ComboFix 08-08-24.03 - Ryan 2008-08-25 9:35:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2454 [GMT -7:00]
Running from: C:\Documents and Settings\Ryan\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\#SharedObjects\JPZP2JYA\interclick.com
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\#SharedObjects\JPZP2JYA\interclick.com\ud.sol
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\#SharedObjects\JPZP2JYA\static.youku.com
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\#SharedObjects\JPZP2JYA\static.youku.com\v1.0.0305\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\Documents and Settings\Ryan\Desktop\Error Cleaner.url
C:\Documents and Settings\Ryan\Desktop\Privacy Protector.url
C:\Documents and Settings\Ryan\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Ryan\Favorites\Error Cleaner.url
C:\Documents and Settings\Ryan\Favorites\Privacy Protector.url
C:\Documents and Settings\Ryan\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\system32\Cache
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-07-25 to 2008-08-25 )))))))))))))))))))))))))))))))
.
2008-08-25 09:47 . 2008-08-25 09:47 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\TmpRecentIcons
2008-08-25 08:40 . 2008-08-25 08:40 578,560 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
2008-08-25 08:38 . 2008-08-25 08:38 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-25 08:33 . 2008-08-25 08:45 <DIR> d-------- C:\SDFix
2008-08-25 08:30 . 2008-08-25 08:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-24 23:24 . 2008-08-24 23:24 <DIR> d-------- C:\Program Files\ERUNT
2008-08-24 21:01 . 2008-08-24 21:04 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-08-24 20:13 . 2008-08-24 20:21 <DIR> d-------- C:\Program Files\RogueRemover FREE
2008-08-24 17:59 . 2008-08-24 03:45 380,928 --a------ C:\WINDOWS\rodqgpvlkoa.dll
2008-08-24 17:59 . 2008-08-24 03:45 233,472 --a------ C:\WINDOWS\pdoskegl.dll
2008-08-24 17:59 . 2008-08-24 03:45 188,416 --a------ C:\WINDOWS\rqbmvpso.dll
2008-08-24 17:59 . 2008-08-24 03:45 86,016 --a------ C:\WINDOWS\rvoelbxt.exe
2008-08-18 16:20 . 2008-08-18 16:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-08-18 16:11 . 2008-08-18 16:11 <DIR> d-------- C:\Program Files\Bonjour
2008-08-18 16:02 . 2008-08-18 16:02 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-08-18 15:27 . 2008-08-18 15:29 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\FrostWire
2008-08-17 20:45 . 2008-08-17 20:45 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\Talkback
2008-08-17 20:45 . 2008-08-17 20:45 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-17 20:44 . 2008-08-18 15:50 <DIR> d-------- C:\Program Files\Common Files\Real
2008-08-15 08:48 . 2008-08-25 01:10 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-15 08:48 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-15 08:48 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-15 08:27 . 2008-08-15 08:27 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\Malwarebytes
2008-08-15 08:27 . 2008-08-15 08:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-15 07:44 . 2008-08-24 18:39 <DIR> d-------- C:\Program Files\VirtualDJ
2008-08-14 21:28 . 2008-08-14 21:28 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-14 21:27 . 2008-08-14 21:27 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-08-14 21:27 . 2008-04-13 17:12 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-08-14 17:39 . 2008-05-01 07:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-14 17:38 . 2008-04-11 12:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-13 00:45 . 2008-08-13 00:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-08-13 00:45 . 2008-08-13 00:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logishrd
2008-08-13 00:43 . 2008-08-13 00:45 <DIR> d-------- C:\Program Files\Logitech
2008-08-13 00:42 . 2008-08-13 00:45 <DIR> d-------- C:\Program Files\Common Files\logishrd
2008-08-11 14:06 . 2008-08-11 14:06 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\Windows Search
2008-08-10 23:51 . 2008-08-10 23:51 <DIR> d-------- C:\Program Files\Winamp
2008-08-10 23:51 . 2008-08-10 23:51 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\Winamp
2008-08-09 23:22 . 2008-08-09 23:49 <DIR> d-------- C:\Program Files\Spectrasonics
2008-08-09 23:17 . 2008-08-09 23:17 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\vlc
2008-08-09 11:52 . 2008-08-09 11:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-09 11:51 . 2008-08-18 16:18 <DIR> d-------- C:\Program Files\Yahoo!
2008-08-05 14:53 . 2008-08-05 14:53 <DIR> d-------- C:\Program Files\Common Files\Digidesign
2008-08-05 14:53 . 2006-09-20 14:11 163,840 --a------ C:\WINDOWS\system32\ArtFfct.dll
2008-08-05 14:09 . 2008-08-23 22:26 <DIR> d-------- C:\Program Files\Arturia
2008-08-05 14:00 . 2008-08-05 14:00 <DIR> d-------- C:\Program Files\Timeworks
2008-08-05 13:57 . 1998-11-22 03:13 53,248 --a------ C:\WINDOWS\system32\stu.dll
2008-08-04 15:42 . 2008-08-04 15:42 0 --ah----- C:\Documents and Settings\Ryan\Application Data\.D5F9F79257A0E5FA.sys
2008-08-03 21:44 . 2008-08-03 21:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-08-03 21:28 . 2008-08-03 21:28 <DIR> d-------- C:\Program Files\VOB
2008-08-03 21:28 . 2002-08-28 11:09 611,840 --a------ C:\WINDOWS\system32\vobhw.dll
2008-08-03 21:28 . 2002-09-26 17:34 153,088 --a------ C:\WINDOWS\system32\IWUninstall.exe
2008-08-03 21:28 . 2000-04-27 12:31 19,456 --a------ C:\WINDOWS\system32\asapi.dll
2008-08-03 21:28 . 2002-04-17 20:27 11,264 --a------ C:\WINDOWS\system32\drivers\asapi.sys
2008-08-03 21:27 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-08-03 21:26 . 2008-08-03 21:26 <DIR> d-------- C:\Documents and Settings\Ryan\WINDOWS
2008-08-03 21:16 . 2008-08-03 21:28 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\FXpansion
2008-08-03 21:13 . 2008-08-03 21:13 <DIR> d-------- C:\Program Files\Nomad Factory
2008-08-03 21:13 . 2003-06-20 12:28 1,777,664 --a------ C:\WINDOWS\system32\gdiplus.dll
2008-08-03 21:13 . 2003-03-18 18:04 765,952 --a------ C:\WINDOWS\system32\msvcp71d.dll
2008-08-03 21:13 . 2003-03-18 18:03 544,768 --a------ C:\WINDOWS\system32\msvcr71d.dll
2008-07-29 12:02 . 2008-07-29 12:02 <DIR> d-------- C:\WINDOWS\system32\INF
2008-07-29 12:02 . 2008-07-29 12:02 <DIR> d-------- C:\Program Files\M-Audio MA_CMIDI
2008-07-29 12:02 . 2005-06-14 13:44 85,504 --a------ C:\WINDOWS\system32\ma_cmidn.dll
2008-07-29 12:02 . 2005-06-14 13:44 21,888 --a------ C:\WINDOWS\system32\drivers\ma_cmidi.sys
2008-07-29 12:02 . 2005-06-14 13:44 17,920 --a------ C:\WINDOWS\system32\MA_CMIDI.DLL
2008-07-29 12:02 . 2005-06-14 13:44 14,176 --a------ C:\WINDOWS\system32\MA_CMIDI.DRV
2008-07-29 12:02 . 2005-06-14 13:44 7,282 --a------ C:\WINDOWS\system32\MA_CMIDI.VXD
2008-07-29 09:44 . 2008-07-29 09:44 <DIR> d-------- C:\Program Files\MagicDisc
2008-07-29 09:44 . 2008-07-28 17:19 116,736 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys
2008-07-26 22:13 . 2008-04-13 11:45 60,032 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-07-26 22:13 . 2008-04-13 11:45 60,032 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-07-26 22:13 . 2008-04-13 17:11 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-07-26 22:13 . 2008-04-13 17:11 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-07-26 22:13 . 2008-04-13 11:45 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-07-26 22:13 . 2008-04-13 11:45 10,368 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-07-26 22:12 . 2008-04-13 11:45 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-07-26 22:12 . 2008-04-13 11:45 32,128 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-07-26 15:48 . 2008-07-26 15:48 <DIR> d-------- C:\WINDOWS\Sun
2008-07-26 15:48 . 2008-07-26 15:48 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-07-26 15:48 . 2008-08-03 14:08 23 --a------ C:\Documents and Settings\Ryan\jagex_runescape_preferences.dat
2008-07-26 15:29 . 2008-07-26 15:29 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-26 15:22 . 2008-07-26 15:22 <DIR> d-------- C:\Program Files\Viewpoint
2008-07-26 15:22 . 2008-07-26 15:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-26 15:22 . 2008-07-26 15:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-07-26 15:22 . 2008-07-26 15:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-07-26 15:21 . 2008-08-24 22:59 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-07-26 15:21 . 2008-07-26 15:22 458 --ah----- C:\IPH.PH
2008-07-26 14:57 . 2008-07-26 14:58 <DIR> d-------- C:\Program Files\Waves
2008-07-26 14:57 . 2008-08-17 20:44 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-07-26 14:57 . 2008-08-17 20:44 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-07-26 14:45 . 2008-08-24 17:58 <DIR> d-------- C:\Program Files\VSTplugins
2008-07-26 14:45 . 2008-07-26 14:45 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\DivX
2008-07-26 14:38 . 2008-07-26 14:38 <DIR> d-------- C:\Program Files\Outsim
2008-07-26 14:38 . 2008-08-24 18:40 <DIR> d-------- C:\Program Files\ASIO4ALL v2
2008-07-26 14:38 . 2002-07-07 15:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-07-26 14:37 . 2008-07-27 07:54 <DIR> d-------- C:\Program Files\Image-Line
2008-07-26 14:21 . 2008-04-13 11:45 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-26 14:20 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-26 14:19 . 2008-07-26 17:22 <DIR> d-------- C:\Program Files\Java
2008-07-26 14:19 . 2008-07-26 14:19 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-26 14:17 . 2008-07-26 14:17 <DIR> d-------- C:\System Update
2008-07-26 14:17 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-26 14:17 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-26 14:16 . 2008-08-23 01:56 <DIR> d-------- C:\Documents and Settings\Ryan\Application Data\SiteAdvisor
2008-07-26 14:16 . 2008-08-24 23:28 <DIR> d-------- C:\Documents and Settings\Ryan
2008-07-26 14:01 . 2008-07-26 14:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
2008-07-26 13:25 . 2008-07-26 13:25 <DIR> d-------- C:\Program Files\Microsoft Works
2008-07-26 13:25 . 2006-10-26 19:58 30,512 --a------ C:\WINDOWS\system32\mdimon.dll
2008-07-26 13:24 . 2008-07-26 13:24 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-07-26 13:21 . 2008-07-26 13:21 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-07-26 13:21 . 2008-08-14 21:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-26 13:20 . 2008-07-26 13:20 <DIR> dr-h----- C:\MSOCache
2008-07-26 12:43 . 2006-11-07 14:58 356,352 --a------ C:\WINDOWS\system32\nvunrm.exe
2008-07-26 12:43 . 2006-10-05 16:35 356,352 --------- C:\WINDOWS\system32\nvuide.exe
2008-07-26 12:43 . 2006-10-19 09:36 3,903 --a------ C:\WINDOWS\system32\nvnrm.nvu
2008-07-26 12:40 . 2008-07-26 12:40 <DIR> d-------- C:\Documents and Settings\Yeoman\Application Data\InstallShield
2008-07-26 12:20 . 2008-07-26 12:20 <DIR> d-------- C:\Program Files\DivX
2008-07-26 12:15 . 2008-07-27 07:52 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\SiteAdvisor
2008-07-26 12:13 . 2008-07-26 12:13 <DIR> d-------- C:\WINDOWS\system32\GroupPolicy
2008-07-26 12:13 . 2008-07-26 12:13 <DIR> d-------- C:\Program Files\Windows Desktop Search
2008-07-26 12:13 . 2008-07-26 12:13 <DIR> d-------- C:\Documents and Settings\Yeoman\Application Data\Windows Desktop Search
2008-07-26 12:13 . 2008-03-07 10:02 192,000 -----c--- C:\WINDOWS\system32\dllcache\offfilt.dll
2008-07-26 12:13 . 2008-03-07 10:02 98,304 -----c--- C:\WINDOWS\system32\dllcache\nlhtml.dll
2008-07-26 12:13 . 2008-03-07 10:02 29,696 -----c--- C:\WINDOWS\system32\dllcache\mimefilt.dll
2008-07-26 12:12 . 2008-07-26 12:12 <DIR> d-------- C:\Temp\ext18866
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-26 17:49 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-07-26 14:58 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E350B1C6-A8DC-4EEF-90DB-61DCAE9D1B67}]
2008-08-24 03:45 380928 --a------ C:\WINDOWS\rodqgpvlkoa.dll
C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2008-07-29 09:44:47 575488]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 1 (0x1)
"DisableTaskMgr"= 0 (0x0)
"NoDispCPL"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoToolbarCustomize"= 1 (0x1)
"StartMenuLogoff"= 1 (0x1)
"NoStartMenuMorePrograms"= 1 (0x1)
"NoSetFolders"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 22:19 304128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pdoskegl"= {95EE052B-EE5C-4AA3-B542-CBD18353E224} - C:\WINDOWS\pdoskegl.dll [2008-08-24 03:45 233472]
"rqbmvpso"= {5F06A0A0-5A3F-4C90-8904-B9E24295011E} - C:\WINDOWS\rqbmvpso.dll [2008-08-24 03:45 188416]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= ma_cmidn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2002-04-17 20:27]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 14:38]
S0 nvgts;nvgts;C:\WINDOWS\system32\DRIVERS\nvgts.sys [2008-01-17 11:51]
S3 MA_CMIDI;%EVOL_USB.SvcDesc%;C:\WINDOWS\system32\drivers\ma_cmidi.sys [2005-06-14 13:44]
.
Contents of the 'Scheduled Tasks' folder
2008-07-26 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{18C388BB-5014-4906-AE38-E62BA5AA7387} - C:\WINDOWS\qalkfxor.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\wzb1lee4.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
.
------- File Associations (Beta) -------
.
regfile=regedit.exe "%1" %*
scrfile="%1" %*
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-25 09:47:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Data]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Networking]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for Oracle]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for SqlServer]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NETFramework]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Abiosdsk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\abp480n5]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPI]
"ImagePath"="System32\DRIVERS\ACPI.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPIEC]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\adpu160m]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aec]
"ImagePath"="system32\drivers\aec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AFD]
"ImagePath"="\SystemRoot\System32\drivers\afd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Aha154x]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78u2]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78xx]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Alerter]
"ServiceDll"="%SystemRoot%\system32\alrsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AliIde]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\amsint]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Arp1394]
"ImagePath"="System32\DRIVERS\arp1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Asapi]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3350p]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3550]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_1.1.4322]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_2.0.50727]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aspnet_state]
"ImagePath"="%SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\atapi]
"ImagePath"="System32\DRIVERS\atapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atdisk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atmarpc]
"ImagePath"="System32\DRIVERS\atmarpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\audiosrv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\audstub]
"ImagePath"="System32\DRIVERS\audstub.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BattC]
"MofImagePath"="System32\Drivers\battc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Beep]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BITS]
"ServiceDll"="%systemroot%\system32\qmgr.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Bonjour Service]
"ImagePath"="\"C:\Program Files\Bonjour\mDNSResponder.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CamDrL]
"ImagePath"="system32\DRIVERS\Camdrl.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme]
"ImagePath"="\??\C:\ComboFix\catchme.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cbidf2k]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CCDECODE]
"ImagePath"="system32\DRIVERS\CCDECODE.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cd20xrnt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdaudio]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdrom]
"ImagePath"="System32\DRIVERS\cdrom.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Changer]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cisvc]
"ImagePath"="%SystemRoot%\system32\cisvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ClipSrv]
"ImagePath"="%SystemRoot%\system32\clipsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\clr_optimization_v2.0.50727_32]
"ImagePath"="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmdIde]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\COMSysApp]
"ImagePath"="C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentFilter]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentIndex]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cpqarray]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\System32\cryptsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac2w2k]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac960nt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dhcp]
"ServiceDll"="%SystemRoot%\System32\dhcpcsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Disk]
"ImagePath"="System32\DRIVERS\disk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmadmin]
"ImagePath"="%SystemRoot%\System32\dmadmin.exe /com"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmboot]
"ImagePath"="System32\drivers\dmboot.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmio]
"ImagePath"="System32\drivers\dmio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmload]
"ImagePath"="System32\drivers\dmload.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmserver]
"ServiceDll"="%SystemRoot%\System32\dmserver.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DMusic]
"ImagePath"="system32\drivers\DMusic.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dot3svc]
"ServiceDll"="%SystemRoot%\System32\dot3svc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dpti2o]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EapHost]
"ServiceDll"="%SystemRoot%\System32\eapsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ERSvc]
"ServiceDll"="%SystemRoot%\System32\ersvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EventSystem]
"ServiceDll"="C:\WINDOWS\System32\es.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fastfat]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FastUserSwitchingCompatibility]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fax]
"ImagePath"="%systemroot%\system32\fxssvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fdc]
"ImagePath"="System32\DRIVERS\fdc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fips]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FLEXnet Licensing Service]
"ImagePath"="\"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Flpydisk]
"ImagePath"="System32\DRIVERS\flpydisk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FltMgr]
"ImagePath"="system32\drivers\fltmgr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fs_Rec]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ftdisk]
"ImagePath"="System32\DRIVERS\ftdisk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Gpc]
"ImagePath"="System32\DRIVERS\msgpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gusvc]
"ImagePath"="\"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HDAudBus]
"ImagePath"="System32\DRIVERS\HDAudBus.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\helpsvc]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hkmsvc]
"ServiceDll"="%SystemRoot%\System32\kmsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpn]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTP]
"ImagePath"="System32\Drivers\HTTP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter]
"ServiceDll"="%SystemRoot%\System32\w3ssl.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omp]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt]
"ImagePath"="System32\DRIVERS\i8042prt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IISADMIN]
"ImagePath"="C:\WINDOWS\System32\inetsrv\inetinfo.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Imapi]
"ImagePath"="System32\DRIVERS\imapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ImapiService]
"ImagePath"="%systemroot%\system32\imapi.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\inetaccs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\InetInfo]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ini910u]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Inport]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntcAzAudAddService]
"ImagePath"="system32\drivers\RtkHDAud.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntelIde]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\intelppm]
"ImagePath"="System32\DRIVERS\intelppm.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ip6fw]
"ImagePath"="system32\drivers\ip6fw.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpFilterDriver]
"ImagePath"="System32\DRIVERS\ipfltdrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpInIp]
"ImagePath"="System32\DRIVERS\ipinip.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpNat]
"ImagePath"="System32\DRIVERS\ipnat.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IPSec]
"ImagePath"="System32\DRIVERS\ipsec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IRENUM]
"ImagePath"="System32\DRIVERS\irenum.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISAPISearch]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\isapnp]
"ImagePath"="System32\DRIVERS\isapnp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Kbdclass]
"ImagePath"="System32\DRIVERS\kbdclass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kmixer]
"ImagePath"="system32\drivers\kmixer.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KSecDD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanserver]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanworkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lbrtfdc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ldap]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LicenseService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LmHosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LPDSVC]
"ImagePath"="%SystemRoot%\System32\tcpsvcs.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LVcKap]
"ImagePath"="system32\DRIVERS\LVcKap.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LVMVDrv]
"ImagePath"="system32\DRIVERS\LVMVDrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LVPr2Mon]
"ImagePath"="system32\DRIVERS\LVPr2Mon.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LVPrcSrv]
"ImagePath"="c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LVSrvLauncher]
"ImagePath"="C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LVUSBSta]
"ImagePath"="system32\DRIVERS\LVUSBSta.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MADFUUSB]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MA_CMIDI]
"ImagePath"="system32\drivers\ma_cmidi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MA_CMIDI_InstallerService]
"ImagePath"="C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mcdbus]
"ImagePath"="system32\DRIVERS\mcdbus.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mcmscsvc]
"ImagePath"="C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\McNASvc]
"ImagePath"="\"c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\McODS]
"ImagePath"="C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\McProxy]
"ImagePath"="c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\McShield]
"ImagePath"="C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\McSysmon]
"ImagePath"="C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MDM]
"ImagePath"="\"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Messenger]
"ServiceDll"="%SystemRoot%\System32\msgsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mfeavfk]
"ImagePath"="system32\drivers\mfeavfk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mfebopk]
"ImagePath"="system32\drivers\mfebopk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mfehidk]
"ImagePath"="system32\drivers\mfehidk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mferkdk]
"ImagePath"="system32\drivers\mferkdk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mfesmfk]
"ImagePath"="system32\drivers\mfesmfk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmdd]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmsrvc]
"ImagePath"="C:\WINDOWS\System32\mnmsrvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Modem]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mouclass]
"ImagePath"="System32\DRIVERS\mouclass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MountMgr]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MPFP]
"ImagePath"="System32\Drivers\Mpfp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MpfService]
"ImagePath"="\"C:\Program Files\McAfee\MPF\MPFSrv.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MQAC]
"ImagePath"="\??\C:\WINDOWS\System32\drivers\mqac.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mraid35x]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxDAV]
"ImagePath"="System32\DRIVERS\mrxdav.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxSmb]
"ImagePath"="System32\DRIVERS\mrxsmb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSDTC]
"ImagePath"="C:\WINDOWS\System32\msdtc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Msfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSFtpsvc]
"ImagePath"="%SystemRoot%\System32\inetsrv\inetinfo.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSIServer]
"ImagePath"="%systemroot%\system32\msiexec.exe /V"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSMQ]
"ImagePath"="C:\WINDOWS\System32\mqsvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSMQTriggers]
"ImagePath"="C:\WINDOWS\System32\mqtgsvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSSCNTRS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mssmbios]
"ImagePath"="System32\DRIVERS\mssmbios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSTEE]
"ImagePath"="system32\drivers\MSTEE.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mup]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NABTSFEC]
"ImagePath"="system32\DRIVERS\NABTSFEC.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\napagent]
"ServiceDll"="%SystemRoot%\System32\qagentrt.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDIS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisIP]
"ImagePath"="system32\DRIVERS\NdisIP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisTapi]
"ImagePath"="System32\DRIVERS\ndistapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ndisuio]
"ImagePath"="System32\DRIVERS\ndisuio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisWan]
"ImagePath"="System32\DRIVERS\ndiswan.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDProxy]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBIOS]
"ImagePath"="System32\DRIVERS\netbios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBT]
"ImagePath"="System32\DRIVERS\netbt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDE]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDEdsdm]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIC1394]
"ImagePath"="System32\DRIVERS\nic1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Nla]
"ServiceDll"="%SystemRoot%\System32\mswsock.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Npfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ntfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NTFSDRV]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtLmSsp]
"ImagePath"="%SystemRoot%\System32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc]
"ServiceDll"="%SystemRoot%\system32\ntmssvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Null]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nv]
"ImagePath"="system32\DRIVERS\nv4_mini.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvata]
"ImagePath"="system32\DRIVERS\nvata.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NVENETFD]
"ImagePath"="system32\DRIVERS\NVENETFD.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvgts]
"ImagePath"="System32\DRIVERS\nvgts.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvnetbus]
"ImagePath"="system32\DRIVERS\nvnetbus.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NVSvc]
"ImagePath"="%SystemRoot%\system32\nvsvc32.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFlt]
"ImagePath"="System32\DRIVERS\nwlnkflt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFwd]
"ImagePath"="System32\DRIVERS\nwlnkfwd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\odserv]
"ImagePath"="\"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ohci1394]
"ImagePath"="System32\DRIVERS\ohci1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ose]
"ImagePath"="\"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Outlook]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Parport]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PartMgr]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ParVdm]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCI]
"ImagePath"="System32\DRIVERS\pci.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIDump]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIIde]
"ImagePath"="System32\DRIVERS\pciide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pcmcia]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDCOMP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDFRAME]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRELI]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRFRAME]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2hib]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfDisk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfNet]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfOS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfProc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PlugPlay]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PolicyAgent]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PptpMiniport]
"ImagePath"="System32\DRIVERS\raspptp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Processor]
"ImagePath"="System32\DRIVERS\processr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSched]
"ImagePath"="System32\DRIVERS\psched.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ptilink]
"ImagePath"="System32\DRIVERS\ptilink.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PxHelp20]
"ImagePath"="System32\Drivers\PxHelp20.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1080]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ql10wnt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql12160]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1240]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1280]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAcd]
"ImagePath"="System32\DRIVERS\rasacd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rasl2tp]
"ImagePath"="System32\DRIVERS\rasl2tp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasPppoe]
"ImagePath"="System32\DRIVERS\raspppoe.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Raspti]
"ImagePath"="System32\DRIVERS\raspti.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rdbss]
"ImagePath"="System32\DRIVERS\rdbss.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPDD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rdpdr]
"ImagePath"="System32\DRIVERS\rdpdr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPNP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPWD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDSessMgr]
"ImagePath"="C:\WINDOWS\system32\sessmgr.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\redbook]
"ImagePath"="System32\DRIVERS\redbook.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteAccess]
"ServiceDll"="%SystemRoot%\System32\mprdim.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RMCAST]
"ImagePath"="\??\C:\WINDOWS\System32\drivers\RMCast.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcLocator]
"ImagePath"="%SystemRoot%\System32\locator.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcSs]
"ServiceDll"="%SystemRoot%\System32\rpcss.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RSVP]
"ImagePath"="%SystemRoot%\System32\rsvp.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SCardSvr]
"ImagePath"="%SystemRoot%\System32\SCardSvr.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Schedule]
"ServiceDll"="%SystemRoot%\system32\schedsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ScsiPort]
"ImagePath"="%SystemRoot%\system32\drivers\scsiport.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Secdrv]
"ImagePath"="System32\DRIVERS\secdrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seclogon]
"ServiceDll"="%SystemRoot%\System32\seclogon.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\serenum]
"ImagePath"="System32\DRIVERS\serenum.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Serial]
"ImagePath"="System32\DRIVERS\serial.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sfloppy]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess]
"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ShellHWDetection]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Simbad]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SimpTcp]
"ImagePath"="%SystemRoot%\System32\tcpsvcs.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SiteAdvisor Service]
"ImagePath"="\"C:\Program Files\SiteAdvisor\6261\SAService.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SLIP]
"ImagePath"="system32\DRIVERS\SLIP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SMTPSVC]
"ImagePath"="C:\WINDOWS\System32\inetsrv\inetinfo.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNMP]
"ImagePath"="%SystemRoot%\System32\snmp.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNMPTRAP]
"ImagePath"="%SystemRoot%\System32\snmptrap.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sparrow]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\splitter]
"ImagePath"="system32\drivers\splitter.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Spooler]
"ImagePath"="%SystemRoot%\system32\spoolsv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sr]
"ImagePath"="System32\DRIVERS\sr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srservice]
"ServiceDll"="C:\WINDOWS\System32\srsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Srv]
"ImagePath"="System32\DRIVERS\srv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SSDPSRV]
"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\stisvc]
"ServiceDll"="%SystemRoot%\system32\wiase