1804 ( 652) McProxy.exe
PID: 1816 (1748) rundll32.exe
 size: 44544
PID: 1836 ( 652) Mcshield.exe
PID: 1920 ( 652) MpfSrv.exe
PID: 2040 ( 652) svchost.exe
 size: 21504
PID: 1140 ( 652) SeaPort.exe
PID:  516 ( 652) svchost.exe
 size: 21504
PID: 1232 ( 652) svchost.exe
 size: 21504
PID: 1276 ( 652) SearchIndexer.exe
 size: 441344
PID: 2276 ( 652) SDWinSec.exe
PID: 2364 ( 444) taskeng.exe
 size: 169984
PID: 2204 ( 356) C:\Windows\System32\dwm.exe
PID: 2332 ( 444) C:\Windows\System32\taskeng.exe
 size: 169984
  MD5: E5BBFC283D6F5D69B41E464676361020
PID: 2624 (1728) C:\Windows\explorer.exe
 size: 3079168
  MD5: 6B08E54A451B3F95E4109DBA7E594270
PID: 2876 (2624) C:\Windows\System32\igfxtray.exe
PID: 2532 (2624) C:\Program Files\Windows Defender\MSASCui.exe
 size: 1584184
  MD5: 48DD40677817CE1053C2315F5A87E0D3
PID: 1012 (2624) C:\Program Files\Windows Sidebar\sidebar.exe
 size: 1555968
  MD5: 9C5A0F070196B601D629F5BA9AA921F8
PID: 1404 (2624) C:\Windows\ehome\ehtray.exe
 size: 138240
  MD5: 65437DAD4F238EA9549408A783002222
PID: 3320 (2624) C:\Program Files\Dell\DellDock\DellDock.exe
 size: 1295656
  MD5: 58D9C70B01DBF2DEAEA787A1D7C869BB
PID: 3380 ( 652) mcmscsvc.exe
PID: 3044 ( 652) mcsysmon.exe
PID: 3640 ( 652) McNASvc.exe
PID:  480 (2624) C:\Users\John Jr\Documents\ProcessExplorer[1]\procexp64.exe
 size: 879880
  MD5: 7A31EF490116D2863AE9FF2325DF5DBD
PID:  644 ( 868) C:\Windows\System32\dllhost.exe
 size: 7168
  MD5: BE01E566D1F569AAB32D0335613E1EEA


--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 9/22/2009 12:09:20 PM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
  http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
  Preserve
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
  http://g.msn.com/USCON/1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
  http://g.msn.com/USCON/1
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
  http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
  http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
  http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
  http://go.microsoft.com/fwlink/?LinkId=54896


--- Winsock Layered Service Provider list ---
Namespace Provider  1: E-mail Naming Shim Provider
        GUID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
    Filename:

Namespace Provider  2: PNRP Cloud Namespace Provider
        GUID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
    Filename:

Namespace Provider  3: PNRP Name Namespace Provider
        GUID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
    Filename:



--- Uninstall list ---


--- System Services ---
Service (registry key): .NET CLR Data
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): .NET CLR Networking
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): .NET Data Provider for Oracle
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): .NET Data Provider for SqlServer
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): .NETFramework
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): ACDaemon
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: ArcSoft Connect Daemon
   Object name: LocalSystem
    Image path: C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    Image size: 109056
     Image MD5: 769DB4F484957CC98153B3C1B5D1162F
   Control Set: CurrentControlSet
         Start: 4
          Type: 16
 Error Control: 0

Service (registry key): ACPI
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft ACPI Driver
    Image path: system32\drivers\acpi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): adp94xx
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\adp94xx.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): adpahci
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\adpahci.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): adpu160m
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\adpu160m.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): adpu320
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\adpu320.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): adsi
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): AeLookupSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\aelupsvc.dll,-1
   Description: @%SystemRoot%\system32\aelupsvc.dll,-2
   Object name: localSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): AERTFilters
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Andrea RT Filters Service
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\AERTSr64.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1

Service (registry key): AFD
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Ancilliary Function Driver for Winsock
   Description: Ancilliary Function Driver for Winsock
    Image path: \SystemRoot\system32\drivers\afd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): agp440
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Intel AGP Bus Filter
    Image path: \SystemRoot\system32\drivers\agp440.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): aic78xx
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\djsvs.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): ALG
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\Alg.exe,-112
   Description: @%SystemRoot%\system32\Alg.exe,-113
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\alg.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1

Service (registry key): aliide
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\aliide.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): amdide
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\amdide.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): AmdK8
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: AMD K8 Processor Driver
    Image path: \SystemRoot\system32\drivers\amdk8.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): Appinfo
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\appinfo.dll,-100
   Description: @%systemroot%\system32\appinfo.dll,-101
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,ProfSvc

Service (registry key): AppMgmt
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): arc
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\arc.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): arcsas
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\arcsas.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): AsyncMac
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\rascfg.dll,-32000
   Description: @%systemroot%\system32\rascfg.dll,-32000
    Image path: system32\DRIVERS\asyncmac.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): atapi
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: IDE Channel
    Image path: system32\drivers\atapi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): AudioEndpointBuilder
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\audiosrv.dll,-204
   Description: @%SystemRoot%\System32\audiosrv.dll,-205
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: PlugPlay

Service (registry key): AudioSrv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\audiosrv.dll,-200
   Description: @%SystemRoot%\System32\audiosrv.dll,-201
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: AudioEndpointBuilder,RpcSs,MMCSS

Service (registry key): BattC
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): BFE
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\bfe.dll,-1001
   Description: @%SystemRoot%\system32\bfe.dll,-1002
   Object name: NT AUTHORITY\LocalService
    Image path: %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): BITS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\qmgr.dll,-1000
   Description: @%SystemRoot%\system32\qmgr.dll,-1001
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,EventSystem

Service (registry key): blbdrive
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\blbdrive.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): bowser
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Bowser
   Description: Implements the datagram receiver for the computer browser browser service.
    Image path: system32\DRIVERS\bowser.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1

Service (registry key): BrFiltLo
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Brother USB Mass-Storage Lower Filter Driver
    Image path: \SystemRoot\system32\drivers\brfiltlo.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): BrFiltUp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Brother USB Mass-Storage Upper Filter Driver
    Image path: \SystemRoot\system32\drivers\brfiltup.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): Browser
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\browser.dll,-100
   Description: @%systemroot%\system32\browser.dll,-101
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: LanmanWorkstation,LanmanServer

Service (registry key): Brserid
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Brother MFC Serial Port Interface Driver (WDM)
    Image path: \SystemRoot\system32\drivers\brserid.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): BrSerWdm
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Brother WDM Serial driver
    Image path: \SystemRoot\system32\drivers\brserwdm.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): BrUsbMdm
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Brother MFC USB Fax Only Modem
    Image path: \SystemRoot\system32\drivers\brusbmdm.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): BrUsbSer
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Brother MFC USB Serial WDM Driver
    Image path: \SystemRoot\system32\drivers\brusbser.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): BTHMODEM
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Bluetooth Serial Communications Driver
    Image path: \SystemRoot\system32\drivers\bthmodem.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): BTHPORT
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): cdfs
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: CD/DVD File System Reader
   Description: ISO9660/Joliet File System Reader for CD/DVDs. (Core) (All pieces)
    Image path: system32\DRIVERS\cdfs.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 2
 Error Control: 1
 Depends On group: "SCSI CDROM Class"

Service (registry key): cdrom
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: CD-ROM Driver
    Image path: system32\DRIVERS\cdrom.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): CertPropSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\certprop.dll,-11
   Description: @%SystemRoot%\System32\certprop.dll,-12
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): circlass
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Consumer IR Devices
    Image path: \SystemRoot\system32\drivers\circlass.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): CLFS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Common Log (CLFS)
   Description: Common Log (CLFS)
    Image path: System32\CLFS.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): clr_optimization_v2.0.50727_32
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft .NET Framework NGEN v2.0.50727_X86
   Description: Microsoft .NET Framework NGEN
   Object name: LocalSystem
    Image path: %systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    Image size: 66368
     Image MD5: 8EE772032E2FE80A924F3B8DD5082194
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 0

Service (registry key): clr_optimization_v2.0.50727_64
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft .NET Framework NGEN v2.0.50727_X64
   Description: Microsoft .NET Framework NGEN
   Object name: LocalSystem
    Image path: %systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    Image size: 89920
     Image MD5: CE07A466201096F021CD09D631B21540
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 0

Service (registry key): cmdide
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\cmdide.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): Compbatt
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Composite Battery Driver
    Image path: \SystemRoot\system32\drivers\compbatt.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): COMSysApp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @comres.dll,-947
   Description: @comres.dll,-948
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    Image size: 7168
     Image MD5: BE01E566D1F569AAB32D0335613E1EEA
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: RpcSs,EventSystem,SENS

Service (registry key): crcdisk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Crcdisk Filter Driver
    Image path: system32\drivers\crcdisk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 1

Service (registry key): crypt32
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): CryptSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\cryptsvc.dll,-1001
   Description: @%SystemRoot%\system32\cryptsvc.dll,-1002
   Object name: NT Authority\NetworkService
    Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): CscService
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): DCLocator
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): DcomLaunch
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @oleres.dll,-5012
   Description: @oleres.dll,-5013
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k DcomLaunch
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): DfsC
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\drivers\dfsc.sys,-101
   Description: @%systemroot%\system32\drivers\dfsc.sys,-102
    Image path: System32\Drivers\dfsc.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 2
 Error Control: 1
 Depends On services: Mup

Service (registry key): DFSR
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @dfsrres.dll,-101
   Description: @dfsrres.dll,-102
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\DFSR.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: RpcSs,EventSystem

Service (registry key): Dhcp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\dhcpcsvc.dll,-100
   Description: @%SystemRoot%\system32\dhcpcsvc.dll,-101
   Object name: NT Authority\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: NSI,Tdx,Afd

Service (registry key): disk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Disk Driver
    Image path: system32\drivers\disk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 1

Service (registry key): dldt_device
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: dldt_device
   Object name: LocalSystem
    Image path: C:\Windows\system32\dldtcoms.exe -service
    Image size: 595184
     Image MD5: F6AD58179B79C7D6272588FF468AA1AB
   Control Set: CurrentControlSet
         Start: 4
          Type: 272
 Error Control: 1

Service (registry key): Dnscache
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\dnsapi.dll,-101
   Description: @%SystemRoot%\System32\dnsapi.dll,-102
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: Tdx

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #17 on: September 22, 2009, 11:59:05 am »

Service (registry key): DockLoginService
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Dock Login Service
   Description: Dock Login Service
   Object name: LocalSystem
    Image path: C:\Program Files\Dell\DellDock\DockLogin.exe
    Image size: 155648
     Image MD5: DB29915209770D8B59654345EC2D943A
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1

Service (registry key): dot3svc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\dot3svc.dll,-1102
   Description: @%systemroot%\system32\dot3svc.dll,-1103
   Object name: localSystem
    Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,Ndisuio,Eaphost

Service (registry key): DPS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\dps.dll,-500
   Description: @%systemroot%\system32\dps.dll,-501
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): drmkaud
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Kernel DRM Audio Descrambler
    Image path: system32\drivers\drmkaud.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): DXGKrnl
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: LDDM Graphics Subsystem
   Description: Controls the underlying video driver stacks to provide fully-featured display capabilities.
    Image path: \SystemRoot\System32\drivers\dxgkrnl.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): e1express
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Intel(R) PRO/1000 PCI Express Network Connection Driver
    Image path: system32\DRIVERS\e1e6032e.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): E1G60
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Intel(R) PRO/1000 NDIS 6 Adapter Driver
    Image path: system32\DRIVERS\E1G6032E.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): EapHost
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\eapsvc.dll,-1
   Description: @%systemroot%\system32\eapsvc.dll,-2
   Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RPCSS,KeyIso

Service (registry key): Ecache
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: ReadyBoost Caching Driver
   Description: ReadyBoost Caching Driver
    Image path: System32\drivers\ecache.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): ehRecvr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\ehome\ehrecvr.exe,-101
   Description: @%SystemRoot%\ehome\ehrecvr.exe,-102
   Object name: NT AUTHORITY\networkService
    Image path: %systemroot%\ehome\ehRecvr.exe
    Image size: 344064
     Image MD5: 14CE384D2E27B64C256BDA4DC39C312D
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 0
 Depends On services: RPCSS

Service (registry key): ehSched
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\ehome\ehsched.exe,-101
   Description: @%SystemRoot%\ehome\ehsched.exe,-102
   Object name: NT AUTHORITY\networkService
    Image path: %systemroot%\ehome\ehsched.exe
    Image size: 153600
     Image MD5: B93159C1313D66FDFBBE876F5189CD52
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 0
 Depends On services: RPCSS

Service (registry key): ehstart
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\ehome\ehstart.dll,-101
   Description: @%SystemRoot%\ehome\ehstart.dll,-102
   Object name: NT AUTHORITY\LocalService
    Image path: %windir%\system32\svchost.exe -k LocalServiceNoNetwork
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 0
 Depends On services: RPCSS

Service (registry key): elxstor
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\elxstor.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): EmdCache
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): EMDMgmt
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\emdmgmt.dll,-1000
   Description: @%SystemRoot%\system32\emdmgmt.dll,-1001
   Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 0
 Depends On services: rpcss,ecache,slsvc,fileinfo

Service (registry key): ErrDev
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Hardware Error Device Driver
    Image path: \SystemRoot\system32\drivers\errdev.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): ESENT
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): Eventlog
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\wevtsvc.dll,-200
   Description: @%SystemRoot%\system32\wevtsvc.dll,-201
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): EventSystem
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @comres.dll,-2450
   Description: @comres.dll,-2451
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: rpcss

Service (registry key): exfat
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: exFAT File System Driver
   Description: exFAT File System Driver
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1

Service (registry key): fastfat
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: FAT12/16/32 File System Driver
   Description: Note - dependance on CDROM.SYS only if required to read/write DVD-RAM media (which appears as CD class device). (Core) (All pieces)
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1

Service (registry key): fdc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Floppy Disk Controller Driver
    Image path: system32\DRIVERS\fdc.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): fdPHost
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\fdPHost.dll,-100
   Description: @%systemroot%\system32\fdPHost.dll,-101
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,http

Service (registry key): FDResPub
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\fdrespub.dll,-100
   Description: @%systemroot%\system32\fdrespub.dll,-101
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,http

Service (registry key): FileInfo
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: File Information FS MiniFilter
   Description: Collects information about files in memory to be consumed by other system services.
    Image path: system32\drivers\fileinfo.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 2
 Error Control: 1
 Depends On services: fltmgr

Service (registry key): Filetrace
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: FileTrace
   Description: ETW File Trace Filter
    Image path: system32\drivers\filetrace.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1
 Depends On services: FltMgr

Service (registry key): flpydisk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Floppy Disk Driver
    Image path: system32\DRIVERS\flpydisk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): FltMgr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: FltMgr
   Description: File System Filter Manager Driver
    Image path: system32\drivers\fltmgr.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 2
 Error Control: 3

Service (registry key): FontCache3.0.0.0
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\PresentationHost.exe,-3309
   Description: @%SystemRoot%\system32\PresentationHost.exe,-3310
   Object name: NT Authority\LocalService
    Image path: %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    Image size: 42840
     Image MD5: BC5B0BE5AF3510B0FD8C140EE42C6D3E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1

Service (registry key): Fs_Rec
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 1
          Type: 8
 Error Control: 0

Service (registry key): gagp30kx
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms
    Image path: \SystemRoot\system32\drivers\gagp30kx.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): gpsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @gpapi.dll,-112
   Description: @gpapi.dll,-113
   Object name: LocalSystem
    Image path: %windir%\system32\svchost.exe -k GPSvcGroup
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1
 Depends On services: RPCSS,Mup

Service (registry key): HDAudBus
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft UAA Bus Driver for High Definition Audio
    Image path: system32\DRIVERS\HDAudBus.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): HidBth
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Bluetooth HID Miniport
    Image path: \SystemRoot\system32\drivers\hidbth.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 0

Service (registry key): HidIr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Infrared HID Driver
    Image path: \SystemRoot\system32\drivers\hidir.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 0

Service (registry key): hidserv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\hidserv.dll,-101
   Description: @%SystemRoot%\System32\hidserv.dll,-102
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): HidUsb
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft HID Class Driver
    Image path: system32\DRIVERS\hidusb.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): hkmsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\kmsvc.dll,-6
   Description: @%SystemRoot%\system32\kmsvc.dll,-7
   Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): HpCISSs
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\hpcisss.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): HTTP
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: HTTP
   Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start.
    Image path: system32\drivers\HTTP.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): i2omp
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\i2omp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): i8042prt
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: i8042 Keyboard and PS/2 Mouse Port Driver
    Image path: system32\DRIVERS\i8042prt.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): ialm
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): iaStor
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Intel RAID Controller
    Image path: \SystemRoot\system32\drivers\iastor.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): iaStorV
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Intel RAID Controller Vista
    Image path: \SystemRoot\system32\drivers\iastorv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): idsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193
   Description: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8192
   Object name: LocalSystem
    Image path: "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe"
    Image size: 857432
     Image MD5: 749F5F8CEDCA70F2A512945325FC489D
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): igfx
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: system32\DRIVERS\igdkmd64.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): iirsp
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\iirsp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): IKEEXT
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\ikeext.dll,-501
   Description: @%SystemRoot%\system32\ikeext.dll,-502
   Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: BFE

Service (registry key): inetaccs
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): IntcAzAudAddService
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Service for Realtek HD Audio (WDM)
    Image path: system32\drivers\RTKVHD64.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): intelide
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\intelide.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): intelppm
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Intel Processor Driver
    Image path: system32\DRIVERS\intelppm.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): IPBusEnum
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\IPBusEnum.dll,-102
   Description: @%systemroot%\system32\IPBusEnum.dll,-103
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,fdPHost

Service (registry key): IpFilterDriver
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\rascfg.dll,-32013
   Description: @%systemroot%\system32\rascfg.dll,-32013
    Image path: system32\DRIVERS\ipfltdrv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 1
 Error Control: 1
 Depends On services: Tcpip

Service (registry key): iphlpsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\iphlpsvc.dll,-200
   Description: @%SystemRoot%\system32\iphlpsvc.dll,-201
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k NetSvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSS,Tdx,winmgmt,tcpip,nsi

Service (registry key): IpInIp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: IP in IP Tunnel Driver
   Description: IP in IP Tunnel Driver
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1
 Depends On services: Tcpip

Service (registry key): IPMIDRV
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\ipmidrv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): IPNAT
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: IP Network Address Translator
   Description: IP Network Address Translator
    Image path: system32\DRIVERS\ipnat.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1
 Depends On services: Tcpip

Service (registry key): IRENUM
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: IR Bus Enumerator
   Description: IR Bus Enumerator
    Image path: system32\drivers\irenum.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): isapnp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: PnP ISA/EISA Bus Driver
    Image path: \SystemRoot\system32\drivers\isapnp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): iScsiPrt
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: iScsiPort Driver
    Image path: system32\DRIVERS\msiscsi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): iteatapi
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: ITEATAPI_Service_Install
    Image path: \SystemRoot\system32\drivers\iteatapi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): iteraid
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: ITERAID_Service_Install
    Image path: \SystemRoot\system32\drivers\iteraid.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): kbdclass
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Keyboard Class Driver
    Image path: system32\DRIVERS\kbdclass.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): kbdhid
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Keyboard HID Driver
    Image path: system32\DRIVERS\kbdhid.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 0

Service (registry key): KeyIso
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @keyiso.dll,-100
   Description: @keyiso.dll,-101
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): KSecDD
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: System32\Drivers\ksecdd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): ksthunk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Kernel Streaming Thunks
    Image path: \SystemRoot\system32\drivers\ksthunk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): KtmRm
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @comres.dll,-2946
   Description: @comres.dll,-2947
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\System32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RPCSS,SamSS

Service (registry key): LanmanServer
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\srvsvc.dll,-100
   Description: @%systemroot%\system32\srvsvc.dll,-101
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: SamSS,Srv

Service (registry key): LanmanWorkstation
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\wkssvc.dll,-100
   Description: @%systemroot%\system32\wkssvc.dll,-101
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: Bowser,MRxSmb10,MRxSmb20,NSI

Service (registry key): ldap
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): lltdio
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Link-Layer Topology Discovery Mapper I/O Driver
    Image path: system32\DRIVERS\lltdio.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 1
 Error Control: 1

Service (registry key): lltdsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\lltdres.dll,-1
   Description: @%SystemRoot%\system32\lltdres.dll,-2
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: rpcss,lltdio

Service (registry key): lmhosts
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\lmhsvc.dll,-101
   Description: @%SystemRoot%\system32\lmhsvc.dll,-102
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: NetBT,Afd

Service (registry key): Lsa
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): LSI_FC
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\lsi_fc.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): LSI_SAS
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\lsi_sas.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): LSI_SCSI
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\lsi_scsi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): luafv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: UAC File Virtualization
   Description: Virtualizes file write failures to per-user locations.
    Image path: \SystemRoot\system32\drivers\luafv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 2
 Error Control: 1
 Depends On services: FltMgr

Service (registry key): McAfee SiteAdvisor Service
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee SiteAdvisor Service
   Description: Provides low-level support for McAfee SiteAdvisor
   Object name: LocalSystem
    Image path: "C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe"
    Image size: 203280
     Image MD5: AAC3B33BA020D2AF530D694A5A920180
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1
 Depends On services: RPCSS

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #18 on: September 22, 2009, 11:59:58 am »
Service (registry key): mcmscsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Services
   Description: McAfee Services
   Object name: LocalSystem
    Image path: C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe
    Image size: 865832
     Image MD5: 0FC36E77D779F8D021D338BDC7368181
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1

Service (registry key): McNASvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Network Agent
   Description: Allows McAfee applications to communicate securely on the local network.
   Object name: LocalSystem
    Image path: "c:\PROGRA~2\COMMON~1\mcafee\mna\mcnasvc.exe"
    Image size: 2482848
     Image MD5: 2988E515570E4F8B9D9B256137F8E8F4
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): McODS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Scanner
   Description: McAfee Scanner
   Object name: LocalSystem
    Image path: C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    Image size: 696848
     Image MD5: F3E4D19E857E2A4AEBF7DAC1E75A29BC
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1

Service (registry key): McProxy
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Proxy Service
   Description: McAfee Proxy Service
   Object name: LocalSystem
    Image path: c:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe
    Image size: 359952
     Image MD5: C85968D24449E37653B891B03188140C
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1

Service (registry key): McShield
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Real-time Scanner
   Description: Scans files for viruses and other threats when they are accessed by this computer.
   Object name: LocalSystem
    Image path: C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    Image size: 155456
     Image MD5: 86275173C8145FEB39EA1148738F236A
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1

Service (registry key): McSysmon
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee SystemGuards
   Description: Monitors potentially unauthorized changes to this computer.
   Object name: LocalSystem
    Image path: C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe
    Image size: 606736
     Image MD5: 85C5C2F93015C12B1EA2F1D8BE8EB195
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1

Service (registry key): Mcx2Svc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\ehome\ehres.dll,-15501
   Description: @%SystemRoot%\ehome\ehres.dll,-15502
   Object name: NT Authority\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: SSDPSRV,IPBusEnum,TermService,fdphost

Service (registry key): megasas
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\megasas.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): MegaSR
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\megasr.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): mfeavfk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Inc. mfeavfk
    Image path: system32\drivers\mfeavfk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): mfehidk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Inc. mfehidk
    Image path: system32\drivers\mfehidk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): mferkdk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Inc. mferkdk
    Image path: system32\drivers\mferkdk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): mfesmfk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Inc. mfesmfk
    Image path: system32\drivers\mfesmfk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): MMCSS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\mmcss.dll,-100
   Description: @%systemroot%\system32\mmcss.dll,-101
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): Modem
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: system32\drivers\modem.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): monitor
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Monitor Class Function Driver Service
    Image path: system32\DRIVERS\monitor.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): mouclass
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Mouse Class Driver
    Image path: system32\DRIVERS\mouclass.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): mouhid
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Mouse HID Driver
    Image path: system32\DRIVERS\mouhid.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): MountMgr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Mount Point Manager
   Description: Driver responsible with maintaining persistent drive letters and names for volumes
    Image path: System32\drivers\mountmgr.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): MPFP
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: MPFP
    Image path: System32\Drivers\Mpfp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1
 Depends On services: TcpIp

Service (registry key): MpfService
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: McAfee Personal Firewall Service
   Description: Helps protect your computer from intrusion and let's you manage your computer's trusted programs.
   Object name: LocalSystem
    Image path: "C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe"
    Image size: 894136
     Image MD5: 276C6D7DEEE788FE1B96A9A07F460213
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1

Service (registry key): mpio
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Multi-Path Bus Driver
    Image path: \SystemRoot\system32\drivers\mpio.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): mpsdrv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\FirewallAPI.dll,-23092
   Description: @%SystemRoot%\system32\FirewallAPI.dll,-23093
    Image path: System32\drivers\mpsdrv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): MpsSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\FirewallAPI.dll,-23090
   Description: @%SystemRoot%\system32\FirewallAPI.dll,-23091
   Object name: NT Authority\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: mpsdrv,bfe

Service (registry key): Mraid35x
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\mraid35x.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): MRxDAV
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: WebDav Client Redirector Driver
   Description: WebDav Client Redirector Driver
    Image path: \SystemRoot\system32\drivers\mrxdav.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1
 Depends On services: rdbss

Service (registry key): mrxsmb
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SMB MiniRedirector Wrapper and Engine
   Description: Implements the framework for the SMB filesystem redirector
    Image path: system32\DRIVERS\mrxsmb.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1
 Depends On services: rdbss

Service (registry key): mrxsmb10
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SMB 1.x MiniRedirector
   Description: Implements the SMB 1.x (CIFS) protocol. This protocol provides connectivity to network resources on pre-Windows Vista servers
    Image path: system32\DRIVERS\mrxsmb10.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1
 Depends On services: mrxsmb

Service (registry key): mrxsmb20
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SMB 2.0 MiniRedirector
   Description: Implements the SMB 2.0 protocol, which provides connectivity to network resources on Windows Vista and later servers
    Image path: system32\DRIVERS\mrxsmb20.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1
 Depends On services: mrxsmb

Service (registry key): msahci
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\msahci.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): msdsm
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Multi-Path Device Specific Module
    Image path: \SystemRoot\system32\drivers\msdsm.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): MSDTC
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @comres.dll,-2797
   Description: @comres.dll,-2798
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\System32\msdtc.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: RPCSS,SamSS

Service (registry key): MSDTC Bridge 3.0.0.0
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): Msfs
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 1
          Type: 2
 Error Control: 1

Service (registry key): msisadrv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: ISA/EISA Class Driver
    Image path: system32\drivers\msisadrv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): MSiSCSI
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\iscsidsc.dll,-5000
   Description: @%SystemRoot%\system32\iscsidsc.dll,-5001
   Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): msiserver
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\msimsg.dll,-27
   Description: @%SystemRoot%\system32\msimsg.dll,-32
   Object name: LocalSystem
    Image path: %systemroot%\system32\msiexec /V
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: rpcss

Service (registry key): MSKSSRV
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Streaming Service Proxy
    Image path: system32\drivers\MSKSSRV.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): MSPCLOCK
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Streaming Clock Proxy
    Image path: system32\drivers\MSPCLOCK.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): MSPQM
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Streaming Quality Manager Proxy
    Image path: system32\drivers\MSPQM.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): MsRPC
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): MSSCNTRS
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): mssmbios
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft System Management BIOS Driver
    Image path: system32\DRIVERS\mssmbios.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): MSTEE
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Streaming Tee/Sink-to-Sink Converter
    Image path: system32\drivers\MSTEE.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): Mup
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Mup
   Description: Multiple UNC Provider
    Image path: System32\Drivers\mup.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 2
 Error Control: 1

Service (registry key): napagent
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\qagentrt.dll,-6
   Description: @%SystemRoot%\system32\qagentrt.dll,-7
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\System32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): NativeWifiP
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: NativeWiFi Filter
    Image path: system32\DRIVERS\nwifi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): NDIS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: NDIS System Driver
   Description: NDIS System Driver
    Image path: system32\drivers\ndis.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): NdisTapi
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\rascfg.dll,-32001
   Description: @%systemroot%\system32\rascfg.dll,-32001
    Image path: system32\DRIVERS\ndistapi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): Ndisuio
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: NDIS Usermode I/O Protocol
    Image path: system32\DRIVERS\ndisuio.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): NdisWan
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\rascfg.dll,-32002
   Description: @%systemroot%\system32\rascfg.dll,-32002
    Image path: system32\DRIVERS\ndiswan.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): NDProxy
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): NetBIOS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: NetBIOS Interface
   Description: NetBIOS Interface
    Image path: system32\DRIVERS\netbios.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 2
 Error Control: 1

Service (registry key): netbt
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: NETBT
   Description: This service implements NetBios over TCP/IP.
    Image path: System32\DRIVERS\netbt.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1
 Depends On services: Tdx,tcpip,MPFP

Service (registry key): Netlogon
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\netlogon.dll,-102
   Description: @%SystemRoot%\System32\netlogon.dll,-103
   Object name: LocalSystem
    Image path: %systemroot%\system32\lsass.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: LanmanWorkstation

Service (registry key): Netman
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\netman.dll,-109
   Description: @%SystemRoot%\system32\netman.dll,-110
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,nsi

Service (registry key): netprofm
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\netprof.dll,-246
   Description: @%SystemRoot%\system32\netprof.dll,-247
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,nlasvc

Service (registry key): NetTcpPortSharing
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201
   Description: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8200
   Object name: NT AUTHORITY\LocalService
    Image path: "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe"
    Image size: 117592
     Image MD5: 74751DDA198165947FD7454D83F49825
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1

Service (registry key): nfrd960
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\nfrd960.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): NlaSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\nlasvc.dll,-1
   Description: @%SystemRoot%\System32\nlasvc.dll,-2
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\System32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: NSI,RpcSs,TcpIp

Service (registry key): Npfs
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 1
          Type: 2
 Error Control: 1

Service (registry key): nsi
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\nsisvc.dll,-200
   Description: @%SystemRoot%\system32\nsisvc.dll,-201
   Object name: NT Authority\LocalService
    Image path: %systemroot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: nsiproxy

Service (registry key): nsiproxy
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: NSI proxy service
   Description: NSI proxy service
    Image path: system32\drivers\nsiproxy.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): NTDS
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): Ntfs
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1

Service (registry key): Null
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): nvraid
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: NVIDIA nForce RAID Driver   
    Image path: \SystemRoot\system32\drivers\nvraid.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): nvstor
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\nvstor.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): nv_agp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: NVIDIA nForce AGP Bus Filter
    Image path: \SystemRoot\system32\drivers\nv_agp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): NwlnkFlt
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: IPX Traffic Filter Driver
   Description: IPX Traffic Filter Driver
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1
 Depends On services: NwlnkFwd

Service (registry key): NwlnkFwd
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: IPX Traffic Forwarder Driver
   Description: IPX Traffic Forwarder Driver
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): OA002Afx
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Provides a software interface to control audio effects of OA002 camera.
    Image path: \??\C:\Windows\system32\Drivers\OA002Afx.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): OA002Ufd
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Creative Camera OA002 Upper Filter Driver
   Description: Provides a software interface to control effects of Monitor Webcam.
    Image path: system32\DRIVERS\OA002Ufd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): OA002Vid
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Creative Camera OA002 Function Driver
   Description: Provides a software interface to control Monitor Webcam.
    Image path: system32\DRIVERS\OA002Vid.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): ohci1394
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: AGERE OHCI Compliant IEEE 1394 Host Controller
    Image path: system32\DRIVERS\ohci1394.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): p2pimsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\p2psvc.dll,-8004
   Description: @%SystemRoot%\system32\p2psvc.dll,-8005
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): p2psvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\p2psvc.dll,-8006
   Description: @%SystemRoot%\system32\p2psvc.dll,-8007
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: p2pimsvc,PNRPSvc

Service (registry key): Parport
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Parallel port driver
    Image path: \SystemRoot\system32\drivers\parport.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): partmgr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Partition Manager
   Description: Disk class filter driver that auctions out partitions to volume managers
    Image path: System32\drivers\partmgr.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): PcaSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\pcasvc.dll,-1
   Description: @%SystemRoot%\system32\pcasvc.dll,-2
   Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): pci
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: PCI Bus Driver
    Image path: system32\drivers\pci.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): pciide
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: system32\drivers\pciide.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): pcmcia
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\pcmcia.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): PCTCore
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): PEAUTH
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: PEAUTH
    Image path: system32\drivers\peauth.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 1
 Error Control: 1

Service (registry key): PerfDisk
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): PerfHost
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\sysWow64\perfhost.exe,-2
   Description: @%systemroot%\SysWow64\perfhost.exe,-1
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\SysWow64\perfhost.exe
    Image size: 19968
     Image MD5: 0ED8727EA0172860F47258456C06CAEA
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): PerfNet
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): PerfOS
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): PerfProc
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): pla
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\pla.dll,-500
   Description: @%systemroot%\system32\pla.dll,-501
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): PlugPlay
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\umpnpmgr.dll,-100
   Description: @%SystemRoot%\system32\umpnpmgr.dll,-101
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k DcomLaunch
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): PNRPAutoReg
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\p2psvc.dll,-8002
   Description: @%SystemRoot%\system32\p2psvc.dll,-8003
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: pnrpsvc

Service (registry key): PNRPsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\p2psvc.dll,-8000
   Description: @%SystemRoot%\system32\p2psvc.dll,-8001
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: p2pimsvc

Service (registry key): PolicyAgent
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\polstore.dll,-5010
   Description: @%SystemRoot%\system32\polstore.dll,-5011
   Object name: NT Authority\NetworkService
    Image path: %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: Tcpip,bfe

Service (registry key): PptpMiniport
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\rascfg.dll,-32006
   Description: @%systemroot%\system32\rascfg.dll,-32006
    Image path: system32\DRIVERS\raspptp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): Processor
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Processor Driver
    Image path: \SystemRoot\system32\drivers\processr.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): ProfSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\profsvc.dll,-300
   Description: @%systemroot%\system32\profsvc.dll,-301
   Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): ProtectedStorage
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\psbase.dll,-300
   Description: @%systemroot%\system32\psbase.dll,-301
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): PSched
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\drivers\pacer.sys,-101
   Description: @%SystemRoot%\System32\drivers\pacer.sys,-101
    Image path: system32\DRIVERS\pacer.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): PxHlpa64
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: PxHlpa64
    Image path: System32\Drivers\PxHlpa64.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 1

Service (registry key): ql2300
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: QLogic Fibre Channel Miniport Driver
    Image path: \SystemRoot\system32\drivers\ql2300.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): ql40xx
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: QLogic iSCSI Miniport Driver
    Image path: \SystemRoot\system32\drivers\ql40xx.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): QWAVE
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\qwave.dll,-1
   Description: @%SystemRoot%\system32\qwave.dll,-2
   Object name: NT AUTHORITY\LocalService
    Image path: %windir%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: rpcss,psched,QWAVEdrv,LLTDIO

Service (registry key): QWAVEdrv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\drivers\qwavedrv.sys,-1
   Description: @%SystemRoot%\system32\drivers\qwavedrv.sys,-2
    Image path: \SystemRoot\system32\drivers\qwavedrv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): R300
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: system32\DRIVERS\atikmdag.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): RasAcd
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Remote Access Auto Connection Driver
   Description: Remote Access Auto Connection Driver
    Image path: System32\DRIVERS\rasacd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #19 on: September 22, 2009, 12:02:08 pm »

Service (registry key): RasAuto
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%Systemroot%\system32\rasauto.dll,-200
   Description: @%Systemroot%\system32\rasauto.dll,-201
   Object name: localSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RasMan,Tapisrv

Service (registry key): Rasl2tp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\rascfg.dll,-32005
   Description: @%systemroot%\system32\rascfg.dll,-32005
    Image path: system32\DRIVERS\rasl2tp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): RasMan
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%Systemroot%\system32\rasmans.dll,-200
   Description: @%Systemroot%\system32\rasmans.dll,-201
   Object name: localSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: Tapisrv,SstpSvc

Service (registry key): RasPppoe
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\rascfg.dll,-32007
   Description: @%systemroot%\system32\rascfg.dll,-32007
    Image path: system32\DRIVERS\raspppoe.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): RasSstp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\sstpsvc.dll,-202
   Description: @%systemroot%\system32\sstpsvc.dll,-202
    Image path: system32\DRIVERS\rassstp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): rdbss
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Redirected Buffering Sub Sysytem
   Description: Provides the framework for network mini-redirectors
    Image path: system32\DRIVERS\rdbss.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 2
 Error Control: 1
 Depends On services: Mup

Service (registry key): RDPCDD
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: RDPCDD
   Description: RDPDD Chained DD
    Image path: System32\DRIVERS\RDPCDD.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 0

Service (registry key): RDPDD
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): rdpdr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Terminal Server Device Redirector Driver
    Image path: \SystemRoot\system32\drivers\rdpdr.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): RDPENCDD
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: RDP Encoder Mirror Driver
   Description: RDP Encoder Mirror Driver
    Image path: system32\drivers\rdpencdd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 0

Service (registry key): RDPNP
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\drprov.dll,-100
   Description: @%systemroot%\system32\drprov.dll,-101
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): RDPWD
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: RDP Winstation Driver
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): RemoteAccess
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%Systemroot%\system32\mprdim.dll,-200
   Description: @%Systemroot%\system32\mprdim.dll,-201
   Object name: localSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: RpcSS,RasMan,bfe
 Depends On group: NetBIOSGroup

Service (registry key): RemoteRegistry
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @regsvc.dll,-1
   Description: @regsvc.dll,-2
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k regsvc
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): RLDesignVirtualAudioCableWdm
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Live! Cam Virtual
    Image path: system32\DRIVERS\livecamv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): RpcLocator
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\Locator.exe,-2
   Description: @%systemroot%\system32\Locator.exe,-3
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\system32\locator.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1

Service (registry key): RpcSs
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @oleres.dll,-5010
   Description: @oleres.dll,-5011
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\system32\svchost.exe -k rpcss
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: DcomLaunch

Service (registry key): rspndr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Link-Layer Topology Discovery Responder
    Image path: system32\DRIVERS\rspndr.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 1
 Error Control: 1

Service (registry key): RTL8169
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Realtek 8169 NT Driver
    Image path: system32\DRIVERS\Rtlh64.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): SamSs
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\samsrv.dll,-1
   Description: @%SystemRoot%\system32\samsrv.dll,-2
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\lsass.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): sbp2port
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SBP-2 Transport/Protocol Bus Driver
    Image path: \SystemRoot\system32\drivers\sbp2port.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): SBSDWSCService
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SBSD Security Center Service
   Object name: LocalSystem
    Image path: C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    Image size: 1153368
     Image MD5: 794D4B48DFB6E999537C7C3947863463
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1
 Depends On services: wscsvc

Service (registry key): SCardSvr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\SCardSvr.dll,-1
   Description: @%SystemRoot%\System32\SCardSvr.dll,-5
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: PlugPlay

Service (registry key): Schedule
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\schedsvc.dll,-100
   Description: @%SystemRoot%\system32\schedsvc.dll,-101
   Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RPCSS,EventLog

Service (registry key): SCPolicySvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\certprop.dll,-13
   Description: @%SystemRoot%\System32\certprop.dll,-14
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): SDRSVC
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\sdrsvc.dll,-107
   Description: @%SystemRoot%\system32\sdrsvc.dll,-102
   Object name: localSystem
    Image path: %SystemRoot%\system32\svchost.exe -k SDRSVC
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): SeaPort
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SeaPort
   Description: Enables the detection, download and installation of up-to-date configuration files for Microsoft Search Enhancement applications. Also provides server communication for the customer experience improvement program. If this service is disabled, search enhancement features such as search history may not work correctly.
   Object name: LocalSystem
    Image path: "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
    Image size: 240512
     Image MD5: 271077B91D7AD1B616F8AFDFE8E3F981
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1

Service (registry key): secdrv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Security Driver
   Control Set: CurrentControlSet
         Start: 2
          Type: 1
 Error Control: 1

Service (registry key): seclogon
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\seclogon.dll,-7001
   Description: @%SystemRoot%\system32\seclogon.dll,-7000
   Object name: LocalSystem
    Image path: %windir%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): SENS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\Sens.dll,-200
   Description: @%SystemRoot%\system32\Sens.dll,-201
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: EventSystem

Service (registry key): Serenum
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Serenum Filter Driver
    Image path: \SystemRoot\system32\drivers\serenum.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): Serial
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Serial Port Driver
    Image path: \SystemRoot\system32\drivers\serial.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 0

Service (registry key): sermouse
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Serial Mouse Driver
    Image path: \SystemRoot\system32\drivers\sermouse.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): ServiceModelEndpoint 3.0.0.0
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): ServiceModelOperation 3.0.0.0
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): ServiceModelService 3.0.0.0
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): SessionEnv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\SessEnv.dll,-1026
   Description: @%SystemRoot%\System32\SessEnv.dll,-1027
   Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RPCSS,LanmanWorkstation

Service (registry key): sffdisk
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SFF Storage Class Driver
    Image path: \SystemRoot\system32\drivers\sffdisk.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): sffp_mmc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SFF Storage Protocol Driver for MMC
    Image path: \SystemRoot\system32\drivers\sffp_mmc.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): sffp_sd
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: SFF Storage Protocol Driver for SDBus
    Image path: \SystemRoot\system32\drivers\sffp_sd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): sfloppy
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: High-Capacity Floppy Disk Drive
    Image path: \SystemRoot\system32\drivers\sfloppy.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): SharedAccess
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\ipnathlp.dll,-106
   Description: @%SystemRoot%\system32\ipnathlp.dll,-107
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: Netman,WinMgmt,RasMan,BFE

Service (registry key): ShellHWDetection
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\shsvcs.dll,-12288
   Description: @%SystemRoot%\System32\shsvcs.dll,-12289
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 0
 Depends On services: RpcSs

Service (registry key): SiSRaid2
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\sisraid2.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): SiSRaid4
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\sisraid4.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): slsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\SLsvc.exe,-101
   Description: @%SystemRoot%\system32\SLsvc.exe,-102
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\system32\SLsvc.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): SLUINotify
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\SLUINotify.dll,-103
   Description: @%SystemRoot%\system32\SLUINotify.dll,-102
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: SLSvc,netprofm,EventSystem

Service (registry key): Smb
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\tcpipcfg.dll,-50005
   Description: @%SystemRoot%\system32\tcpipcfg.dll,-50006
    Image path: system32\DRIVERS\smb.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1
 Depends On services: Tcpip

Service (registry key): SMSvcHost 3.0.0.0
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): SNMPTRAP
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\snmptrap.exe,-3
   Description: @%SystemRoot%\system32\snmptrap.exe,-4
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\snmptrap.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 16
 Error Control: 1

Service (registry key): spldr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Security Processor Loader Driver
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): Spooler
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\spoolsv.exe,-1
   Description: @%systemroot%\system32\spoolsv.exe,-2
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\spoolsv.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 272
 Error Control: 1
 Depends On services: RPCSS,http

Service (registry key): srv
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: System32\DRIVERS\srv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1
 Depends On services: srv2

Service (registry key): srv2
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: srv2
   Description: Default SDDL for Windows Resource Protected file
    Image path: System32\DRIVERS\srv2.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1
 Depends On services: srvnet

Service (registry key): srvnet
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: System32\DRIVERS\srvnet.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 2
 Error Control: 1

Service (registry key): SSDPSRV
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\ssdpsrv.dll,-100
   Description: @%systemroot%\system32\ssdpsrv.dll,-101
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: HTTP

Service (registry key): SstpSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\sstpsvc.dll,-200
   Description: @%SystemRoot%\system32\sstpsvc.dll,-201
   Object name: NT Authority\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): stisvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\wiaservc.dll,-9
   Description: @%SystemRoot%\system32\wiaservc.dll,-10
   Object name: NT Authority\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k imgsvc
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1
 Depends On services: RpcSs,ShellHWDetection

Service (registry key): stllssvr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: stllssvr
   Object name: LocalSystem
    Image path: "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe"
    Image size: 74384
     Image MD5: 1D0063597C3666404FCF97698ABEB019
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 0

Service (registry key): swenum
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Software Bus Driver
    Image path: system32\DRIVERS\swenum.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): swprv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\swprv.dll,-103
   Description: @%SystemRoot%\System32\swprv.dll,-102
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k swprv
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): Symc8xx
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\symc8xx.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): Sym_hi
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\sym_hi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): Sym_u3
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\sym_u3.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): SysMain
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\sysmain.dll,-1000
   Description: @%SystemRoot%\system32\sysmain.dll,-1001
   Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 0
 Depends On services: rpcss,fileinfo

Service (registry key): TabletInputService
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\TabSvc.dll,-100
   Description: @%SystemRoot%\system32\TabSvc.dll,-101
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: PlugPlay,RpcSs

Service (registry key): TapiSrv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\tapisrv.dll,-10100
   Description: @%SystemRoot%\system32\tapisrv.dll,-10101
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\System32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: PlugPlay,RpcSs

Service (registry key): TBS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\tbssvc.dll,-100
   Description: @%SystemRoot%\system32\tbssvc.dll,-101
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): Tcpip
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\tcpipcfg.dll,-50003
   Description: @%SystemRoot%\system32\tcpipcfg.dll,-50003
    Image path: System32\drivers\tcpip.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): Tcpip6
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft IPv6 Protocol Driver
   Description: Microsoft IPv6 Protocol Driver
    Image path: system32\DRIVERS\tcpip.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1
 Depends On services: Tcpip

Service (registry key): tcpipreg
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: TCP/IP Registry Compatibility
   Description: Provides compatibility for legacy applications which interact with TCP/IP through the registry. If this service is stopped, certain applications may have impaired functionality.
    Image path: System32\drivers\tcpipreg.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 2
          Type: 1
 Error Control: 1
 Depends On services: tcpip

Service (registry key): TDPIPE
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: TDPIPE
    Image path: system32\drivers\tdpipe.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): TDTCP
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: TDTCP
    Image path: system32\drivers\tdtcp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): tdx
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\tcpipcfg.dll,-50004
   Description: @%SystemRoot%\system32\tcpipcfg.dll,-50004
    Image path: system32\DRIVERS\tdx.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1
 Depends On services: Tcpip

Service (registry key): TermDD
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Terminal Device Driver
    Image path: system32\DRIVERS\termdd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): TermService
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\termsrv.dll,-268
   Description: @%SystemRoot%\System32\termsrv.dll,-267
   Object name: NT Authority\NetworkService
    Image path: %SystemRoot%\System32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RPCSS,TermDD

Service (registry key): Themes
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\shsvcs.dll,-8192
   Description: @%SystemRoot%\System32\shsvcs.dll,-8193
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): THREADORDER
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\mmcss.dll,-102
   Description: @%systemroot%\system32\mmcss.dll,-103
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): TrkWks
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\trkwks.dll,-1
   Description: @%SystemRoot%\system32\trkwks.dll,-2
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): TrustedInstaller
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\servicing\TrustedInstaller.exe,-100
   Description: @%SystemRoot%\servicing\TrustedInstaller.exe,-101
   Object name: localSystem
    Image path: %SystemRoot%\servicing\TrustedInstaller.exe
    Image size: 42496
     Image MD5: 66328B08EF5A9305D8EDE36B93930369
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1

Service (registry key): TSDDD
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): tssecsrv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Terminal Services Security Filter Driver
   Description: Terminal Services Security Filter Driver
    Image path: System32\DRIVERS\tssecsrv.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): tunmp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Tun Miniport Adapter Driver
    Image path: system32\DRIVERS\tunmp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): tunnel
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft IPv6 Tunnel Miniport Adapter Driver
    Image path: system32\DRIVERS\tunnel.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): uagp35
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft AGPv3.5 Filter
    Image path: \SystemRoot\system32\drivers\uagp35.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): udfs
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: udfs
   Description: Reads/Writes UDF 1.02,1.5,2.0x,2.5 disc formats, usually found on C/DVD discs. (Core) (All pieces)
    Image path: system32\DRIVERS\udfs.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 2
 Error Control: 1

Service (registry key): UGatherer
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): UGTHRSVC
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): UI0Detect
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\ui0detect.exe,-101
   Description: @%SystemRoot%\system32\ui0detect.exe,-102
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\UI0Detect.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 272
 Error Control: 1

Service (registry key): uliagpkx
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Uli AGP Bus Filter
    Image path: \SystemRoot\system32\drivers\uliagpkx.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): uliahci
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\uliahci.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): UlSata
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\ulsata.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): ulsata2
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\ulsata2.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): umbus
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: UMBus Enumerator Driver
    Image path: system32\DRIVERS\umbus.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #20 on: September 22, 2009, 12:05:23 pm »
Service (registry key): UmRdpService
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): upnphost
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\upnphost.dll,-213
   Description: @%systemroot%\system32\upnphost.dll,-214
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: SSDPSRV,HTTP

Service (registry key): usb
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): usbaudio
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: USB Audio Driver (WDM)
    Image path: system32\drivers\usbaudio.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): usbccgp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft USB Generic Parent Driver
    Image path: system32\DRIVERS\usbccgp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): usbcir
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: eHome Infrared Receiver (USBCIR)
    Image path: \SystemRoot\system32\drivers\usbcir.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): usbehci
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
    Image path: system32\DRIVERS\usbehci.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): usbhub
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: USB2 Enabled Hub
    Image path: system32\DRIVERS\usbhub.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): usbohci
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft USB Open Host Controller Miniport Driver
    Image path: \SystemRoot\system32\drivers\usbohci.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): usbprint
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft USB PRINTER Class
    Image path: system32\DRIVERS\usbprint.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): usbscan
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: USB Scanner Driver
    Image path: system32\DRIVERS\usbscan.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): USBSTOR
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: USB Mass Storage Driver
    Image path: system32\DRIVERS\USBSTOR.SYS
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): usbuhci
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft USB Universal Host Controller Miniport Driver
    Image path: system32\DRIVERS\usbuhci.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): usbvideo
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: USB Video Device (WDM)
    Image path: System32\Drivers\usbvideo.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): UxSms
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\dwm.exe,-2000
   Description: @%SystemRoot%\system32\dwm.exe,-2001
   Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): vds
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\vds.exe,-100
   Description: @%SystemRoot%\system32\vds.exe,-112
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\vds.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: RpcSs,PlugPlay

Service (registry key): vga
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: system32\DRIVERS\vgapnp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 0

Service (registry key): VgaSave
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\System32\drivers\vga.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 0

Service (registry key): viaide
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\viaide.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 3

Service (registry key): volmgr
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Volume Manager Driver
    Image path: system32\drivers\volmgr.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): volmgrx
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Dynamic Volume Manager
   Description: Extension of the volume manager driver that manages software RAID volumes (spanned, striped, mirrored, RAID-5) on dynamic disks
    Image path: System32\drivers\volmgrx.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): volsnap
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Storage volumes
    Image path: system32\drivers\volsnap.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 3

Service (registry key): vsmraid
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: \SystemRoot\system32\drivers\vsmraid.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): VSS
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\vssvc.exe,-102
   Description: @%systemroot%\system32\vssvc.exe,-101
   Object name: LocalSystem
    Image path: %systemroot%\system32\vssvc.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): VxD
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): W32Time
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\w32time.dll,-200
   Description: @%SystemRoot%\system32\w32time.dll,-201
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1

Service (registry key): W3SVC
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): WacomPen
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Wacom Serial Pen HID Driver
    Image path: \SystemRoot\system32\drivers\wacompen.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): Wanarp
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Remote Access IP ARP Driver
   Description: Remote Access IP ARP Driver
    Image path: system32\DRIVERS\wanarp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): Wanarpv6
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Remote Access IPv6 ARP Driver
   Description: Remote Access IPv6 ARP Driver
    Image path: system32\DRIVERS\wanarp.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 1
          Type: 1
 Error Control: 1

Service (registry key): wcncsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\wcncsvc.dll,-3
   Description: @%SystemRoot%\system32\wcncsvc.dll,-4
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: rpcss

Service (registry key): WcsPlugInService
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\WcsPlugInService.dll,-200
   Description: @%SystemRoot%\system32\WcsPlugInService.dll,-201
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k wcssvc
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): Wd
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Watchdog Timer Driver
    Image path: \SystemRoot\system32\drivers\wd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): Wdf01000
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Kernel Mode Driver Frameworks service
    Image path: system32\drivers\Wdf01000.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 0
          Type: 1
 Error Control: 1

Service (registry key): WdiServiceHost
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\wdi.dll,-502
   Description: @%systemroot%\system32\wdi.dll,-503
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k wdisvc
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): WdiSystemHost
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\wdi.dll,-500
   Description: @%systemroot%\system32\wdi.dll,-501
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): WebClient
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\webclnt.dll,-100
   Description: @%systemroot%\system32\webclnt.dll,-101
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: MRxDAV

Service (registry key): Wecsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\wecsvc.dll,-200
   Description: @%SystemRoot%\system32\wecsvc.dll,-201
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\system32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: HTTP,Eventlog,mpssvc

Service (registry key): wercplsupport
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\wercplsupport.dll,-101
   Description: @%SystemRoot%\System32\wercplsupport.dll,-100
   Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1

Service (registry key): WerSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\wersvc.dll,-100
   Description: @%SystemRoot%\System32\wersvc.dll,-101
   Object name: localSystem
    Image path: %SystemRoot%\System32\svchost.exe -k WerSvcGroup
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 0

Service (registry key): WinDefend
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Windows Defender
   Description: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-3068
   Object name: LocalSystem
    Image path: %SystemRoot%\System32\svchost.exe -k secsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): Windows Workflow Foundation 3.0.0.0
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): WinHttpAutoProxySvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\winhttp.dll,-100
   Description: @%SystemRoot%\system32\winhttp.dll,-101
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: Dhcp

Service (registry key): Winmgmt
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%Systemroot%\system32\wbem\wmisvc.dll,-205
   Description: @%Systemroot%\system32\wbem\wmisvc.dll,-204
   Object name: localSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 0
 Depends On services: RPCSS

Service (registry key): WinRM
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%Systemroot%\system32\wsmsvc.dll,-101
   Description: @%Systemroot%\system32\wsmsvc.dll,-102
   Object name: NT AUTHORITY\NetworkService
    Image path: %SystemRoot%\System32\svchost.exe -k NetworkService
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: RPCSS,HTTP

Service (registry key): Winsock
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 3
          Type: 4
 Error Control: 1

Service (registry key): WinSock2
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): Wlansvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\wlansvc.dll,-257
   Description: @%SystemRoot%\System32\wlansvc.dll,-258
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: nativewifip,RpcSs,Ndisuio,Eaphost

Service (registry key): WmiAcpi
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Microsoft Windows Management Interface for ACPI
    Image path: \SystemRoot\system32\drivers\wmiacpi.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): WmiApRpl
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): wmiApSrv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110
   Description: @%Systemroot%\system32\wbem\wmiapsrv.exe,-111
   Object name: localSystem
    Image path: %systemroot%\system32\wbem\WmiApSrv.exe
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1

Service (registry key): WMPNetworkSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101
   Description: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-102
   Object name: NT AUTHORITY\NetworkService
    Image path: "%ProgramFiles%\Windows Media Player\wmpnetwk.exe"
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 16
 Error Control: 1
 Depends On services: UPnPHost,http

Service (registry key): WPCSvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\wpcsvc.dll,-100
   Description: @%SystemRoot%\system32\wpcsvc.dll,-101
   Object name: NT Authority\LocalService
    Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 3
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): WPDBusEnum
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\wpdbusenum.dll,-100
   Description: @%SystemRoot%\system32\wpdbusenum.dll,-101
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 4
          Type: 32
 Error Control: 1
 Depends On services: RpcSs

Service (registry key): WpdUsb
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: WpdUsb
    Image path: system32\DRIVERS\wpdusb.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): ws2ifsl
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: Winsock IFS driver
   Description: Winsock IFS driver
    Image path: \SystemRoot\system32\drivers\ws2ifsl.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 4
          Type: 1
 Error Control: 1

Service (registry key): wscsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\System32\wscsvc.dll,-200
   Description: @%SystemRoot%\System32\wscsvc.dll,-201
   Object name: NT AUTHORITY\LocalService
    Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: RpcSs,WinMgmt

Service (registry key): WSearch
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\SearchIndexer.exe,-103
   Description: @%systemroot%\system32\SearchIndexer.exe,-104
   Object name: LocalSystem
    Image path: %systemroot%\system32\SearchIndexer.exe /Embedding
    Image size: 441344
     Image MD5: AED0DFF80C6B3914769407E78D7AB21A
   Control Set: CurrentControlSet
         Start: 2
          Type: 16
 Error Control: 1
 Depends On services: RPCSS

Service (registry key): WSearchIdxPi
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): wuauserv
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%systemroot%\system32\wuaueng.dll,-105
   Description: @%systemroot%\system32\wuaueng.dll,-106
   Object name: LocalSystem
    Image path: %systemroot%\system32\svchost.exe -k netsvcs
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: rpcss

Service (registry key): WUDFRd
 Registry path: \SYSTEM\CurrentControlSet\Services\
    Image path: system32\DRIVERS\WUDFRd.sys
    Image size: 0
     Image MD5: D41D8CD98F00B204E9800998ECF8427E
   Control Set: CurrentControlSet
         Start: 3
          Type: 1
 Error Control: 1

Service (registry key): wudfsvc
 Registry path: \SYSTEM\CurrentControlSet\Services\
  Display name: @%SystemRoot%\system32\wudfsvc.dll,-1000
   Description: @%SystemRoot%\system32\wudfsvc.dll,-1001
   Object name: LocalSystem
    Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
    Image size: 21504
     Image MD5: 3794B461C45882E06856F282EEF025AF
   Control Set: CurrentControlSet
         Start: 2
          Type: 32
 Error Control: 1
 Depends On services: PlugPlay

Service (registry key): xmlprov
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): {CEA5D0B9-BDDF-4FCC-BE5B-1795EE2E539E}
 Registry path: \SYSTEM\CurrentControlSet\Services\
   Control Set: CurrentControlSet
         Start: 0
          Type: 0
 Error Control: 0

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #21 on: September 22, 2009, 12:10:04 pm »
well i found it, i pretty sure i have something running in background or a key logger i think my curser blinks way to much and it shouldnt take as long to load stuff as it does.


thank you for your time.

Offline Hoov

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 25852
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #22 on: September 22, 2009, 03:24:44 pm »
When you say your cursor is blinking rapidly, are you talking about the mouse or the cursor in text windows? As for any registry optimizer, generally they are not worth wasting your time.

Also you mention in your previous post that you found it. What did you find?

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #23 on: September 22, 2009, 10:21:18 pm »
the curser in text windows blinks, like after every entery. i found the spybot log, you did not mention if it was clean or not, thank you for reviewing this once again.

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #24 on: September 23, 2009, 11:28:42 am »
under property's in jusched.exe or any other procces running, i find a account unknown and this after it (5-1-5-5-0-31718769) should this be there its under almost all that i right-click and go to security tab, i try to remove it but says denied?

Offline Hoov

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 25852
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #25 on: September 23, 2009, 06:32:08 pm »
Can you do a screen shot of the window showing this account? 
I need you to start hijackthis, but go into the Misc tools and scroll to the top. Click the startup list log button. DON'T check the two boxes next to it. Post the log that is generated.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #26 on: September 23, 2009, 11:57:09 pm »
StartupList report, 9/24/2009, 12:47:48 AM
StartupList version: 1.52.2
Started from : C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows Vista SP2 (WinNT 6.00.1906)
Detected: Internet Explorer v8.00 (8.00.6001.18813)
* Using default options
==================================================

Running processes:

c:\PROGRA~2\mcafee.com\agent\mcagent.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\MySpace\Toolbar\1.0.45.0\MSTBCoreContainer.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Users\John Jr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\Windows\system32\Userinit.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

mcagent_exe = "C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe" /runkey
SunJavaUpdateSched = "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Sidebar = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
ehTray.exe = C:\Windows\ehome\ehTray.exe
Speech Recognition = "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
 =

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\Windows\SysWOW64\mshta.exe "%1" %*

--------------------------------------------------

Shell & screensaver key from C:\Windows\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=explorer.exe
SCRNSAVE.EXE=C:\Windows\system32\ssText3d.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

AcroIEHelperStub - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
(no name) - C:\Program Files (x86)\MySpace\Toolbar\1.0.45.0\MySpaceToolbar.dll - {28AED1AF-B164-44CD-B435-CF04AA955015}
(no name) - C:\Program Files (x86)\CommentsBar_-_Stickers_and_Comments\tbCom1.dll - {29456bfc-6fb2-4b36-b6a6-086a4cfc6770}
(no name) - C:\PROGRA~2\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - __BHODemonDisabled (file missing) - {5C255C8A-E604-49b4-9D64-90988571CECB}
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B}
scriptproxy - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll - {7DB2D5A0-7241-4E79-B68D-6309F01C5231}
(no name) - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll - {B164E929-A1B6-4A06-B104-2CD0E90A88FF}
(no name) - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
(no name) - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}

--------------------------------------------------

Enumerating Task Scheduler jobs:

EasyShare Registration Task.job
McDefragTask.job
McQcTask.job
User_Feed_Synchronization-{3B8C8D56-3DA1-4243-84AA-53D9C3DAD313}.job
User_Feed_Synchronization-{7E9F4C0D-6983-4552-9DEE-A9A5CA91B84F}.job

--------------------------------------------------

Enumerating Download Program Files:

[Windows Live Safety Center Base Module]
InProcServer32 = C:\Windows\Downloaded Program Files\wlscBase.dll
CODEBASE = http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\Windows\system32\NLAapi.dll
NameSpace #2: C:\Windows\system32\napinsp.dll
NameSpace #3: C:\Windows\system32\pnrpnsp.dll
NameSpace #4: C:\Windows\system32\pnrpnsp.dll

--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\Users\JOHNJR~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\index.dat||C:\Users\JOHNJR~1\AppData\Roaming\MICROS~1\Windows\Cookies\index.dat||C:\Users\JOHNJR~1\AppData\Roaming\MICROS~1\Windows\Cookies\Low\index.dat||C:\Users\JOHNJR~1\AppData\Local\MICROS~1\Windows\History\History.IE5\index.dat|||?

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\Windows\SysWOW64\webcheck.dll

--------------------------------------------------
End of report, 6,353 bytes
Report generated in 0.031 seconds

Command line options:
   /verbose  - to add additional info on each section
   /complete - to include empty sections and unsuspicious data
   /full     - to include several rarely-important sections
   /force9x  - to include Win9x-only startups even if running on WinNT
   /forcent  - to include WinNT-only startups even if running on Win9x
   /forceall - to include all Win9x and WinNT startups, regardless of platform
   /history  - to list version history only

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #27 on: September 24, 2009, 12:02:00 am »
only way i can get you the image is threw my snipping tool but cant paste it in reply any idea's?

Offline Hoov

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 25852
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #28 on: September 24, 2009, 11:36:49 am »
If you save it as a jpg, you can attach it to a post. When you hit the reply button there is an option below the text area that is marked additional options.  In there is where you can attach it.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline spawnjr

  • Bronze Member
  • Posts: 41
Re: [In Progress] malware bytes found a few rogue.errorfix & rogue.Acentive
« Reply #29 on: September 24, 2009, 11:50:15 am »
hers a jpeg, so was the hijack logs clean?