Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

only some sites blocked - please help [Solved]


  • This topic is locked This topic is locked

#31
godawgs

godawgs

    Teacher

  • Retired Staff
  • 8,228 posts
Hi,

Let's try this another way. Forget about the last set of instructions and we'll go with these.


Step-1.

Please delete the tssunq.txt file on the desktop.

  • Please copy all of the text in the code box below. To do this, highlight everything inside the code box below, right click and click Copy.
    REN "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0000\svc0000\tsk0000.dta" CFSvcs.exe
    COPY "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0000\svc0000\CFSvcs.exe" C:\Program Files\TOSHIBA\ConfigFree\
    
    REN "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0001\svc0000\tsk0000.dta" kr10i.sys
    COPY "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0001\svc0000\tsk0000.dta" C:\Windows\system32\drivers\
    
    REN "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0002\svc0000\tsk0000.dta" kr10n.sys
    COPY "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0002\svc0000\tsk0000.dta" C:\Windows\system32\drivers\
    
    REN "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0003\svc0000\tsk0000.dta" kr3npxp.sys
    COPY "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0003\svc0000\tsk0000.dta" C:\Windows\system32\drivers\
    
    REN "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0004\svc0000\tsk0000.dta" tifm21.sys
    COPY "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0004\svc0000\tsk0000.dta" C:\Windows\system32\drivers\
    
    REN "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0005\svc0000\tsk0000.dta" TODDSrv.exe
    COPY "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0005\svc0000\tsk0000.dta" C:\Windows\system32\
    
    REN "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0006\svc0000\tsk0000.dta" TosBtSrv.exe
    COPY "C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0006\svc0000\tsk0000.dta" C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
  • Run TDSSQlook.exe again.
  • Type B and press the Enter key. A notepad window will open titled imput.txt.
  • Put the mouse cursor inside the notepad window and right click and click Paste. This will put the text in the input.txt file.
  • At the top of the notepad window, click File. Then click Save.
  • Click File again and then click Exit.
    This will automatically run the input.txt script and your files should now be returned to their correct location.
  • Type Q and press the Enter key to close the program
  • Reboot the computer.


Now let's check and see if the files were restored.


Step-2.

Download and run SystemLook

For 32bit systems, please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2


You must be logged in as an Administrator to run SystemLook

  • Double-click the SystemLook.exe file to run it.
  • Copy and Paste the contents of the following codebox into the main textfield:
    :filefind
    *CFSvcs.exe
    *kr10i.sys
    *kr10n.sys
    *kr3npxp.sys
    *tifm21.sys
    *TODDSrv.exe
    *TosBtSrv.exe
    
    :reg
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Step-3.

Things For Your Next Post:Things For Your Next Post:
1. The SystemLook.txt log
  • 0

Advertisements


#32
wmpendle

wmpendle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts
This is the only computer on the router. I will work on the new steps tonight.
  • 0

#33
godawgs

godawgs

    Teacher

  • Retired Staff
  • 8,228 posts
OK! If I can ask another question...do you have a DSL modem and the router is connected to it, then the computer is connected to the router, or do you have a dedicated internet line coming into your home and the router is connected to it?
  • 0

#34
wmpendle

wmpendle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts
There is what I believe is a phone line (but it could be ethernet cable) that comes in from the outside of the house. There is some sort of an adapter on that, looks like a splitter of some sort, because it has open ports, I could plug in another line to it. The router is connected to that line, and then the computer is connected to the router by ethernet cable. Basically:

Outside cable/line --> inside cable/line--> splitter/adapter --> more cable/line --> router --> more cable/line --> computer
  • 0

#35
wmpendle

wmpendle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts
SystemLook log:

SystemLook 30.07.11 by jpshortstuff
Log created at 19:42 on 17/07/2012 by Wendi
Administrator - Elevation successful

========== filefind ==========

Searching for "*CFSvcs.exe"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0000\svc0000\CFSvcs.exe --a---- 40960 bytes [22:07 07/07/2012] [22:07 07/07/2012] C82162949BBA6CC5D006C7BD008F3CF1

Searching for "*kr10i.sys"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0001\svc0000\kr10i.sys --a---- 216320 bytes [22:07 07/07/2012] [22:07 07/07/2012] 1E0D65F7FFEB4E99B2EEC1CCB5754CC8
C:\Windows\System32\DriverStore\FileRepository\kr10i.inf_b16c2100\KR10I.sys --a---- 216320 bytes [19:07 28/02/2007] [08:43 03/01/2007] 1E0D65F7FFEB4E99B2EEC1CCB5754CC8

Searching for "*kr10n.sys"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0002\svc0000\kr10n.sys --a---- 207104 bytes [22:07 07/07/2012] [22:07 07/07/2012] A1963360E74931222A67356C8AD48378
C:\Windows\System32\DriverStore\FileRepository\kr10n.inf_f8c77270\KR10N.sys --a---- 207104 bytes [19:07 28/02/2007] [08:43 03/01/2007] A1963360E74931222A67356C8AD48378

Searching for "*kr3npxp.sys"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0003\svc0000\kr3npxp.sys --a---- 479488 bytes [22:07 07/07/2012] [22:07 07/07/2012] 485E005CD51FF502FB16483EB4B69C17
C:\Windows\System32\DriverStore\FileRepository\kr3np.inf_cac3a23d\kr3npxp.sys --a---- 479488 bytes [19:08 28/02/2007] [08:43 03/01/2007] 485E005CD51FF502FB16483EB4B69C17

Searching for "*tifm21.sys"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0004\svc0000\tifm21.sys --a---- 290304 bytes [22:07 07/07/2012] [22:07 07/07/2012] E4C85C291DDB3DC5E4A2F227CA465BA6
C:\Windows\tiinst\tifm21.sys --a---- 290304 bytes [22:44 24/01/2007] [22:44 24/01/2007] E4C85C291DDB3DC5E4A2F227CA465BA6

Searching for "*TODDSrv.exe"
C:\Program Files\Toshiba\TOSHIBA Disc Creator\TODDSrv.exe --a---- 114688 bytes [02:30 26/05/2006] [02:30 26/05/2006] D540858E65BFA6FDED41AD2495ECE344
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0005\svc0000\TODDSrv.exe --a---- 114688 bytes [22:07 07/07/2012] [22:07 07/07/2012] D540858E65BFA6FDED41AD2495ECE344

Searching for "*TosBtSrv.exe"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0006\svc0000\TosBtSrv.exe --a---- 118784 bytes [22:07 07/07/2012] [22:07 07/07/2012] 5480ABFC2C6B19972D2871F576EBCAA3

========== reg ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
(No values found)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Data]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking 4.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET Data Provider for Oracle]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET Data Provider for SqlServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NETFramework]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeFlashPlayerUpdateSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adp94xx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpahci]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu320]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AeLookupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AgereModemAudio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AgereSoftModem]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\agp440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aliide]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amdagp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amdide]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AmdK7]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AmdK8]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Appinfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\arc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\arcsas]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AsyncMac]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Audiosrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BattC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BHDrvx86]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\blbdrive]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BrFiltLo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BrFiltUp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Brserid]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BrSerWdm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BrUsbMdm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BrUsbSer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHMODEM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ccSet_NIS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdfs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdrom]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertPropSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\circlass]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CLFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_32]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmBatt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdide]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Compbatt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSysApp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crcdisk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Crusoe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DCLocator]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DfsC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DFSR]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dot3svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DPS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drmkaud]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DXGKrnl]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\E1G60]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ecache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eeCtrl]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ehRecvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ehSched]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ehstart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\elxstor]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EmdCache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EMDMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EraserUtilRebootDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ESENT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\exfat]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fastfat]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fdc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fdPHost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FDResPub]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FileInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Filetrace]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\flpydisk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FltMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fs_Rec]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTDIBUS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTSER2K]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FwLnk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gagp30kx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\getPlusHelper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gpsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HdAudAddService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HDAudBus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidBth]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidIr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hidserv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidUsb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hkmsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HpCISSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ialm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iaStorV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\idsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IDSVix86]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\igfx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iirsp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\inetaccs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IntcAzAudAddService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelide]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IO_Memory]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPBusEnum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpFilterDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iphlpsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpInIp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPMIDRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPNAT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRENUM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iScsiPrt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iteatapi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iteraid]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdclass]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KSecDD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KtmRm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ldap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lltdio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lltdsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lmhosts]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Lsa]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LSI_FC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LSI_SAS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LSI_SCSI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\luafv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mcx2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MDM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\megasas]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Modem]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\monitor]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouclass]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MountMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mpio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mpsdrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mraid35x]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msahci]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msdsm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC Bridge 3.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC Bridge 4.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Msfs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msisadrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSiSCSI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msiserver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSKSSRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPCLOCK]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPQM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsRPC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSCNTRS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSTEE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NAVENG]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NAVEX15]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDProxy]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netbt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw3v32]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw4v32]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw5v32]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nfrd960]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nsiproxy]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ntfs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntrigdigi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Null]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvraid]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvstor]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv_agp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFlt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFwd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ohci1394]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ose]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Outlook]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\p2pimsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\p2psvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Parport]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\partmgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Parvdm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PcaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pci]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pciide]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pcmcia]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PEAUTH]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfDisk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfNet]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfOS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfProc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pinger]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pla]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PNRPAutoReg]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PNRPsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PortProxy]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PptpMiniport]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Processor]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PxHelp20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql2300]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql40xx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVEdrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rasl2tp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasSstp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPDD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpdr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPENCDD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPWD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RimUsb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rspndr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sbp2port]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCPolicySvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SDRSVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\secdrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serenum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serial]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sermouse]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelEndpoint 3.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelOperation 3.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelService 3.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SessionEnv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sffdisk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sffp_mmc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sffp_sd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sfloppy]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sisagp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SiSRaid2]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SiSRaid4]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\slsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SLUINotify]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Smb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMSvcHost 3.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMSvcHost 4.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMPTRAP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\spldr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SRTSP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SRTSPX]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srv2]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvnet]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SstpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\StillCam]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swprv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Swupdtmr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Symc8xx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SymDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SymEFA]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SymEvent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SymIRON]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SYMTDIv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sym_hi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sym_u3]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SynTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysMain]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpipreg]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TcUsb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdcmdpst]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDPIPE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDTCP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermDD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\THREADORDER]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TosCoSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tosrfbd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tosrfcom]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tosrfusb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TSDDD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tssecsrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tunmp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tunnel]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TVALZ]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\uagp35]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\udfs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UGatherer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UGTHRSVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UI0Detect]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\uliagpkx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\uliahci]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UlSata]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ulsata2]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\umbus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbccgp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbcir]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbehci]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbohci]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbprint]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbscan]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbuhci]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbvideo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UVCFTR]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UxSms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vds]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vga]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VgaSave]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\viaagp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ViaC7]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\viaide]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\volmgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\volmgrx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\volsnap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vsmraid]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WacomPen]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wanarp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wanarpv6]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wcncsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WcsPlugInService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wdf01000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiServiceHost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiSystemHost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wecsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wercplsupport]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WerSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Workflow Foundation 3.0.0.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winmgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinRM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiAcpi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiApRpl]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wmiApSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WMPNetworkSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WPCSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WPDBusEnum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WPFFontCache_v0400]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ws2ifsl]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WSearch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WSearchIdxPi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WUDFRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wudfsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\yukonwlh]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{5CF63800-A8B9-4061-BFD6-E01C4FF176F2}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{EBA294B6-1341-4F2E-94B5-117DF86E04D7}]


-= EOF =-
  • 0

#36
godawgs

godawgs

    Teacher

  • Retired Staff
  • 8,228 posts
Hi wempendle,

Thanks for the information on how the computer is connected to the internet.

The TDSSQlook program renamed the files but it didn't put them back where they were. I'm sorry but that was my error. So since they have already been renamed we will restore them with a batch file. Then I want you to re-run the SystemLook scan again and we'll see if the files are back.


Step-1.

Run a Batch File

Please download the attached tdss.bat batch file to your desktop.
  • Close all open windows and browsers
  • Right click the tdss.bat file and click Run as administrator to run it.
  • If Windows asks you if you want to overwrite an existing file click Yes


Step-2.

Run SystemLook

You must be logged in as an Administrator to run SystemLook

  • Double-click the SystemLook.exe file to run it.
  • Copy and Paste the contents of the following codebox into the main textfield:
    :filefind
    *CFSvcs.exe
    *kr10i.sys
    *kr10n.sys
    *kr3npxp.sys
    *tifm21.sys
    *TODDSrv.exe
    *TosBtSrv.exe
    
    :service
    CFSvcs
    KR10I
    KR10N
    KR3NPXP
    tifm21
    TODDSrv
    TOSHIBA Bluetooth Service
    
    :regfind
    CFSvcs
    KR10I
    KR10N
    KR3NPXP
    tifm21
    TODDSrv
    TOSHIBA Bluetooth Service
    
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Step-3.

Things For Your Next Post:
1. The SystemLook.txt log
  • 0

#37
wmpendle

wmpendle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts
Ok here is the new log:

SystemLook 30.07.11 by jpshortstuff
Log created at 22:24 on 18/07/2012 by Wendi
Administrator - Elevation successful

========== filefind ==========

Searching for "*CFSvcs.exe"
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe --a---- 40960 bytes [05:24 19/07/2012] [22:07 07/07/2012] C82162949BBA6CC5D006C7BD008F3CF1
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0000\svc0000\CFSvcs.exe --a---- 40960 bytes [22:07 07/07/2012] [22:07 07/07/2012] C82162949BBA6CC5D006C7BD008F3CF1

Searching for "*kr10i.sys"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0001\svc0000\kr10i.sys --a---- 216320 bytes [22:07 07/07/2012] [22:07 07/07/2012] 1E0D65F7FFEB4E99B2EEC1CCB5754CC8
C:\Windows\System32\drivers\kr10i.sys --a---- 216320 bytes [05:24 19/07/2012] [22:07 07/07/2012] 1E0D65F7FFEB4E99B2EEC1CCB5754CC8
C:\Windows\System32\DriverStore\FileRepository\kr10i.inf_b16c2100\KR10I.sys --a---- 216320 bytes [19:07 28/02/2007] [08:43 03/01/2007] 1E0D65F7FFEB4E99B2EEC1CCB5754CC8

Searching for "*kr10n.sys"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0002\svc0000\kr10n.sys --a---- 207104 bytes [22:07 07/07/2012] [22:07 07/07/2012] A1963360E74931222A67356C8AD48378
C:\Windows\System32\drivers\kr10n.sys --a---- 207104 bytes [05:24 19/07/2012] [22:07 07/07/2012] A1963360E74931222A67356C8AD48378
C:\Windows\System32\DriverStore\FileRepository\kr10n.inf_f8c77270\KR10N.sys --a---- 207104 bytes [19:07 28/02/2007] [08:43 03/01/2007] A1963360E74931222A67356C8AD48378

Searching for "*kr3npxp.sys"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0003\svc0000\kr3npxp.sys --a---- 479488 bytes [22:07 07/07/2012] [22:07 07/07/2012] 485E005CD51FF502FB16483EB4B69C17
C:\Windows\System32\drivers\kr3npxp.sys --a---- 479488 bytes [05:24 19/07/2012] [22:07 07/07/2012] 485E005CD51FF502FB16483EB4B69C17
C:\Windows\System32\DriverStore\FileRepository\kr3np.inf_cac3a23d\kr3npxp.sys --a---- 479488 bytes [19:08 28/02/2007] [08:43 03/01/2007] 485E005CD51FF502FB16483EB4B69C17

Searching for "*tifm21.sys"
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0004\svc0000\tifm21.sys --a---- 290304 bytes [22:07 07/07/2012] [22:07 07/07/2012] E4C85C291DDB3DC5E4A2F227CA465BA6
C:\Windows\System32\drivers\tifm21.sys --a---- 290304 bytes [05:24 19/07/2012] [22:07 07/07/2012] E4C85C291DDB3DC5E4A2F227CA465BA6
C:\Windows\tiinst\tifm21.sys --a---- 290304 bytes [22:44 24/01/2007] [22:44 24/01/2007] E4C85C291DDB3DC5E4A2F227CA465BA6

Searching for "*TODDSrv.exe"
C:\Program Files\Toshiba\TOSHIBA Disc Creator\TODDSrv.exe --a---- 114688 bytes [02:30 26/05/2006] [02:30 26/05/2006] D540858E65BFA6FDED41AD2495ECE344
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0005\svc0000\TODDSrv.exe --a---- 114688 bytes [22:07 07/07/2012] [22:07 07/07/2012] D540858E65BFA6FDED41AD2495ECE344
C:\Windows\System32\TODDSrv.exe --a---- 114688 bytes [05:24 19/07/2012] [22:07 07/07/2012] D540858E65BFA6FDED41AD2495ECE344

Searching for "*TosBtSrv.exe"
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe --a---- 118784 bytes [05:24 19/07/2012] [22:07 07/07/2012] 5480ABFC2C6B19972D2871F576EBCAA3
C:\TDSSKiller_Quarantine\07.07.2012_15.05.54\susp0006\svc0000\TosBtSrv.exe --a---- 118784 bytes [22:07 07/07/2012] [22:07 07/07/2012] 5480ABFC2C6B19972D2871F576EBCAA3

========== service ==========

CFSvcs - Unable to open Service Handle.

KR10I - Unable to open Service Handle.

KR10N - Unable to open Service Handle.

KR3NPXP - Unable to open Service Handle.

tifm21 - Unable to open Service Handle.

TODDSrv - Unable to open Service Handle.

TOSHIBA Bluetooth Service - Unable to open Service Handle.

========== regfind ==========

Searching for "CFSvcs"
No data found.

Searching for "KR10I"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_2653&SUBSYS_0F001179]
"Service"="KR10I"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_0F001179]
"Service"="KR10I"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\KR10I]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_2653&SUBSYS_0F001179]
"Service"="KR10I"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_0F001179]
"Service"="KR10I"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\KR10I]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_2653&SUBSYS_0F001179]
"Service"="KR10I"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_0F001179]
"Service"="KR10I"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\KR10I]

Searching for "KR10N"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_2653&SUBSYS_0F101179]
"Service"="KR10N"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_0F101179]
"Service"="KR10N"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\KR10N]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_2653&SUBSYS_0F101179]
"Service"="KR10N"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_0F101179]
"Service"="KR10N"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\KR10N]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_2653&SUBSYS_0F101179]
"Service"="KR10N"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_0F101179]
"Service"="KR10N"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\KR10N]

Searching for "KR3NPXP"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_FF011179]
"Service"="KR3NPXP"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\KR3NPXP]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_FF011179]
"Service"="KR3NPXP"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\KR3NPXP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\PCI#VEN_8086&DEV_27C5&SUBSYS_FF011179]
"Service"="KR3NPXP"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\KR3NPXP]

Searching for "tifm21"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\FlashMedia\XDDevice0\5&57dcb7b&0&006\Device Parameters]
"Icons"="%SystemRoot%\system32\drivers\tifm21.sys,-106"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\FlashMedia\XDDevice0\5&57dcb7b&0&006\Device Parameters]
"Icons"="%SystemRoot%\system32\drivers\tifm21.sys,-106"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\FlashMedia\XDDevice0\5&57dcb7b&0&006\Device Parameters]
"Icons"="%SystemRoot%\system32\drivers\tifm21.sys,-106"

Searching for "TODDSrv"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DAD6FACE26F12243A727191C4BA5F27]
"F20E0AD5B079B424FB1415A305814E0C"="C?\Program Files\TOSHIBA\TOSHIBA Disc Creator\TODDSrv.exe"

Searching for "TOSHIBA Bluetooth Service"
No data found.

-= EOF =-
  • 0

#38
godawgs

godawgs

    Teacher

  • Retired Staff
  • 8,228 posts
Hello wmpendle,

I'm sorry for the delay in getting back to you.

OK....the TDSSQlook program renamed the files in the Quarantine folder. The batch file restored the files, but it didn't restore the registry keys that TDSSKiller removed. Our options are to manually recreate the registry keys to put the information back in the registry or reinstall the drivers. I have been looking for any place that might have the information in those registry keys so that we could merge them back into the registry. Unfortunately I haven't found them anywhere. So we're gonna need to reinstall the drivers.
The CFSvcs.exe file belongs to the ConfigFree program for Toshiba's wireless internet card. That program will need to be reinstalled.

Here is a brief description of the files and what they are related to:

CFSvcs.exe is the ConfigFree program for Toshiba's wireless card configuration utility.

kr10i.sys is a toshiba raid driver

Kr10n.sys is a Toshiba raid driver

Kr3npxp.sys is a Toshiba raid driver

Tifm21.sys is a driver belonging to Texas Instruments PCIxx21 UltraMedia smart card reader

TODDSrv.exe is a driver for the Toshiba Optical Disc Drive service belonging to the Toshiba Backup Utility

Tosbtsrv.exe is TOSHIBA's Bluetooth Service belonging to product Bluetooth Stack for Windows by TOSHIBA.

Can you give me the make and model of your computer so I can look on the Toshiba site for the drivers if we need to get them from there.

Do you have the Drivers disk that came with your computer?

Do you have a disk that came with your computer that has the software that was installed on the computer?
  • 0

#39
wmpendle

wmpendle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts
I know the computer came with discs, I have no idea where they are at now. If we need them I can start searching for them.

The computer itself is Toshiba Satellite A205.
Don't know if you need to know this also but it was on the same page
Processor: Intel Core Duo CPU, T2450 @ 2.00GHz 2.00GHz
32-bit operating system
  • 0

#40
godawgs

godawgs

    Teacher

  • Retired Staff
  • 8,228 posts
Thanks for the information.
Yes, if you could start looking for the drivers disk that came with the computer it will have the drivers we need to reinstall. If there was a software cd/dvd, or individual software disks, one of them might have the ConfigFree program on it. In the meantime I will search the Toshiba site for the drivers in case you can't find the disk.
  • 0

Advertisements


#41
wmpendle

wmpendle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts
ok, I found some discs. I think the one we want is the Toshiba Recovery and Applications/Drivers Media. There is another one but I think it is specific to Vista and upgrading Windows.
  • 0

#42
godawgs

godawgs

    Teacher

  • Retired Staff
  • 8,228 posts
Hi,

The info you got me has an incomplete model number. The A205 model number should look like this:

A205 SXXXX(where the underlined X's are numbers)
A205 SPXXXX(where the underlined X's are numbers)

Please click the Start Orb. Right click Computer and click Properties. A System window will open up.
On the left side under Tasks, click Device Manager. Click Continue on the UAC screen. The Device Manager window will open.
On the Menu Bar at the top of the window click View and click [b/]show hidden devices[/b].
If there are any yellow exclamation marks or red X's beside any of the devices in Device Manager, take a screen shot of the the Device Manager window and post it.
  • 0

#43
wmpendle

wmpendle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts
A205 S4557
  • 0

#44
wmpendle

wmpendle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts
No red x's but one question mark and yellow triangle..

Attached Thumbnails

  • Device Mngr.jpg

  • 0

#45
godawgs

godawgs

    Teacher

  • Retired Staff
  • 8,228 posts
Hi wmpendle,

The only thing showing up in device manager is something under Other Devices. The yellow exclamation point indicates that the driver isn't installed so Windows doesn't recognize what it is. Since it is a mass storage controller it is probably the Texas Instruments card reader, I want you to uninstall the device and reboot the computer. Windows should recognize the device and it will attempt to automatically install the driver.

If you get a message that Windows can't find the software (driver), please write down the hardware that it found and we'll see if we can find the driver.

  • Open up the Device Manager again.
  • Click the arrow beside Other Devices
  • Right click on Mass Storage Device and click uninstall
  • Reboot the computer.

If Windows found a driver you should get a message that Windows successfully installed the new hardware.

Reboot the computer and open Device Manager again and see if any additional Question marks, yellow Exclamation marks, ect are there now.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP