Trojansk hest Dropper.Generic_c.MMI.
Windows 7 Home PremiumProcessor: AMD Athlon(tm)X2 Dual-Core QL-62 2.00 Ghz
Systemtype: 64-bit operativsystem
Min AVG Resident Shield popper hele tiden op med "Trussel detekteret!" og med følgende besked:
Filnavn: c:\Windows\System32\services.exe
Trusselnavn: Trojansh hest Dropper.Generic_c.MMI (mere info)
Detekteret ved åbning
Jeg kan ikke flytte den til 'vault', men kan kun ignorér truslen. Jeg har kørt følgende virusprogrammer, der alle finder forskellige trojanske heste, men som ikke kan fjerne dem:
- Malwarebytes - Anti malware
- AVG - Antivirus (free edition)
- Spybot
- Eset online scanner
Malvarebytes:
Siger efter mange scanninger (hvor den tidligere har fundet op til 9 trusler og forsøgt at fjerne dem), at der ingen trusler pt er på computeren.
AVG:
Popper op med ovenstående besked og efter scanning giver den følgende meddelelse:
"Objektnavn";"C:\Windows\System32\services.exe"
"Detekteringsnavn";"Trojansk hest Dropper.Generic_c.MMI"
"Objekttype";"fil"
"SDK-type";"Kerne"
"Resultat";"Objektet er hvidlistet (kritisk fil/systemfil, som ikke bør fjernes)"
"Hændelseshistorik";""
eller
Detektering af flere trusler:
- "c:\Windows\assembly\GAC_64\Desktop.ini";"Trojansk hest Generic28.ANIC";"Inficeret"
- "c:\Windows\assembly\GAC_64\Desktop.ini";"Trojansk hest Generic28.ANIC";"Inficeret"
- "c:\Windows\System32\services.exe";"Trojansk hest Dropper.Generic_c.MMI";"Objektet er hvidlistet (kritisk fil/systemfil, som ikke bør fjernes)"
--> her kan jeg så sige fjern valgte, hvorefter den nogle gange svarer, at filerne ikke kan fjernes eller, at det er nødvendigt at genstarte for at fjerne dem. Efter genstart dukker AVG-meddelelsen op igen om, at den har fundet ovenstående trusler.
Spybot:
--- Search result list ---
Babylon.Toolbar: [SBI $E0B59C7B] Class ID (Registreringsdatabasenøgle, fixing failed)
HKEY_CLASSES_ROOT\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
Babylon.Toolbar: [SBI $295D1CA8] Class ID (Registreringsdatabasenøgle, fixing failed)
HKEY_CLASSES_ROOT\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}
Babylon.Toolbar: [SBI $DEB52F26] Program mappe % 0D % 0A (Mappe, fixing failed)
C:\ProgramData\Babylon\
Babylon.Toolbar: [SBI $D1EDD9CA] Indstillinger (Registreringsdatabasenøgle, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Babylon
Babylon.Toolbar: [SBI $3BE29F71] Indstillinger (Registreringsdatabasenøgle, fixing failed)
HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}
Babylon.Toolbar: [SBI $3BE29F71] Indstillinger (Registreringsdatabasenøgle, fixing failed)
HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}
Babylon.Toolbar: [SBI $B04483F7] Rod klassificering (Registreringsdatabasenøgle, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Babylon.Toolbar: [SBI $B04483F7] Rod klassificering (Registreringsdatabasenøgle, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Babylon.Toolbar: [SBI $B04483F7] Class ID (Registreringsdatabasenøgle, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
Babylon.Toolbar: [SBI $B04483F7] Rod klassificering (Registreringsdatabasenøgle, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Babylon.Toolbar: [SBI $B04483F7] Rod klassificering (Registreringsdatabasenøgle, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
IWinGames: [SBI $8D161E83] Brugergrænseflade (Registreringsdatabasenøgle, fixing failed)
HKEY_CLASSES_ROOT\Interface\{E3ED53C5-7AD5-4DF5-9734-AFB6E7E5D9DB}
IWinGames: [SBI $8D161E83] Brugergrænseflade (Registreringsdatabasenøgle, fixing failed)
HKEY_CLASSES_ROOT\Interface\{E3ED53C5-7AD5-4DF5-9734-AFB6E7E5D9DB}
IWinGames: [SBI $FF593BF7] M mappe type (Registreringsdatabasenøgle, fixing failed)
HKEY_CLASSES_ROOT\TypeLib\{495874FE-4A82-4AD1-9476-0B957E0B95EB}
IWinGames: [SBI $FF593BF7] M mappe type (Registreringsdatabasenøgle, fixing failed)
HKEY_CLASSES_ROOT\TypeLib\{495874FE-4A82-4AD1-9476-0B957E0B95EB}
IWinGames: [SBI $E8B83F64] Indstillinger (Registreringsdatabasenøgle, fixing failed)
HKEY_USERS\.DEFAULT\Software\iWinArcade
IWinGames: [SBI $E8B83F64] Indstillinger (Registreringsdatabasenøgle, fixing failed)
HKEY_USERS\S-1-5-18\Software\iWinArcade
IWinGames: [SBI $3B64B144] Indstillinger (Registreringsdatabasenøgle, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\iWinArcade
iCrossRider: [SBI $C6832577] Indstillinger (Registrerings database værdi, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.crossrider.com
iCrossRider: [SBI $52E714A1] Indstillinger (Registrerings database værdi, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\New Windows\Allow\*.crossrider.com
iCrossRider: [SBI $52E714A1] Indstillinger (Registrerings database værdi, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\New Windows\Allow\*.crossrider.com
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-01-26 TeaTimer.exe (1.6.4.26)
2012-07-17 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-01-26 advcheck.dll (1.6.2.15)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2012-01-16 Includes\Adware.sbi (*)
2012-07-03 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-11-29 Includes\DialerC.sbi (*)
2012-01-31 Includes\HeavyDuty.sbi (*)
2012-06-19 Includes\Hijackers.sbi (*)
2012-05-16 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2012-03-13 Includes\Keyloggers.sbi (*)
2012-03-13 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2012-06-18 Includes\Malware.sbi (*)
2012-07-10 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2012-07-10 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-06-19 Includes\Security.sbi (*)
2011-12-13 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2012-01-17 Includes\Spyware.sbi (*)
2012-05-08 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2011-09-28 Includes\Trojans.sbi (*)
2012-07-06 Includes\TrojansC-02.sbi (*)
2012-07-06 Includes\TrojansC-03.sbi (*)
2012-07-10 Includes\TrojansC-04.sbi (*)
2012-07-05 Includes\TrojansC-05.sbi (*)
2012-07-10 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--- System information ---
Unknown Windows version 6.1 (Build: 7601) Service Pack 1 (6.1.7601)
--- Startup entries list ---
Located: HK_LM:Run, Adobe ARM
command: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
file: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
size: 843712
MD5: B8E421C0890356CD4A793D8A346D9096
Located: HK_LM:Run, AVG_TRAY
command: "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
file: C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
size: 2587008
MD5: 80956486306D1F546EDC1DD7FAE87F62
Located: HK_LM:Run, DivXUpdate
command: "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
file: C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
size: 1259376
MD5: 4EB0C6C3EF4D8885CF2B5D0062F31E44
Located: HK_LM:Run, Malwarebytes' Anti-Malware
command: "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
file: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
size: 462920
MD5: 84DB35F319E5B67838A4877C11748866
Located: HK_LM:Run, Mobile Connectivity Suite
command: "C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
file: C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe
size: 598016
MD5: A16EA57F424885DC42827386D43FE857
Located: HK_LM:Run, ROC_roc_dec12
command: "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
file: C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
file: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
size: 254696
MD5: 6E3245DF783E58375B3465F03274743E
Located: HK_LM:Run, TkBellExe
command: "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
file: c:\program files (x86)\real\realplayer\Update\realsched.exe
size: 296056
MD5: 8E53B67FA3816E854B07C5DC66E10730
Located: HK_CU:Run, DriverScanner
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: "C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe" delay 20000
file: C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe
size: 338808
MD5: 734933D4A949A455D1FA51CA78B3FCB0
Located: HK_CU:Run, msnmsgr
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
file: C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
size: 4280184
MD5: 24B1666FD14CC71C7B0679AC61625B90
Located: HK_CU:Run, Optimizer Pro
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
file: C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
size: 81912
MD5: 38C4B87861E6E748B7986E10DB49A7ED
Located: HK_CU:Run, RegistryBooster
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000
file: C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, Skype
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
file: C:\Program Files (x86)\Skype\Phone\Skype.exe
size: 17148552
MD5: B6080F3A1CA495190D1583C2202CAA61
Located: HK_CU:Run, Spotify Web Helper
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: "C:\Users\Bruger\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
file: C:\Users\Bruger\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
size: 1192664
MD5: E81DF366705E8ADE900E722BFEAFE0E6
Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
size: 2144088
MD5: 896A1DB9A972AD2339C2E8569EC926D1
Located: HK_CU:Run, Steam
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: "C:\Program Files (x86)\Steam\steam.exe" -silent
file: C:\Program Files (x86)\Steam\steam.exe
size: 1242448
MD5: 67384147DD005E54D2C0A20408E28579
Located: HK_CU:Run, swg
where: S-1-5-21-2189995665-1447193883-1847730144-1000...
command: "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
file: C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
size: 39408
MD5: 5D61BE7DB55B026A5D61A3EED09D0EAD
Located: Startup (bruger), OOo-dev 3.4.lnk
where: C:\Users\Bruger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup...
command: C:\Program Files (x86)\OOo-dev 3\program\quickstart.exe
file: C:\Program Files (x86)\OOo-dev 3\program\quickstart.exe
size: 1198592
MD5: 5983D03ACB98CCEB38FEBD3776BFFE3E
Located: Startup (bruger), OpenOffice.org 3.3.lnk
where: C:\Users\Bruger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup...
command: C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
file: C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
size: 1198592
MD5: F7DCE54077EE9D8A351C4B1FFA866EE7
--- Browser helper object list ---
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AcroIEHelperStub
CLSID name: Adobe PDF Link Helper
Path: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelperShim.dll
Short name: ACROIE~2.DLL
Date (created): 04-04-2012 07:53:56
Date (last access): 11-04-2012 21:15:06
Date (last write): 04-04-2012 07:53:56
Filesize: 63912
Attributes: archive
MD5: 60E5AF8B7B4140C711B050FAE5A3AB70
CRC32: E4411B75
Version: 10.1.3.23
{3049C3E9-B461-4BC5-8870-4C09146192CA} (RealPlayer Download and Record Plugin for Internet Explorer)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: RealPlayer Download and Record Plugin for Internet Explorer
Path: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\
Long name: rpbrowserrecordplugin.dll
Short name: RPBROW~1.DLL
Date (created): 10-06-2012 18:51:20
Date (last access): 10-06-2012 18:51:20
Date (last write): 10-06-2012 18:51:20
Filesize: 425680
Attributes: archive
MD5: 3DE544A34B868038BC704CEF76C40A09
CRC32: 56086E53
Version: 15.0.4.53
{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} (AVG Do Not Track)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AVG Do Not Track
CLSID name: AVG Do Not Track
Path: C:\Program Files (x86)\AVG\AVG2012\
Long name: avgdtiex.dll
Short name:
Date (created): 13-06-2012 03:47:44
Date (last access): 02-07-2012 16:08:08
Date (last write): 13-06-2012 03:47:44
Filesize: 937592
Attributes: archive
MD5: 258E3E0CCF74A7FA34D053E7ADEA5062
CRC32: 4880EC73
Version: 12.0.0.2187
{326E768D-4182-46FD-9C16-1449A49795F4} (Increase performance and video formats for your HTML5 <video>)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: Increase performance and video formats for your HTML5 <video>
CLSID name: DivX Plus Web Player HTML5 <video>
Path: C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\
Long name: DivXHTML5.dll
Short name: DIVXHT~1.DLL
Date (created): 12-12-2011 15:13:22
Date (last access): 12-04-2012 16:32:18
Date (last write): 12-12-2011 15:13:22
Filesize: 194432
Attributes: archive
MD5: BC8AB9AA21934B663A07F79F7EFA0123
CRC32: EBDB33B6
Version: 2.1.2.145
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (WormRadar.com IESiteBlocker.NavFilter)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: WormRadar.com IESiteBlocker.NavFilter
CLSID name: AVG Safe Search
Path: C:\Program Files (x86)\AVG\AVG2012\
Long name: avgssie.dll
Short name:
Date (created): 24-06-2012 04:12:06
Date (last access): 02-07-2012 16:08:10
Date (last write): 24-06-2012 04:12:06
Filesize: 1417336
Attributes: archive
MD5: 9FE93E05194427727A755032436533B3
CRC32: 331053F7
Version: 12.0.0.2191
{9030D464-4C02-4ABF-8ECC-5164760863C6} (Hjælp til logon til Windows Live ID)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Hjælp til logon til Windows Live ID
Path: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\
Long name: WindowsLiveLogin.dll
Short name: WINDOW~1.DLL
Date (created): 28-03-2011 20:35:06
Date (last access): 15-10-2011 17:52:02
Date (last write): 28-03-2011 20:35:06
Filesize: 441216
Attributes: archive
MD5: CF39A105CD553EED31E2255AFF4C6742
CRC32: 3D1149C5
Version: 7.250.4232.0
{99079a25-328f-4bd4-be04-00955acaa0a7} (Searchqu Toolbar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: Searchqu Toolbar
CLSID name: Searchqu Toolbar
Path: C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\
Long name: searchqudtx.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
info link: http://toolbar.google.com/
info source: TonyKlein
Path: C:\Program Files (x86)\Google\Google Toolbar\
Long name: GoogleToolbar_32.dll
Short name: GOOGLE~1.DLL
Date (created): 26-05-2011 15:50:30
Date (last access): 26-05-2011 15:50:30
Date (last write): 19-03-2012 22:13:04
Filesize: 192112
Attributes: archive
MD5: 5B97AB550022B2783894C558FA2E1310
CRC32: 66F3ED5B
Version: 7.3.2710.138
{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java(tm) Plug-In 2 SSV Helper
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 18-10-2011 19:05:34
Date (last access): 13-11-2011 13:08:54
Date (last write): 18-10-2011 19:05:34
Filesize: 42272
Attributes: archive
MD5: DC365B6E595683F67BC21A203432E336
CRC32: ADEC3F07
Version: 6.0.290.11
--- ActiveX list ---
{149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control)
DPF name:
CLSID name: SpinTop DRM Control
Installer:
Codebase: file:///C:/Program%20Files%20(x86)/Delicious%20-%20Emily's%20Taste%20of%20Fame/Images/stg_drm.ocx
Path: C:\Program Files (x86)\Farm Frenzy 3 - American Pie\Images\
Long name: stg_drm.ocx
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\Windows\Downloaded Program Files\swdir.inf
Codebase: http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
description: Macromedia ShockWave Flash Player 7
classification: Unknown
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\Windows\SysWow64\Adobe\Director\
Long name: SwDir.dll
Short name:
Date (created): 02-11-2011 11:53:06
Date (last access): 26-11-2011 22:54:24
Date (last write): 02-11-2011 11:53:06
Filesize: 279480
Attributes: archive
MD5: 3D370A2465AA3C09721FF34E3A0AF223
CRC32: 03BC2515
Version: 11.6.3.633
{74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player)
DPF name:
CLSID name: GameHouse Games Player
Installer: C:\Windows\Downloaded Program Files\GHGamesPlayer.inf
Codebase: http://www.shockwave.com/content/delicioustasteoffame/sis/gamehouseplayer.cab
Path: C:\Windows\Downloaded Program Files\
Long name: ghgamesplayer.dll
Short name: GHGAME~1.DLL
Date (created): 29-08-2007 16:14:10
Date (last access): 29-08-2007 16:14:10
Date (last write): 29-08-2007 16:14:10
Filesize: 147456
Attributes: archive
MD5: 4B6C008A17D64A10AADF1163CB3AA1EF
CRC32: 92D37B23
Version: 2.0.0.1
{7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control)
DPF name:
CLSID name: OnlineScanner Control
Installer: C:\Windows\Downloaded Program Files\OnlineScanner.inf
Codebase: http://download.eset.com/special/eos/OnlineScanner.cab
Path: C:\PROGRA~2\ESET\ESETON~1\
Long name: OnlineScanner.ocx
Short name: ONLINE~1.OCX
Date (created): 17-07-2012 10:16:38
Date (last access): 17-07-2012 10:16:38
Date (last write): 30-09-2011 09:28:08
Filesize: 3405744
Attributes: archive
MD5: 751EE920D6811584E5B1F0B153A5A4E2
CRC32: E2EE1C02
Version: 1.0.0.6583
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_29
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 29-05-2011 19:12:42
Date (last access): 03-10-2011 07:11:30
Date (last write): 03-10-2011 06:06:06
Filesize: 108320
Attributes: archive
MD5: F4AE1B6811B4E7B3F9B5C7F0FE76BBFC
CRC32: 0F37B160
Version: 6.0.290.11
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_22
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 29-05-2011 19:12:42
Date (last access): 03-10-2011 07:11:30
Date (last write): 03-10-2011 06:06:06
Filesize: 108320
Attributes: archive
MD5: F4AE1B6811B4E7B3F9B5C7F0FE76BBFC
CRC32: 0F37B160
Version: 6.0.290.11
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_29
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 29-05-2011 19:12:42
Date (last access): 03-10-2011 07:11:30
Date (last write): 03-10-2011 06:06:06
Filesize: 108320
Attributes: archive
MD5: F4AE1B6811B4E7B3F9B5C7F0FE76BBFC
CRC32: 0F37B160
Version: 6.0.290.11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_29
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: npjpi160_29.dll
Short name: NPJPI1~1.DLL
Date (created): 03-10-2011 03:37:54
Date (last access): 03-10-2011 07:11:40
Date (last write): 03-10-2011 06:06:12
Filesize: 141088
Attributes: archive
MD5: A8F3D654E83D928FBBD4714D2D54AB39
CRC32: A1FB5317
Version: 6.0.290.11
{CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control)
DPF name:
CLSID name: ArmHelper Control
Installer:
Codebase: file:///C:/Program%20Files%20(x86)/Delicious%20-%20Emily's%20Taste%20of%20Fame/Images/armhelper.ocx
Path:
Long name: ./Images/armhelper.ocx
{D27CDB6E-AE6D-11CF-96B8-444552440000} ()
DPF name:
CLSID name:
Installer: C:\Windows\Downloaded Program Files\CONFLICT.1\swflash.inf
Codebase: http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} ()
DPF name:
CLSID name:
Installer: C:\Windows\Downloaded Program Files\gp.inf
Codebase: http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
--- Process list ---
PID: 0 ( 0) [System]
PID: 2488 (1288) C:\Users\Bruger\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
size: 1192664
MD5: E81DF366705E8ADE900E722BFEAFE0E6
PID: 2640 (1288) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
size: 2144088
MD5: 896A1DB9A972AD2339C2E8569EC926D1
PID: 2748 (2712) C:\Program Files (x86)\OOo-dev 3\program\soffice.exe
size: 11593216
MD5: E31B5A583D5B4FF066BBE5770FD0C320
PID: 2756 (2732) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
size: 11322880
MD5: 11E8D8272FDBE213ADE3DAD91427CE35
PID: 2788 (2756) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
size: 11314688
MD5: 2337EC951C4AF6E1AF65D10BD9615BEB
PID: 2796 (2672) C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
size: 2587008
MD5: 80956486306D1F546EDC1DD7FAE87F62
PID: 2844 (2672) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
size: 254696
MD5: 6E3245DF783E58375B3465F03274743E
PID: 2864 (2672) C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe
size: 598016
MD5: A16EA57F424885DC42827386D43FE857
PID: 2156 (2748) C:\Program Files (x86)\OOo-dev 3\program\soffice.bin
size: 11585024
MD5: 512D9DED3C1B8259EA79D622285A86AD
PID: 2432 (2672) C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
size: 1259376
MD5: 4EB0C6C3EF4D8885CF2B5D0062F31E44
PID: 2496 (2672) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
size: 296056
MD5: 8E53B67FA3816E854B07C5DC66E10730
PID: 3024 ( 904) C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
size: 557056
MD5: EAD947DE0151F89AB968944F00BA1F0F
PID: 3712 ( 904) C:\Program Files (x86)\Common Files\Teleca Shared\logger.exe
size: 106496
MD5: CBA29D7C16A56A701C0B3D7A68D84128
PID: 4036 ( 904) C:\Program Files (x86)\Common Files\Teleca Shared\CapabilityManager.exe
size: 139264
MD5: 7646CB9C5A4FF8BA647E0912A3568C41
PID: 4180 (3024) C:\Program Files (x86)\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
size: 389120
MD5: D8717065908A46E08697F40310D75236
PID: 4212 ( 904) C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
size: 1011712
MD5: 147C73E395BE482C4554BDA774DFBBF7
PID: 4500 (4212) C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\DbgOut.exe
size: 356352
MD5: 960542EE21D995075E3FEAECA16D0686
PID: 4904 ( 904) C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
size: 462848
MD5: 5ADFCB35574F707B8DB81E2E26D529DA
PID: 4944 (4904) C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
size: 253952
MD5: 7FEDFF546879C6B31BA2D00B443F800C
PID: 4084 (1288) C:\Program Files (x86)\Internet Explorer\iexplore.exe
size: 748664
MD5: 34B01BBD8F00B6B9C9248DC4F1E3CD01
PID: 4392 (4084) C:\Program Files (x86)\Internet Explorer\iexplore.exe
size: 748664
MD5: 34B01BBD8F00B6B9C9248DC4F1E3CD01
PID: 3820 (4084) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
size: 307824
MD5: 7A6DFCE4B8033CCD303918FACCCA9588
PID: 956 ( 904) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.exe
size: 686280
MD5: 7317348C529B501C98330771F8109700
PID: 2852 (4084) C:\Program Files (x86)\Internet Explorer\iexplore.exe
size: 748664
MD5: 34B01BBD8F00B6B9C9248DC4F1E3CD01
PID: 3692 (1288) C:\Program Files (x86)\AVG\AVG2012\avgui.exe
size: 4368504
MD5: 0A527DA865EA7E91CABFACE9A9279022
PID: 5104 (4084) C:\Program Files (x86)\Internet Explorer\iexplore.exe
size: 748664
MD5: 34B01BBD8F00B6B9C9248DC4F1E3CD01
PID: 5168 (1288) C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 4 ( 0) System
PID: 264 ( 4) smss.exe
PID: 352 ( 340) avgrsa.exe
PID: 408 ( 400) csrss.exe
PID: 472 ( 352) avgcsrva.exe
PID: 516 ( 400) wininit.exe
size: 96256
PID: 552 ( 532) csrss.exe
PID: 716 ( 516) services.exe
PID: 748 ( 516) lsass.exe
PID: 756 ( 516) lsm.exe
PID: 812 ( 532) winlogon.exe
PID: 904 ( 716) svchost.exe
size: 20992
PID: 988 ( 716) svchost.exe
size: 20992
PID: 364 ( 716) atiesrxx.exe
PID: 372 ( 716) svchost.exe
size: 20992
PID: 752 ( 716) svchost.exe
size: 20992
PID: 1040 ( 716) svchost.exe
size: 20992
PID: 1104 ( 716) stacsv64.exe
PID: 1296 ( 716) svchost.exe
size: 20992
PID: 1356 ( 716) hpservice.exe
PID: 1412 ( 716) svchost.exe
size: 20992
PID: 1488 ( 364) atieclxx.exe
PID: 1556 ( 716) spoolsv.exe
PID: 1624 ( 716) svchost.exe
size: 20992
PID: 1716 ( 716) armsvc.exe
PID: 1788 ( 716) AESTSr64.exe
PID: 1832 ( 716) avgwdsvc.exe
PID: 1940 ( 716) NitroPDFReaderDriverService2x64.exe
PID: 1200 ( 752) C:\Windows\System32\dwm.exe
PID: 1288 (2000) C:\Windows\explorer.exe
size: 2871808
MD5: 332FEAB1435662FC6C672E25BEB37BE3
PID: 1508 ( 716) svchost.exe
size: 20992
PID: 1680 ( 716) svchost.exe
size: 20992
PID: 2092 ( 716) WLIDSVC.EXE
PID: 2204 ( 716) avgidsagent.exe
PID: 2312 (2092) WLIDSVCM.EXE
PID: 2372 (1288) C:\Program Files\IDT\WDM\sttray64.exe
size: 487424
MD5: 49EA3B1A7834A15B828E849C17DADEC5
PID: 2380 (1288) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
size: 2057000
MD5: 671951DA6AD104A0F7692F355289A5A1
PID: 2240 ( 716) SDWinSec.exe
PID: 3352 ( 716) SearchIndexer.exe
size: 427520
PID: 3380 (1832) avgnsa.exe
PID: 3400 (1832) avgemca.exe
PID: 3804 ( 716) svchost.exe
size: 20992
PID: 4368 (2380) SynTPHelper.exe
PID: 4664 ( 716) svchost.exe
size: 20992
PID: 2112 (4816) GoogleUpdate.exe
PID: 2828 ( 716) wmpnetwk.exe
PID: 4668 ( 904) C:\Windows\explorer.exe
size: 2871808
MD5: 332FEAB1435662FC6C672E25BEB37BE3
PID: 880 ( 904) C:\Windows\explorer.exe
size: 2871808
MD5: 332FEAB1435662FC6C672E25BEB37BE3
PID: 5352 (2852) OnlineCmdLineScanner.exe
PID: 3116 ( 552) conhost.exe
PID: 4308 (5352) OnlineCmdLineScanner.exe
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 17-07-2012 11:44:47
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\Windows\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://dk.msn.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://dk.msn.com/?ocid=OIE9HP
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\Windows\SysWOW64\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://search.searchonme.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896
--- Winsock Layered Service Provider list ---
Namespace Provider 1: Shim-provider til e-mail-navngivning
GUID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
Filename:
Namespace Provider 2: Provider til navneområde for PNRP-sky
GUID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
Filename:
Namespace Provider 3: Provider til navneområde for PNRP-navne
GUID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
Filename:
Namespace Provider 6: WindowsLive NSP
GUID: {4177DDE9-6028-479E-B7B7-03591A63FF3A}
Filename: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
Namespace Provider 7: WindowsLive Local NSP
GUID: {229F2A2C-5F18-4A06-8F89-3A372170624D}
Filename: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
--- Uninstall list ---
--- System Services ---
Service (registry key): .NET CLR Data
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET CLR Networking
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET CLR Networking 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET Data Provider for Oracle
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET Data Provider for SqlServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NETFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): 1394ohci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 OHCI-kompatibel værtscontroller
Image path: \SystemRoot\system32\drivers\1394ohci.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Accelerometer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: HP Mobile Data Protection Sensor
Image path: system32\DRIVERS\Accelerometer.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ACPI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft ACPI-driver
Image path: system32\drivers\ACPI.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3
Service (registry key): AcpiPmi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Driver til ACPI-strømmåler
Image path: \SystemRoot\system32\drivers\acpipmi.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): AdobeARMservice
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Adobe Acrobat Update Service
Description: Adobe Acrobat Updater holder din Adobe-software opdateret.
Object name: LocalSystem
Image path: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
Image size: 63928
Image MD5: 62B7936F9036DD6ED36E6A7EFA805DC0
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 0
Service (registry key): AdobeFlashPlayerUpdateSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Adobe Flash Player Update Service
Description: This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes.
Object name: LocalSystem
Image path: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Image size: 250056
Image MD5: 5E1A953C6472E7BB644892A4D0DF5E72
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): adp94xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\adp94xx.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): adpahci
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\adpahci.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): adpu320
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\adpu320.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): adsi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): AeLookupSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\aelupsvc.dll,-1
Description: @%SystemRoot%\system32\aelupsvc.dll,-2
Object name: localSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): AESTFilters
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Andrea ST Filters Service
Object name: LocalSystem
Image path: C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_471277d5d45019ea\AESTSr64.exe
Image size: 89600
Image MD5: A6FB9DB8F1A86861D955FD6975977AE0
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): AFD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\drivers\afd.sys,-1000
Description: @%systemroot%\system32\drivers\afd.sys,-1000
Image path: \SystemRoot\system32\drivers\afd.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): agp440
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Intel AGP-busfilter
Image path: \SystemRoot\system32\drivers\agp440.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ALG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\Alg.exe,-112
Description: @%SystemRoot%\system32\Alg.exe,-113
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\alg.exe
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): aliide
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\drivers\aliide.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 3
Service (registry key): AMD External Events Utility
Registry path: \SYSTEM\CurrentControlSet\Services\
Object name: LocalSystem
Image path: %SystemRoot%\system32\atiesrxx.exe
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): amdide
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\drivers\amdide.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 3
Service (registry key): AmdK8
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AMD K8 Processor Driver
Image path: \SystemRoot\system32\DRIVERS\amdk8.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): amdkmdag
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\atikmdag.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): amdkmdap
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\atikmpag.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): AmdPPM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Driver til AMD-processor
Image path: system32\DRIVERS\amdppm.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): amdsata
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\drivers\amdsata.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): amdsbs
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\amdsbs.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): amdxata
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\drivers\amdxata.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): amd_sata
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\amd_sata.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): amd_xata
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\amd_xata.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): AppID
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\appidsvc.dll,-102
Description: @%systemroot%\system32\appidsvc.dll,-103
Image path: \SystemRoot\system32\drivers\appid.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: FltMgr,DisCache
Service (registry key): AppIDSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\appidsvc.dll,-100
Description: @%systemroot%\system32\appidsvc.dll,-101
Object name: NT Authority\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,AppID,CryptSvc
Service (registry key): Appinfo
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\appinfo.dll,-100
Description: @%systemroot%\system32\appinfo.dll,-101
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,ProfSvc
Service (registry key): AppMgmt
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): arc
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\arc.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): arcsas
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\arcsas.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): AsyncMac
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\rascfg.dll,-32000
Description: @%systemroot%\system32\rascfg.dll,-32000
Image path: system32\DRIVERS\asyncmac.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): atapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IDE-kanal
Image path: system32\drivers\atapi.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3
Service (registry key): athr
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Atheros Extensible Wireless LAN device driver
Image path: system32\DRIVERS\athrx.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Atierecord
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): AtiHDAudioService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ATI Function Driver for HD Audio Service
Image path: system32\drivers\AtihdW76.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): atikmdag
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\atikmdag.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): AudioEndpointBuilder
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\audiosrv.dll,-204
Description: @%SystemRoot%\System32\audiosrv.dll,-205
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay
Service (registry key): AudioSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\audiosrv.dll,-200
Description: @%SystemRoot%\System32\audiosrv.dll,-201
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: AudioEndpointBuilder,RpcSs,MMCSS
Service (registry key): Avg
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): AVGIDSAgent
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVGIDSAgent
Description: Giver identitetsbeskyttelse mod kriminalitet på nettet.
Object name: LocalSystem
Image path: "C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe"
Image size: 5160568
Image MD5: D67719BCFDE5798F5C30D14EFED3BCAF
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Depends On services: AVGIDSDriver
Service (registry key): AVGIDSDriver
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVGIDSDriver
Description: AVG Technologies IDS Application Activity Monitor Driver
Image path: system32\DRIVERS\avgidsdrivera.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: AVGIDSFilter
Service (registry key): AVGIDSFilter
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVGIDSFilter
Description: AVG Technologies IDS Application Activity Monitor Filter Driver
Image path: system32\DRIVERS\avgidsfiltera.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): AVGIDSHA
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVGIDSHA
Description: AVG Technologies IDS Application Activity Monitor Helper Driver
Image path: system32\DRIVERS\avgidsha.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): Avgldx64
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG AVI Loader Driver
Image path: system32\DRIVERS\avgldx64.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): Avgmfx64
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG Mini-Filter Resident Anti-Virus Shield
Image path: system32\DRIVERS\avgmfx64.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Depends On services: FltMgr
Service (registry key): Avgrkx64
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG Anti-Rootkit Driver
Image path: system32\DRIVERS\avgrkx64.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 2
Error Control: 1
Service (registry key): Avgtdia
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG TDI Driver
Image path: system32\DRIVERS\avgtdia.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): avgwd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG WatchDog
Description: AVG Watchdog-service
Object name: LocalSystem
Image path: "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe"
Image size: 193288
Image MD5: EA1145DEBCD508FD25BD1E95C4346929
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): AxInstSV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\AxInstSV.dll,-103
Description: @%SystemRoot%\system32\AxInstSV.dll,-104
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: rpcss
Service (registry key): b06bdrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Broadcom NetXtreme II VBD
Image path: \SystemRoot\system32\DRIVERS\bxvbda.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): b57nd60a
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
Image path: system32\DRIVERS\b57nd60a.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BattC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): BDESVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\bdesvc.dll,-100
Description: @%SystemRoot%\system32\bdesvc.dll,-101
Object name: localSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): Beep
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Beep
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): BFE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\bfe.dll,-1001
Description: @%SystemRoot%\system32\bfe.dll,-1002
Object name: NT AUTHORITY\LocalService
Image path: %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): BITS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\qmgr.dll,-1000
Description: @%SystemRoot%\system32\qmgr.dll,-1001
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,EventSystem
Service (registry key): blbdrive
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\blbdrive.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): bowser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\browser.dll,-102
Description: @%systemroot%\system32\browser.dll,-103
Image path: system32\DRIVERS\bowser.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 2
Error Control: 1
Service (registry key): BrFiltLo
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Brother USB Mass-Storage Lower Filter Driver
Image path: \SystemRoot\system32\DRIVERS\BrFiltLo.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BrFiltUp
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Brother USB Mass-Storage Upper Filter Driver
Image path: \SystemRoot\system32\DRIVERS\BrFiltUp.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BridgeMP
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\bridgeres.dll,-1
Image path: system32\DRIVERS\bridge.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Browser
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\browser.dll,-100
Description: @%systemroot%\system32\browser.dll,-101
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: LanmanWorkstation,LanmanServer
Service (registry key): Brserid
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Brother MFC Serial Port Interface Driver (WDM)
Image path: \SystemRoot\System32\Drivers\Brserid.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BrSerWdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Brother WDM Serial driver
Image path: \SystemRoot\System32\Drivers\BrSerWdm.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BrUsbMdm
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Brother MFC USB Fax Only Modem
Image path: \SystemRoot\System32\Drivers\BrUsbMdm.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BrUsbSer
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Brother MFC USB Serial WDM Driver
Image path: \SystemRoot\System32\Drivers\BrUsbSer.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BTHMODEM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Bluetooth Serial Communications Driver
Image path: \SystemRoot\system32\DRIVERS\bthmodem.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BTHPORT
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): bthserv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\System32\bthserv.dll,-101
Description: @%SystemRoot%\System32\bthserv.dll,-102
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k bthsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): cdfs
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: CD/DVD File System Reader
Description: ISO9660/Joliet File System Reader for CD/DVDs. (Core) (All pieces)
Image path: system32\DRIVERS\cdfs.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 4
Type: 2
Error Control: 1
Depends On group: "SCSI CDROM Class"
Service (registry key): cdrom
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Cd-rom-driver
Image path: \SystemRoot\system32\drivers\cdrom.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): CertPropSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\System32\certprop.dll,-11
Description: @%SystemRoot%\System32\certprop.dll,-12
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): circlass
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: IR-brugerenheder
Image path: system32\DRIVERS\circlass.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): CLFS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\clfs.sys,-100
Description: @%SystemRoot%\system32\clfs.sys,-101
Image path: System32\CLFS.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3
Service (registry key): clr_optimization_v2.0.50727_32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft .NET Framework NGEN v2.0.50727_X86
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: %systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
Image size: 66384
Image MD5: D88040F816FDA31C3B466F0FA0918F29
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 0
Service (registry key): clr_optimization_v2.0.50727_64
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft .NET Framework NGEN v2.0.50727_X64
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: %systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
Image size: 89920
Image MD5: D1CEEA2B47CB998321C579651CE3E4F8
Control Set: CurrentControlSet
Start: 4
Type: 16
Error Control: 0
Service (registry key): clr_optimization_v4.0.30319_32
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft .NET Framework NGEN v4.0.30319_X86
Description: Microsoft .NET Framework NGEN
Object name: LocalSystem
Image path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
Image size: 130384