Jump to content

bcousins

Members
  • Posts

    7
  • Joined

  • Last visited

Posts posted by bcousins

  1. The computer hasnt been popping up virus warnings from AVG since the RogueKiller step. So far it seems great! Thanks for all your help. Let me know if there is anything else I still need to do. :)

    The log:

    ComboFix 12-11-13.02 - Brandy.C 13/11/2012 15:45:45.1.4 - x64

    Microsoft Windows 7 Professional 6.1.7601.1.1252.2.1033.18.4009.2716 [GMT -6:00]

    Running from: c:\users\Brandy.C\Desktop\ComboFix.exe

    AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}

    SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}

    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\users\Brandy.C\AppData\Local\WideSearch

    .

    .

    ((((((((((((((((((((((((( Files Created from 2012-10-13 to 2012-11-13 )))))))))))))))))))))))))))))))

    .

    .

    2012-11-12 16:47 . 2012-11-12 16:47 -------- d-----w- c:\users\Brandy.C\AppData\Roaming\Malwarebytes

    2012-11-12 16:47 . 2012-11-12 16:47 -------- d-----w- c:\programdata\Malwarebytes

    2012-11-12 16:47 . 2012-11-12 16:47 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

    2012-11-12 16:47 . 2012-09-30 01:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-11-12 15:43 . 2012-11-12 15:43 -------- d-----w- c:\users\Brandy.C\AppData\Roaming\AVG2013

    2012-11-12 15:41 . 2012-11-12 15:41 -------- d-----w- c:\users\Brandy.C\AppData\Roaming\TuneUp Software

    2012-11-12 15:40 . 2012-11-12 15:41 -------- d-----w- c:\programdata\AVG2013

    2012-11-12 15:40 . 2012-11-12 15:40 -------- d-----w- C:\$AVG

    2012-11-12 15:40 . 2012-11-12 15:40 -------- d-----w- c:\program files (x86)\AVG

    2012-11-12 15:36 . 2012-11-13 17:04 -------- d-----w- c:\programdata\MFAData

    2012-11-12 15:36 . 2012-11-12 17:26 -------- d-----w- c:\users\Brandy.C\AppData\Local\Avg2013

    2012-11-12 15:36 . 2012-11-12 15:36 -------- d--h--w- c:\programdata\Common Files

    2012-11-12 15:36 . 2012-11-12 15:36 -------- d-----w- c:\users\Brandy.C\AppData\Local\MFAData

    2012-11-05 14:58 . 2012-11-05 14:58 -------- d-----w- c:\users\Brandy.C\AppData\Local\Google

    2012-11-05 14:56 . 2012-11-08 14:48 -------- d-----w- c:\program files\Google

    2012-11-05 14:54 . 2012-11-08 14:48 -------- d-----w- c:\program files (x86)\Google

    2012-11-02 17:11 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe

    2012-10-31 19:18 . 2012-10-31 19:18 -------- d-----w- c:\users\Brandy.C\AppData\Local\Diagnostics

    2012-10-23 13:56 . 2012-11-02 17:48 -------- d-----w- C:\Downloads

    2012-10-22 19:02 . 2012-10-22 19:02 154464 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys

    2012-10-16 18:45 . 2012-10-16 18:45 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%

    2012-10-16 18:33 . 2012-11-02 17:37 -------- d-----w- c:\users\Brandy.C\AppData\Local\GetBooks

    2012-10-16 18:32 . 2012-11-02 17:57 -------- d-----w- c:\users\Brandy.C\AppData\Roaming\Free Download Manager

    2012-10-16 08:22 . 2012-08-30 07:27 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21766D0E-7EDC-4D86-A844-106130139B29}\mpengine.dll

    2012-10-15 09:48 . 2012-10-15 09:48 63328 ----a-w- c:\windows\system32\drivers\avgidsha.sys

    .

    .

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-10-05 09:32 . 2012-10-05 09:32 111456 ----a-w- c:\windows\system32\drivers\avgmfx64.sys

    2012-10-02 09:30 . 2012-10-02 09:30 185696 ----a-w- c:\windows\system32\drivers\avgldx64.sys

    2012-09-21 09:46 . 2012-09-21 09:46 200032 ----a-w- c:\windows\system32\drivers\avgtdia.sys

    2012-09-21 09:46 . 2012-09-21 09:46 225120 ----a-w- c:\windows\system32\drivers\avgloga.sys

    2012-09-14 19:19 . 2012-10-10 02:57 2048 ----a-w- c:\windows\system32\tzres.dll

    2012-09-14 18:28 . 2012-10-10 02:57 2048 ----a-w- c:\windows\SysWow64\tzres.dll

    2012-09-14 09:05 . 2012-09-14 09:05 40800 ----a-w- c:\windows\system32\drivers\avgrkx64.sys

    2012-09-04 12:29 . 2012-05-29 05:08 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

    2012-09-04 12:29 . 2012-05-29 05:08 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

    2012-08-31 18:19 . 2012-10-10 02:57 1659760 ----a-w- c:\windows\system32\drivers\ntfs.sys

    2012-08-30 18:03 . 2012-10-10 02:57 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe

    2012-08-30 17:12 . 2012-10-10 02:57 3968880 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

    2012-08-30 17:12 . 2012-10-10 02:57 3914096 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

    2012-08-24 18:05 . 2012-10-10 02:57 220160 ----a-w- c:\windows\system32\wintrust.dll

    2012-08-24 16:57 . 2012-10-10 02:57 172544 ----a-w- c:\windows\SysWow64\wintrust.dll

    2012-08-24 11:15 . 2012-09-21 21:29 17810944 ----a-w- c:\windows\system32\mshtml.dll

    2012-08-24 10:39 . 2012-09-21 21:29 10925568 ----a-w- c:\windows\system32\ieframe.dll

    2012-08-24 10:31 . 2012-09-21 21:29 2312704 ----a-w- c:\windows\system32\jscript9.dll

    2012-08-24 10:22 . 2012-09-21 21:29 1346048 ----a-w- c:\windows\system32\urlmon.dll

    2012-08-24 10:21 . 2012-09-21 21:29 1392128 ----a-w- c:\windows\system32\wininet.dll

    2012-08-24 10:20 . 2012-09-21 21:29 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

    2012-08-24 10:18 . 2012-09-21 21:29 237056 ----a-w- c:\windows\system32\url.dll

    2012-08-24 10:17 . 2012-09-21 21:29 85504 ----a-w- c:\windows\system32\jsproxy.dll

    2012-08-24 10:14 . 2012-09-21 21:29 173056 ----a-w- c:\windows\system32\ieUnatt.exe

    2012-08-24 10:14 . 2012-09-21 21:29 816640 ----a-w- c:\windows\system32\jscript.dll

    2012-08-24 10:13 . 2012-09-21 21:29 599040 ----a-w- c:\windows\system32\vbscript.dll

    2012-08-24 10:12 . 2012-09-21 21:29 2144768 ----a-w- c:\windows\system32\iertutil.dll

    2012-08-24 10:11 . 2012-09-21 21:29 729088 ----a-w- c:\windows\system32\msfeeds.dll

    2012-08-24 10:10 . 2012-09-21 21:29 96768 ----a-w- c:\windows\system32\mshtmled.dll

    2012-08-24 10:09 . 2012-09-21 21:29 2382848 ----a-w- c:\windows\system32\mshtml.tlb

    2012-08-24 10:04 . 2012-09-21 21:29 248320 ----a-w- c:\windows\system32\ieui.dll

    2012-08-24 06:59 . 2012-09-21 21:29 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

    2012-08-24 06:51 . 2012-09-21 21:29 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

    2012-08-24 06:51 . 2012-09-21 21:29 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

    2012-08-24 06:47 . 2012-09-21 21:29 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

    2012-08-24 06:47 . 2012-09-21 21:29 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

    2012-08-24 06:43 . 2012-09-21 21:29 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

    2012-08-23 20:34 . 2012-08-23 20:34 410984 ----a-w- c:\windows\SysWow64\deploytk.dll

    2012-08-23 17:19 . 2010-06-24 16:33 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

    2012-08-22 18:12 . 2012-09-12 14:56 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys

    2012-08-22 18:12 . 2012-09-12 14:56 950128 ----a-w- c:\windows\system32\drivers\ndis.sys

    2012-08-22 18:12 . 2012-09-12 14:56 376688 ----a-w- c:\windows\system32\drivers\netio.sys

    2012-08-22 18:12 . 2012-09-12 14:56 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS

    2012-08-21 21:01 . 2012-09-26 06:22 245760 ----a-w- c:\windows\system32\OxpsConverter.exe

    2012-08-20 18:48 . 2012-10-10 02:57 362496 ----a-w- c:\windows\system32\wow64win.dll

    2012-08-20 18:48 . 2012-10-10 02:57 243200 ----a-w- c:\windows\system32\wow64.dll

    2012-08-20 18:48 . 2012-10-10 02:57 13312 ----a-w- c:\windows\system32\wow64cpu.dll

    2012-08-20 18:48 . 2012-10-10 02:57 215040 ----a-w- c:\windows\system32\winsrv.dll

    2012-08-20 18:48 . 2012-10-10 02:57 16384 ----a-w- c:\windows\system32\ntvdm64.dll

    2012-08-20 18:48 . 2012-10-10 02:57 424448 ----a-w- c:\windows\system32\KernelBase.dll

    2012-08-20 18:48 . 2012-10-10 02:57 1162240 ----a-w- c:\windows\system32\kernel32.dll

    2012-08-20 18:46 . 2012-10-10 02:57 338432 ----a-w- c:\windows\system32\conhost.exe

    2012-08-20 18:38 . 2012-10-10 02:57 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll

    2012-08-20 18:38 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll

    2012-08-20 17:40 . 2012-10-10 02:57 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll

    2012-08-20 17:38 . 2012-10-10 02:57 44032 ----a-w- c:\windows\apppatch\acwow64.dll

    2012-08-20 17:38 . 2012-10-10 02:57 25600 ----a-w- c:\windows\SysWow64\setup16.exe

    2012-08-20 17:37 . 2012-10-10 02:57 5120 ----a-w- c:\windows\SysWow64\wow32.dll

    2012-08-20 17:37 . 2012-10-10 02:57 274944 ----a-w- c:\windows\SysWow64\KernelBase.dll

    2012-08-20 17:32 . 2012-10-10 02:57 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll

    2012-08-20 17:32 . 2012-10-10 02:57 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

    "aux"=wdmaud.drv

    .

    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

    R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]

    R3 netvsc;netvsc;c:\windows\system32\DRIVERS\netvsc60.sys [2010-11-21 168448]

    R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys [2010-11-21 22528]

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]

    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-08-24 1255736]

    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

    S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-10-15 63328]

    S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-09-21 225120]

    S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-10-05 111456]

    S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-09-14 40800]

    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]

    S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-10-22 154464]

    S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-10-02 185696]

    S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-21 200032]

    S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-07 5814392]

    S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]

    S2 DellDigitalDelivery;Dell Digital Delivery Service;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe [2012-10-09 173568]

    S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]

    S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2012-02-16 1695040]

    S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]

    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]

    .

    .

    --- Other Services/Drivers In Memory ---

    .

    *NewlyCreated* - WS2IFSL

    .

    Contents of the 'Scheduled Tasks' folder

    .

    2012-11-10 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job

    - c:\program files\Dell Support Center\uaclauncher.exe [2011-12-14 04:09]

    .

    2012-11-12 c:\windows\Tasks\SystemToolsDailyTest.job

    - c:\program files\Dell Support Center\pcdrcui.exe [2011-12-14 04:09]

    .

    .

    --------- X64 Entries -----------

    .

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-04 167960]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-04 391704]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-04 418328]

    .

    ------- Supplementary Scan -------

    .

    uLocal Page = c:\windows\system32\blank.htm

    uStart Page = hxxp://www.google.ca/

    mLocal Page = c:\windows\SysWOW64\blank.htm

    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

    .

    - - - - ORPHANS REMOVED - - - -

    .

    Toolbar-Locked - (no file)

    Toolbar-Locked - (no file)

    .

    .

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Data]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking 4.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET Data Provider for Oracle]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET Data Provider for SqlServer]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET Memory Cache 4.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NETFramework]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\1394ohci]

    "ImagePath"="\SystemRoot\system32\drivers\1394ohci.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI]

    "ImagePath"="system32\drivers\ACPI.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AcpiPmi]

    "ImagePath"="\SystemRoot\system32\drivers\acpipmi.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice]

    "ImagePath"="\"c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\adp94xx]

    "ImagePath"="\SystemRoot\system32\drivers\adp94xx.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\adpahci]

    "ImagePath"="\SystemRoot\system32\drivers\adpahci.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\adpu320]

    "ImagePath"="\SystemRoot\system32\drivers\adpu320.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\adsi]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc]

    "ServiceDll"="%SystemRoot%\System32\aelupsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AFD]

    "ImagePath"="\SystemRoot\system32\drivers\afd.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\agp440]

    "ImagePath"="\SystemRoot\system32\drivers\agp440.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG]

    "ImagePath"="%SystemRoot%\System32\alg.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aliide]

    "ImagePath"="\SystemRoot\system32\drivers\aliide.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\amdide]

    "ImagePath"="\SystemRoot\system32\drivers\amdide.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AmdK8]

    "ImagePath"="\SystemRoot\system32\drivers\amdk8.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AmdPPM]

    "ImagePath"="\SystemRoot\system32\drivers\amdppm.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\amdsata]

    "ImagePath"="\SystemRoot\system32\drivers\amdsata.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\amdsbs]

    "ImagePath"="\SystemRoot\system32\drivers\amdsbs.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\amdxata]

    "ImagePath"="system32\drivers\amdxata.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppID]

    "ImagePath"="\SystemRoot\system32\drivers\appid.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc]

    "ServiceDll"="%SystemRoot%\System32\appidsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo]

    "ServiceDll"="%SystemRoot%\System32\appinfo.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt]

    "ServiceDll"="%SystemRoot%\System32\appmgmts.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\arc]

    "ImagePath"="\SystemRoot\system32\drivers\arc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\arcsas]

    "ImagePath"="\SystemRoot\system32\drivers\arcsas.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ASP.NET]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ASP.NET_4.0.30319]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state]

    "ImagePath"="%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AsyncMac]

    "ImagePath"="system32\DRIVERS\asyncmac.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\atapi]

    "ImagePath"="system32\drivers\atapi.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\athr]

    "ImagePath"="system32\DRIVERS\athrx.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder]

    "ServiceDll"="%SystemRoot%\System32\Audiosrv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv]

    "ServiceDll"="%SystemRoot%\System32\Audiosrv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avg]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AVGIDSAgent]

    "ImagePath"="\"c:\program files (x86)\AVG\AVG2013\avgidsagent.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AVGIDSDriver]

    "ImagePath"="system32\DRIVERS\avgidsdrivera.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AVGIDSHA]

    "ImagePath"="system32\DRIVERS\avgidsha.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgldx64]

    "ImagePath"="system32\DRIVERS\avgldx64.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgloga]

    "ImagePath"="system32\DRIVERS\avgloga.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgmfx64]

    "ImagePath"="system32\DRIVERS\avgmfx64.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgrkx64]

    "ImagePath"="system32\DRIVERS\avgrkx64.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgtdia]

    "ImagePath"="system32\DRIVERS\avgtdia.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\avgwd]

    "ImagePath"="\"c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV]

    "ServiceDll"="%SystemRoot%\System32\AxInstSV.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\b06bdrv]

    "ImagePath"="\SystemRoot\system32\drivers\bxvbda.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\b57nd60a]

    "ImagePath"="system32\DRIVERS\b57nd60a.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BattC]

    "MofImagePath"="system32\drivers\battc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC]

    "ServiceDll"="%SystemRoot%\System32\bdesvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Beep]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE]

    "ServiceDll"="%SystemRoot%\System32\bfe.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS]

    "ServiceDll"="%systemroot%\system32\qmgr.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\blbdrive]

    "ImagePath"="system32\DRIVERS\blbdrive.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bowser]

    "ImagePath"="system32\DRIVERS\bowser.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrFiltLo]

    "ImagePath"="\SystemRoot\system32\drivers\BrFiltLo.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrFiltUp]

    "ImagePath"="\SystemRoot\system32\drivers\BrFiltUp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BridgeMP]

    "ImagePath"="system32\DRIVERS\bridge.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Browser]

    "ServiceDll"="%SystemRoot%\System32\browser.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Brserid]

    "ImagePath"="\SystemRoot\System32\Drivers\Brserid.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrSerWdm]

    "ImagePath"="\SystemRoot\System32\Drivers\BrSerWdm.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrUsbMdm]

    "ImagePath"="\SystemRoot\System32\Drivers\BrUsbMdm.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrUsbSer]

    "ImagePath"="\SystemRoot\System32\Drivers\BrUsbSer.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BTHMODEM]

    "ImagePath"="\SystemRoot\system32\drivers\bthmodem.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BTHPORT]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv]

    "ServiceDll"="%SystemRoot%\system32\bthserv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cdfs]

    "ImagePath"="system32\DRIVERS\cdfs.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cdrom]

    "ImagePath"="system32\DRIVERS\cdrom.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc]

    "ServiceDll"="%SystemRoot%\System32\certprop.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\circlass]

    "ImagePath"="\SystemRoot\system32\drivers\circlass.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CLFS]

    "ImagePath"="System32\CLFS.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32]

    "ImagePath"="%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64]

    "ImagePath"="%systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32]

    "ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64]

    "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CmBatt]

    "ImagePath"="\SystemRoot\system32\drivers\CmBatt.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cmdide]

    "ImagePath"="\SystemRoot\system32\drivers\cmdide.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CNG]

    "ImagePath"="System32\Drivers\cng.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CnxtHdAudService]

    "ImagePath"="system32\drivers\CHDRT64.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Compbatt]

    "ImagePath"="\SystemRoot\system32\drivers\compbatt.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CompositeBus]

    "ImagePath"="system32\DRIVERS\CompositeBus.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp]

    "ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crcdisk]

    "ImagePath"="\SystemRoot\system32\drivers\crcdisk.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc]

    "ServiceDll"="%SystemRoot%\system32\cryptsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CSC]

    "ImagePath"="system32\drivers\csc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CscService]

    "ServiceDll"="%SystemRoot%\System32\cscsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DCLocator]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch]

    "ServiceDll"="%SystemRoot%\system32\rpcss.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc]

    "ServiceDll"="%Systemroot%\System32\defragsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DellDigitalDelivery]

    "ImagePath"="\"c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DfsC]

    "ImagePath"="System32\Drivers\dfsc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dhcp]

    "ServiceDll"="%SystemRoot%\system32\dhcpcore.dll"

    --

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\discache]

    "ImagePath"="System32\drivers\discache.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Disk]

    "ImagePath"="system32\drivers\disk.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dmvsc]

    "ImagePath"="\SystemRoot\system32\drivers\dmvsc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache]

    "ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc]

    "ServiceDll"="%SystemRoot%\System32\dot3svc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DPS]

    "ServiceDll"="%SystemRoot%\system32\dps.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\drmkaud]

    "ImagePath"="system32\drivers\drmkaud.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DXGKrnl]

    "ImagePath"="\SystemRoot\System32\drivers\dxgkrnl.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost]

    "ServiceDll"="%SystemRoot%\System32\eapsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ebdrv]

    "ImagePath"="\SystemRoot\system32\drivers\evbda.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS]

    "ImagePath"="%SystemRoot%\System32\lsass.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr]

    "ImagePath"="%systemroot%\ehome\ehRecvr.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched]

    "ImagePath"="%systemroot%\ehome\ehsched.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\elxstor]

    "ImagePath"="\SystemRoot\system32\drivers\elxstor.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ErrDev]

    "ImagePath"="\SystemRoot\system32\drivers\errdev.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ESENT]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog]

    "ServiceDll"="%SystemRoot%\System32\wevtsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem]

    "ServiceDll"="%systemroot%\system32\es.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\exfat]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fastfat]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax]

    "ImagePath"="%systemroot%\system32\fxssvc.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdc]

    "ImagePath"="\SystemRoot\system32\drivers\fdc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost]

    "ServiceDll"="%SystemRoot%\system32\fdPHost.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub]

    "ServiceDll"="%SystemRoot%\system32\fdrespub.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FileInfo]

    "ImagePath"="system32\drivers\fileinfo.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Filetrace]

    "ImagePath"="system32\drivers\filetrace.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\flpydisk]

    "ImagePath"="\SystemRoot\system32\drivers\flpydisk.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FltMgr]

    "ImagePath"="system32\drivers\fltmgr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache]

    "ServiceDll"="%SystemRoot%\system32\FntCache.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0]

    "ImagePath"="%systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FsDepends]

    "ImagePath"="System32\drivers\FsDepends.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fs_Rec]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fvevol]

    "ImagePath"="System32\DRIVERS\fvevol.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gagp30kx]

    "ImagePath"="\SystemRoot\system32\drivers\gagp30kx.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc]

    "ServiceDll"="%SystemRoot%\System32\gpsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hcw85cir]

    "ImagePath"="\SystemRoot\system32\drivers\hcw85cir.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus]

    "ImagePath"="system32\DRIVERS\HDAudBus.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HidBatt]

    "ImagePath"="\SystemRoot\system32\drivers\HidBatt.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HidBth]

    "ImagePath"="\SystemRoot\system32\drivers\hidbth.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HidIr]

    "ImagePath"="\SystemRoot\system32\drivers\hidir.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv]

    "ServiceDll"="%SystemRoot%\System32\hidserv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HidUsb]

    "ImagePath"="system32\DRIVERS\hidusb.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc]

    "ServiceDLL"="%SystemRoot%\system32\kmsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener]

    "ServiceDll"="%SystemRoot%\system32\ListSvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider]

    "ServiceDll"="%SystemRoot%\system32\provsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HpSAMD]

    "ImagePath"="\SystemRoot\system32\drivers\HpSAMD.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HTTP]

    "ImagePath"="system32\drivers\HTTP.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hwpolicy]

    "ImagePath"="System32\drivers\hwpolicy.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\i8042prt]

    "ImagePath"="\SystemRoot\system32\drivers\i8042prt.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ialm]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iaStorV]

    "ImagePath"="\SystemRoot\system32\drivers\iaStorV.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc]

    "ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\igfx]

    "ImagePath"="system32\DRIVERS\igdkmd64.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iirsp]

    "ImagePath"="\SystemRoot\system32\drivers\iirsp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IKEEXT]

    "ServiceDll"="%SystemRoot%\System32\ikeext.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\inetaccs]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IntcDAud]

    "ImagePath"="system32\DRIVERS\IntcDAud.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelide]

    "ImagePath"="system32\drivers\intelide.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm]

    "ImagePath"="system32\DRIVERS\intelppm.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum]

    "ServiceDll"="%SystemRoot%\system32\ipbusenum.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IpFilterDriver]

    "ImagePath"="system32\DRIVERS\ipfltdrv.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc]

    "ServiceDll"="%SystemRoot%\System32\iphlpsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPMIDRV]

    "ImagePath"="\SystemRoot\system32\drivers\IPMIDrv.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPNAT]

    "ImagePath"="System32\drivers\ipnat.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IRENUM]

    "ImagePath"="system32\drivers\irenum.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\isapnp]

    "ImagePath"="\SystemRoot\system32\drivers\isapnp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iScsiPrt]

    "ImagePath"="\SystemRoot\system32\drivers\msiscsi.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\kbdclass]

    "ImagePath"="system32\DRIVERS\kbdclass.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\kbdhid]

    "ImagePath"="system32\DRIVERS\kbdhid.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso]

    "ImagePath"="%SystemRoot%\system32\lsass.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KSecDD]

    "ImagePath"="System32\Drivers\ksecdd.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KSecPkg]

    "ImagePath"="System32\Drivers\ksecpkg.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ksthunk]

    "ImagePath"="\SystemRoot\system32\drivers\ksthunk.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm]

    "ServiceDll"="%systemroot%\system32\msdtckrm.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer]

    "ServiceDll"="%SystemRoot%\System32\srvsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation]

    "ServiceDll"="%SystemRoot%\System32\wkssvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ldap]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdio]

    "ImagePath"="system32\DRIVERS\lltdio.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc]

    "ServiceDll"="%SystemRoot%\System32\lltdsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts]

    "ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Lsa]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LSI_FC]

    "ImagePath"="\SystemRoot\system32\drivers\lsi_fc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LSI_SAS]

    "ImagePath"="\SystemRoot\system32\drivers\lsi_sas.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LSI_SAS2]

    "ImagePath"="\SystemRoot\system32\drivers\lsi_sas2.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LSI_SCSI]

    "ImagePath"="\SystemRoot\system32\drivers\lsi_scsi.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\luafv]

    "ImagePath"="\SystemRoot\system32\drivers\luafv.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc]

    "ServiceDll"="%SystemRoot%\system32\Mcx2Svc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\megasas]

    "ImagePath"="\SystemRoot\system32\drivers\megasas.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MegaSR]

    "ImagePath"="\SystemRoot\system32\drivers\MegaSR.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEIx64]

    "ImagePath"="system32\DRIVERS\HECIx64.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Microsoft Office Groove Audit Service]

    "ImagePath"="\"c:\program files (x86)\Microsoft Office\Office12\GrooveAuditService.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MMCSS]

    "ServiceDll"="%SystemRoot%\system32\mmcss.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Modem]

    "ImagePath"="system32\drivers\modem.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor]

    "ImagePath"="system32\DRIVERS\monitor.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mouclass]

    "ImagePath"="system32\DRIVERS\mouclass.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mouhid]

    "ImagePath"="system32\DRIVERS\mouhid.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mountmgr]

    "ImagePath"="System32\drivers\mountmgr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mpio]

    "ImagePath"="\SystemRoot\system32\drivers\mpio.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mpsdrv]

    "ImagePath"="System32\drivers\mpsdrv.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc]

    "ServiceDll"="%SystemRoot%\system32\mpssvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MRxDAV]

    "ImagePath"="\SystemRoot\system32\drivers\mrxdav.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mrxsmb]

    "ImagePath"="system32\DRIVERS\mrxsmb.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mrxsmb10]

    "ImagePath"="system32\DRIVERS\mrxsmb10.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mrxsmb20]

    "ImagePath"="system32\DRIVERS\mrxsmb20.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msahci]

    "ImagePath"="\SystemRoot\system32\drivers\msahci.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msdsm]

    "ImagePath"="\SystemRoot\system32\drivers\msdsm.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC]

    "ImagePath"="%SystemRoot%\System32\msdtc.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC Bridge 3.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC Bridge 4.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Msfs]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mshidkmdf]

    "ImagePath"="\SystemRoot\System32\drivers\mshidkmdf.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msisadrv]

    "ImagePath"="system32\drivers\msisadrv.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI]

    "ServiceDll"="%systemroot%\system32\iscsiexe.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver]

    "ImagePath"="%systemroot%\system32\msiexec.exe /V"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSKSSRV]

    "ImagePath"="system32\drivers\MSKSSRV.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSPCLOCK]

    "ImagePath"="system32\drivers\MSPCLOCK.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSPQM]

    "ImagePath"="system32\drivers\MSPQM.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MsRPC]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSSCNTRS]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios]

    "ImagePath"="system32\DRIVERS\mssmbios.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSTEE]

    "ImagePath"="system32\drivers\MSTEE.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MTConfig]

    "ImagePath"="\SystemRoot\system32\drivers\MTConfig.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mup]

    "ImagePath"="System32\Drivers\mup.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent]

    "ServiceDLL"="%SystemRoot%\system32\qagentRT.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NativeWifiP]

    "ImagePath"="system32\DRIVERS\nwifi.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS]

    "ImagePath"="system32\drivers\ndis.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NdisCap]

    "ImagePath"="system32\DRIVERS\ndiscap.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NdisTapi]

    "ImagePath"="system32\DRIVERS\ndistapi.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Ndisuio]

    "ImagePath"="system32\DRIVERS\ndisuio.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NdisWan]

    "ImagePath"="system32\DRIVERS\ndiswan.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDProxy]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBIOS]

    "ImagePath"="system32\DRIVERS\netbios.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT]

    "ImagePath"="System32\DRIVERS\netbt.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon]

    "ImagePath"="%SystemRoot%\system32\lsass.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netman]

    "ServiceDll"="%SystemRoot%\System32\netman.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator]

    "ImagePath"="\"c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe\" -NetMsmqActivator"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator]

    "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\netprofm]

    "ServiceDll"="%SystemRoot%\System32\netprofm.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator]

    "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing]

    "ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\netvsc]

    "ImagePath"="system32\DRIVERS\netvsc60.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nfrd960]

    "ImagePath"="\SystemRoot\system32\drivers\nfrd960.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NlaSvc]

    "ServiceDll"="%SystemRoot%\System32\nlasvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NOBU]

    "ImagePath"="\"c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe\" SERVICE"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Npfs]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nsi]

    "ServiceDll"="%systemroot%\system32\nsisvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nsiproxy]

    "ImagePath"="system32\drivers\nsiproxy.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NTDS]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Ntfs]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Null]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nvraid]

    "ImagePath"="\SystemRoot\system32\drivers\nvraid.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nvstor]

    "ImagePath"="\SystemRoot\system32\drivers\nvstor.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nv_agp]

    "ImagePath"="\SystemRoot\system32\drivers\nv_agp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\odserv]

    "ImagePath"="\"c:\program files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ohci1394]

    "ImagePath"="\SystemRoot\system32\drivers\ohci1394.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose]

    "ImagePath"="\"c:\program files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Outlook]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc]

    "ServiceDll"="%SystemRoot%\system32\pnrpsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc]

    "ServiceDll"="%SystemRoot%\system32\p2psvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Parport]

    "ImagePath"="\SystemRoot\system32\drivers\parport.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\partmgr]

    "ImagePath"="System32\drivers\partmgr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PcaSvc]

    "ServiceDll"="%SystemRoot%\System32\pcasvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pci]

    "ImagePath"="system32\drivers\pci.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pciide]

    "ImagePath"="\SystemRoot\system32\drivers\pciide.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pcmcia]

    "ImagePath"="\SystemRoot\system32\drivers\pcmcia.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pcw]

    "ImagePath"="System32\drivers\pcw.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PEAUTH]

    "ImagePath"="system32\drivers\peauth.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc]

    "ServiceDll"="%SystemRoot%\system32\peerdistsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfDisk]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost]

    "ImagePath"="%SystemRoot%\SysWow64\perfhost.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfNet]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfOS]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfProc]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Perf_iCrcPerfMonMgr]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla]

    "ServiceDll"="%systemroot%\system32\pla.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PlugPlay]

    "ServiceDll"="%SystemRoot%\system32\umpnpmgr.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg]

    "ServiceDll"="%SystemRoot%\system32\pnrpauto.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc]

    "ServiceDll"="%SystemRoot%\system32\pnrpsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent]

    "ServiceDll"="%SystemRoot%\System32\ipsecsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PortProxy]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Power]

    "ServiceDll"="%SystemRoot%\system32\umpo.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PptpMiniport]

    "ImagePath"="system32\DRIVERS\raspptp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Processor]

    "ImagePath"="\SystemRoot\system32\drivers\processr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProfSvc]

    "ServiceDll"="%systemroot%\system32\profsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage]

    "ImagePath"="%SystemRoot%\system32\lsass.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Psched]

    "ImagePath"="system32\DRIVERS\pacer.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PxHlpa64]

    "ImagePath"="System32\Drivers\PxHlpa64.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ql2300]

    "ImagePath"="\SystemRoot\system32\drivers\ql2300.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ql40xx]

    "ImagePath"="\SystemRoot\system32\drivers\ql40xx.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE]

    "ServiceDll"="%windir%\system32\qwave.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVEdrv]

    "ImagePath"="\SystemRoot\system32\drivers\qwavedrv.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAcd]

    "ImagePath"="System32\DRIVERS\rasacd.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAgileVpn]

    "ImagePath"="system32\DRIVERS\AgileVpn.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto]

    "ServiceDll"="%SystemRoot%\System32\rasauto.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rasl2tp]

    "ImagePath"="system32\DRIVERS\rasl2tp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan]

    "ServiceDll"="%SystemRoot%\System32\rasmans.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasPppoe]

    "ImagePath"="system32\DRIVERS\raspppoe.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasSstp]

    "ImagePath"="system32\DRIVERS\rassstp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rdbss]

    "ImagePath"="system32\DRIVERS\rdbss.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rdpbus]

    "ImagePath"="system32\DRIVERS\rdpbus.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPCDD]

    "ImagePath"="System32\DRIVERS\RDPCDD.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPDD]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPDR]

    "ImagePath"="System32\drivers\rdpdr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPENCDD]

    "ImagePath"="system32\drivers\rdpencdd.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPREFMP]

    "ImagePath"="system32\drivers\rdprefmp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPWD]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rdyboost]

    "ImagePath"="System32\drivers\rdyboost.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess]

    "ServiceDLL"="%SystemRoot%\System32\mprdim.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry]

    "ServiceDll"="%SystemRoot%\system32\regsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RimUsb]

    "ImagePath"="System32\Drivers\RimUsb_AMD64.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper]

    "ServiceDll"="%SystemRoot%\System32\RpcEpMap.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator]

    "ImagePath"="%SystemRoot%\system32\locator.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs]

    "ServiceDll"="%SystemRoot%\system32\rpcss.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rspndr]

    "ImagePath"="system32\DRIVERS\rspndr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RTL8167]

    "ImagePath"="system32\DRIVERS\Rt64win7.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\s3cap]

    "ImagePath"="\SystemRoot\system32\drivers\vms3cap.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs]

    "ImagePath"="%SystemRoot%\system32\lsass.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sbp2port]

    "ImagePath"="\SystemRoot\system32\drivers\sbp2port.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr]

    "ServiceDll"="%SystemRoot%\System32\SCardSvr.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\scfilter]

    "ImagePath"="System32\DRIVERS\scfilter.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Schedule]

    "ServiceDll"="%systemroot%\system32\schedsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc]

    "ServiceDll"="%SystemRoot%\System32\certprop.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC]

    "ServiceDll"="%Systemroot%\System32\SDRSVC.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\secdrv]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon]

    "ServiceDll"="%windir%\system32\seclogon.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SENS]

    "ServiceDll"="%SystemRoot%\system32\sens.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc]

    "ServiceDll"="%SystemRoot%\system32\sensrsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Serenum]

    "ImagePath"="\SystemRoot\system32\drivers\serenum.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Serial]

    "ImagePath"="\SystemRoot\system32\drivers\serial.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sermouse]

    "ImagePath"="\SystemRoot\system32\drivers\sermouse.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ServiceModelEndpoint 3.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ServiceModelOperation 3.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ServiceModelService 3.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv]

    "ServiceDLL"="%SystemRoot%\system32\sessenv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sffdisk]

    "ImagePath"="\SystemRoot\system32\drivers\sffdisk.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sffp_mmc]

    "ImagePath"="\SystemRoot\system32\drivers\sffp_mmc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sffp_sd]

    "ImagePath"="\SystemRoot\system32\drivers\sffp_sd.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sfloppy]

    "ImagePath"="\SystemRoot\system32\drivers\sfloppy.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SftService]

    "ImagePath"="\"c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess]

    "ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ShellHWDetection]

    "ServiceDll"="%SystemRoot%\System32\shsvcs.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SiSRaid2]

    "ImagePath"="\SystemRoot\system32\drivers\SiSRaid2.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SiSRaid4]

    "ImagePath"="\SystemRoot\system32\drivers\sisraid4.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Smb]

    "ImagePath"="system32\DRIVERS\smb.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SMSvcHost 3.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SMSvcHost 4.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP]

    "ImagePath"="%SystemRoot%\System32\snmptrap.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\spldr]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler]

    "ImagePath"="%SystemRoot%\System32\spoolsv.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc]

    "ImagePath"="%SystemRoot%\system32\sppsvc.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify]

    "ServiceDll"="%SystemRoot%\system32\sppuinotify.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\srv]

    "ImagePath"="System32\DRIVERS\srv.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\srv2]

    "ImagePath"="System32\DRIVERS\srv2.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\srvnet]

    "ImagePath"="System32\DRIVERS\srvnet.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV]

    "ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc]

    "ServiceDll"="%SystemRoot%\system32\sstpsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stexstor]

    "ImagePath"="\SystemRoot\system32\drivers\stexstor.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc]

    "ServiceDll"="%SystemRoot%\System32\wiaservc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc]

    "ServiceDll"="%SystemRoot%\system32\storsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\storvsc]

    "ImagePath"="\SystemRoot\system32\drivers\storvsc.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swenum]

    "ImagePath"="system32\DRIVERS\swenum.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv]

    "ServiceDll"="%Systemroot%\System32\swprv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SynthVid]

    "ImagePath"="system32\DRIVERS\VMBusVideoM.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain]

    "ServiceDll"="%systemroot%\system32\sysmain.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService]

    "ServiceDll"="%SystemRoot%\System32\TabSvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv]

    "ServiceDll"="%SystemRoot%\System32\tapisrv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS]

    "ServiceDll"="%SystemRoot%\System32\tbssvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip]

    "ImagePath"="System32\drivers\tcpip.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6]

    "ImagePath"="system32\DRIVERS\tcpip.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6TUNNEL]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tcpipreg]

    "ImagePath"="System32\drivers\tcpipreg.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIPTUNNEL]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TDPIPE]

    "ImagePath"="system32\drivers\tdpipe.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TDTCP]

    "ImagePath"="system32\drivers\tdtcp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tdx]

    "ImagePath"="system32\DRIVERS\tdx.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermDD]

    "ImagePath"="system32\DRIVERS\termdd.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService]

    "ServiceDll"="%SystemRoot%\System32\termsrv.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Themes]

    "ServiceDll"="%SystemRoot%\system32\themeservice.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER]

    "ServiceDll"="%SystemRoot%\system32\mmcss.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrkWks]

    "ServiceDll"="%SystemRoot%\System32\trkwks.dll"

    --

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller]

    "ImagePath"="%SystemRoot%\servicing\TrustedInstaller.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TSDDD]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tssecsrv]

    "ImagePath"="System32\DRIVERS\tssecsrv.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TsUsbFlt]

    "ImagePath"="system32\drivers\tsusbflt.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TsUsbGD]

    "ImagePath"="\SystemRoot\system32\drivers\TsUsbGD.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tunnel]

    "ImagePath"="system32\DRIVERS\tunnel.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\uagp35]

    "ImagePath"="\SystemRoot\system32\drivers\uagp35.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\udfs]

    "ImagePath"="system32\DRIVERS\udfs.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UGatherer]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UGTHRSVC]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect]

    "ImagePath"="%SystemRoot%\system32\UI0Detect.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\uliagpkx]

    "ImagePath"="\SystemRoot\system32\drivers\uliagpkx.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\umbus]

    "ImagePath"="system32\DRIVERS\umbus.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmPass]

    "ImagePath"="\SystemRoot\system32\drivers\umpass.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService]

    "ServiceDll"="%SystemRoot%\System32\umrdp.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost]

    "ServiceDll"="%SystemRoot%\System32\upnphost.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbccgp]

    "ImagePath"="system32\DRIVERS\usbccgp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbcir]

    "ImagePath"="\SystemRoot\system32\drivers\usbcir.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbehci]

    "ImagePath"="system32\DRIVERS\usbehci.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbhub]

    "ImagePath"="system32\DRIVERS\usbhub.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbohci]

    "ImagePath"="\SystemRoot\system32\drivers\usbohci.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbprint]

    "ImagePath"="system32\DRIVERS\usbprint.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\USBSTOR]

    "ImagePath"="system32\DRIVERS\USBSTOR.SYS"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbuhci]

    "ImagePath"="\SystemRoot\system32\drivers\usbuhci.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UxSms]

    "ServiceDll"="%SystemRoot%\System32\uxsms.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc]

    "ImagePath"="%SystemRoot%\system32\lsass.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vdrvroot]

    "ImagePath"="system32\drivers\vdrvroot.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds]

    "ImagePath"="%SystemRoot%\System32\vds.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vga]

    "ImagePath"="system32\DRIVERS\vgapnp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VgaSave]

    "ImagePath"="\SystemRoot\System32\drivers\vga.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vhdmp]

    "ImagePath"="\SystemRoot\system32\drivers\vhdmp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\viaide]

    "ImagePath"="\SystemRoot\system32\drivers\viaide.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VMBusHID]

    "ImagePath"="\SystemRoot\system32\drivers\VMBusHID.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\volmgr]

    "ImagePath"="system32\drivers\volmgr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\volmgrx]

    "ImagePath"="System32\drivers\volmgrx.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\volsnap]

    "ImagePath"="system32\drivers\volsnap.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vpcbus]

    "ImagePath"="system32\DRIVERS\vpchbus.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vpcnfltr]

    "ImagePath"="system32\DRIVERS\vpcnfltr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vpcusb]

    "ImagePath"="system32\DRIVERS\vpcusb.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vpcvmm]

    "ImagePath"="system32\drivers\vpcvmm.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vsmraid]

    "ImagePath"="\SystemRoot\system32\drivers\vsmraid.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS]

    "ImagePath"="%systemroot%\system32\vssvc.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vwifibus]

    "ImagePath"="system32\DRIVERS\vwifibus.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vwififlt]

    "ImagePath"="system32\DRIVERS\vwififlt.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time]

    "ServiceDll"="%systemroot%\system32\w32time.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W3SVC]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WacomPen]

    "ImagePath"="\SystemRoot\system32\drivers\wacompen.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WANARP]

    "ImagePath"="system32\DRIVERS\wanarp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wanarpv6]

    "ImagePath"="system32\DRIVERS\wanarp.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WatAdminSvc]

    "ImagePath"="%SystemRoot%\system32\Wat\WatAdminSvc.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine]

    "ImagePath"="\"%systemroot%\system32\wbengine.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc]

    "ServiceDll"="%SystemRoot%\System32\wbiosrvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc]

    "ServiceDll"="%SystemRoot%\System32\wcncsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService]

    "ServiceDll"="%SystemRoot%\System32\WcsPlugInService.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wd]

    "ImagePath"="\SystemRoot\system32\drivers\wd.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wdf01000]

    "ImagePath"="system32\drivers\Wdf01000.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiServiceHost]

    "ServiceDll"="%SystemRoot%\system32\wdi.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiSystemHost]

    "ServiceDll"="%SystemRoot%\system32\wdi.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient]

    "ServiceDll"="%SystemRoot%\System32\webclnt.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc]

    "ServiceDll"="%SystemRoot%\system32\wecsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport]

    "ServiceDll"="%SystemRoot%\System32\wercplsupport.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc]

    "ServiceDll"="%SystemRoot%\System32\WerSvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WfpLwf]

    "ImagePath"="system32\DRIVERS\wfplwf.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WimFltr]

    "ImagePath"="system32\DRIVERS\wimfltr.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WIMMount]

    "ImagePath"="system32\drivers\wimmount.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend]

    "ServiceDll"="%ProgramFiles%\Windows Defender\mpsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Windows Workflow Foundation 3.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Windows Workflow Foundation 4.0.0.0]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc]

    "ServiceDll"="winhttp.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt]

    "ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM]

    "ServiceDll"="%SystemRoot%\system32\WsmSvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winsock]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc]

    "ServiceDll"="%SystemRoot%\System32\wlansvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wlcrasvc]

    "ImagePath"="\"c:\program files\Windows Live\Mesh\wlcrasvc.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wlidsvc]

    "ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WmiAcpi]

    "ImagePath"="\SystemRoot\system32\drivers\wmiacpi.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WmiApRpl]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv]

    "ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc]

    "ImagePath"="\"%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe\""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc]

    "ServiceDll"="%SystemRoot%\System32\wpcsvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum]

    "ServiceDll"="%SystemRoot%\system32\wpdbusenum.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ws2ifsl]

    "ImagePath"="\SystemRoot\system32\drivers\ws2ifsl.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch]

    "ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearchIdxPi]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv]

    "ServiceDll"="%systemroot%\system32\wuaueng.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WudfPf]

    "ImagePath"="system32\drivers\WudfPf.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WUDFRd]

    "ImagePath"="system32\DRIVERS\WUDFRd.sys"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc]

    "ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc]

    "ServiceDll"="%SystemRoot%\System32\wwansvc.dll"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\xmlprov]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{91FE5567-57D5-428B-916D-546692D35888}]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{CAAF42B5-6227-4B1E-9962-13182EA23F53}]

    .

    --------------------- LOCKED REGISTRY KEYS ---------------------

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker5"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Shockwave Flash Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

    @="0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

    @="ShockwaveFlash.ShockwaveFlash.11"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="ShockwaveFlash.ShockwaveFlash"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Macromedia Flash Factory Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

    @="FlashFactory.FlashFactory.1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="FlashFactory.FlashFactory"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker5"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

    @Denied: (Full) (Everyone)

    .

    ------------------------ Other Running Processes ------------------------

    .

    c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe

    c:\program files (x86)\Dell DataSafe Local Backup\TOASTER.EXE

    c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

    .

    **************************************************************************

    .

    Completion time: 2012-11-13 15:55:20 - machine was rebooted

    ComboFix-quarantined-files.txt 2012-11-13 21:55

    .

    Pre-Run: 431,333,998,592 bytes free

    Post-Run: 431,327,141,888 bytes free

    .

    - - End Of File - - 893B02106E82AF359682651D5A5C1D26

  2. RogueKiller V8.2.3 [11/07/2012] by Tigzy

    mail: tigzyRK<at>gmail<dot>com

    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

    Website: http://tigzy.geekstogo.com/roguekiller.php

    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version

    Started in : Normal mode

    User : Brandy.C [Admin rights]

    Mode : Remove -- Date : 11/13/2012 15:32:39

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    [ZeroAccess][FOLDER] ROOT : C:\Windows\Installer\{1a05c27a-4a3e-8fa6-d8b4-ad7821980b1c}\U --> REMOVED

    [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> REMOVED

    [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> REMOVED

    ¤¤¤ Driver : [NOT LOADED] ¤¤¤

    ¤¤¤ Infection : ZeroAccess ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤

    --> C:\Windows\system32\drivers\etc\hosts

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++

    --- User ---

    [MBR] 21debc1748c9d5e1da4b5774dca9369c

    [bSP] 366997afff2489cacd282eb3bc9248a1 : Windows Vista MBR Code

    Partition table:

    0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo

    1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 24732 Mo

    2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 50733056 | Size: 452164 Mo

    User = LL1 ... OK!

    User = LL2 ... OK!

    Finished : << RKreport[4]_D_11132012_02d1532.txt >>

    RKreport[1]_S_11132012_02d1528.txt ; RKreport[2]_D_11132012_02d1529.txt ; RKreport[3]_S_11132012_02d1532.txt ; RKreport[4]_D_11132012_02d1532.txt

  3. # AdwCleaner v2.007 - Logfile created 11/13/2012 at 15:24:21

    # Updated 06/11/2012 by Xplode

    # Operating system : Windows 7 Professional Service Pack 1 (64 bits)

    # User : Brandy.C - AARLEGALPC

    # Boot Mode : Normal

    # Running from : C:\Users\Brandy.C\Desktop\AdwCleaner.exe

    # Option [Delete]

    ***** [services] *****

    ***** [Files / Folders] *****

    ***** [Registry] *****

    ***** [internet Browsers] *****

    -\\ Internet Explorer v9.0.8112.16421

    [OK] Registry is clean.

    *************************

    AdwCleaner[s1].txt - [523 octets] - [13/11/2012 15:24:21]

    ########## EOF - C:\AdwCleaner[s1].txt - [582 octets] ##########

  4. Results of screen317's Security Check version 0.99.54

    Windows 7 Service Pack 1 x64 (UAC is enabled)

    Internet Explorer 9

    ``````````````Antivirus/Firewall Check:``````````````

    Windows Security Center service is not running! This report may not be accurate!

    avast! Antivirus

    Antivirus up to date! (On Access scanning disabled!)

    `````````Anti-malware/Other Utilities Check:`````````

    Malwarebytes Anti-Malware version 1.65.1.1000

    Java 6 Update 13

    Java version out of Date!

    Adobe Reader X (10.1.4)

    ````````Process Check: objlist.exe by Laurent````````

    AVG avgwdsvc.exe

    `````````````````System Health check`````````````````

    Total Fragmentation on Drive C: 2%

    ````````````````````End of Log``````````````````````

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.