You are on page 1of 103

--- Search result list --Facebook.

Messenger: [SBI $63375265] User settings (Registry key, nothing done) HKEY_USERS\S-1-5-21-2571257942-20741344-1747675557-1001\Software\Classes\CLSID \{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F} Facebook.Messenger: [SBI $9191B288] User settings (Registry key, nothing done) HKEY_USERS\S-1-5-21-2571257942-20741344-1747675557-1001\Software\Classes\CLSID \{5E71E4F3-E8C7-4906-9626-973E418762B6} Facebook.Messenger: [SBI $6D1029B1] User settings (Registry key, nothing done) HKEY_USERS\S-1-5-21-2571257942-20741344-1747675557-1001\Software\Classes\Faceb ookUpdate.OnDemandCOMClassUser Facebook.Messenger: [SBI $7F45EA00] User settings (Registry key, nothing done) HKEY_USERS\S-1-5-21-2571257942-20741344-1747675557-1001\Software\Classes\Faceb ookUpdate.OnDemandCOMClassUser.1.0 Facebook.Messenger: [SBI $59117437] User settings (Registry key, nothing done) HKEY_USERS\S-1-5-21-2571257942-20741344-1747675557-1001\Software\Facebook Facebook.Messenger: [SBI $62F77180] Settings (Registry key, nothing done) HKEY_CLASSES_ROOT\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F} Facebook.Messenger: [SBI $9051916D] Settings (Registry key, nothing done) HKEY_CLASSES_ROOT\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6} Facebook.Messenger: [SBI $573FFD1B] Settings (Registry key, nothing done) HKEY_CLASSES_ROOT\Interface\{132885F2-8DE9-40F2-BEAE-1B31FDBAB159} Facebook.Messenger: [SBI $BAA66334] Settings (Registry key, nothing done) HKEY_CLASSES_ROOT\Interface\{3B692A7D-330E-4388-A955-724500AC0BC5} Facebook.Messenger: [SBI $C061D222] Settings (Registry key, nothing done) HKEY_CLASSES_ROOT\Interface\{649D9E01-9847-4EE9-9145-2CB4BC8298D0} Facebook.Messenger: [SBI $6B188C64] Settings (Registry key, nothing done) HKEY_CLASSES_ROOT\Interface\{71692661-DCBA-484A-BD41-A39404532B52} Facebook.Messenger: [SBI $D849531E] Settings (Registry key, nothing done) HKEY_CLASSES_ROOT\Interface\{B72C7377-0AA5-4F52-BDA2-85C4D1DB930E} Facebook.Messenger: [SBI $06D47759] Settings (Registry key, nothing done) HKEY_CLASSES_ROOT\Interface\{D0843545-5E7C-4C6D-B4E2-05948F759440} Facebook.Messenger: [SBI $917BFFAB] Program directory (Directory, nothing done) C:\Users\Mor\AppData\Local\Facebook\ Facebook.Messenger: [SBI $21F6393C] Program directory (Directory, nothing done) C:\Users\Mor\AppData\Local\Facebook\CrashReports\ Facebook.Messenger: [SBI $05D5B32B] Program directory (Directory, nothing done) C:\Users\Mor\AppData\Local\Facebook\Update\ Facebook.Messenger: [SBI $EA825272] Program directory (Directory, nothing done) C:\Users\Mor\AppData\Local\Facebook\Update\Manifest\ Facebook.Messenger: [SBI $EB8149C2] Program directory (Directory, nothing done) C:\Users\Mor\AppData\Local\Facebook\Update\Manifest\Initial\

Zedo: Tracking cookie (Internet Explorer: Mor) (Cookie, nothing done) DoubleClick: Tracking cookie (Internet Explorer: Mor) (Cookie, nothing done)

--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --2009-01-26 2009-01-26 2009-01-26 2009-01-26 2009-01-26 2009-01-26 2009-01-26 2009-01-26 2012-08-11 2009-01-26 2009-01-26 2007-04-02 2008-06-14 2009-01-26 2008-06-19 2009-01-26 2009-01-16 2012-04-04 2012-08-07 2010-08-13 2010-12-14 2011-11-29 2012-01-31 2012-06-19 2012-07-31 2010-09-15 2012-03-13 2012-03-13 2004-11-29 2012-06-18 2012-08-08 2011-02-24 2012-07-19 2010-01-25 2012-06-19 2011-12-13 2008-06-03 2008-06-03 2012-07-23 2012-07-31 2010-03-08 2011-09-28 2012-08-07 2012-08-06 2012-08-01 2012-08-07 2012-08-06 2008-03-04 2008-03-05 2008-02-26 2007-12-24 blindman.exe (1.0.0.8) SDFiles.exe (1.6.1.7) SDMain.exe (1.0.0.6) SDShred.exe (1.0.2.5) SDUpdate.exe (1.6.0.12) SDWinSec.exe (1.0.0.12) SpybotSD.exe (1.6.2.46) TeaTimer.exe (1.6.4.26) unins000.exe (51.49.0.0) Update.exe (1.6.0.7) advcheck.dll (1.6.2.15) aports.dll (2.1.0.0) DelZip179.dll (1.79.11.1) SDHelper.dll (1.6.2.14) sqlite3.dll Tools.dll (2.1.6.10) UninsSrv.dll (1.0.0.0) Includes\Adware.sbi (*) Includes\AdwareC.sbi (*) Includes\Cookies.sbi (*) Includes\Dialer.sbi (*) Includes\DialerC.sbi (*) Includes\HeavyDuty.sbi (*) Includes\Hijackers.sbi (*) Includes\HijackersC.sbi (*) Includes\iPhone.sbi (*) Includes\Keyloggers.sbi (*) Includes\KeyloggersC.sbi (*) Includes\LSP.sbi (*) Includes\Malware.sbi (*) Includes\MalwareC.sbi (*) Includes\PUPS.sbi (*) Includes\PUPSC.sbi (*) Includes\Revision.sbi (*) Includes\Security.sbi (*) Includes\SecurityC.sbi (*) Includes\Spybots.sbi (*) Includes\SpybotsC.sbi (*) Includes\Spyware.sbi (*) Includes\SpywareC.sbi (*) Includes\Tracks.uti Includes\Trojans.sbi (*) Includes\TrojansC-02.sbi (*) Includes\TrojansC-03.sbi (*) Includes\TrojansC-04.sbi (*) Includes\TrojansC-05.sbi (*) Includes\TrojansC.sbi (*) Plugins\Chai.dll Plugins\Fennel.dll Plugins\Mate.dll Plugins\TCPIPAddress.dll

--- System information --Unknown Windows version 6.1 (Build: 7601) Service Pack 1 (6.1.7601) --- Startup entries list --Located: HK_LM:Run, command: file: size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: command: file: size: MD5: Located: command: file: size: MD5: Located: command: avp.exe" file: vp.exe size: MD5: Located: command: file: size: MD5: Located: command: file: size: MD5: Located: command: tart.exe file: tart.exe size: MD5: Located: command: file: size: HK_LM:Run, Adobe ARM "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe 932288 BAD6BEA0DE1F69C82BDB74378CE0C20A HK_LM:Run, Adobe Reader Speed Launcher "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe 35736 E97140424C378ACBD47DF493A6AB7235 HK_LM:Run, AVP "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\a 352976 946D70667B0119F2BEEAE0849E1D46A2 HK_LM:Run, Easybits Recovery C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe 61112 30D7BB258A97BDA7C7E2EC63C23554AA HK_LM:Run, HP Quick Launch C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe 578944 8192B2E274607D1D530F5C191698C544 HK_LM:Run, HPConnectionManager C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayS C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayS 94264 E8A16EF3D77F38CC49A381F4C721716E HK_LM:Run, HPOSD C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe 318520

MD5: 7DA09CA48751B9E0B67C90C337D4B387 Located: command: on.exe file: on.exe size: MD5: Located: command: file: size: MD5: HK_LM:Run, IAStorIcon C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIc 283160 41D1214B86A06FD29423A797EBDA17E4 HK_LM:Run, SunJavaUpdateSched "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 254696 98A078F838A70F84E1BD490D7C7675F4

Located: HK_CU:Run, Facebook Update where: S-1-5-21-2571257942-20741344-1747675557-1001... command: "C:\Users\Mor\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /noc rashserver file: C:\Users\Mor\AppData\Local\Facebook\Update\FacebookUpdate.exe size: 138096 MD5: 9EB925EDC8CF1C3D06E50E9348B54A0A Located: HK_CU:Run, RemEngine where: S-1-5-21-2571257942-20741344-1747675557-1001... command: rundll32.exe "C:\Users\Mor\AppData\Local\SoftGrid Client\RemEngine\ohde fgxl.dll",CreateInstance file: C:\Users\Mor\AppData\Local\SoftGrid Client\RemEngine\ohdefgxl.dll size: 1675776 MD5: 824700710D75B30523CDA70F8A924220 Located: where: command: file: size: MD5: Located: where: tup... command: file: size: MD5: HK_CU:Run, SpybotSD TeaTimer S-1-5-21-2571257942-20741344-1747675557-1001... C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe 2144088 896A1DB9A972AD2339C2E8569EC926D1 Startup (user), OpenOffice.org 3.3.lnk C:\Users\Mor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Star C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe 1198592 F7DCE54077EE9D8A351C4B1FFA866EE7

--- Browser helper object list --{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\ BHO name: AcroIEHelperStub CLSID name: Adobe PDF Link Helper Path: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\ Long name: AcroIEHelperShim.dll Short name: ACROIE~2.DLL Date (created): 11/16/2010 12:02:22 AM Date (last access): 4/18/2011 3:44:16 PM

Date (last write): 11/16/2010 12:02:22 AM Filesize: 62376 Attributes: archive MD5: 0EE9E4D28CC1C671061CAD0334C9B59F CRC32: 145C5067 Version: 10.0.0.396 {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} (IEVkbdBHO) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\ BHO name: IEVkbdBHO CLSID name: IEVkbdBHO Class Path: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Secu rity 2011\ Long name: ievkbd.dll Short name: Date (created): 7/1/2010 9:35:08 PM Date (last access): 10/9/2011 11:19:18 AM Date (last write): 7/1/2010 9:35:08 PM Filesize: 68280 Attributes: archive MD5: CC3EA6117D430710B501B5950394F077 CRC32: 93F3288D Version: 11.0.1.400 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Java(tm) Plug-In SSV Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\ BHO name: CLSID name: Java(tm) Plug-In SSV Helper Path: C:\Program Files (x86)\Java\jre6\bin\ Long name: ssv.dll Short name: Date (created): 4/19/2012 2:20:52 AM Date (last access): 4/19/2012 2:20:52 AM Date (last write): 4/19/2012 2:20:52 AM Filesize: 325408 Attributes: archive MD5: 8E6C86726B67D3FAA3144849B9AAC06C CRC32: B1F4AB5B Version: 6.0.310.5 {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live ID Sign-in Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\ BHO name: CLSID name: Windows Live ID Sign-in Helper Path: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\ Long name: WindowsLiveLogin.dll Short name: WINDOW~1.DLL Date (created): 9/21/2010 5:08:38 PM Date (last access): 4/18/2011 3:40:52 PM Date (last write): 9/21/2010 5:08:38 PM Filesize: 439168 Attributes: archive MD5: 6BF01E200063D7274F3AF06D226671F5 CRC32: C8953126 Version: 7.250.4225.0

{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\ BHO name: CLSID name: Java(tm) Plug-In 2 SSV Helper Path: C:\Program Files (x86)\Java\jre6\bin\ Long name: jp2ssv.dll Short name: Date (created): 4/19/2012 2:20:52 AM Date (last access): 4/19/2012 2:20:52 AM Date (last write): 4/19/2012 2:20:52 AM Filesize: 42272 Attributes: archive MD5: A9770771B622A871643EA2A4A3983E95 CRC32: D1C0DA03 Version: 6.0.310.5 {E33CF602-D945-461A-83F0-819F76A199F8} (link filter bho) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\ BHO name: link filter bho CLSID name: FilterBHO Class Path: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Secu rity 2011\ Long name: klwtbbho.dll Short name: Date (created): 7/1/2010 9:35:14 PM Date (last access): 10/9/2011 11:19:20 AM Date (last write): 7/1/2010 9:35:14 PM Filesize: 191160 Attributes: archive MD5: B028E719312D1A6106DBEF76FA81D965 CRC32: 59ADDFC3 Version: 11.0.1.400

--- ActiveX list --{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_31 Installer: Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i 586.cab description: Sun Java classification: Legitimate known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll info link: info source: Patrick M. Kolla Path: C:\Program Files (x86)\Java\jre6\bin\ Long name: jp2iexp.dll Short name: Date (created): 4/19/2012 2:20:52 AM Date (last access): 4/19/2012 2:20:52 AM Date (last write): 4/19/2012 2:20:52 AM Filesize: 104224 Attributes: archive MD5: C7AD5E5E4FC8AF697A91BF56D1806B8D CRC32: D5225578 Version: 6.0.310.5

{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_31 Installer: Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i 586.cab Path: C:\Program Files (x86)\Java\jre6\bin\ Long name: jp2iexp.dll Short name: Date (created): 4/19/2012 2:20:52 AM Date (last access): 4/19/2012 2:20:52 AM Date (last write): 4/19/2012 2:20:52 AM Filesize: 104224 Attributes: archive MD5: C7AD5E5E4FC8AF697A91BF56D1806B8D CRC32: D5225578 Version: 6.0.310.5 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_31 Installer: Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i 586.cab Path: C:\Program Files (x86)\Java\jre6\bin\ Long name: npjpi160_31.dll Short name: NPJPI1~1.DLL Date (created): 4/19/2012 2:20:52 AM Date (last access): 4/19/2012 2:20:52 AM Date (last write): 4/19/2012 2:20:52 AM Filesize: 141088 Attributes: archive MD5: 77149DCA2C3134C50150ECD33593F4A8 CRC32: 88B54397 Version: 6.0.310.5

--- Process list --PID: 0 ( 0) [System] PID: 3344 (3212) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe size: 136488 MD5: B7F55E2AE978D3D34F7876EE5D689AAE PID: 4156 (2964) C:\Windows\SysWOW64\rundll32.exe size: 44544 MD5: 51138BEEA3E2C21EC44D0932C71762A8 PID: 4260 (2112) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ IAStorIcon.exe size: 283160 MD5: 41D1214B86A06FD29423A797EBDA17E4 PID: 4348 (4176) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe size: 11322880 MD5: 11E8D8272FDBE213ADE3DAD91427CE35 PID: 4412 (2112) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe size: 932288 MD5: BAD6BEA0DE1F69C82BDB74378CE0C20A PID: 4592 (2112) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPO SD.exe size: 318520

MD5: 7DA09CA48751B9E0B67C90C337D4B387 PID: 4692 (2112) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.ex e size: 254696 MD5: 98A078F838A70F84E1BD490D7C7675F4 PID: 4780 (4348) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin size: 11314688 MD5: 2337EC951C4AF6E1AF65D10BD9615BEB PID: 4820 (2112) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC .exe size: 578944 MD5: 8192B2E274607D1D530F5C191698C544 PID: 2816 (2824) C:\Program Files (x86)\Mozilla Firefox\firefox.exe size: 913888 MD5: D3C0837346C49095B8AF9EF54AD7E90A PID: 3504 (5984) C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe size: 5365592 MD5: 0477C2F9171599CA5BC3307FDFBA8D89 PID: 4220 (2816) C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe size: 16864 MD5: 41623176FEF9DF3C113EAADADBB5FB42 PID: 3724 ( 892) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10n_ActiveX.exe size: 234656 MD5: 6CBF6DCC830A1C32EBCF7036A4978C8C PID: 4 ( 0) System PID: 380 ( 4) smss.exe PID: 492 ( 484) csrss.exe PID: 616 ( 484) wininit.exe size: 96256 PID: 640 ( 624) csrss.exe PID: 692 ( 616) services.exe PID: 728 ( 616) lsass.exe PID: 736 ( 616) lsm.exe PID: 820 ( 624) winlogon.exe PID: 892 ( 692) svchost.exe size: 20992 PID: 980 ( 692) svchost.exe size: 20992 PID: 472 ( 692) svchost.exe size: 20992 PID: 520 ( 692) svchost.exe size: 20992 PID: 548 ( 692) svchost.exe size: 20992 PID: 588 ( 692) stacsv64.exe PID: 1260 ( 692) svchost.exe size: 20992 PID: 1360 ( 692) svchost.exe size: 20992 PID: 1500 ( 692) spoolsv.exe PID: 1560 ( 692) svchost.exe size: 20992 PID: 1648 ( 692) avp.exe PID: 1720 ( 692) ezSharedSvcHost.exe size: 514232 PID: 1776 ( 692) svchost.exe size: 20992 PID: 1808 ( 692) HPClientServices.exe PID: 1848 ( 692) HPWMISVC.exe PID: 1944 ( 692) RNowSvc.exe

PID: 2140 ( 692) sftvsa.exe PID: 2168 ( 692) svchost.exe size: 20992 PID: 2212 ( 692) WLIDSVC.EXE PID: 2300 ( 692) sftlist.exe PID: 2472 (2212) WLIDSVCM.EXE PID: 2612 ( 692) C:\Windows\System32\taskhost.exe PID: 2704 ( 692) CVHSVC.EXE PID: 2792 ( 520) C:\Windows\System32\dwm.exe PID: 2824 (2772) C:\Windows\explorer.exe size: 2871808 MD5: 332FEAB1435662FC6C672E25BEB37BE3 PID: 3164 ( 692) svchost.exe size: 20992 PID: 3908 (2824) C:\Windows\System32\igfxtray.exe PID: 3212 ( 548) C:\Windows\System32\taskeng.exe size: 192000 MD5: 4F2659160AFCCA990305816946F69407 PID: 3372 (2824) C:\Windows\System32\hkcmd.exe PID: 3280 (2824) C:\Windows\System32\igfxpers.exe PID: 3596 (2824) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe size: 2538280 MD5: 06E4F688ECABF110AE74909D1D7A171B PID: 3744 (2824) C:\Program Files\IDT\WDM\sttray64.exe size: 1128448 MD5: 15DE7F748C7F632275603ABC0D5139B6 PID: 3560 ( 692) SearchIndexer.exe size: 427520 PID: 2964 (2824) C:\Windows\System32\rundll32.exe size: 44544 MD5: 51138BEEA3E2C21EC44D0932C71762A8 PID: 4132 (3596) SynTPHelper.exe PID: 4500 ( 692) wmpnetwk.exe PID: 4792 ( 892) WmiPrvSE.exe PID: 2156 ( 892) WmiPrvSE.exe PID: 4432 ( 692) svchost.exe size: 20992 PID: 1088 ( 692) hpqWmiEx.exe PID: 4140 ( 892) dllhost.exe size: 7168 PID: 2380 ( 692) HPSA_Service.exe PID: 3036 ( 692) HPWA_Service.exe PID: 4088 ( 692) IAStorDataMgrSvc.exe PID: 4864 ( 692) LMS.exe PID: 5480 ( 692) UNS.exe PID: 5616 (2108) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Mai n.exe size: 363064 MD5: CB443C9D1485A3F7B21D15BE2D3CF168 PID: 3136 (4292) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HP ConnectionManager.exe size: 2913336 MD5: 5732049E0D07DBAE6DB6E4CC762A3EA1 PID: 3720 ( 692) hpCMSrv.exe PID: 6016 ( 548) C:\Windows\System32\wuauclt.exe PID: 1524 ( 692) PresentationFontCache.exe PID: 2760 ( 892) C:\Windows\SysWOW64\DllHost.exe size: 7168 MD5: A63DC5C2EA944E6657203E0C8EDEAF61 PID: 6112 ( 472) audiodg.exe

PID: 5136 (3560) SearchProtocolHost.exe size: 164352 --- Browser start & search pages list --Spybot - Search & Destroy browser pages report, 8/11/2012 1:16:49 PM HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page C:\Windows\system32\blank.htm HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page http://go.microsoft.com/fwlink/?LinkId=54896 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page http://www.msn.com/?pc=Z128&install_date=20110930 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://g.msn.com/HPNOT/1 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page C:\Windows\SysWOW64\blank.htm HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page http://go.microsoft.com/fwlink/?LinkId=54896 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page http://g.msn.com/HPNOT/1 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://g.msn.com/HPNOT/1 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL http://go.microsoft.com/fwlink/?LinkId=54896 --- Winsock Layered Service Provider list --Namespace Provider 1: E-mail Naming Shim Provider GUID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE} Filename: Namespace Provider 2: PNRP Cloud Namespace Provider GUID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D} Filename: Namespace Provider 3: PNRP Name Namespace Provider GUID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D} Filename: Namespace Provider 6: WindowsLive NSP GUID: {4177DDE9-6028-479E-B7B7-03591A63FF3A} Filename: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\ WLIDNSP.DLL Namespace Provider 7: WindowsLive Local NSP GUID: {229F2A2C-5F18-4A06-8F89-3A372170624D} Filename: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\ WLIDNSP.DLL

--- Uninstall list ----- System Services --Service (registry key): .NET CLR Data Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0

Type: 0 Error Control: 0 Service (registry key): .NET CLR Networking Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NET CLR Networking 4.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NET Data Provider for Oracle Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NET Data Provider for SqlServer Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NETFramework Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): 1394ohci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: 1394 OHCI Compliant Host Controller Image path: \SystemRoot\system32\drivers\1394ohci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ACPI Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft ACPI Driver Image path: system32\drivers\ACPI.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3

Service (registry key): AcpiPmi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ACPI Power Meter Driver Image path: \SystemRoot\system32\drivers\acpipmi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): adp94xx Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\adp94xx.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): adpahci Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\adpahci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): adpu320 Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\adpu320.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): adsi Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): AeLookupSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\aelupsvc.dll,-1 Description: @%SystemRoot%\system32\aelupsvc.dll,-2 Object name: localSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1

Service (registry key): AFD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drivers\afd.sys,-1000 Description: @%systemroot%\system32\drivers\afd.sys,-1000 Image path: \SystemRoot\system32\drivers\afd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): agp440 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel AGP Bus Filter Image path: \SystemRoot\system32\drivers\agp440.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ALG Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\Alg.exe,-112 Description: @%SystemRoot%\system32\Alg.exe,-113 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\alg.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): aliide Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\aliide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 3 Service (registry key): amdide Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\amdide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 3 Service (registry key): AmdK8 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: AMD K8 Processor Driver

Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

\SystemRoot\system32\drivers\amdk8.sys 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): AmdPPM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: AMD Processor Driver Image path: \SystemRoot\system32\drivers\amdppm.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): amdsata Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\amdsata.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): amdsbs Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\amdsbs.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): amdxata Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\drivers\amdxata.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): AppID Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\appidsvc.dll,-102 Description: @%systemroot%\system32\appidsvc.dll,-103 Image path: \SystemRoot\system32\drivers\appid.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1

Depends On services: FltMgr,DisCache Service (registry key): AppIDSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\appidsvc.dll,-100 Description: @%systemroot%\system32\appidsvc.dll,-101 Object name: NT Authority\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonat ion Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,AppID,CryptSvc Service (registry key): Appinfo Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\appinfo.dll,-100 Description: @%systemroot%\system32\appinfo.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,ProfSvc Service (registry key): arc Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\arc.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): arcsas Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\arcsas.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): AsyncMac Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32000 Description: @%systemroot%\system32\rascfg.dll,-32000 Image path: system32\DRIVERS\asyncmac.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3

Type: 1 Error Control: 1 Service (registry key): atapi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IDE Channel Image path: system32\drivers\atapi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): AudioEndpointBuilder Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\audiosrv.dll,-204 Description: @%SystemRoot%\System32\audiosrv.dll,-205 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: PlugPlay Service (registry key): AudioSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\audiosrv.dll,-200 Description: @%SystemRoot%\System32\audiosrv.dll,-201 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrict ed Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: AudioEndpointBuilder,RpcSs,MMCSS Service (registry key): AVP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Kaspersky Anti-Virus Service Description: Provides computer protection against viruses, dangerous software , network attacks, internet fraud and spam. Object name: LocalSystem Image path: "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Securit y 2011\avp.exe" -r Image size: 352976 Image MD5: 946D70667B0119F2BEEAE0849E1D46A2 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Service (registry key): AxInstSV

Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\AxInstSV.dll,-103 Description: @%SystemRoot%\system32\AxInstSV.dll,-104 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k AxInstSVGroup Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: rpcss Service (registry key): b06bdrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Broadcom NetXtreme II VBD Image path: \SystemRoot\system32\drivers\bxvbda.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): b57nd60a Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 Image path: system32\DRIVERS\b57nd60a.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): BattC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): BCM43XX Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Broadcom 802.11 Network Adapter Driver Image path: system32\DRIVERS\bcmwl664.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): BDESVC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\bdesvc.dll,-100 Description: @%SystemRoot%\system32\bdesvc.dll,-101 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992

Image MD5: Control Set: Start: Type: Error Control:

54A47F6B5E09A77E61649109C6A08866 CurrentControlSet 3 32 1

Service (registry key): Beep Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Beep Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): BFE Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\bfe.dll,-1001 Description: @%SystemRoot%\system32\bfe.dll,-1002 Object name: NT AUTHORITY\LocalService Image path: %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): BITS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\qmgr.dll,-1000 Description: @%SystemRoot%\system32\qmgr.dll,-1001 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,EventSystem Service (registry key): blbdrive Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\blbdrive.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): bowser Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\browser.dll,-102 Description: @%systemroot%\system32\browser.dll,-103 Image path: system32\DRIVERS\bowser.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet

Start: 3 Type: 2 Error Control: 1 Service (registry key): BrFiltLo Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Brother USB Mass-Storage Lower Filter Driver Image path: \SystemRoot\system32\drivers\BrFiltLo.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): BrFiltUp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Brother USB Mass-Storage Upper Filter Driver Image path: \SystemRoot\system32\drivers\BrFiltUp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Browser Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\browser.dll,-100 Description: @%systemroot%\system32\browser.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation,LanmanServer Service (registry key): Brserid Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Brother MFC Serial Port Interface Driver (WDM) Image path: \SystemRoot\System32\Drivers\Brserid.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): BrSerWdm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Brother WDM Serial driver Image path: \SystemRoot\System32\Drivers\BrSerWdm.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1

Error Control: 1 Service (registry key): BrUsbMdm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Brother MFC USB Fax Only Modem Image path: \SystemRoot\System32\Drivers\BrUsbMdm.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): BrUsbSer Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Brother MFC USB Serial WDM Driver Image path: \SystemRoot\System32\Drivers\BrUsbSer.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): BTHMODEM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Bluetooth Serial Communications Driver Image path: \SystemRoot\system32\drivers\bthmodem.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): BTHPORT Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): bthserv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\bthserv.dll,-101 Description: @%SystemRoot%\System32\bthserv.dll,-102 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k bthsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): cdfs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: CD/DVD File System Reader Description: ISO9660/Joliet File System Reader for CD/DVDs. (Core) (All piece

s) Image path: system32\DRIVERS\cdfs.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Depends On group: "SCSI CDROM Class" Service (registry key): cdrom Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: CD-ROM Driver Image path: system32\DRIVERS\cdrom.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): CertPropSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\certprop.dll,-11 Description: @%SystemRoot%\System32\certprop.dll,-12 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): circlass Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Consumer IR Devices Image path: \SystemRoot\system32\drivers\circlass.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): CLFS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\clfs.sys,-100 Description: @%SystemRoot%\system32\clfs.sys,-101 Image path: System32\CLFS.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): clr_optimization_v2.0.50727_32 Registry path: \SYSTEM\CurrentControlSet\Services\

Display name: Description: Object name: Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

Microsoft .NET Framework NGEN v2.0.50727_X86 Microsoft .NET Framework NGEN LocalSystem %systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 66384 D88040F816FDA31C3B466F0FA0918F29 CurrentControlSet 4 16 0

Service (registry key): clr_optimization_v2.0.50727_64 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft .NET Framework NGEN v2.0.50727_X64 Description: Microsoft .NET Framework NGEN Object name: LocalSystem Image path: %systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe Image size: 89920 Image MD5: D1CEEA2B47CB998321C579651CE3E4F8 Control Set: CurrentControlSet Start: 4 Type: 16 Error Control: 0 Service (registry key): clr_optimization_v4.0.30319_32 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft .NET Framework NGEN v4.0.30319_X86 Description: Microsoft .NET Framework NGEN Object name: LocalSystem Image path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe Image size: 130384 Image MD5: C5A75EB48E2344ABDC162BDA79E16841 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Service (registry key): clr_optimization_v4.0.30319_64 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft .NET Framework NGEN v4.0.30319_X64 Description: Microsoft .NET Framework NGEN Object name: LocalSystem Image path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe Image size: 138576 Image MD5: C6F9AF94DCD58122A4D7E89DB6BED29D Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Service (registry key): clwvd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: CyberLink WebCam Virtual Driver Image path: system32\DRIVERS\clwvd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1

Service (registry key): CmBatt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft ACPI Control Method Battery Driver Image path: \SystemRoot\system32\drivers\CmBatt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): cmdide Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\cmdide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 3 Service (registry key): CNG Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\Drivers\cng.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): Compbatt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Composite Battery Driver Image path: system32\drivers\compbatt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): CompositeBus Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Composite Bus Enumerator Driver Image path: \SystemRoot\system32\drivers\CompositeBus.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): COMSysApp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @comres.dll,-947 Description: @comres.dll,-948 Object name: LocalSystem Image path: %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1

-960D-00805FC79235} Image size: 7168 Image MD5: A63DC5C2EA944E6657203E0C8EDEAF61 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RpcSs,EventSystem,SENS Service (registry key): crcdisk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Crcdisk Filter Driver Image path: \SystemRoot\system32\drivers\crcdisk.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): crypt32 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): CryptSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\cryptsvc.dll,-1001 Description: @%SystemRoot%\system32\cryptsvc.dll,-1002 Object name: NT Authority\NetworkService Image path: %SystemRoot%\system32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): cvhsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Client Virtualization Handler Description: Client Virtualization Handler Service (unlocalized description) Object name: LocalSystem Image path: "C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualiza tion Handler\CVHSVC.EXE" Image size: 822624 Image MD5: 72794D112CBAFF3BC0C29BF7350D4741 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: sftlist Service (registry key): DCLocator Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0

Type: 0 Error Control: 0 Service (registry key): DcomLaunch Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @oleres.dll,-5012 Description: @oleres.dll,-5013 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k DcomLaunch Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): defragsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\defragsvc.dll,-101 Description: @%SystemRoot%\system32\defragsvc.dll,-102 Object name: localSystem Image path: %SystemRoot%\system32\svchost.exe -k defragsvc Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): DfsC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drivers\dfsc.sys,-101 Description: @%systemroot%\system32\drivers\dfsc.sys,-102 Image path: System32\Drivers\dfsc.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Depends On services: Mup Service (registry key): DgiVecp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: DgiVecp Image path: \??\C:\Windows\system32\Drivers\DgiVecp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Service (registry key): Dhcp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\dhcpcore.dll,-100 Description: @%SystemRoot%\system32\dhcpcore.dll,-101 Object name: NT Authority\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestrict

ed Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: NSI,Tdx,Afd Service (registry key): discache Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drivers\discache.sys,-102 Description: @%systemroot%\system32\drivers\discache.sys,-101 Image path: System32\drivers\discache.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): Disk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Disk Driver Image path: system32\drivers\disk.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): Dnscache Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\dnsapi.dll,-101 Description: @%SystemRoot%\System32\dnsapi.dll,-102 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\system32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: Tdx,nsi Service (registry key): dot3svc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\dot3svc.dll,-1102 Description: @%systemroot%\system32\dot3svc.dll,-1103 Object name: localSystem Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,Ndisuio,Eaphost

Service (registry key): DPS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\dps.dll,-500 Description: @%systemroot%\system32\dps.dll,-501 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): drmkaud Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Trusted Audio Drivers Image path: system32\drivers\drmkaud.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): DXGKrnl Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: LDDM Graphics Subsystem Description: Controls the underlying video driver stacks to provide fully-fea tured display capabilities. Image path: \SystemRoot\System32\drivers\dxgkrnl.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): EapHost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\eapsvc.dll,-1 Description: @%systemroot%\system32\eapsvc.dll,-2 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS,KeyIso Service (registry key): ebdrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Broadcom NetXtreme II 10 GigE VBD Image path: \SystemRoot\system32\drivers\evbda.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3

Type: 1 Error Control: 1 Service (registry key): EFS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\efssvc.dll,-100 Description: @%SystemRoot%\system32\efssvc.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\System32\lsass.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): ehRecvr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\ehome\ehrecvr.exe,-101 Description: @%SystemRoot%\ehome\ehrecvr.exe,-102 Object name: NT AUTHORITY\networkService Image path: %systemroot%\ehome\ehRecvr.exe Image size: 696832 Image MD5: C4002B6B41975F057D98C439030CEA07 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Depends On services: RPCSS Service (registry key): ehSched Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\ehome\ehsched.exe,-101 Description: @%SystemRoot%\ehome\ehsched.exe,-102 Object name: NT AUTHORITY\networkService Image path: %systemroot%\ehome\ehsched.exe Image size: 127488 Image MD5: 4705E8EF9934482C5BB488CE28AFC681 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Depends On services: RPCSS Service (registry key): elxstor Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\elxstor.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ErrDev Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Hardware Error Device Driver Image path: \SystemRoot\system32\drivers\errdev.sys Image size: 0

Image MD5: Control Set: Start: Type: Error Control:

D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): ESENT Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): eventlog Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\wevtsvc.dll,-200 Description: @%SystemRoot%\system32\wevtsvc.dll,-201 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrict ed Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): EventSystem Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @comres.dll,-2450 Description: @comres.dll,-2451 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: rpcss Service (registry key): exfat Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: exFAT File System Driver Description: exFAT File System Driver Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): ezSharedSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Easybits Services for Windows Description: Provides licensing, security and parental control services for E asyBits applications. If this service is stopped or disabled, these applications will not function properly. Object name: LocalSystem Image path: C:\Windows\System32\ezSharedSvcHost.exe Image size: 514232 Image MD5: CA793DCC1D5F619021EF1D37CC7A831E

Control Set: Start: Type: Error Control:

CurrentControlSet 2 16 1

Service (registry key): fastfat Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: FAT12/16/32 File System Driver Description: Note - dependance on CDROM.SYS only if required to read/write DV D-RAM media (which appears as CD class device). (Core) (All pieces) Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): Fax Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\fxsresm.dll,-118 Description: @%systemroot%\system32\fxsresm.dll,-122 Object name: NT AUTHORITY\NetworkService Image path: %systemroot%\system32\fxssvc.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: TapiSrv,RpcSs,PlugPlay,Spooler Service (registry key): fdc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Floppy Disk Controller Driver Image path: \SystemRoot\system32\drivers\fdc.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): fdPHost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\fdPHost.dll,-100 Description: @%systemroot%\system32\fdPHost.dll,-101 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,http Service (registry key): FDResPub Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\fdrespub.dll,-100 Description: @%systemroot%\system32\fdrespub.dll,-101 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonat

ion Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,http Service (registry key): FileInfo Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\fileinfo.sys,-100 Description: @%SystemRoot%\system32\drivers\fileinfo.sys,-101 Image path: system32\drivers\fileinfo.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Depends On services: fltmgr Service (registry key): Filetrace Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\filetrace.sys,-10001 Description: @%SystemRoot%\system32\drivers\filetrace.sys,-10000 Image path: system32\drivers\filetrace.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Depends On services: FltMgr Service (registry key): flpydisk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Floppy Disk Driver Image path: \SystemRoot\system32\drivers\flpydisk.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): FltMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\fltmgr.sys,-10001 Description: @%SystemRoot%\system32\drivers\fltmgr.sys,-10000 Image path: system32\drivers\fltmgr.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 3 Service (registry key): FontCache Registry path: \SYSTEM\CurrentControlSet\Services\

Display name: Description: Object name: Image path: ion Image size: Image MD5: Control Set: Start: Type: Error Control:

@%systemroot%\system32\FntCache.dll,-100 @%systemroot%\system32\FntCache.dll,-101 NT AUTHORITY\LocalService %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonat 20992 54A47F6B5E09A77E61649109C6A08866 CurrentControlSet 2 32 1

Service (registry key): FontCache3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\PresentationHost.exe,-3309 Description: @%SystemRoot%\system32\PresentationHost.exe,-3310 Object name: NT Authority\LocalService Image path: %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFont Cache.exe Image size: 42856 Image MD5: A8B7F3818AB65695E3A0BB3279F6DCE6 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): FsDepends Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\fsdepends.sys,-10001 Description: @%SystemRoot%\system32\drivers\fsdepends.sys,-10000 Image path: System32\drivers\FsDepends.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 3 Depends On services: fltmgr Service (registry key): Fs_Rec Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 8 Error Control: 0 Service (registry key): fvevol Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\fvevol.sys,-100 Description: @%SystemRoot%\system32\drivers\fvevol.sys,-100 Image path: System32\DRIVERS\fvevol.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): gagp30kx Registry path: \SYSTEM\CurrentControlSet\Services\

Display name: Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms \SystemRoot\system32\drivers\gagp30kx.sys 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): GamesAppService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: GamesAppService Description: WT Games App Services Object name: LocalSystem Image path: "C:\Program Files (x86)\WildTangent Games\App\GamesAppService.ex e" Image size: 206072 Image MD5: C403C5DB49A0F9AAF4F2128EDC0106D8 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS,EVENTLOG Service (registry key): gpsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @gpapi.dll,-112 Description: @gpapi.dll,-113 Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS,Mup Service (registry key): hcw85cir Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Hauppauge Consumer Infrared Receiver Image path: \SystemRoot\system32\drivers\hcw85cir.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HdAudAddService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft 1.1 UAA Function Driver for High Definition Audio Serv ice Image path: system32\drivers\HdAudio.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1

Service (registry key): HDAudBus Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft UAA Bus Driver for High Definition Audio Image path: \SystemRoot\system32\drivers\HDAudBus.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HECIx64 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel(R) Management Engine Interface Image path: system32\DRIVERS\HECIx64.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HidBatt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HID UPS Battery Driver Image path: \SystemRoot\system32\drivers\HidBatt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HidBth Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Bluetooth HID Miniport Image path: \SystemRoot\system32\drivers\hidbth.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): HidIr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Infrared HID Driver Image path: \SystemRoot\system32\drivers\hidir.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): hidserv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\hidserv.dll,-101 Description: @%SystemRoot%\System32\hidserv.dll,-102

Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricte d Image size: Image MD5: Control Set: Start: Type: Error Control: 20992 54A47F6B5E09A77E61649109C6A08866 CurrentControlSet 3 32 1

Service (registry key): HidUsb Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft HID Class Driver Image path: system32\DRIVERS\hidusb.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): hkmsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\kmsvc.dll,-6 Description: @%SystemRoot%\system32\kmsvc.dll,-7 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): HomeGroupListener Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\ListSvc.dll,-100 Description: @%SystemRoot%\System32\ListSvc.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: LanmanServer Service (registry key): HomeGroupProvider Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\provsvc.dll,-100 Description: @%SystemRoot%\System32\provsvc.dll,-101 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrict ed Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet

Start: 3 Type: 32 Error Control: 1 Depends On services: netprofm,fdrespub,fdphost Service (registry key): HP Support Assistant Service Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HP Support Assistant Service Description: HP Support Assistant Service Object name: LocalSystem Image path: "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hps a_service.exe" Image size: 86072 Image MD5: 13BB1114451C63BFB41BA7DAA4D70A29 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Service (registry key): HP Wireless Assistant Service Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HP Wireless Assistant Service Description: This service monitors the wireless devices in this computer and allows the HP Wireless Assistant application to turn devices on and off. Object name: LocalSystem Image path: "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Ser vice.exe" Image size: 103992 Image MD5: C930128C8F8FF03D8F8C42B570920D56 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: winmgmt Service (registry key): HPClientSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HP Client Services Object name: LocalSystem Image path: "C:\Program Files\Hewlett-Packard\HP Client Services\HPClientSer vices.exe" Image size: 346168 Image MD5: 6A181452D4E240B8ECC7614B9A19BDE9 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Service (registry key): hpCMSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HP Connection Manager 4.0 Service Object name: LocalSystem Image path: "C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hp CMSrv.exe" Image size: 1071160 Image MD5: E040F0064D39F73BB4995D494F3DCBB8 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1

Depends On services: RPCSS Service (registry key): hpqwmiex Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HP Software Framework Service Object name: LocalSystem Image path: "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe" Image size: 994176 Image MD5: E7C7829BA0395E48F8C8FE16B8832344 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): HpSAMD Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\HpSAMD.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HPWMISVC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HPWMISVC Object name: LocalSystem Image path: C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC. exe Image size: 35200 Image MD5: 2BEC76BDCD1BC080210325E7B5094834 Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Service (registry key): HTTP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\http.sys,-1 Description: @%SystemRoot%\system32\drivers\http.sys,-2 Image path: system32\drivers\HTTP.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): hwpolicy Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drivers\hwpolicy.sys,-101 Description: @%systemroot%\system32\drivers\hwpolicy.sys,-102 Image path: System32\drivers\hwpolicy.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1

Error Control: 1 Service (registry key): i8042prt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: i8042 Keyboard and PS/2 Mouse Port Driver Image path: \SystemRoot\system32\drivers\i8042prt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ialm Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): iaStor Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel AHCI Controller Image path: system32\DRIVERS\iaStor.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): IAStorDataMgrSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel(R) Rapid Storage Technology Description: Provides storage event notification and manages communication be tween the storage driver and user space applications. Object name: LocalSystem Image path: "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ IAStorDataMgrSvc.exe" Image size: 13336 Image MD5: 983FC69644DDF0486C8DFEA262948D1A Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: winmgmt Service (registry key): iaStorV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel RAID Controller Windows 7 Image path: \SystemRoot\system32\drivers\iaStorV.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): idsvc Registry path: \SYSTEM\CurrentControlSet\Services\

Display name: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communicati on Foundation\ServiceModelInstallRC.dll,-8193 Description: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communicati on Foundation\ServiceModelInstallRC.dll,-8192 Object name: LocalSystem Image path: "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communicati on Foundation\infocard.exe" Image size: 856400 Image MD5: 5988FC40F8DB5B0739CD1E3A5D0D78BD Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): igfx Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\igdkmd64.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): iirsp Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\iirsp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): IKEEXT Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\ikeext.dll,-501 Description: @%SystemRoot%\system32\ikeext.dll,-502 Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: BFE Service (registry key): Impcd Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\Impcd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): inetaccs Registry path: \SYSTEM\CurrentControlSet\Services\

Control Set: Start: Type: Error Control:

CurrentControlSet 0 0 0

Service (registry key): IntcDAud Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel(R) Display Audio Image path: system32\DRIVERS\IntcDAud.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): intelide Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\intelide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 3 Service (registry key): intelppm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel Processor Driver Image path: system32\DRIVERS\intelppm.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): IPBusEnum Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\IPBusEnum.dll,-102 Description: @%systemroot%\system32\IPBusEnum.dll,-103 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,fdPHost Service (registry key): IpFilterDriver Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32013 Description: @%systemroot%\system32\rascfg.dll,-32013 Image path: system32\DRIVERS\ipfltdrv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet

Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): iphlpsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\iphlpsvc.dll,-500 Description: @%SystemRoot%\system32\iphlpsvc.dll,-501 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k NetSvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSS,Tdx,winmgmt,tcpip,nsi Service (registry key): IPMIDRV Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\IPMIDrv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): IPNAT Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IP Network Address Translator Image path: System32\drivers\ipnat.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): IRENUM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\irenum.sys,-100 Description: @%SystemRoot%\system32\drivers\irenum.sys,-101 Image path: system32\drivers\irenum.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): isapnp Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\isapnp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3

Type: 1 Error Control: 3 Service (registry key): iScsiPrt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: iScsiPort Driver Image path: \SystemRoot\system32\drivers\msiscsi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): kbdclass Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Keyboard Class Driver Image path: \SystemRoot\system32\drivers\kbdclass.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): kbdhid Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Keyboard HID Driver Image path: \SystemRoot\system32\drivers\kbdhid.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): KeyIso Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @keyiso.dll,-100 Description: @keyiso.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): KL1 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: kl1 Image path: system32\DRIVERS\kl1.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1

Service (registry key): kl2 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: kl2 Image path: system32\DRIVERS\kl2.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): KLIF Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Kaspersky Lab Driver Description: Kaspersky Lab Interceptor and Filter Image path: system32\DRIVERS\klif.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Depends On services: FltMgr Service (registry key): KLIM6 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Kaspersky Anti-Virus NDIS 6 Filter Description: Kaspersky Anti-Virus NDIS 6 Filter Image path: system32\DRIVERS\klim6.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): klmouflt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Kaspersky Lab KLMOUFLT Description: Kaspersky Lab Mouse Class Filter Image path: system32\DRIVERS\klmouflt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): KSecDD Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\Drivers\ksecdd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): KSecPkg

Registry path: Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

\SYSTEM\CurrentControlSet\Services\ System32\Drivers\ksecpkg.sys 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 0 1 3

Service (registry key): ksthunk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Kernel Streaming Thunks Image path: \SystemRoot\system32\drivers\ksthunk.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): KtmRm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @comres.dll,-2946 Description: @comres.dll,-2947 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImperson ation Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS,SamSS Service (registry key): LanmanServer Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\srvsvc.dll,-100 Description: @%systemroot%\system32\srvsvc.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: SamSS,Srv Service (registry key): LanmanWorkstation Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wkssvc.dll,-100 Description: @%systemroot%\system32\wkssvc.dll,-101 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\System32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32

Error Control: 1 Depends On services: Bowser,MRxSmb10,MRxSmb20,NSI Service (registry key): ldap Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): lltdio Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Link-Layer Topology Discovery Mapper I/O Driver Image path: system32\DRIVERS\lltdio.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Service (registry key): lltdsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\lltdres.dll,-1 Description: @%SystemRoot%\system32\lltdres.dll,-2 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: rpcss,lltdio Service (registry key): lmhosts Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\lmhsvc.dll,-101 Description: @%SystemRoot%\system32\lmhsvc.dll,-102 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestrict ed Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: NetBT,Afd Service (registry key): LMS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel(R) Management and Security Application Local Management Se rvice Description: Allows applications to access the local Intel(R) Management and Security Application using its locally-available selected network interfaces. Object name: LocalSystem Image path: C:\Program Files (x86)\Intel\Intel(R) Management Engine Componen ts\LMS\LMS.exe Image size: 325656

Image MD5: Control Set: Start: Type: Error Control:

9D8B95C0EAE145C46BC4A727B23DA395 CurrentControlSet 2 16 1

Service (registry key): Lsa Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): LSI_FC Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\lsi_fc.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): LSI_SAS Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\lsi_sas.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): LSI_SAS2 Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\lsi_sas2.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): LSI_SCSI Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\lsi_scsi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): luafv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drivers\luafv.sys,-100 Description: @%systemroot%\system32\drivers\luafv.sys,-101 Image path: \SystemRoot\system32\drivers\luafv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E

Control Set: CurrentControlSet Start: 2 Type: 2 Error Control: 1 Depends On services: FltMgr Service (registry key): MAV Client PerfMon Provider Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Mcx2Svc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\ehome\ehres.dll,-15501 Description: @%SystemRoot%\ehome\ehres.dll,-15502 Object name: NT Authority\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonat ion Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: SSDPSRV,IPBusEnum,TermService,fdphost Service (registry key): megasas Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\megasas.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MegaSR Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\MegaSR.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MMCSS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\mmcss.dll,-100 Description: @%systemroot%\system32\mmcss.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1

Service (registry key): Modem Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\drivers\modem.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): monitor Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Monitor Class Function Driver Service Image path: system32\DRIVERS\monitor.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): mouclass Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mouse Class Driver Image path: system32\DRIVERS\mouclass.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): mouhid Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mouse HID Driver Image path: system32\DRIVERS\mouhid.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): mountmgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\mountmgr.sys,-100 Description: @%SystemRoot%\system32\drivers\mountmgr.sys,-101 Image path: System32\drivers\mountmgr.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): MozillaMaintenance Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mozilla Maintenance Service Description: The Mozilla Maintenance Service ensures that you have the latest

and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recomm ends that you keep this service enabled. Object name: LocalSystem Image path: C:\Program Files (x86)\Mozilla Maintenance Service\maintenancese rvice.exe Image size: 113120 Image MD5: 15D5398EED42C2504BB3D4FC875C15D1 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): mpio Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\mpio.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): mpsdrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\FirewallAPI.dll,-23092 Description: @%SystemRoot%\system32\FirewallAPI.dll,-23093 Image path: System32\drivers\mpsdrv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MpsSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\FirewallAPI.dll,-23090 Description: @%SystemRoot%\system32\FirewallAPI.dll,-23091 Object name: NT Authority\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: mpsdrv,bfe Service (registry key): MRxDAV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\webclnt.dll,-104 Description: @%systemroot%\system32\webclnt.dll,-105 Image path: \SystemRoot\system32\drivers\mrxdav.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1

Depends On services: rdbss Service (registry key): mrxsmb Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wkssvc.dll,-1002 Description: @%systemroot%\system32\wkssvc.dll,-1003 Image path: system32\DRIVERS\mrxsmb.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Depends On services: rdbss Service (registry key): mrxsmb10 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wkssvc.dll,-1004 Description: @%systemroot%\system32\wkssvc.dll,-1005 Image path: system32\DRIVERS\mrxsmb10.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Depends On services: mrxsmb Service (registry key): mrxsmb20 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wkssvc.dll,-1006 Description: @%systemroot%\system32\wkssvc.dll,-1007 Image path: system32\DRIVERS\mrxsmb20.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Depends On services: mrxsmb Service (registry key): msahci Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\drivers\msahci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): msdsm Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\msdsm.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1

Service (registry key): MSDTC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @comres.dll,-2797 Description: @comres.dll,-2798 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\System32\msdtc.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS,SamSS Service (registry key): MSDTC Bridge 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): MSDTC Bridge 4.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Msfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): mshidkmdf Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\mshidkmdf.sys,-100 Description: @%SystemRoot%\system32\drivers\mshidkmdf.sys,-101 Image path: \SystemRoot\System32\drivers\mshidkmdf.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): msisadrv Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\drivers\msisadrv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): MSiSCSI Registry path: \SYSTEM\CurrentControlSet\Services\

Display name: Description: Object name: Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

@%SystemRoot%\system32\iscsidsc.dll,-5000 @%SystemRoot%\system32\iscsidsc.dll,-5001 LocalSystem %systemroot%\system32\svchost.exe -k netsvcs 20992 54A47F6B5E09A77E61649109C6A08866 CurrentControlSet 3 32 1

Service (registry key): msiserver Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\msimsg.dll,-27 Description: @%SystemRoot%\system32\msimsg.dll,-32 Object name: LocalSystem Image path: %systemroot%\system32\msiexec.exe /V Image size: 73216 Image MD5: EEE470F2A771FC0B543BDEEF74FCECA0 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: rpcss Service (registry key): MSKSSRV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Service Proxy Image path: system32\drivers\MSKSSRV.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MSPCLOCK Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Clock Proxy Image path: system32\drivers\MSPCLOCK.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MSPQM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Quality Manager Proxy Image path: system32\drivers\MSPQM.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MsRPC Registry path: \SYSTEM\CurrentControlSet\Services\

Control Set: Start: Type: Error Control:

CurrentControlSet 3 1 1

Service (registry key): MSSCNTRS Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): mssmbios Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft System Management BIOS Driver Image path: \SystemRoot\system32\drivers\mssmbios.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): MSTEE Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Tee/Sink-to-Sink Converter Image path: system32\drivers\MSTEE.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MTConfig Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Input Configuration Driver Image path: \SystemRoot\system32\drivers\MTConfig.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Mup Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drivers\mup.sys,-101 Description: @%systemroot%\system32\drivers\mup.sys,-102 Image path: System32\Drivers\mup.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Service (registry key): napagent Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\qagentrt.dll,-6

Description: @%SystemRoot%\system32\qagentrt.dll,-7 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\System32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): NativeWifiP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NativeWiFi Filter Image path: system32\DRIVERS\nwifi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NDIS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\ndis.sys,-200 Description: @%SystemRoot%\system32\drivers\ndis.sys,-201 Image path: system32\drivers\ndis.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): NdisCap Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NDIS Capture LightWeight Filter Description: NDIS Capture LightWeight Filter Image path: system32\DRIVERS\ndiscap.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NdisTapi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32001 Description: @%systemroot%\system32\rascfg.dll,-32001 Image path: system32\DRIVERS\ndistapi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Ndisuio Registry path: \SYSTEM\CurrentControlSet\Services\

Display name: Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

NDIS Usermode I/O Protocol system32\DRIVERS\ndisuio.sys 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): NdisWan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32002 Description: @%systemroot%\system32\rascfg.dll,-32002 Image path: system32\DRIVERS\ndiswan.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NDProxy Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NetBIOS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NetBIOS Interface Description: NetBIOS Interface Image path: system32\DRIVERS\netbios.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): NetBT Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\netbt.sys,-2 Description: @%SystemRoot%\system32\drivers\netbt.sys,-1 Image path: System32\DRIVERS\netbt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: Tdx,tcpip Service (registry key): Netlogon Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\netlogon.dll,-102 Description: @%SystemRoot%\System32\netlogon.dll,-103 Object name: LocalSystem Image path: %systemroot%\system32\lsass.exe Image size: 0

Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): Netman Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\netman.dll,-109 Description: @%SystemRoot%\system32\netman.dll,-110 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,nsi Service (registry key): netprofm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\netprofm.dll,-202 Description: @%SystemRoot%\system32\netprofm.dll,-203 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,nlasvc Service (registry key): netr28x Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Ralink 802.11n Extensible Wireless Driver Image path: system32\DRIVERS\netr28x.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NetTcpPortSharing Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communicati on Foundation\ServiceModelInstallRC.dll,-8201 Description: @%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communicati on Foundation\ServiceModelInstallRC.dll,-8200 Object name: NT AUTHORITY\LocalService Image path: "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communicati on Foundation\SMSvcHost.exe" Image size: 116560 Image MD5: 3E5A36127E201DDF663176B66828FAFE Control Set: CurrentControlSet Start: 4

Type: 32 Error Control: 1 Service (registry key): nfrd960 Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\nfrd960.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NlaSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\nlasvc.dll,-1 Description: @%SystemRoot%\System32\nlasvc.dll,-2 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\System32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: NSI,RpcSs,TcpIp Service (registry key): Npfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): nsi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\nsisvc.dll,-200 Description: @%SystemRoot%\system32\nsisvc.dll,-201 Object name: NT Authority\LocalService Image path: %systemroot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: nsiproxy Service (registry key): nsiproxy Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\nsiproxy.sys,-2 Description: @%SystemRoot%\system32\drivers\nsiproxy.sys,-1 Image path: system32\drivers\nsiproxy.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1

Service (registry key): NTDS Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Ntfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): Null Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): NVENETFD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NVIDIA nForce Networking Controller Driver Image path: system32\DRIVERS\nvm62x64.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): nvraid Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\nvraid.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): nvstor Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\nvstor.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 3 Service (registry key): nv_agp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NVIDIA nForce AGP Bus Filter Image path: \SystemRoot\system32\drivers\nv_agp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3

Type: 1 Error Control: 1 Service (registry key): ohci1394 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: 1394 OHCI Compliant Host Controller (Legacy) Image path: \SystemRoot\system32\drivers\ohci1394.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ose Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Office Source Engine Description: Saves installation files used for updates and repairs and is req uired for the downloading of Setup updates and Watson error reports. Object name: LocalSystem Image path: "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Eng ine\OSE.EXE" Image size: 149352 Image MD5: 9D10F99A6712E28F8ACD5641E3A7EA6B Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): osppsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Office Software Protection Platform Description: Office Software Protection Platform Service (unlocalized descrip tion) Object name: NT AUTHORITY\NetworkService Image path: "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwarePr otectionPlatform\OSPPSVC.EXE" Image size: 4925184 Image MD5: 61BFFB5F57AD12F83AB64B7181829B34 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RpcSs Service (registry key): p2pimsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\pnrpsvc.dll,-8004 Description: @%SystemRoot%\system32\pnrpsvc.dll,-8005 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): p2psvc Registry path: \SYSTEM\CurrentControlSet\Services\

Display name: @%SystemRoot%\system32\p2psvc.dll,-8006 Description: @%SystemRoot%\system32\p2psvc.dll,-8007 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: p2pimsvc,PNRPSvc Service (registry key): Parport Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Parallel port driver Image path: \SystemRoot\system32\drivers\parport.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): partmgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\partmgr.sys,-100 Description: @%SystemRoot%\system32\drivers\partmgr.sys,-101 Image path: System32\drivers\partmgr.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): PcaSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\pcasvc.dll,-1 Description: @%SystemRoot%\system32\pcasvc.dll,-2 Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): pci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PCI Bus Driver Image path: system32\drivers\pci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3

Service (registry key): pciide Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\pciide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 3 Service (registry key): pcmcia Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\pcmcia.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): pcw Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Performance Counters for Windows Driver Image path: System32\drivers\pcw.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): PEAUTH Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PEAUTH Image path: system32\drivers\peauth.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Service (registry key): PerfDisk Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfHost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\sysWow64\perfhost.exe,-2 Description: @%systemroot%\SysWow64\perfhost.exe,-1 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\SysWow64\perfhost.exe Image size: 20992 Image MD5: E495E408C93141E8FC72DC0C6046DDFA Control Set: CurrentControlSet Start: 3

Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): PerfNet Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfOS Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfProc Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): pla Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\pla.dll,-500 Description: @%systemroot%\system32\pla.dll,-501 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): PlugPlay Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\umpnpmgr.dll,-100 Description: @%SystemRoot%\system32\umpnpmgr.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k DcomLaunch Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): PNRPAutoReg Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\pnrpauto.dll,-8002 Description: @%SystemRoot%\system32\pnrpauto.dll,-8003 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866

Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: pnrpsvc Service (registry key): PNRPsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\pnrpsvc.dll,-8000 Description: @%SystemRoot%\system32\pnrpsvc.dll,-8001 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: p2pimsvc Service (registry key): PolicyAgent Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\polstore.dll,-5010 Description: @%SystemRoot%\system32\polstore.dll,-5011 Object name: NT Authority\NetworkService Image path: %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestri cted Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Tcpip,bfe Service (registry key): PortProxy Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Power Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\umpo.dll,-100 Description: @%SystemRoot%\system32\umpo.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k DcomLaunch Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): PptpMiniport Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32006 Description: @%systemroot%\system32\rascfg.dll,-32006 Image path: system32\DRIVERS\raspptp.sys

Image size: Image MD5: Control Set: Start: Type: Error Control:

0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): Processor Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Processor Driver Image path: \SystemRoot\system32\drivers\processr.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ProfSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\profsvc.dll,-300 Description: @%systemroot%\system32\profsvc.dll,-301 Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): ProtectedStorage Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\psbase.dll,-300 Description: @%systemroot%\system32\psbase.dll,-301 Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): Psched Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\drivers\pacer.sys,-101 Description: @%SystemRoot%\System32\drivers\pacer.sys,-101 Image path: system32\DRIVERS\pacer.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): ql2300 Registry path: \SYSTEM\CurrentControlSet\Services\

Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

\SystemRoot\system32\drivers\ql2300.sys 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): ql40xx Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\ql40xx.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): QWAVE Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\qwave.dll,-1 Description: @%SystemRoot%\system32\qwave.dll,-2 Object name: NT AUTHORITY\LocalService Image path: %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: rpcss,psched,QWAVEdrv,LLTDIO Service (registry key): QWAVEdrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\qwavedrv.sys,-1 Description: @%SystemRoot%\system32\drivers\qwavedrv.sys,-2 Image path: \SystemRoot\system32\drivers\qwavedrv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): RasAcd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access Auto Connection Driver Description: Remote Access Auto Connection Driver Image path: System32\DRIVERS\rasacd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): RasAgileVpn Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WAN Miniport (IKEv2) Description: WAN Miniport (IKEv2)

Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

system32\DRIVERS\AgileVpn.sys 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): RasAuto Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%Systemroot%\system32\rasauto.dll,-200 Description: @%Systemroot%\system32\rasauto.dll,-201 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RasMan,TapiSrv,RasAcd Service (registry key): Rasl2tp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32005 Description: @%systemroot%\system32\rascfg.dll,-32005 Image path: system32\DRIVERS\rasl2tp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): RasMan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%Systemroot%\system32\rasmans.dll,-200 Description: @%Systemroot%\system32\rasmans.dll,-201 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Tapisrv,SstpSvc Service (registry key): RasPppoe Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32007 Description: @%systemroot%\system32\rascfg.dll,-32007 Image path: system32\DRIVERS\raspppoe.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1

Service (registry key): RasSstp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\sstpsvc.dll,-202 Description: @%systemroot%\system32\sstpsvc.dll,-202 Image path: system32\DRIVERS\rassstp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): rdbss Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wkssvc.dll,-1000 Description: @%systemroot%\system32\wkssvc.dll,-1001 Image path: system32\DRIVERS\rdbss.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Depends On services: Mup Service (registry key): rdpbus Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Desktop Device Redirector Bus Driver Image path: \SystemRoot\system32\drivers\rdpbus.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): RDPCDD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\DRIVERS\RDPCDD.sys,-100 Description: @%systemroot%\system32\DRIVERS\RDPCDD.sys,-101 Image path: System32\DRIVERS\RDPCDD.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): RDPDD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): RDPENCDD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drivers\RDPENCDD.sys,-101 Description: @%systemroot%\system32\drivers\RDPENCDD.sys,-100 Image path: system32\drivers\rdpencdd.sys

Image size: Image MD5: Control Set: Start: Type: Error Control:

0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 1 1 0

Service (registry key): RDPNP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drprov.dll,-100 Description: @%systemroot%\system32\drprov.dll,-101 Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): RDPREFMP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\drivers\RdpRefMp.sys,-101 Description: @%systemroot%\system32\drivers\RdpRefMp.sys,-100 Image path: system32\drivers\rdprefmp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): RDPWD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: RDP Winstation Driver Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): rdyboost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ReadyBoost Description: ReadyBoost Image path: System32\drivers\rdyboost.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): RemoteAccess Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%Systemroot%\system32\mprdim.dll,-200 Description: @%Systemroot%\system32\mprdim.dll,-201 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1

Depends On services: RpcSS,Bfe,RasMan,Http Depends On group: NetBIOSGroup Service (registry key): RemoteRegistry Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @regsvc.dll,-1 Description: @regsvc.dll,-2 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k regsvc Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): Revoflt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Revoflt Description: Revo Uninstaller Filter driver Image path: system32\DRIVERS\revoflt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Depends On services: FltMgr Service (registry key): RoxioNow Service Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: RoxioNow Service Object name: LocalSystem Image path: C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe Image size: 399344 Image MD5: 085D18C71AB2611A3D61528132B6501E Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Service (registry key): RpcEptMapper Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%windir%\system32\RpcEpMap.dll,-1001 Description: @%windir%\system32\RpcEpMap.dll,-1002 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\system32\svchost.exe -k RPCSS Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): RpcLocator Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\Locator.exe,-2 Description: @%systemroot%\system32\Locator.exe,-3 Object name: NT AUTHORITY\NetworkService

Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

%SystemRoot%\system32\locator.exe 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 16 1

Service (registry key): RpcSs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @oleres.dll,-5010 Description: @oleres.dll,-5011 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\system32\svchost.exe -k rpcss Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcEptMapper,DcomLaunch Service (registry key): RSPCIESTOR Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Realtek PCIE CardReader Driver Image path: system32\DRIVERS\RtsPStor.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): rspndr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Link-Layer Topology Discovery Responder Image path: system32\DRIVERS\rspndr.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Service (registry key): RTL8167 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Realtek 8167 NT Driver Image path: system32\DRIVERS\Rt64win7.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SamSs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\samsrv.dll,-1 Description: @%SystemRoot%\system32\samsrv.dll,-2 Object name: LocalSystem

Image path: %SystemRoot%\system32\lsass.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): sbp2port Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\sbp2port.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SBSDWSCService Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Depends On services: wscsvc Service (registry key): SCardSvr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\SCardSvr.dll,-1 Description: @%SystemRoot%\System32\SCardSvr.dll,-5 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonat ion Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: PlugPlay Service (registry key): scfilter Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\drivers\scfilter.sys,-11 Description: @%SystemRoot%\System32\drivers\scfilter.sys,-12 Image path: System32\DRIVERS\scfilter.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Schedule Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\schedsvc.dll,-100 Description: @%SystemRoot%\system32\schedsvc.dll,-101 Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs

Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS,EventLog Service (registry key): SCPolicySvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\certprop.dll,-13 Description: @%SystemRoot%\System32\certprop.dll,-14 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): sdbus Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\sdbus.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SDRSVC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\sdrsvc.dll,-107 Description: @%SystemRoot%\system32\sdrsvc.dll,-102 Object name: localSystem Image path: %SystemRoot%\system32\svchost.exe -k SDRSVC Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): secdrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Security Driver Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Service (registry key): seclogon Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\seclogon.dll,-7001 Description: @%SystemRoot%\system32\seclogon.dll,-7000 Object name: LocalSystem Image path: %windir%\system32\svchost.exe -k netsvcs

Image size: Image MD5: Control Set: Start: Type: Error Control:

20992 54A47F6B5E09A77E61649109C6A08866 CurrentControlSet 3 32 1

Service (registry key): SENS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\Sens.dll,-200 Description: @%SystemRoot%\system32\Sens.dll,-201 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: EventSystem Service (registry key): SensrSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\sensrsvc.dll,-1000 Description: @%SystemRoot%\System32\sensrsvc.dll,-1001 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonat ion Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): Serenum Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Serenum Filter Driver Image path: \SystemRoot\system32\drivers\serenum.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Serial Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\serial.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): sermouse Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Serial Mouse Driver Image path: \SystemRoot\system32\drivers\sermouse.sys

Image size: Image MD5: Control Set: Start: Type: Error Control:

0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): ServiceModelEndpoint 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ServiceModelOperation 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ServiceModelService 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): SessionEnv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\SessEnv.dll,-1026 Description: @%SystemRoot%\System32\SessEnv.dll,-1027 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS,LanmanWorkstation Service (registry key): sffdisk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SFF Storage Class Driver Image path: \SystemRoot\system32\drivers\sffdisk.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): sffp_mmc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SFF Storage Protocol Driver for MMC Image path: \SystemRoot\system32\drivers\sffp_mmc.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet

Start: 3 Type: 1 Error Control: 1 Service (registry key): sffp_sd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SFF Storage Protocol Driver for SDBus Image path: \SystemRoot\system32\drivers\sffp_sd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): sfloppy Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: High-Capacity Floppy Disk Drive Image path: \SystemRoot\system32\drivers\sfloppy.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Sftfs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Sftfs Description: Sftfs Driver Image path: system32\DRIVERS\Sftfslh.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Sftvol Service (registry key): sftlist Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Application Virtualization Client Description: Streams and manages applications. Object name: LocalSystem Image path: "C:\Program Files (x86)\Microsoft Application Virtualization Cli ent\sftlist.exe" Image size: 508776 Image MD5: 13693B6354DD6E72DC5131DA7D764B90 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: sftplay,sftfs,sftvsa Service (registry key): Sftplay Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Sftplay Description: Sftplay Driver Image path: system32\DRIVERS\Sftplaylh.sys Image size: 0

Image MD5: Control Set: Start: Type: Error Control:

D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): Sftredir Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Sftredir Description: Sftredir Mini-Filter Driver Image path: system32\DRIVERS\Sftredirlh.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Depends On services: FltMgr Service (registry key): Sftvol Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Sftvol Description: Sftvol Driver Image path: system32\DRIVERS\Sftvollh.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): sftvsa Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Application Virtualization Service Agent Description: Monitors global service events and launches virtual services. Object name: LocalSystem Image path: "C:\Program Files (x86)\Microsoft Application Virtualization Cli ent\sftvsa.exe" Image size: 219496 Image MD5: C3CDDD18F43D44AB713CF8C4916F7696 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): SharedAccess Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\ipnathlp.dll,-106 Description: @%SystemRoot%\system32\ipnathlp.dll,-107 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Netman,WinMgmt,RasMan,BFE

Service (registry key): ShellHWDetection Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\shsvcs.dll,-12288 Description: @%SystemRoot%\System32\shsvcs.dll,-12289 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RpcSs Service (registry key): SiSRaid2 Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\SiSRaid2.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SiSRaid4 Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\sisraid4.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Smb Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\tcpipcfg.dll,-50005 Description: @%SystemRoot%\system32\tcpipcfg.dll,-50006 Image path: system32\DRIVERS\smb.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): SMSvcHost 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): SMSvcHost 4.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0

Service (registry key): SNMPTRAP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\snmptrap.exe,-3 Description: @%SystemRoot%\system32\snmptrap.exe,-4 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\snmptrap.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): spldr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Security Processor Loader Driver Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): Spooler Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\spoolsv.exe,-1 Description: @%systemroot%\system32\spoolsv.exe,-2 Object name: LocalSystem Image path: %SystemRoot%\System32\spoolsv.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Depends On services: RPCSS,http Service (registry key): sppsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\sppsvc.exe,-101 Description: @%SystemRoot%\system32\sppsvc.exe,-100 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\system32\sppsvc.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RpcSs Service (registry key): sppuinotify Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\sppuinotify.dll,-103 Description: @%SystemRoot%\system32\sppuinotify.dll,-102 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3

Type: 32 Error Control: 1 Depends On services: EventSystem Service (registry key): srv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\srvsvc.dll,-102 Description: @%systemroot%\system32\srvsvc.dll,-103 Image path: System32\DRIVERS\srv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Depends On services: srv2 Service (registry key): srv2 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\srvsvc.dll,-104 Description: @%systemroot%\system32\srvsvc.dll,-105 Image path: System32\DRIVERS\srv2.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Depends On services: srvnet Service (registry key): SrvHsfHDA Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\VSTAZL6.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SrvHsfV92 Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\VSTDPV6.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SrvHsfWinac Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\VSTCNXT6.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0

Service (registry key): srvnet Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\DRIVERS\srvnet.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): SSDPSRV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\ssdpsrv.dll,-100 Description: @%systemroot%\system32\ssdpsrv.dll,-101 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonat ion Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: HTTP Service (registry key): SSPORT Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SSPORT Image path: \??\C:\Windows\system32\Drivers\SSPORT.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Service (registry key): SstpSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\sstpsvc.dll,-200 Description: @%SystemRoot%\system32\sstpsvc.dll,-201 Object name: NT Authority\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): STacSV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\stlang64.dll,-10101 Description: @%SystemRoot%\system32\stlang64.dll,-10201 Object name: LocalSystem Image path: C:\Program Files\IDT\WDM\STacSV64.exe Image size: 296448 Image MD5: 54DE4331FBCFABCDFDA5C845F856D848 Control Set: CurrentControlSet Start: 2 Type: 16

Error Control: 1 Service (registry key): stexstor Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\stexstor.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): STHDA Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\stlang64.dll,-10301 Image path: system32\DRIVERS\stwrt64.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): stisvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\wiaservc.dll,-9 Description: @%SystemRoot%\system32\wiaservc.dll,-10 Object name: NT Authority\LocalService Image path: %SystemRoot%\system32\svchost.exe -k imgsvc Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RpcSs,ShellHWDetection Service (registry key): swenum Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Software Bus Driver Image path: \SystemRoot\system32\drivers\swenum.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): swprv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\swprv.dll,-103 Description: @%SystemRoot%\System32\swprv.dll,-102 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k swprv Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1

Depends On services: RPCSS Service (registry key): SynTP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Synaptics TouchPad Driver Image path: system32\DRIVERS\SynTP.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SysMain Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\sysmain.dll,-1000 Description: @%SystemRoot%\system32\sysmain.dll,-1001 Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: rpcss,fileinfo Service (registry key): TabletInputService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\TabSvc.dll,-100 Description: @%SystemRoot%\system32\TabSvc.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: PlugPlay,RpcSs Service (registry key): TapiSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\tapisrv.dll,-10100 Description: @%SystemRoot%\system32\tapisrv.dll,-10101 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\System32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: PlugPlay,RpcSs Service (registry key): TBS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\tbssvc.dll,-100

Description: @%SystemRoot%\system32\tbssvc.dll,-101 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonat ion Image size: Image MD5: Control Set: Start: Type: Error Control: 20992 54A47F6B5E09A77E61649109C6A08866 CurrentControlSet 3 32 1

Service (registry key): Tcpip Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\tcpipcfg.dll,-50003 Description: @%SystemRoot%\system32\tcpipcfg.dll,-50003 Image path: System32\drivers\tcpip.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): TCPIP6 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft IPv6 Protocol Driver Description: Microsoft IPv6 Protocol Driver Image path: system32\DRIVERS\tcpip.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): TCPIP6TUNNEL Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): tcpipreg Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: TCP/IP Registry Compatibility Description: Provides compatibility for legacy applications which interact wi th TCP/IP through the registry. If this service is stopped, certain applications may have impaired functionality. Image path: System32\drivers\tcpipreg.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Depends On services: tcpip Service (registry key): TCPIPTUNNEL Registry path: \SYSTEM\CurrentControlSet\Services\

Control Set: Start: Type: Error Control:

CurrentControlSet 0 0 0

Service (registry key): TDPIPE Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: TDPIPE Image path: system32\drivers\tdpipe.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): TDTCP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: TDTCP Image path: system32\drivers\tdtcp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): tdx Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\tcpipcfg.dll,-50004 Description: @%SystemRoot%\system32\tcpipcfg.dll,-50004 Image path: system32\DRIVERS\tdx.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): TermDD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Terminal Device Driver Image path: \SystemRoot\system32\drivers\termdd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): TermService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\termsrv.dll,-268 Description: @%SystemRoot%\System32\termsrv.dll,-267 Object name: NT Authority\NetworkService Image path: %SystemRoot%\System32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet

Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS,TermDD Service (registry key): Themes Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\themeservice.dll,-8192 Description: @%SystemRoot%\System32\themeservice.dll,-8193 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): THREADORDER Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\mmcss.dll,-102 Description: @%systemroot%\system32\mmcss.dll,-103 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): TrkWks Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\trkwks.dll,-1 Description: @%SystemRoot%\system32\trkwks.dll,-2 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): TrustedInstaller Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 Description: @%SystemRoot%\servicing\TrustedInstaller.exe,-101 Object name: localSystem Image path: %SystemRoot%\servicing\TrustedInstaller.exe Image size: 194048 Image MD5: 773212B2AAA24C1E31F10246B15B276C Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): TSDDD

Registry path: Control Set: Start: Type: Error Control:

\SYSTEM\CurrentControlSet\Services\ CurrentControlSet 0 0 0

Service (registry key): tssecsrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101 Description: @%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-102 Image path: System32\DRIVERS\tssecsrv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): TsUsbFlt Registry path: \SYSTEM\CurrentControlSet\Services\ Description: @%SystemRoot%\system32\drivers\tsusbflt.sys,-1000 Image path: system32\drivers\tsusbflt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): TsUsbGD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Desktop Generic USB Device Image path: \SystemRoot\system32\drivers\TsUsbGD.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): tunnel Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Tunnel Miniport Adapter Driver Image path: system32\DRIVERS\tunnel.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): uagp35 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft AGPv3.5 Filter Image path: \SystemRoot\system32\drivers\uagp35.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1

Error Control: 1 Service (registry key): udfs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: udfs Description: Reads/Writes UDF 1.02,1.5,2.0x,2.5 disc formats, usually found o n C/DVD discs. (Core) (All pieces) Image path: system32\DRIVERS\udfs.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Service (registry key): UGatherer Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): UGTHRSVC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): UI0Detect Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\ui0detect.exe,-101 Description: @%SystemRoot%\system32\ui0detect.exe,-102 Object name: LocalSystem Image path: %SystemRoot%\system32\UI0Detect.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 272 Error Control: 1 Service (registry key): uliagpkx Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Uli AGP Bus Filter Image path: \SystemRoot\system32\drivers\uliagpkx.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): umbus Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: UMBus Enumerator Driver Image path: system32\DRIVERS\umbus.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet

Start: 3 Type: 1 Error Control: 1 Service (registry key): UmPass Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft UMPass Driver Image path: \SystemRoot\system32\drivers\umpass.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): UNS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel(R) Management & Security Application User Notification Ser vice Description: Intel(R) Management and Security Application User Notification S ervice - Updates the Windows Event Log with notifications of pre defined events received from the local Intel(R) Management and Security Application Device. Object name: LocalSystem Image path: "C:\Program Files (x86)\Intel\Intel(R) Management Engine Compone nts\UNS\UNS.exe" Image size: 2538520 Image MD5: 0B0B9F55B12767A755932C26B5FED715 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: LMS Service (registry key): upnphost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\upnphost.dll,-213 Description: @%systemroot%\system32\upnphost.dll,-214 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonat ion Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: SSDPSRV,HTTP Service (registry key): usbccgp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB Generic Parent Driver Image path: system32\DRIVERS\usbccgp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbcir

Registry path: Display name: Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

\SYSTEM\CurrentControlSet\Services\ eHome Infrared Receiver (USBCIR) \SystemRoot\system32\drivers\usbcir.sys 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 3 1 1

Service (registry key): usbehci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver Image path: \SystemRoot\system32\drivers\usbehci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbhub Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB Standard Hub Driver Image path: system32\DRIVERS\usbhub.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbohci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB Open Host Controller Miniport Driver Image path: \SystemRoot\system32\drivers\usbohci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbprint Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB PRINTER Class Image path: system32\DRIVERS\usbprint.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbscan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB Scanner Driver Image path: system32\DRIVERS\usbscan.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E

Control Set: Start: Type: Error Control:

CurrentControlSet 3 1 1

Service (registry key): USBSTOR Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB Mass Storage Driver Image path: system32\DRIVERS\USBSTOR.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbuhci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB Universal Host Controller Miniport Driver Image path: \SystemRoot\system32\drivers\usbuhci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbvideo Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB Video Device (WDM) Image path: System32\Drivers\usbvideo.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): UxSms Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\dwm.exe,-2000 Description: @%SystemRoot%\system32\dwm.exe,-2001 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): VaultSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\vaultsvc.dll,-1003 Description: @%SystemRoot%\system32\vaultsvc.dll,-1004 Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E

Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: rpcss Service (registry key): vdrvroot Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Virtual Drive Enumerator Driver Image path: system32\drivers\vdrvroot.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): vds Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\vds.exe,-100 Description: @%SystemRoot%\system32\vds.exe,-112 Object name: LocalSystem Image path: %SystemRoot%\System32\vds.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RpcSs,PlugPlay Service (registry key): vga Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\vgapnp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): VgaSave Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\drivers\vga.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): vhdmp Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\vhdmp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1

Service (registry key): viaide Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\viaide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 3 Service (registry key): volmgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Volume Manager Driver Image path: system32\drivers\volmgr.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): volmgrx Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\drivers\volmgrx.sys,-100 Description: @%SystemRoot%\system32\drivers\volmgrx.sys,-101 Image path: System32\drivers\volmgrx.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): volsnap Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Storage volumes Image path: system32\drivers\volsnap.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): vsmraid Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\vsmraid.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): VSS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\vssvc.exe,-102 Description: @%systemroot%\system32\vssvc.exe,-101 Object name: LocalSystem

Image path: %systemroot%\system32\vssvc.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): vwifibus Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Virtual WiFi Bus Driver Description: Virtual WiFi Bus Driver Image path: system32\DRIVERS\vwifibus.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): vwififlt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Virtual WiFi Filter Driver Description: Virtual WiFi Filter Driver Image path: system32\DRIVERS\vwififlt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): vwifimp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Virtual WiFi Miniport Service Image path: system32\DRIVERS\vwifimp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): W32Time Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\w32time.dll,-200 Description: @%SystemRoot%\system32\w32time.dll,-201 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): W3SVC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet

Start: 0 Type: 0 Error Control: 0 Service (registry key): WacomPen Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Wacom Serial Pen HID Driver Image path: \SystemRoot\system32\drivers\wacompen.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WANARP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32011 Description: @%systemroot%\system32\rascfg.dll,-32011 Image path: system32\DRIVERS\wanarp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Wanarpv6 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\rascfg.dll,-32012 Description: @%systemroot%\system32\rascfg.dll,-32012 Image path: system32\DRIVERS\wanarp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): WatAdminSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\Wat\WatUX.exe,-601 Description: @%SystemRoot%\system32\Wat\WatUX.exe,-602 Object name: LocalSystem Image path: %SystemRoot%\system32\Wat\WatAdminSvc.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): wbengine Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wbengine.exe,-104 Description: @%systemroot%\system32\wbengine.exe,-105 Object name: localSystem Image path: "%systemroot%\system32\wbengine.exe" Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E

Control Set: Start: Type: Error Control:

CurrentControlSet 3 16 1

Service (registry key): WbioSrvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wbiosrvc.dll,-100 Description: @%systemroot%\system32\wbiosrvc.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k WbioSvcGroup Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,VaultSvc,WUDFSvc Service (registry key): wcncsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\wcncsvc.dll,-3 Description: @%SystemRoot%\system32\wcncsvc.dll,-4 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonat ion Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: rpcss Service (registry key): WcsPlugInService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\WcsPlugInService.dll,-200 Description: @%SystemRoot%\system32\WcsPlugInService.dll,-201 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k wcssvc Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): Wd Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\system32\drivers\wd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Wdf01000 Registry path: \SYSTEM\CurrentControlSet\Services\

Display name: Image path: Image size: Image MD5: Control Set: Start: Type: Error Control:

Kernel Mode Driver Frameworks service system32\drivers\Wdf01000.sys 0 D41D8CD98F00B204E9800998ECF8427E CurrentControlSet 0 1 1

Service (registry key): WdiServiceHost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wdi.dll,-502 Description: @%systemroot%\system32\wdi.dll,-503 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): WdiSystemHost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wdi.dll,-500 Description: @%systemroot%\system32\wdi.dll,-501 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): WebClient Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\webclnt.dll,-100 Description: @%systemroot%\system32\webclnt.dll,-101 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: MRxDAV Service (registry key): Wecsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\wecsvc.dll,-200 Description: @%SystemRoot%\system32\wecsvc.dll,-201 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\system32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3

Type: 32 Error Control: 1 Depends On services: HTTP,Eventlog Service (registry key): wercplsupport Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\wercplsupport.dll,-101 Description: @%SystemRoot%\System32\wercplsupport.dll,-100 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): WerSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\wersvc.dll,-100 Description: @%SystemRoot%\System32\wersvc.dll,-101 Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k WerSvcGroup Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 0 Service (registry key): WfpLwf Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WFP Lightweight Filter Description: WFP Lightweight Filter Image path: system32\DRIVERS\wfplwf.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): WIMMount Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WIMMount Description: WIM Image mount service driver Image path: system32\drivers\wimmount.sys Image size: 19008 Image MD5: 5CF95B35E59E2A38023836FFF31BE64C Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): WinDefend Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 Description: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-1176 Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k secsvcs

Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): Windows Workflow Foundation 3.0.0.0 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): WinHttpAutoProxySvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\winhttp.dll,-100 Description: @%SystemRoot%\system32\winhttp.dll,-101 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Dhcp Service (registry key): Winmgmt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%Systemroot%\system32\wbem\wmisvc.dll,-205 Description: @%Systemroot%\system32\wbem\wmisvc.dll,-204 Object name: localSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RPCSS Service (registry key): WinRM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%Systemroot%\system32\wsmsvc.dll,-101 Description: @%Systemroot%\system32\wsmsvc.dll,-102 Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\System32\svchost.exe -k NetworkService Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS,HTTP Service (registry key): Winsock Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet

Start: 3 Type: 4 Error Control: 1 Service (registry key): WinSock2 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): WinUsb Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WinUsb Image path: system32\DRIVERS\WinUsb.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Wlansvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\wlansvc.dll,-257 Description: @%SystemRoot%\System32\wlansvc.dll,-258 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: nativewifip,RpcSs,Ndisuio,Eaphost Service (registry key): wlcrasvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Live Mesh remote connections service Description: @C:\Program Files\Windows Live\Mesh\WLRemoteServiceResource.dll, -102 Object name: LocalSystem Image path: "C:\Program Files\Windows Live\Mesh\wlcrasvc.exe" Image size: 57184 Image MD5: 06C8FA1CF39DE6A735B54D906BA791C6 Control Set: CurrentControlSet Start: 4 Type: 16 Error Control: 1 Service (registry key): wlidsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Live ID Sign-in Assistant Description: Enables Windows Live ID authentication. Object name: LocalSystem Image path: "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLI DSVC.EXE" Image size: 2286976 Image MD5: 7E47C328FC4768CB8BEAFBCFAFA70362

Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RpcSs Service (registry key): WmiAcpi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Windows Management Interface for ACPI Image path: \SystemRoot\system32\drivers\wmiacpi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WmiApRpl Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): wmiApSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 Description: @%Systemroot%\system32\wbem\wmiapsrv.exe,-111 Object name: localSystem Image path: %systemroot%\system32\wbem\WmiApSrv.exe Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): WMPNetworkSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 Description: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-102 Object name: NT AUTHORITY\NetworkService Image path: "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: http Service (registry key): WPCSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\wpcsvc.dll,-100 Description: @%SystemRoot%\system32\wpcsvc.dll,-101 Object name: NT Authority\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestrict ed Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866

Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): WPDBusEnum Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\wpdbusenum.dll,-100 Description: @%SystemRoot%\system32\wpdbusenum.dll,-101 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): ws2ifsl Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\System32\drivers\ws2ifsl.sys,-1000 Description: @%systemroot%\System32\drivers\ws2ifsl.sys,-1000 Image path: \SystemRoot\system32\drivers\ws2ifsl.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): wscsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\wscsvc.dll,-200 Description: @%SystemRoot%\System32\wscsvc.dll,-201 Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrict ed Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,WinMgmt Service (registry key): WSearch Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\SearchIndexer.exe,-103 Description: @%systemroot%\system32\SearchIndexer.exe,-104 Object name: LocalSystem Image path: %systemroot%\system32\SearchIndexer.exe /Embedding Image size: 427520 Image MD5: 236F286E103FD44BD85FDD93097FD5DD Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1

Depends On services: RPCSS Service (registry key): WSearchIdxPi Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): wuauserv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%systemroot%\system32\wuaueng.dll,-105 Description: @%systemroot%\system32\wuaueng.dll,-106 Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: rpcss Service (registry key): WudfPf Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: User Mode Driver Frameworks Platform Driver Image path: system32\drivers\WudfPf.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WUDFRd Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\WUDFRd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): wudfsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\system32\wudfsvc.dll,-1000 Description: @%SystemRoot%\system32\wudfsvc.dll,-1001 Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricte d Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: PlugPlay,WudfPf Service (registry key): WwanSvc

Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: @%SystemRoot%\System32\wwansvc.dll,-257 Description: @%SystemRoot%\System32\wwansvc.dll,-258 Object name: NT Authority\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork Image size: 20992 Image MD5: 54A47F6B5E09A77E61649109C6A08866 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: PlugPlay,RpcSs,NdisUio,NlaSvc Service (registry key): xmlprov Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {74B5C26A-06A3-4252-A7E0-5898B8A36F89} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {99DC9BFC-D06B-4541-A122-ED45C2DBD43F} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {AA5F4DAB-5398-497A-AA0C-BF293ABC9222} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): {D848A115-75AC-42F8-97E2-7EB76ABE2955} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0