Well, I'm sending you these entries, because I'm sure something is wrong, I see several repeated services that have strange names and also the software shows very old program dates
Like 1905, I'm worried, I'll be sending the AutoRuns file and a Hijackthis log.
Dont find how to upload lol
This is do a System Scan and save a Log
Spoiler
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 4:48:37 AM, on 10/23/2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17763.0771)
Boot mode: Normal
Running processes:
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Doido\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKCU\..\Run: [Discord] C:\Users\Doido\AppData\Local\Discord\app-0.0.305\Discord.exe
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
--
End of file - 3322 bytes
Scan saved at 4:48:37 AM, on 10/23/2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17763.0771)
Boot mode: Normal
Running processes:
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Doido\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKCU\..\Run: [Discord] C:\Users\Doido\AppData\Local\Discord\app-0.0.305\Discord.exe
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
--
End of file - 3322 bytes
And this its from Startuplist
Spoiler
StartupList report, 10/23/2019, 5:26:05 AM
StartupList version: 1.52.2
Started from : C:\Users\Doido\Desktop\HijackThis.EXE
Detected: Unknown Windows (WinNT 6.02.1008)
Detected: Internet Explorer v11.0 (11.00.17763.0771)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================
Running processes:
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Doido\Desktop\HijackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Users\Doido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
*No files*
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
*No files*
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Discord = C:\Users\Doido\AppData\Local\Discord\app-0.0.305\Discord.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" /S
--------------------------------------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
*Registry value not found*
--------------------------------------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = %SystemRoot%\system32\unregmp2.exe /ShowWMP
[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = %SystemRoot%\system32\unregmp2.exe /FirstLogon
[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
--------------------------------------------------
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps
*Registry key not found*
--------------------------------------------------
Load/Run keys from C:\Windows\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=
--------------------------------------------------
Shell & screensaver key from C:\Windows\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Checking for EXPLORER.EXE instances:
C:\Windows\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\Windows\Explorer\Explorer.exe: not present
C:\Windows\System\Explorer.exe: not present
C:\Windows\System32\Explorer.exe: not present
C:\Windows\Command\Explorer.exe: not present
C:\Windows\Fonts\Explorer.exe: not present
--------------------------------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: *Registry key not found*
.shb: *Registry key not found*
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------------------------------
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\Windows
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename NOT OK: 'REGEDIT.EXE.MUI'
- File description: 'Registry Editor'
Registry check failed!
--------------------------------------------------
Enumerating Browser Helper Objects:
*No BHO's found*
--------------------------------------------------
Enumerating Task Scheduler jobs:
*No jobs found*
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\Windows\system32\napinsp.dll
NameSpace #2: C:\Windows\System32\mswsock.dll
NameSpace #3: C:\Windows\System32\winrnr.dll
NameSpace #4: C:\Windows\system32\NLAapi.dll
NameSpace #5: C:\Windows\system32\wshbth.dll
Protocol #1: C:\Windows\system32\mswsock.dll
Protocol #2: C:\Windows\system32\mswsock.dll
Protocol #3: C:\Windows\system32\mswsock.dll
Protocol #4: C:\Windows\system32\mswsock.dll
Protocol #5: C:\Windows\system32\mswsock.dll
Protocol #6: C:\Windows\system32\mswsock.dll
Protocol #7: C:\Windows\system32\mswsock.dll
Protocol #8: C:\Windows\system32\mswsock.dll
Protocol #9: C:\Windows\system32\mswsock.dll
Protocol #10: C:\Windows\system32\mswsock.dll
Protocol #11: C:\Windows\system32\mswsock.dll
--------------------------------------------------
Enumerating Windows NT/2000/XP services
3ware: System32\drivers\3ware.sys (system)
@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver: System32\drivers\ACPI.sys (system)
@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver: \SystemRoot\System32\drivers\AcpiDev.sys (manual start)
Microsoft ACPIEx Driver: System32\Drivers\acpiex.sys (system)
@acpipagr.inf,%SvcDesc%;ACPI Processor Aggregator Driver: \SystemRoot\System32\drivers\acpipagr.sys (manual start)
@acpipmi.inf,%AcpiPmi.SvcDesc%;ACPI Power Meter Driver: \SystemRoot\System32\drivers\acpipmi.sys (manual start)
@acpitime.inf,%AcpiTime.SvcDesc%;ACPI Wake Alarm Driver: \SystemRoot\System32\drivers\acpitime.sys (manual start)
Adobe Flash Player Update Service: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (manual start)
ADP80XX: System32\drivers\ADP80XX.SYS (system)
@%systemroot%\system32\drivers\afd.sys,-1000: \SystemRoot\system32\drivers\afd.sys (system)
afunix: \SystemRoot\system32\drivers\afunix.sys (system)
@%systemroot%\system32\drivers\ahcache.sys,-102: system32\DRIVERS\ahcache.sys (system)
@%SystemRoot%\system32\Alg.exe,-112: %SystemRoot%\System32\alg.exe (manual start)
@cpu.inf,%AmdK8.SvcDesc%;AMD K8 Processor Driver: \SystemRoot\System32\drivers\amdk8.sys (manual start)
@cpu.inf,%AmdPPM.SvcDesc%;AMD Processor Driver: \SystemRoot\System32\drivers\amdppm.sys (manual start)
amdsata: System32\drivers\amdsata.sys (system)
amdsbs: System32\drivers\amdsbs.sys (system)
amdxata: System32\drivers\amdxata.sys (system)
ammntdrv: \??\C:\Windows\System32\ammntdrv.sys (autostart)
amwrtdrv: \??\C:\Windows\System32\amwrtdrv.sys (autostart)
@%systemroot%\system32\srpapi.dll,-100: system32\drivers\appid.sys (manual start)
@%systemroot%\system32\appidsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%systemroot%\system32\appinfo.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@%systemroot%\system32\srpapi.dll,-102: system32\drivers\applockerfltr.sys (manual start)
@appmgmts.dll,-3250: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\System32\AppReadiness.dll,-1000: %SystemRoot%\System32\svchost.exe -k AppReadiness -p (manual start)
@%SystemRoot%\system32\appxdeploymentserver.dll,-1: %systemroot%\system32\svchost.exe -k wsappx -p (disabled)
@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver: System32\drivers\arcsas.sys (system)
@%systemroot%\system32\mprmsg.dll,-32000: \SystemRoot\System32\drivers\asyncmac.sys (manual start)
@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel: System32\drivers\atapi.sys (system)
@%SystemRoot%\system32\AudioEndpointBuilder.dll,-204: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (autostart)
@%SystemRoot%\system32\audiosrv.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p (autostart)
@netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD: System32\drivers\bxvbda.sys (system)
@%SystemRoot%\system32\drivers\bam.sys,-100: system32\drivers\bam.sys (system)
BasicDisplay: \SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_5103ac179273be89\BasicDisplay.sys (system)
BasicRender: \SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_0b8d03c3bc0e7fd9\BasicRender.sys (system)
@bcmfn2.inf,%bcmfn2.SVCDESC%;bcmfn2 Service: \SystemRoot\System32\drivers\bcmfn2.sys (manual start)
@%SystemRoot%\system32\bfe.dll,-1001: %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p (autostart)
@%SystemRoot%\system32\qmgr.dll,-1000: %SystemRoot%\System32\svchost.exe -k netsvcs -p (disabled)
@%SystemRoot%\system32\Microsoft.Bluetooth.UserService.dll,-101: %SystemRoot%\system32\svchost.exe -k BthAppGroup -p (disabled)
Bluetooth User Support Service_21363: C:\Windows\system32\svchost.exe -k BthAppGroup -p (disabled)
@%systemroot%\system32\wkssvc.dll,-2001: system32\DRIVERS\bowser.sys (manual start)
@%windir%\system32\bisrv.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%SystemRoot%\system32\BTAGService.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted (manual start)
@%SystemRoot%\system32\BthAvctpSvc.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalService -p (manual start)
@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service: \SystemRoot\System32\drivers\BthEnum.sys (manual start)
@bthhfenum.inf,%BthHFEnum.SVCDESC%;Bluetooth Hands-Free Audio Profile: \SystemRoot\System32\drivers\bthhfenum.sys (manual start)
@BthLEEnum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver: \SystemRoot\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys (manual start)
@bth.inf,%BTHMINI.SvcDesc%;Bluetooth Radio Driver: \SystemRoot\System32\drivers\BTHMINI.sys (manual start)
@mdmbtmdm.inf,%BthModem.DisplayName%;Bluetooth Modem Communications Driver: \SystemRoot\System32\drivers\bthmodem.sys (manual start)
@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver: \SystemRoot\System32\drivers\BTHport.sys (manual start)
@%SystemRoot%\System32\bthserv.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalService -p (manual start)
@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver: \SystemRoot\System32\drivers\BTHUSB.sys (manual start)
@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices: \SystemRoot\System32\drivers\buttonconverter.sys (manual start)
@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver: \SystemRoot\System32\drivers\CAD.sys (manual start)
@%SystemRoot%\system32\CapabilityAccessManager.dll,-1: %SystemRoot%\system32\svchost.exe -k appmodel -p (manual start)
@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen: \SystemRoot\System32\drivers\capimg.sys (manual start)
CD/DVD File System Reader: system32\DRIVERS\cdfs.sys (disabled)
@%SystemRoot%\system32\cdpusersvc.dll,-100: %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup (autostart)
Connected Devices Platform User Service_21363: C:\Windows\system32\svchost.exe -k UnistackSvcGroup (autostart)
@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver: \SystemRoot\System32\drivers\cdrom.sys (system)
@%SystemRoot%\System32\certprop.dll,-11: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
cht4iscsi: System32\drivers\cht4sx64.sys (system)
@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver: \SystemRoot\System32\drivers\cht4vx64.sys (manual start)
@circlass.inf,%circlass.SVCDESC%;Consumer IR Devices: \SystemRoot\System32\drivers\circlass.sys (manual start)
@%SystemRoot%\system32\drivers\clfs.sys,-100: System32\drivers\CLFS.sys (system)
@%SystemRoot%\system32\ClipSVC.dll,-103: %SystemRoot%\System32\svchost.exe -k wsappx -p (manual start)
@cmbatt.inf,%CmBatt.SvcDesc%;Microsoft ACPI Control Method Battery Driver: \SystemRoot\System32\drivers\CmBatt.sys (manual start)
CNG: System32\Drivers\cng.sys (system)
@%SystemRoot%\system32\drivers\cnghwassist.sys,-100: System32\DRIVERS\cnghwassist.sys (disabled)
@compositebus.inf,%CompositeBus.SVCDESC%;Composite Bus Enumerator Driver: \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_e4d35af746093dc3\CompositeBus.sys (manual start)
@comres.dll,-947: %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Console Driver: System32\drivers\condrv.sys (manual start)
@%SystemRoot%\system32\ConsentUxClient.dll,-100: %SystemRoot%\system32\svchost.exe -k DevicesFlow (manual start)
ConsentUX_21363: C:\Windows\system32\svchost.exe -k DevicesFlow (manual start)
@%SystemRoot%\system32\coremessaging.dll,-1: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p (autostart)
@%SystemRoot%\system32\cryptsvc.dll,-1001: %SystemRoot%\system32\svchost.exe -k NetworkService -p (manual start)
@%SystemRoot%\system32\drivers\dam.sys,-100: system32\drivers\dam.sys (system)
@combase.dll,-5012: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%SystemRoot%\system32\das.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%SystemRoot%\system32\umpnpmgr.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (manual start)
@%SystemRoot%\system32\Windows.Devices.Picker.dll,-1006: %SystemRoot%\system32\svchost.exe -k DevicesFlow (manual start)
DevicePicker_21363: C:\Windows\system32\svchost.exe -k DevicesFlow (manual start)
@%SystemRoot%\system32\DevicesFlowBroker.dll,-103: %SystemRoot%\system32\svchost.exe -k DevicesFlow (manual start)
DevicesFlow_21363: C:\Windows\system32\svchost.exe -k DevicesFlow (manual start)
@%systemroot%\system32\wkssvc.dll,-1008: System32\Drivers\dfsc.sys (system)
@oem34.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.): \SystemRoot\system32\DRIVERS\ssudbus.sys (manual start)
@%SystemRoot%\system32\dhcpcore.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (autostart)
@disk.inf,%disk_ServiceDesc%;Disk Driver: System32\drivers\disk.sys (system)
@%systemroot%\system32\Windows.Internal.Management.dll,-100: %systemroot%\system32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\System32\dnsapi.dll,-101: %SystemRoot%\system32\svchost.exe -k NetworkService -p (autostart)
@%systemroot%\system32\dot3svc.dll,-1102: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@wdmaudio.inf,%drmkaud.SvcDesc%;Microsoft Trusted Audio Drivers: \SystemRoot\System32\drivers\drmkaud.sys (manual start)
@%SystemRoot%\system32\DeviceSetupManager.dll,-1000: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
LDDM Graphics Subsystem: \SystemRoot\System32\drivers\dxgkrnl.sys (system)
@oem2.inf,%e1dExpress.Service.DispName%;Intel® PRO/1000 PCI Express Network Connection Driver D: \SystemRoot\system32\DRIVERS\e1d65x64.sys (manual start)
@%systemroot%\system32\eapsvc.dll,-1: %SystemRoot%\System32\svchost.exe -k netsvcs -p (manual start)
EasyAntiCheat: "C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe" (manual start)
@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD: System32\drivers\evbda.sys (system)
@%SystemRoot%\system32\efssvc.dll,-100: %SystemRoot%\System32\lsass.exe (manual start)
@EnterpriseAppMgmtSvc.dll,-1: %systemroot%\system32\svchost.exe -k appmodel -p (manual start)
@errdev.inf,%ERRDEV.SvcDesc%;Microsoft Hardware Error Device Driver: \SystemRoot\System32\drivers\errdev.sys (manual start)
esihdrv: \??\C:\Users\Doido\AppData\Local\Temp\esihdrv.sys (disabled)
@%SystemRoot%\system32\wevtsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p (autostart)
@comres.dll,-2450: %SystemRoot%\system32\svchost.exe -k LocalService -p (autostart)
@%systemroot%\system32\fdPHost.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService -p (manual start)
@%systemroot%\system32\fdrespub.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p (manual start)
@%systemroot%\system32\drivers\filecrypt.sys,-100: system32\drivers\filecrypt.sys (system)
@%SystemRoot%\system32\drivers\fileinfo.sys,-100: System32\drivers\fileinfo.sys (system)
@%SystemRoot%\system32\drivers\filetrace.sys,-10001: system32\drivers\filetrace.sys (manual start)
@oem5.inf,%FiraDiskService%;FiraDisk Driver: System32\drivers\firadisk.sys (system)
@%SystemRoot%\system32\drivers\fltmgr.sys,-10001: system32\drivers\fltmgr.sys (system)
@%systemroot%\system32\FntCache.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService -p (autostart)
@%SystemRoot%\system32\drivers\fsdepends.sys,-10001: System32\drivers\FsDepends.sys (manual start)
@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class: \SystemRoot\System32\drivers\genericusbfn.sys (manual start)
Microsoft GPIO Class Extension Driver: System32\Drivers\msgpioclx.sys (manual start)
@gpapi.dll,-112: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100: System32\drivers\gpuenergydrv.sys (system)
@hdaudio.inf,યunctionDriverForHdAudio.SvcDesc%;Microsoft 1.1 UAA Function Driver for High Definition Audio Service: \SystemRoot\system32\DRIVERS\HdAudio.sys (manual start)
@hdaudbus.inf,%HDAudBus.SVCDESC%;Microsoft UAA Bus Driver for High Definition Audio: \SystemRoot\System32\drivers\HDAudBus.sys (manual start)
@hidbatt.inf,%HidBatt.SvcDesc%;HID UPS Battery Driver: \SystemRoot\System32\drivers\HidBatt.sys (manual start)
@hidbth.inf,%HIDBTH.SvcDesc%;Microsoft Bluetooth HID Miniport: \SystemRoot\System32\drivers\hidbth.sys (manual start)
@hidi2c.inf,%hidi2c.SVCDESC%;Microsoft I2C HID Miniport Driver: \SystemRoot\System32\drivers\hidi2c.sys (manual start)
@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts: \SystemRoot\System32\drivers\hidinterrupt.sys (manual start)
@hidir.inf,%HIDIR.SvcDesc%;Microsoft Infrared HID Driver: \SystemRoot\System32\drivers\hidir.sys (manual start)
@%SystemRoot%\System32\hidserv.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (disabled)
@hidspi_km.inf,%hidspi.SVCDESC%;Microsoft SPI HID Miniport Driver: \SystemRoot\System32\drivers\hidspi.sys (manual start)
@input.inf,%HID.SvcDesc%;Microsoft HID Class Driver: \SystemRoot\System32\drivers\hidusb.sys (manual start)
HpSAMD: System32\drivers\HpSAMD.sys (system)
@%SystemRoot%\system32\drivers\http.sys,-1: system32\drivers\HTTP.sys (manual start)
Microsoft Hardware Notifications Class Extension Driver: System32\Drivers\mshwnclx.sys (manual start)
@%systemroot%\system32\drivers\hwpolicy.sys,-101: System32\drivers\hwpolicy.sys (system)
@keyboard.inf,%i8042prt.SvcDesc%;i8042 Keyboard and PS/2 Mouse Port Driver: \SystemRoot\System32\drivers\i8042prt.sys (manual start)
@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver: \SystemRoot\System32\drivers\iagpio.sys (manual start)
@iai2c.inf,%iai2c.SVCDESC%;Intel® Serial IO I2C Host Controller: \SystemRoot\System32\drivers\iai2c.sys (manual start)
@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel® Serial IO GPIO Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_GPIO2.sys (manual start)
@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel® Serial IO GPIO Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys (manual start)
@iaLPSS2i_GPIO2_CNL.inf,%iaLPSS2i_GPIO2_CNL.SVCDESC%;Intel® Serial IO GPIO Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_GPIO2_CNL.sys (manual start)
@iaLPSS2i_GPIO2_GLK.inf,%iaLPSS2i_GPIO2_GLK.SVCDESC%;Intel® Serial IO GPIO Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_GPIO2_GLK.sys (manual start)
@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel® Serial IO I2C Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_I2C.sys (manual start)
@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel® Serial IO I2C Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_I2C_BXT_P.sys (manual start)
@iaLPSS2i_I2C_CNL.inf,%iaLPSS2i_I2C_CNL.SVCDESC%;Intel® Serial IO I2C Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_I2C_CNL.sys (manual start)
@iaLPSS2i_I2C_GLK.inf,%iaLPSS2i_I2C_GLK.SVCDESC%;Intel® Serial IO I2C Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_I2C_GLK.sys (manual start)
@ialpssi_gpio.inf,%iaLPSSi_GPIO.SVCDESC%;Intel® Serial IO GPIO Controller Driver: \SystemRoot\System32\drivers\iaLPSSi_GPIO.sys (manual start)
@ialpssi_i2c.inf,%iaLPSSi_I2C.SVCDESC%;Intel® Serial IO I2C Controller Driver: \SystemRoot\System32\drivers\iaLPSSi_I2C.sys (manual start)
@oem0.inf,%iaStorAC.DeviceDesc%;Intel® Chipset SATA/PCIe RST Premium Controller: System32\drivers\iaStorAC.sys (system)
@iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller: System32\drivers\iaStorAVC.sys (system)
@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7: System32\drivers\iaStorV.sys (system)
@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver): \SystemRoot\System32\drivers\ibbus.sys (manual start)
@%SystemRoot%\System32\tetheringservice.dll,-4097: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%SystemRoot%\system32\ikeext.dll,-501: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100: \SystemRoot\System32\drivers\IndirectKmd.sys (manual start)
intelide: System32\drivers\intelide.sys (system)
@intelpep.inf,%INTELPEP.SVCDESC%;Intel® Power Engine Plug-in Driver: System32\drivers\intelpep.sys (system)
@cpu.inf,%IntelPPM.SvcDesc%;Intel Processor Driver: \SystemRoot\System32\drivers\intelppm.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32013: system32\DRIVERS\ipfltdrv.sys (manual start)
@%SystemRoot%\system32\iphlpsvc.dll,-500: %SystemRoot%\System32\svchost.exe -k NetSvcs -p (autostart)
IPMIDRV: \SystemRoot\System32\drivers\IPMIDrv.sys (manual start)
IP Network Address Translator: System32\drivers\ipnat.sys (manual start)
IPT: \SystemRoot\System32\drivers\ipt.sys (manual start)
@%Systemroot%\system32\ipxlatcfg.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
IrDA: \SystemRoot\system32\drivers\irda.sys (manual start)
@%SystemRoot%\system32\drivers\irenum.sys,-100: system32\drivers\irenum.sys (manual start)
@%SystemRoot%\System32\irmon.dll,-2000: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
isapnp: System32\drivers\isapnp.sys (system)
@iscsi.inf,%iScsiPortName%;iScsiPort Driver: \SystemRoot\System32\drivers\msiscsi.sys (manual start)
ItSas35i: System32\drivers\ItSas35i.sys (system)
@keyboard.inf,%kbdclass.SvcDesc%;Keyboard Class Driver: \SystemRoot\System32\drivers\kbdclass.sys (manual start)
@keyboard.inf,%KBDHID.SvcDesc%;Keyboard HID Driver: \SystemRoot\System32\drivers\kbdhid.sys (manual start)
@keyiso.dll,-100: %SystemRoot%\system32\lsass.exe (manual start)
KSecDD: System32\Drivers\ksecdd.sys (system)
KSecPkg: System32\Drivers\ksecpkg.sys (system)
Kernel Streaming Thunks: \SystemRoot\system32\drivers\ksthunk.sys (manual start)
@comres.dll,-2946: %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p (manual start)
@%systemroot%\system32\srvsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (disabled)
@%systemroot%\system32\wkssvc.dll,-100: %SystemRoot%\System32\svchost.exe -k NetworkService -p (disabled)
@%SystemRoot%\system32\licensemanagersvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalService -p (manual start)
@%SystemRoot%\system32\lmhsvc.dll,-101: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p (disabled)
LSI_SAS: System32\drivers\lsi_sas.sys (system)
LSI_SAS2i: System32\drivers\lsi_sas2i.sys (system)
LSI_SAS3i: System32\drivers\lsi_sas3i.sys (system)
LSI_SSS: System32\drivers\lsi_sss.sys (system)
@%windir%\system32\lsm.dll,-1001: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%systemroot%\system32\drivers\luafv.sys,-100: \SystemRoot\system32\drivers\luafv.sys (autostart)
@%SystemRoot%\system32\LanguageOverlayServer.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver: \SystemRoot\System32\drivers\mausbhost.sys (manual start)
@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver: \SystemRoot\System32\drivers\mausbip.sys (manual start)
MBB Network Adapter Class Extension: system32\drivers\MbbCx.sys (manual start)
megasas: System32\drivers\megasas.sys (system)
megasas2i: System32\drivers\MegaSas2i.sys (system)
megasas35i: System32\drivers\megasas35i.sys (system)
megasr: System32\drivers\megasr.sys (system)
@oem8.inf,%TEE_SvcDesc%;Intel® Management Engine Interface : \SystemRoot\System32\DriverStore\FileRepository\oem8.inf_amd64_85021432489d6a1c\x64\TeeDriverW8x64.sys (manual start)
@microsoft_bluetooth_avrcptransport.inf,%Microsoft_Bluetooth_AvrcpTransport.ServiceDescription%;Microsoft Bluetooth Avrcp Transport Driver: \SystemRoot\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys (manual start)
@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator: \SystemRoot\System32\drivers\mlx4_bus.sys (manual start)
@%systemroot%\system32\drivers\mmcss.sys,-100: \SystemRoot\system32\drivers\mmcss.sys (autostart)
Modem: system32\drivers\modem.sys (manual start)
@monitor.inf,%Monitor.SVCDESC%;Microsoft Monitor Class Function Driver Service: \SystemRoot\System32\drivers\monitor.sys (manual start)
@msmouse.inf,%mouclass.SvcDesc%;Mouse Class Driver: \SystemRoot\System32\drivers\mouclass.sys (manual start)
@msmouse.inf,%MOUHID.SvcDesc%;Mouse HID Driver: \SystemRoot\System32\drivers\mouhid.sys (manual start)
@%SystemRoot%\system32\drivers\mountmgr.sys,-100: System32\drivers\mountmgr.sys (system)
Mozilla Maintenance Service: "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" (manual start)
@%SystemRoot%\system32\FirewallAPI.dll,-23090: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p (disabled)
@%systemroot%\system32\wkssvc.dll,-1002: system32\DRIVERS\mrxsmb.sys (manual start)
@%systemroot%\system32\wkssvc.dll,-1006: system32\DRIVERS\mrxsmb20.sys (manual start)
@%SystemRoot%\system32\bridgeres.dll,-1: System32\drivers\bridge.sys (manual start)
@comres.dll,-2797: %SystemRoot%\System32\msdtc.exe (manual start)
@msgpiowin32.inf,%GPIO.SvcDesc%;Common Driver for Buttons, DockMode and Laptop/Slate Indicator: \SystemRoot\System32\drivers\msgpiowin32.sys (manual start)
@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100: \SystemRoot\System32\drivers\mshidkmdf.sys (manual start)
@%SystemRoot%\system32\drivers\mshidumdf.sys,-100: \SystemRoot\System32\drivers\mshidumdf.sys (manual start)
msisadrv: System32\drivers\msisadrv.sys (system)
@%SystemRoot%\system32\iscsidsc.dll,-5000: %systemroot%\system32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\system32\msimsg.dll,-27: %systemroot%\system32\msiexec.exe /V (manual start)
@ksfilter.inf,%MSKSSRV.DeviceDesc%;Microsoft Streaming Service Proxy: \SystemRoot\System32\drivers\MSKSSRV.sys (manual start)
@ksfilter.inf,%MSPCLOCK.DeviceDesc%;Microsoft Streaming Clock Proxy: \SystemRoot\System32\drivers\MSPCLOCK.sys (manual start)
@ksfilter.inf,%MSPQM.DeviceDesc%;Microsoft Streaming Quality Manager Proxy: \SystemRoot\System32\drivers\MSPQM.sys (manual start)
@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver: \SystemRoot\System32\drivers\mssmbios.sys (system)
@ksfilter.inf,%MSTEE.DeviceDesc%;Microsoft Streaming Tee/Sink-to-Sink Converter: \SystemRoot\System32\drivers\MSTEE.sys (manual start)
@mtconfig.inf,%MTConfig.SVCDESC%;Microsoft Input Configuration Driver: \SystemRoot\System32\drivers\MTConfig.sys (manual start)
@%systemroot%\system32\drivers\mup.sys,-101: System32\Drivers\mup.sys (system)
mvumis: System32\drivers\mvumis.sys (system)
@%SystemRoot%\System32\drivers\nwifi.sys,-101: system32\DRIVERS\nwifi.sys (manual start)
@%SystemRoot%\system32\ncasvc.dll,-3009: %SystemRoot%\System32\svchost.exe -k NetSvcs -p (manual start)
@%SystemRoot%\system32\NcdAutoSetup.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p (manual start)
@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service: \SystemRoot\System32\drivers\ndfltr.sys (manual start)
@%SystemRoot%\system32\drivers\ndis.sys,-200: system32\drivers\ndis.sys (system)
@%SystemRoot%\System32\drivers\ndisimplatform.sys,-501: System32\drivers\NdisImPlatform.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32001: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\drivers\ndisuio.sys (manual start)
@%SystemRoot%\System32\drivers\NdisVirtualBus.sys,-200: \SystemRoot\System32\drivers\NdisVirtualBus.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32002: \SystemRoot\System32\drivers\ndiswan.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32014: System32\DRIVERS\ndiswan.sys (manual start)
@%SystemRoot%\system32\drivers\ndproxy.sys,-6000: System32\DRIVERS\NDProxy.sys (manual start)
Network Adapter Wdf Class Extension Library: system32\drivers\NetAdapterCx.sys (manual start)
@%windir%\system32\drivers\netbios.sys,-503: system32\drivers\netbios.sys (system)
@%SystemRoot%\system32\drivers\netbt.sys,-2: System32\DRIVERS\netbt.sys (system)
@%SystemRoot%\System32\netlogon.dll,-102: %systemroot%\system32\lsass.exe (disabled)
@%SystemRoot%\system32\netman.dll,-109: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%SystemRoot%\system32\netprofmsvc.dll,-202: %SystemRoot%\System32\svchost.exe -k LocalService -p (manual start)
@%SystemRoot%\system32\NetSetupSvc.dll,-3: %SystemRoot%\System32\svchost.exe -k netsvcs -p (manual start)
@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201: %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (disabled)
@%SystemRoot%\System32\nlasvc.dll,-1: %SystemRoot%\System32\svchost.exe -k NetworkService -p (autostart)
@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider: \SystemRoot\System32\drivers\npsvctrig.sys (system)
@%SystemRoot%\system32\nsisvc.dll,-200: %systemroot%\system32\svchost.exe -k LocalService -p (autostart)
@%SystemRoot%\system32\drivers\nsiproxy.sys,-2: system32\drivers\nsiproxy.sys (system)
@nvdimm.inf,%nvdimm.SvcDesc%;Microsoft NVDIMM device driver: \SystemRoot\System32\drivers\nvdimm.sys (manual start)
@oem1.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver: \SystemRoot\system32\drivers\nvhda64v.sys (manual start)
nvlddmkm: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_827405c7c65146ab\nvlddmkm.sys (manual start)
nvraid: System32\drivers\nvraid.sys (system)
nvstor: System32\drivers\nvstor.sys (system)
@msports.inf,%Parport.SVCDESC%;Parallel port driver: \SystemRoot\System32\drivers\parport.sys (manual start)
@%SystemRoot%\system32\drivers\partmgr.sys,-100: System32\drivers\partmgr.sys (system)
Program Compatibility Assistant Service: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (disabled)
@pci.inf,%pci_svcdesc%;PCI Bus Driver: System32\drivers\pci.sys (system)
pciide: System32\drivers\pciide.sys (system)
Performance Counters for Windows Driver: System32\drivers\pcw.sys (system)
@%SystemRoot%\system32\drivers\pdc.sys,-100: system32\drivers\pdc.sys (system)
PEAUTH: system32\drivers\peauth.sys (autostart)
percsas2i: System32\drivers\percsas2i.sys (system)
percsas3i: System32\drivers\percsas3i.sys (system)
@%systemroot%\sysWow64\perfhost.exe,-2: %SystemRoot%\SysWow64\perfhost.exe (manual start)
@%systemroot%\system32\pla.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p (manual start)
@%SystemRoot%\system32\umpnpmgr.dll,-200: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (manual start)
@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver: \SystemRoot\System32\drivers\pmem.sys (manual start)
@memory.inf,%PNPMEM.SvcDesc%;Microsoft Memory Module Driver: \SystemRoot\System32\drivers\pnpmem.sys (manual start)
@%SystemRoot%\System32\polstore.dll,-5010: %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p (manual start)
@%SystemRoot%\system32\umpo.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%systemroot%\system32\mprmsg.dll,-32006: \SystemRoot\System32\drivers\raspptp.sys (manual start)
@C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll,-1: %SystemRoot%\system32\svchost.exe -k print (manual start)
@cpu.inf,%Processor.SvcDesc%;Processor Driver: \SystemRoot\System32\drivers\processr.sys (manual start)
@%systemroot%\system32\profsvc.dll,-300: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
Windows RAM Disk Driver: system32\DRIVERS\ramdisk.sys (system)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (manual start)
@netavpna.inf,%Svc-Mp-AgileVpn-DispName%;WAN Miniport (IKEv2): \SystemRoot\System32\drivers\AgileVpn.sys (manual start)
@%Systemroot%\system32\rasauto.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs -p (manual start)
@%systemroot%\system32\mprmsg.dll,-32005: \SystemRoot\System32\drivers\rasl2tp.sys (manual start)
@%Systemroot%\system32\rasmans.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
@%systemroot%\system32\mprmsg.dll,-32007: System32\DRIVERS\raspppoe.sys (manual start)
@%systemroot%\system32\sstpsvc.dll,-202: \SystemRoot\System32\drivers\rassstp.sys (manual start)
@%systemroot%\system32\wkssvc.dll,-1000: system32\DRIVERS\rdbss.sys (system)
@rdpbus.inf,%rdpbus_svcdesc%;Remote Desktop Device Redirector Bus Driver: \SystemRoot\System32\drivers\rdpbus.sys (manual start)
@%SystemRoot%\System32\DRIVERS\rdpdr.sys,-100: System32\drivers\rdpdr.sys (manual start)
Remote Desktop Video Miniport Driver: System32\drivers\rdpvideominiport.sys (manual start)
ReadyBoost: System32\drivers\rdyboost.sys (system)
@%Systemroot%\system32\mprdim.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI): \SystemRoot\System32\drivers\rfcomm.sys (manual start)
@rhproxy.inf,%rhproxy.SVCDESC%;Resource Hub proxy driver: \SystemRoot\System32\drivers\rhproxy.sys (manual start)
@%windir%\system32\RpcEpMap.dll,-1001: %SystemRoot%\system32\svchost.exe -k RPCSS -p (autostart)
@%systemroot%\system32\Locator.exe,-2: %SystemRoot%\system32\locator.exe (manual start)
@combase.dll,-5010: %SystemRoot%\system32\svchost.exe -k rpcss -p (autostart)
@%SystemRoot%\system32\samsrv.dll,-1: %SystemRoot%\system32\lsass.exe (disabled)
@%SystemRoot%\System32\SCardSvr.dll,-1: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (disabled)
@%SystemRoot%\System32\ScDeviceEnum.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (disabled)
@%SystemRoot%\System32\drivers\scfilter.sys,-11: System32\DRIVERS\scfilter.sys (manual start)
@%SystemRoot%\system32\schedsvc.dll,-100: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver: System32\drivers\scmbus.sys (system)
@%SystemRoot%\System32\certprop.dll,-13: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
sdbus: \SystemRoot\System32\drivers\sdbus.sys (manual start)
@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector: \SystemRoot\System32\drivers\SDFRd.sys (manual start)
@sdstor.inf,%sdstor_ServiceDesc%;SD Storage Port Driver: \SystemRoot\System32\drivers\sdstor.sys (manual start)
@%SystemRoot%\system32\seclogon.dll,-7001: %windir%\system32\svchost.exe -k netsvcs -p (disabled)
@%SystemRoot%\system32\Sens.dll,-200: %SystemRoot%\system32\svchost.exe -k netsvcs -p (autostart)
Serial UART Support Library: system32\drivers\SerCx.sys (manual start)
Serial UART Support Library: system32\drivers\SerCx2.sys (manual start)
@msports.inf,%Serenum.SVCDESC%;Serenum Filter Driver: \SystemRoot\System32\drivers\serenum.sys (manual start)
@msports.inf,%Serial.SVCDESC%;Serial port driver: \SystemRoot\System32\drivers\serial.sys (manual start)
@msmouse.inf,%sermouse.SvcDesc%;Serial Mouse Driver: \SystemRoot\System32\drivers\sermouse.sys (manual start)
@%SystemRoot%\System32\SessEnv.dll,-1026: %SystemRoot%\System32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\system32\ipnathlp.dll,-106: %SystemRoot%\System32\svchost.exe -k netsvcs -p (disabled)
@%SystemRoot%\System32\shsvcs.dll,-12288: %SystemRoot%\System32\svchost.exe -k netsvcs -p (autostart)
SiSRaid2: System32\drivers\SiSRaid2.sys (system)
SiSRaid4: System32\drivers\sisraid4.sys (system)
SmartSAMD: System32\drivers\SmartSAMD.sys (system)
smbdirect: System32\DRIVERS\smbdirect.sys (manual start)
@%SystemRoot%\System32\SmsRouterSvc.dll,-10001: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@firewallapi.dll,-50323: %SystemRoot%\System32\snmptrap.exe (manual start)
Simple Peripheral Bus Support Library: system32\drivers\SpbCx.sys (manual start)
@%systemroot%\system32\spoolsv.exe,-1: %SystemRoot%\System32\spoolsv.exe (disabled)
@%SystemRoot%\system32\sppsvc.exe,-101: %SystemRoot%\system32\sppsvc.exe (autostart)
@%systemroot%\system32\srvsvc.dll,-104: System32\DRIVERS\srv2.sys (manual start)
srvnet: System32\DRIVERS\srvnet.sys (manual start)
@%systemroot%\system32\ssdpsrv.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p (disabled)
@%SystemRoot%\system32\sstpsvc.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService -p (manual start)
@oem37.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.): \SystemRoot\system32\DRIVERS\ssudmdm.sys (manual start)
SAMSUNG Mobile Connectivity Service: "C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe" (disabled)
@%SystemRoot%\system32\windows.staterepository.dll,-1: %SystemRoot%\system32\svchost.exe -k appmodel -p (manual start)
Steam Client Service: "C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService (manual start)
stexstor: System32\drivers\stexstor.sys (system)
@%SystemRoot%\system32\wiaservc.dll,-9: %SystemRoot%\system32\svchost.exe -k imgsvc (disabled)
@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver: System32\drivers\storahci.sys (system)
@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver: System32\drivers\stornvme.sys (system)
@%SystemRoot%\System32\StorSvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@storufs.inf,sServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver: System32\drivers\storufs.sys (system)
@swenum.inf,%SWENUM.SVCDESC%;Software Bus Driver: \SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_31f554b660026323\swenum.sys (manual start)
Synth3dVsc: \SystemRoot\System32\drivers\Synth3dVsc.sys (manual start)
@%SystemRoot%\system32\sysmain.dll,-1000: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (disabled)
@%windir%\system32\SystemEventsBrokerServer.dll,-1001: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%SystemRoot%\system32\tapisrv.dll,-10100: %SystemRoot%\System32\svchost.exe -k NetworkService -p (disabled)
@%SystemRoot%\system32\drivers\tcpip.sys,-10001: System32\drivers\tcpip.sys (system)
@todo.dll,-100;Microsoft IPv6 Protocol Driver: System32\drivers\tcpip.sys (manual start)
TCP/IP Registry Compatibility: System32\drivers\tcpipreg.sys (autostart)
@%SystemRoot%\system32\tcpipcfg.dll,-50004: \SystemRoot\system32\DRIVERS\tdx.sys (system)
@termmou.inf,%TermInpt.SVCDESC%;Microsoft Remote Desktop Input Driver: \SystemRoot\System32\drivers\terminpt.sys (manual start)
@%SystemRoot%\System32\termsrv.dll,-268: %SystemRoot%\System32\svchost.exe -k NetworkService (disabled)
@%SystemRoot%\System32\themeservice.dll,-8192: %SystemRoot%\System32\svchost.exe -k netsvcs -p (autostart)
@%windir%\system32\TimeBrokerServer.dll,-1001: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%systemroot%\system32\tokenbroker.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@tpm.inf,%TPM%;TPM: \SystemRoot\System32\drivers\tpm.sys (manual start)
@%SystemRoot%\system32\trkwks.dll,-1: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (autostart)
@%SystemRoot%\servicing\TrustedInstaller.exe,-100: %SystemRoot%\servicing\TrustedInstaller.exe (manual start)
@%SystemRoot%\system32\drivers\tsusbflt.sys,-1000: system32\drivers\tsusbflt.sys (manual start)
@tsgenericusbdriver.inf,%TsUsbGD.DeviceDesc.Generic%;Remote Desktop Generic USB Device: \SystemRoot\System32\drivers\TsUsbGD.sys (manual start)
@tsusbhub.inf,%tsusbhub.SVCDESC%;Remote Desktop USB Hub: \SystemRoot\System32\drivers\tsusbhub.sys (manual start)
@%SystemRoot%\System32\drivers\tunnel.sys,-500: System32\drivers\tunnel.sys (manual start)
@%SystemRoot%\system32\tzautoupdate.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService -p (disabled)
@uaspstor.inf, SPortName%;USB Attached SCSI (UAS) Driver: \SystemRoot\System32\drivers\uaspstor.sys (manual start)
USB Connector Manager KMDF Class Extension: System32\Drivers\UcmCx.sys (manual start)
UCM-TCPCI KMDF Class Extension: System32\Drivers\UcmTcpciCx.sys (manual start)
@UcmUcsi.inf,mUcsi.ServiceName%;USB Connector Manager UCSI Client: \SystemRoot\System32\drivers\UcmUcsi.sys (manual start)
@UcmUcsiAcpiClient.inf,mUcsiAcpiClient.ServiceName%;UCM-UCSI ACPI Client: \SystemRoot\System32\drivers\UcmUcsiAcpiClient.sys (manual start)
UCM-UCSI KMDF Class Extension: System32\Drivers\UcmUcsiCx.sys (manual start)
USB Host Support Library: system32\drivers\ucx01000.sys (manual start)
USB Device Emulation Support Library: system32\drivers\udecx.sys (manual start)
udfs: system32\DRIVERS\udfs.sys (disabled)
@uefi.inf,ïI.SvcDesc%;Microsoft UEFI Driver: \SystemRoot\System32\drivers\UEFI.sys (manual start)
USB Function Class Extension: system32\drivers\ufx01000.sys (manual start)
@ufxchipidea.inf,xChipidea.ServiceName%;USB Chipidea Controller: \SystemRoot\System32\drivers\UfxChipidea.sys (manual start)
@ufxsynopsys.inf,xsynopsys.ServiceName%;USB Synopsys Controller: \SystemRoot\System32\drivers\ufxsynopsys.sys (manual start)
@umbus.inf,%umbus.SVCDESC%;UMBus Enumerator Driver: \SystemRoot\System32\drivers\umbus.sys (manual start)
@umpass.inf,%UmPass.SVCDESC%;Microsoft UMPass Driver: \SystemRoot\System32\drivers\umpass.sys (manual start)
@%SystemRoot%\system32\umrdp.dll,-1000: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%systemroot%\system32\upnphost.dll,-213: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p (manual start)
@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver: \SystemRoot\System32\drivers\urschipidea.sys (manual start)
USB Role-Switch Support Library: system32\drivers\urscx01000.sys (manual start)
@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver: \SystemRoot\System32\drivers\urssynopsys.sys (manual start)
@usb.inf,%GenericParent.SvcDesc%;Microsoft USB Generic Parent Driver: \SystemRoot\System32\drivers\usbccgp.sys (manual start)
@usbcir.inf,%usbcir.SVCDESC%;eHome Infrared Receiver (USBCIR): \SystemRoot\System32\drivers\usbcir.sys (manual start)
@usbport.inf,%EHCIMP.SvcDesc%;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: \SystemRoot\System32\drivers\usbehci.sys (manual start)
@usbport.inf,%ROOTHUB.SvcDesc%;Microsoft USB Standard Hub Driver: \SystemRoot\System32\drivers\usbhub.sys (manual start)
@usbhub3.inf,%UsbHub3.SVCDESC%;SuperSpeed Hub: \SystemRoot\System32\drivers\UsbHub3.sys (manual start)
@usbport.inf,%OHCIMP.SvcDesc%;Microsoft USB Open Host Controller Miniport Driver: \SystemRoot\System32\drivers\usbohci.sys (manual start)
@usbprint.inf,%USBPRINT.SvcDesc%;Microsoft USB PRINTER Class: \SystemRoot\System32\drivers\usbprint.sys (manual start)
@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver: \SystemRoot\system32\DRIVERS\usbser.sys (manual start)
@usbstor.inf,%USBSTOR.SvcDesc%;USB Mass Storage Driver: \SystemRoot\System32\drivers\USBSTOR.SYS (manual start)
@usbport.inf,%UHCIMP.SvcDesc%;Microsoft USB Universal Host Controller Miniport Driver: \SystemRoot\System32\drivers\usbuhci.sys (manual start)
@usbxhci.inf,%PCI\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller: \SystemRoot\System32\drivers\USBXHCI.SYS (manual start)
@%systemroot%\system32\usermgr.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (autostart)
@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator: System32\drivers\vdrvroot.sys (system)
@%SystemRoot%\system32\vds.exe,-100: %SystemRoot%\System32\vds.exe (manual start)
@%SystemRoot%\System32\drivers\VerifierExt.sys,-1000: System32\drivers\VerifierExt.sys (disabled)
vhdmp: \SystemRoot\System32\drivers\vhdmp.sys (manual start)
@hidvhf.inf,%VhfService%;Virtual HID Framework (VHF) Driver: \SystemRoot\System32\drivers\vhf.sys (manual start)
@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver: System32\drivers\volmgr.sys (system)
@%SystemRoot%\system32\drivers\volmgrx.sys,-100: System32\drivers\volmgrx.sys (system)
@volume.inf,%VolumeServiceDesc%;Volume driver: System32\drivers\volume.sys (system)
vsmraid: System32\drivers\vsmraid.sys (system)
@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver: System32\drivers\vstxraid.sys (system)
@%SystemRoot%\System32\drivers\vwifibus.sys,-257: \SystemRoot\System32\drivers\vwifibus.sys (manual start)
@%SystemRoot%\System32\drivers\vwififlt.sys,-259: System32\drivers\vwififlt.sys (system)
@%SystemRoot%\system32\w32time.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
@hiddigi.inf,%WacomPen.SVCDESC%;Wacom Serial Pen HID Driver: \SystemRoot\System32\drivers\wacompen.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32011: System32\DRIVERS\wanarp.sys (autostart)
@%systemroot%\system32\mprmsg.dll,-32012: System32\DRIVERS\wanarp.sys (manual start)
@%SystemRoot%\System32\wcmsvc.dll,-4097: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (autostart)
@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000: system32\drivers\Wdf01000.sys (system)
WDI Driver Framework: system32\DRIVERS\wdiwifi.sys (manual start)
@%SystemRoot%\system32\drivers\WdmCompanionFilter.sys,-1000: system32\drivers\WdmCompanionFilter.sys (manual start)
@%SystemRoot%\System32\wfdsconmgrsvc.dll,-9000: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000: System32\drivers\wfplwfs.sys (system)
@%SystemRoot%\system32\wiarpc.dll,-2: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%SystemRoot%\system32\drivers\wimmount.sys,-101: system32\drivers\wimmount.sys (manual start)
Windows Trusted Execution Environment Class Extension: system32\drivers\WindowsTrustedRT.sys (system)
@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service: System32\drivers\WindowsTrustedRTProxy.sys (system)
@%SystemRoot%\system32\winhttp.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@mlx4_bus.inf,%WinMad.ServiceDesc%;WinMad Service: \SystemRoot\System32\drivers\winmad.sys (manual start)
@%Systemroot%\system32\wbem\wmisvc.dll,-205: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@%SystemRoot%\system32\drivers\winnat.sys,-10001: system32\drivers\winnat.sys (manual start)
@%SystemRoot%\system32\drivers\winquic.sys,-1: system32\drivers\winquic.sys (manual start)
@winusb.inf,%WINUSB_SvcName%;WinUsb Driver: \SystemRoot\System32\drivers\WinUSB.SYS (manual start)
@mlx4_bus.inf,%WinVerbs.ServiceDesc%;WinVerbs Service: \SystemRoot\System32\drivers\winverbs.sys (manual start)
@%SystemRoot%\System32\wlansvc.dll,-257: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%SystemRoot%\system32\wlidsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\system32\lpasvc.dll,-1000: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%systemroot%\system32\Windows.Management.Service.dll,-100: %systemroot%\system32\svchost.exe -k netsvcs -p (manual start)
@wmiacpi.inf,%WMIMAP.SvcDesc%;Microsoft Windows Management Interface for ACPI: \SystemRoot\System32\drivers\wmiacpi.sys (manual start)
@%Systemroot%\system32\wbem\wmiapsrv.exe,-110: %systemroot%\system32\wbem\WmiApSrv.exe (disabled)
@%SystemRoot%\system32\wpdbusenum.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start)
@%systemroot%\System32\drivers\WpdUpFltr.sys,-100: System32\drivers\WpdUpFltr.sys (manual start)
@%SystemRoot%\system32\wpnservice.dll,-1: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@%SystemRoot%\system32\WpnUserService.dll,-1: %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup (autostart)
Windows Push Notifications User Service_21363: C:\Windows\system32\svchost.exe -k UnistackSvcGroup (autostart)
@%systemroot%\System32\drivers\ws2ifsl.sys,-1000: \SystemRoot\system32\drivers\ws2ifsl.sys (disabled)
Windows Search: %systemroot%\system32\SearchIndexer.exe /Embedding (disabled)
Windows Update: %systemroot%\system32\svchost.exe -k netsvcs -p (disabled)
@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000: system32\drivers\WudfPf.sys (manual start)
@wpdfs.inf,%WPDFS_SvcName%;WPD File System driver: \SystemRoot\system32\DRIVERS\WUDFRd.sys (manual start)
WUDFWpdMtp: \SystemRoot\system32\DRIVERS\WUDFRd.sys (manual start)
@%SystemRoot%\System32\wwansvc.dll,-257: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%systemroot%\system32\xboxgipsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@xinputhid.inf,%xinputhid.SvcDesc%;XINPUT HID Filter Driver: \SystemRoot\System32\drivers\xinputhid.sys (manual start)
--------------------------------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute =
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\Users\Doido\AppData\Local\Temp\20341483-971d-4583-9782-762070da52c9.tmp||C:\Users\Doido\AppData\Local\Temp\GoogleUpdate.execc60cd||C:\Users\Doido\AppData\Local\Temp\goopdate.dllcc60cd
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
*Registry key not found*
--------------------------------------------------
End of report, 59,132 bytes
Report generated in 0.063 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
StartupList version: 1.52.2
Started from : C:\Users\Doido\Desktop\HijackThis.EXE
Detected: Unknown Windows (WinNT 6.02.1008)
Detected: Internet Explorer v11.0 (11.00.17763.0771)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================
Running processes:
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Doido\Desktop\HijackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Users\Doido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
*No files*
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
*No files*
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Discord = C:\Users\Doido\AppData\Local\Discord\app-0.0.305\Discord.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" /S
--------------------------------------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
*Registry value not found*
--------------------------------------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = %SystemRoot%\system32\unregmp2.exe /ShowWMP
[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = %SystemRoot%\system32\unregmp2.exe /FirstLogon
[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
--------------------------------------------------
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps
*Registry key not found*
--------------------------------------------------
Load/Run keys from C:\Windows\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=
--------------------------------------------------
Shell & screensaver key from C:\Windows\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Checking for EXPLORER.EXE instances:
C:\Windows\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\Windows\Explorer\Explorer.exe: not present
C:\Windows\System\Explorer.exe: not present
C:\Windows\System32\Explorer.exe: not present
C:\Windows\Command\Explorer.exe: not present
C:\Windows\Fonts\Explorer.exe: not present
--------------------------------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: *Registry key not found*
.shb: *Registry key not found*
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------------------------------
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\Windows
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename NOT OK: 'REGEDIT.EXE.MUI'
- File description: 'Registry Editor'
Registry check failed!
--------------------------------------------------
Enumerating Browser Helper Objects:
*No BHO's found*
--------------------------------------------------
Enumerating Task Scheduler jobs:
*No jobs found*
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\Windows\system32\napinsp.dll
NameSpace #2: C:\Windows\System32\mswsock.dll
NameSpace #3: C:\Windows\System32\winrnr.dll
NameSpace #4: C:\Windows\system32\NLAapi.dll
NameSpace #5: C:\Windows\system32\wshbth.dll
Protocol #1: C:\Windows\system32\mswsock.dll
Protocol #2: C:\Windows\system32\mswsock.dll
Protocol #3: C:\Windows\system32\mswsock.dll
Protocol #4: C:\Windows\system32\mswsock.dll
Protocol #5: C:\Windows\system32\mswsock.dll
Protocol #6: C:\Windows\system32\mswsock.dll
Protocol #7: C:\Windows\system32\mswsock.dll
Protocol #8: C:\Windows\system32\mswsock.dll
Protocol #9: C:\Windows\system32\mswsock.dll
Protocol #10: C:\Windows\system32\mswsock.dll
Protocol #11: C:\Windows\system32\mswsock.dll
--------------------------------------------------
Enumerating Windows NT/2000/XP services
3ware: System32\drivers\3ware.sys (system)
@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver: System32\drivers\ACPI.sys (system)
@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver: \SystemRoot\System32\drivers\AcpiDev.sys (manual start)
Microsoft ACPIEx Driver: System32\Drivers\acpiex.sys (system)
@acpipagr.inf,%SvcDesc%;ACPI Processor Aggregator Driver: \SystemRoot\System32\drivers\acpipagr.sys (manual start)
@acpipmi.inf,%AcpiPmi.SvcDesc%;ACPI Power Meter Driver: \SystemRoot\System32\drivers\acpipmi.sys (manual start)
@acpitime.inf,%AcpiTime.SvcDesc%;ACPI Wake Alarm Driver: \SystemRoot\System32\drivers\acpitime.sys (manual start)
Adobe Flash Player Update Service: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (manual start)
ADP80XX: System32\drivers\ADP80XX.SYS (system)
@%systemroot%\system32\drivers\afd.sys,-1000: \SystemRoot\system32\drivers\afd.sys (system)
afunix: \SystemRoot\system32\drivers\afunix.sys (system)
@%systemroot%\system32\drivers\ahcache.sys,-102: system32\DRIVERS\ahcache.sys (system)
@%SystemRoot%\system32\Alg.exe,-112: %SystemRoot%\System32\alg.exe (manual start)
@cpu.inf,%AmdK8.SvcDesc%;AMD K8 Processor Driver: \SystemRoot\System32\drivers\amdk8.sys (manual start)
@cpu.inf,%AmdPPM.SvcDesc%;AMD Processor Driver: \SystemRoot\System32\drivers\amdppm.sys (manual start)
amdsata: System32\drivers\amdsata.sys (system)
amdsbs: System32\drivers\amdsbs.sys (system)
amdxata: System32\drivers\amdxata.sys (system)
ammntdrv: \??\C:\Windows\System32\ammntdrv.sys (autostart)
amwrtdrv: \??\C:\Windows\System32\amwrtdrv.sys (autostart)
@%systemroot%\system32\srpapi.dll,-100: system32\drivers\appid.sys (manual start)
@%systemroot%\system32\appidsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%systemroot%\system32\appinfo.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@%systemroot%\system32\srpapi.dll,-102: system32\drivers\applockerfltr.sys (manual start)
@appmgmts.dll,-3250: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\System32\AppReadiness.dll,-1000: %SystemRoot%\System32\svchost.exe -k AppReadiness -p (manual start)
@%SystemRoot%\system32\appxdeploymentserver.dll,-1: %systemroot%\system32\svchost.exe -k wsappx -p (disabled)
@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver: System32\drivers\arcsas.sys (system)
@%systemroot%\system32\mprmsg.dll,-32000: \SystemRoot\System32\drivers\asyncmac.sys (manual start)
@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel: System32\drivers\atapi.sys (system)
@%SystemRoot%\system32\AudioEndpointBuilder.dll,-204: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (autostart)
@%SystemRoot%\system32\audiosrv.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p (autostart)
@netbvbda.inf,%vbd_srv_desc%;QLogic Network Adapter VBD: System32\drivers\bxvbda.sys (system)
@%SystemRoot%\system32\drivers\bam.sys,-100: system32\drivers\bam.sys (system)
BasicDisplay: \SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_5103ac179273be89\BasicDisplay.sys (system)
BasicRender: \SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_0b8d03c3bc0e7fd9\BasicRender.sys (system)
@bcmfn2.inf,%bcmfn2.SVCDESC%;bcmfn2 Service: \SystemRoot\System32\drivers\bcmfn2.sys (manual start)
@%SystemRoot%\system32\bfe.dll,-1001: %systemroot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p (autostart)
@%SystemRoot%\system32\qmgr.dll,-1000: %SystemRoot%\System32\svchost.exe -k netsvcs -p (disabled)
@%SystemRoot%\system32\Microsoft.Bluetooth.UserService.dll,-101: %SystemRoot%\system32\svchost.exe -k BthAppGroup -p (disabled)
Bluetooth User Support Service_21363: C:\Windows\system32\svchost.exe -k BthAppGroup -p (disabled)
@%systemroot%\system32\wkssvc.dll,-2001: system32\DRIVERS\bowser.sys (manual start)
@%windir%\system32\bisrv.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%SystemRoot%\system32\BTAGService.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted (manual start)
@%SystemRoot%\system32\BthAvctpSvc.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalService -p (manual start)
@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service: \SystemRoot\System32\drivers\BthEnum.sys (manual start)
@bthhfenum.inf,%BthHFEnum.SVCDESC%;Bluetooth Hands-Free Audio Profile: \SystemRoot\System32\drivers\bthhfenum.sys (manual start)
@BthLEEnum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver: \SystemRoot\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys (manual start)
@bth.inf,%BTHMINI.SvcDesc%;Bluetooth Radio Driver: \SystemRoot\System32\drivers\BTHMINI.sys (manual start)
@mdmbtmdm.inf,%BthModem.DisplayName%;Bluetooth Modem Communications Driver: \SystemRoot\System32\drivers\bthmodem.sys (manual start)
@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver: \SystemRoot\System32\drivers\BTHport.sys (manual start)
@%SystemRoot%\System32\bthserv.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalService -p (manual start)
@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver: \SystemRoot\System32\drivers\BTHUSB.sys (manual start)
@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices: \SystemRoot\System32\drivers\buttonconverter.sys (manual start)
@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver: \SystemRoot\System32\drivers\CAD.sys (manual start)
@%SystemRoot%\system32\CapabilityAccessManager.dll,-1: %SystemRoot%\system32\svchost.exe -k appmodel -p (manual start)
@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen: \SystemRoot\System32\drivers\capimg.sys (manual start)
CD/DVD File System Reader: system32\DRIVERS\cdfs.sys (disabled)
@%SystemRoot%\system32\cdpusersvc.dll,-100: %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup (autostart)
Connected Devices Platform User Service_21363: C:\Windows\system32\svchost.exe -k UnistackSvcGroup (autostart)
@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver: \SystemRoot\System32\drivers\cdrom.sys (system)
@%SystemRoot%\System32\certprop.dll,-11: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
cht4iscsi: System32\drivers\cht4sx64.sys (system)
@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver: \SystemRoot\System32\drivers\cht4vx64.sys (manual start)
@circlass.inf,%circlass.SVCDESC%;Consumer IR Devices: \SystemRoot\System32\drivers\circlass.sys (manual start)
@%SystemRoot%\system32\drivers\clfs.sys,-100: System32\drivers\CLFS.sys (system)
@%SystemRoot%\system32\ClipSVC.dll,-103: %SystemRoot%\System32\svchost.exe -k wsappx -p (manual start)
@cmbatt.inf,%CmBatt.SvcDesc%;Microsoft ACPI Control Method Battery Driver: \SystemRoot\System32\drivers\CmBatt.sys (manual start)
CNG: System32\Drivers\cng.sys (system)
@%SystemRoot%\system32\drivers\cnghwassist.sys,-100: System32\DRIVERS\cnghwassist.sys (disabled)
@compositebus.inf,%CompositeBus.SVCDESC%;Composite Bus Enumerator Driver: \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_e4d35af746093dc3\CompositeBus.sys (manual start)
@comres.dll,-947: %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Console Driver: System32\drivers\condrv.sys (manual start)
@%SystemRoot%\system32\ConsentUxClient.dll,-100: %SystemRoot%\system32\svchost.exe -k DevicesFlow (manual start)
ConsentUX_21363: C:\Windows\system32\svchost.exe -k DevicesFlow (manual start)
@%SystemRoot%\system32\coremessaging.dll,-1: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork -p (autostart)
@%SystemRoot%\system32\cryptsvc.dll,-1001: %SystemRoot%\system32\svchost.exe -k NetworkService -p (manual start)
@%SystemRoot%\system32\drivers\dam.sys,-100: system32\drivers\dam.sys (system)
@combase.dll,-5012: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%SystemRoot%\system32\das.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%SystemRoot%\system32\umpnpmgr.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (manual start)
@%SystemRoot%\system32\Windows.Devices.Picker.dll,-1006: %SystemRoot%\system32\svchost.exe -k DevicesFlow (manual start)
DevicePicker_21363: C:\Windows\system32\svchost.exe -k DevicesFlow (manual start)
@%SystemRoot%\system32\DevicesFlowBroker.dll,-103: %SystemRoot%\system32\svchost.exe -k DevicesFlow (manual start)
DevicesFlow_21363: C:\Windows\system32\svchost.exe -k DevicesFlow (manual start)
@%systemroot%\system32\wkssvc.dll,-1008: System32\Drivers\dfsc.sys (system)
@oem34.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.): \SystemRoot\system32\DRIVERS\ssudbus.sys (manual start)
@%SystemRoot%\system32\dhcpcore.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (autostart)
@disk.inf,%disk_ServiceDesc%;Disk Driver: System32\drivers\disk.sys (system)
@%systemroot%\system32\Windows.Internal.Management.dll,-100: %systemroot%\system32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\System32\dnsapi.dll,-101: %SystemRoot%\system32\svchost.exe -k NetworkService -p (autostart)
@%systemroot%\system32\dot3svc.dll,-1102: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@wdmaudio.inf,%drmkaud.SvcDesc%;Microsoft Trusted Audio Drivers: \SystemRoot\System32\drivers\drmkaud.sys (manual start)
@%SystemRoot%\system32\DeviceSetupManager.dll,-1000: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
LDDM Graphics Subsystem: \SystemRoot\System32\drivers\dxgkrnl.sys (system)
@oem2.inf,%e1dExpress.Service.DispName%;Intel® PRO/1000 PCI Express Network Connection Driver D: \SystemRoot\system32\DRIVERS\e1d65x64.sys (manual start)
@%systemroot%\system32\eapsvc.dll,-1: %SystemRoot%\System32\svchost.exe -k netsvcs -p (manual start)
EasyAntiCheat: "C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe" (manual start)
@netevbda.inf,%vbd_srv_desc%;QLogic 10 Gigabit Ethernet Adapter VBD: System32\drivers\evbda.sys (system)
@%SystemRoot%\system32\efssvc.dll,-100: %SystemRoot%\System32\lsass.exe (manual start)
@EnterpriseAppMgmtSvc.dll,-1: %systemroot%\system32\svchost.exe -k appmodel -p (manual start)
@errdev.inf,%ERRDEV.SvcDesc%;Microsoft Hardware Error Device Driver: \SystemRoot\System32\drivers\errdev.sys (manual start)
esihdrv: \??\C:\Users\Doido\AppData\Local\Temp\esihdrv.sys (disabled)
@%SystemRoot%\system32\wevtsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p (autostart)
@comres.dll,-2450: %SystemRoot%\system32\svchost.exe -k LocalService -p (autostart)
@%systemroot%\system32\fdPHost.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService -p (manual start)
@%systemroot%\system32\fdrespub.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p (manual start)
@%systemroot%\system32\drivers\filecrypt.sys,-100: system32\drivers\filecrypt.sys (system)
@%SystemRoot%\system32\drivers\fileinfo.sys,-100: System32\drivers\fileinfo.sys (system)
@%SystemRoot%\system32\drivers\filetrace.sys,-10001: system32\drivers\filetrace.sys (manual start)
@oem5.inf,%FiraDiskService%;FiraDisk Driver: System32\drivers\firadisk.sys (system)
@%SystemRoot%\system32\drivers\fltmgr.sys,-10001: system32\drivers\fltmgr.sys (system)
@%systemroot%\system32\FntCache.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService -p (autostart)
@%SystemRoot%\system32\drivers\fsdepends.sys,-10001: System32\drivers\FsDepends.sys (manual start)
@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class: \SystemRoot\System32\drivers\genericusbfn.sys (manual start)
Microsoft GPIO Class Extension Driver: System32\Drivers\msgpioclx.sys (manual start)
@gpapi.dll,-112: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100: System32\drivers\gpuenergydrv.sys (system)
@hdaudio.inf,યunctionDriverForHdAudio.SvcDesc%;Microsoft 1.1 UAA Function Driver for High Definition Audio Service: \SystemRoot\system32\DRIVERS\HdAudio.sys (manual start)
@hdaudbus.inf,%HDAudBus.SVCDESC%;Microsoft UAA Bus Driver for High Definition Audio: \SystemRoot\System32\drivers\HDAudBus.sys (manual start)
@hidbatt.inf,%HidBatt.SvcDesc%;HID UPS Battery Driver: \SystemRoot\System32\drivers\HidBatt.sys (manual start)
@hidbth.inf,%HIDBTH.SvcDesc%;Microsoft Bluetooth HID Miniport: \SystemRoot\System32\drivers\hidbth.sys (manual start)
@hidi2c.inf,%hidi2c.SVCDESC%;Microsoft I2C HID Miniport Driver: \SystemRoot\System32\drivers\hidi2c.sys (manual start)
@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts: \SystemRoot\System32\drivers\hidinterrupt.sys (manual start)
@hidir.inf,%HIDIR.SvcDesc%;Microsoft Infrared HID Driver: \SystemRoot\System32\drivers\hidir.sys (manual start)
@%SystemRoot%\System32\hidserv.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (disabled)
@hidspi_km.inf,%hidspi.SVCDESC%;Microsoft SPI HID Miniport Driver: \SystemRoot\System32\drivers\hidspi.sys (manual start)
@input.inf,%HID.SvcDesc%;Microsoft HID Class Driver: \SystemRoot\System32\drivers\hidusb.sys (manual start)
HpSAMD: System32\drivers\HpSAMD.sys (system)
@%SystemRoot%\system32\drivers\http.sys,-1: system32\drivers\HTTP.sys (manual start)
Microsoft Hardware Notifications Class Extension Driver: System32\Drivers\mshwnclx.sys (manual start)
@%systemroot%\system32\drivers\hwpolicy.sys,-101: System32\drivers\hwpolicy.sys (system)
@keyboard.inf,%i8042prt.SvcDesc%;i8042 Keyboard and PS/2 Mouse Port Driver: \SystemRoot\System32\drivers\i8042prt.sys (manual start)
@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver: \SystemRoot\System32\drivers\iagpio.sys (manual start)
@iai2c.inf,%iai2c.SVCDESC%;Intel® Serial IO I2C Host Controller: \SystemRoot\System32\drivers\iai2c.sys (manual start)
@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel® Serial IO GPIO Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_GPIO2.sys (manual start)
@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel® Serial IO GPIO Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys (manual start)
@iaLPSS2i_GPIO2_CNL.inf,%iaLPSS2i_GPIO2_CNL.SVCDESC%;Intel® Serial IO GPIO Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_GPIO2_CNL.sys (manual start)
@iaLPSS2i_GPIO2_GLK.inf,%iaLPSS2i_GPIO2_GLK.SVCDESC%;Intel® Serial IO GPIO Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_GPIO2_GLK.sys (manual start)
@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel® Serial IO I2C Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_I2C.sys (manual start)
@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel® Serial IO I2C Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_I2C_BXT_P.sys (manual start)
@iaLPSS2i_I2C_CNL.inf,%iaLPSS2i_I2C_CNL.SVCDESC%;Intel® Serial IO I2C Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_I2C_CNL.sys (manual start)
@iaLPSS2i_I2C_GLK.inf,%iaLPSS2i_I2C_GLK.SVCDESC%;Intel® Serial IO I2C Driver v2: \SystemRoot\System32\drivers\iaLPSS2i_I2C_GLK.sys (manual start)
@ialpssi_gpio.inf,%iaLPSSi_GPIO.SVCDESC%;Intel® Serial IO GPIO Controller Driver: \SystemRoot\System32\drivers\iaLPSSi_GPIO.sys (manual start)
@ialpssi_i2c.inf,%iaLPSSi_I2C.SVCDESC%;Intel® Serial IO I2C Controller Driver: \SystemRoot\System32\drivers\iaLPSSi_I2C.sys (manual start)
@oem0.inf,%iaStorAC.DeviceDesc%;Intel® Chipset SATA/PCIe RST Premium Controller: System32\drivers\iaStorAC.sys (system)
@iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller: System32\drivers\iaStorAVC.sys (system)
@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7: System32\drivers\iaStorV.sys (system)
@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver): \SystemRoot\System32\drivers\ibbus.sys (manual start)
@%SystemRoot%\System32\tetheringservice.dll,-4097: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%SystemRoot%\system32\ikeext.dll,-501: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100: \SystemRoot\System32\drivers\IndirectKmd.sys (manual start)
intelide: System32\drivers\intelide.sys (system)
@intelpep.inf,%INTELPEP.SVCDESC%;Intel® Power Engine Plug-in Driver: System32\drivers\intelpep.sys (system)
@cpu.inf,%IntelPPM.SvcDesc%;Intel Processor Driver: \SystemRoot\System32\drivers\intelppm.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32013: system32\DRIVERS\ipfltdrv.sys (manual start)
@%SystemRoot%\system32\iphlpsvc.dll,-500: %SystemRoot%\System32\svchost.exe -k NetSvcs -p (autostart)
IPMIDRV: \SystemRoot\System32\drivers\IPMIDrv.sys (manual start)
IP Network Address Translator: System32\drivers\ipnat.sys (manual start)
IPT: \SystemRoot\System32\drivers\ipt.sys (manual start)
@%Systemroot%\system32\ipxlatcfg.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
IrDA: \SystemRoot\system32\drivers\irda.sys (manual start)
@%SystemRoot%\system32\drivers\irenum.sys,-100: system32\drivers\irenum.sys (manual start)
@%SystemRoot%\System32\irmon.dll,-2000: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
isapnp: System32\drivers\isapnp.sys (system)
@iscsi.inf,%iScsiPortName%;iScsiPort Driver: \SystemRoot\System32\drivers\msiscsi.sys (manual start)
ItSas35i: System32\drivers\ItSas35i.sys (system)
@keyboard.inf,%kbdclass.SvcDesc%;Keyboard Class Driver: \SystemRoot\System32\drivers\kbdclass.sys (manual start)
@keyboard.inf,%KBDHID.SvcDesc%;Keyboard HID Driver: \SystemRoot\System32\drivers\kbdhid.sys (manual start)
@keyiso.dll,-100: %SystemRoot%\system32\lsass.exe (manual start)
KSecDD: System32\Drivers\ksecdd.sys (system)
KSecPkg: System32\Drivers\ksecpkg.sys (system)
Kernel Streaming Thunks: \SystemRoot\system32\drivers\ksthunk.sys (manual start)
@comres.dll,-2946: %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p (manual start)
@%systemroot%\system32\srvsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (disabled)
@%systemroot%\system32\wkssvc.dll,-100: %SystemRoot%\System32\svchost.exe -k NetworkService -p (disabled)
@%SystemRoot%\system32\licensemanagersvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalService -p (manual start)
@%SystemRoot%\system32\lmhsvc.dll,-101: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p (disabled)
LSI_SAS: System32\drivers\lsi_sas.sys (system)
LSI_SAS2i: System32\drivers\lsi_sas2i.sys (system)
LSI_SAS3i: System32\drivers\lsi_sas3i.sys (system)
LSI_SSS: System32\drivers\lsi_sss.sys (system)
@%windir%\system32\lsm.dll,-1001: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%systemroot%\system32\drivers\luafv.sys,-100: \SystemRoot\system32\drivers\luafv.sys (autostart)
@%SystemRoot%\system32\LanguageOverlayServer.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver: \SystemRoot\System32\drivers\mausbhost.sys (manual start)
@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver: \SystemRoot\System32\drivers\mausbip.sys (manual start)
MBB Network Adapter Class Extension: system32\drivers\MbbCx.sys (manual start)
megasas: System32\drivers\megasas.sys (system)
megasas2i: System32\drivers\MegaSas2i.sys (system)
megasas35i: System32\drivers\megasas35i.sys (system)
megasr: System32\drivers\megasr.sys (system)
@oem8.inf,%TEE_SvcDesc%;Intel® Management Engine Interface : \SystemRoot\System32\DriverStore\FileRepository\oem8.inf_amd64_85021432489d6a1c\x64\TeeDriverW8x64.sys (manual start)
@microsoft_bluetooth_avrcptransport.inf,%Microsoft_Bluetooth_AvrcpTransport.ServiceDescription%;Microsoft Bluetooth Avrcp Transport Driver: \SystemRoot\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys (manual start)
@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator: \SystemRoot\System32\drivers\mlx4_bus.sys (manual start)
@%systemroot%\system32\drivers\mmcss.sys,-100: \SystemRoot\system32\drivers\mmcss.sys (autostart)
Modem: system32\drivers\modem.sys (manual start)
@monitor.inf,%Monitor.SVCDESC%;Microsoft Monitor Class Function Driver Service: \SystemRoot\System32\drivers\monitor.sys (manual start)
@msmouse.inf,%mouclass.SvcDesc%;Mouse Class Driver: \SystemRoot\System32\drivers\mouclass.sys (manual start)
@msmouse.inf,%MOUHID.SvcDesc%;Mouse HID Driver: \SystemRoot\System32\drivers\mouhid.sys (manual start)
@%SystemRoot%\system32\drivers\mountmgr.sys,-100: System32\drivers\mountmgr.sys (system)
Mozilla Maintenance Service: "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" (manual start)
@%SystemRoot%\system32\FirewallAPI.dll,-23090: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p (disabled)
@%systemroot%\system32\wkssvc.dll,-1002: system32\DRIVERS\mrxsmb.sys (manual start)
@%systemroot%\system32\wkssvc.dll,-1006: system32\DRIVERS\mrxsmb20.sys (manual start)
@%SystemRoot%\system32\bridgeres.dll,-1: System32\drivers\bridge.sys (manual start)
@comres.dll,-2797: %SystemRoot%\System32\msdtc.exe (manual start)
@msgpiowin32.inf,%GPIO.SvcDesc%;Common Driver for Buttons, DockMode and Laptop/Slate Indicator: \SystemRoot\System32\drivers\msgpiowin32.sys (manual start)
@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100: \SystemRoot\System32\drivers\mshidkmdf.sys (manual start)
@%SystemRoot%\system32\drivers\mshidumdf.sys,-100: \SystemRoot\System32\drivers\mshidumdf.sys (manual start)
msisadrv: System32\drivers\msisadrv.sys (system)
@%SystemRoot%\system32\iscsidsc.dll,-5000: %systemroot%\system32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\system32\msimsg.dll,-27: %systemroot%\system32\msiexec.exe /V (manual start)
@ksfilter.inf,%MSKSSRV.DeviceDesc%;Microsoft Streaming Service Proxy: \SystemRoot\System32\drivers\MSKSSRV.sys (manual start)
@ksfilter.inf,%MSPCLOCK.DeviceDesc%;Microsoft Streaming Clock Proxy: \SystemRoot\System32\drivers\MSPCLOCK.sys (manual start)
@ksfilter.inf,%MSPQM.DeviceDesc%;Microsoft Streaming Quality Manager Proxy: \SystemRoot\System32\drivers\MSPQM.sys (manual start)
@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver: \SystemRoot\System32\drivers\mssmbios.sys (system)
@ksfilter.inf,%MSTEE.DeviceDesc%;Microsoft Streaming Tee/Sink-to-Sink Converter: \SystemRoot\System32\drivers\MSTEE.sys (manual start)
@mtconfig.inf,%MTConfig.SVCDESC%;Microsoft Input Configuration Driver: \SystemRoot\System32\drivers\MTConfig.sys (manual start)
@%systemroot%\system32\drivers\mup.sys,-101: System32\Drivers\mup.sys (system)
mvumis: System32\drivers\mvumis.sys (system)
@%SystemRoot%\System32\drivers\nwifi.sys,-101: system32\DRIVERS\nwifi.sys (manual start)
@%SystemRoot%\system32\ncasvc.dll,-3009: %SystemRoot%\System32\svchost.exe -k NetSvcs -p (manual start)
@%SystemRoot%\system32\NcdAutoSetup.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p (manual start)
@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service: \SystemRoot\System32\drivers\ndfltr.sys (manual start)
@%SystemRoot%\system32\drivers\ndis.sys,-200: system32\drivers\ndis.sys (system)
@%SystemRoot%\System32\drivers\ndisimplatform.sys,-501: System32\drivers\NdisImPlatform.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32001: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\drivers\ndisuio.sys (manual start)
@%SystemRoot%\System32\drivers\NdisVirtualBus.sys,-200: \SystemRoot\System32\drivers\NdisVirtualBus.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32002: \SystemRoot\System32\drivers\ndiswan.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32014: System32\DRIVERS\ndiswan.sys (manual start)
@%SystemRoot%\system32\drivers\ndproxy.sys,-6000: System32\DRIVERS\NDProxy.sys (manual start)
Network Adapter Wdf Class Extension Library: system32\drivers\NetAdapterCx.sys (manual start)
@%windir%\system32\drivers\netbios.sys,-503: system32\drivers\netbios.sys (system)
@%SystemRoot%\system32\drivers\netbt.sys,-2: System32\DRIVERS\netbt.sys (system)
@%SystemRoot%\System32\netlogon.dll,-102: %systemroot%\system32\lsass.exe (disabled)
@%SystemRoot%\system32\netman.dll,-109: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%SystemRoot%\system32\netprofmsvc.dll,-202: %SystemRoot%\System32\svchost.exe -k LocalService -p (manual start)
@%SystemRoot%\system32\NetSetupSvc.dll,-3: %SystemRoot%\System32\svchost.exe -k netsvcs -p (manual start)
@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201: %systemroot%\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (disabled)
@%SystemRoot%\System32\nlasvc.dll,-1: %SystemRoot%\System32\svchost.exe -k NetworkService -p (autostart)
@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider: \SystemRoot\System32\drivers\npsvctrig.sys (system)
@%SystemRoot%\system32\nsisvc.dll,-200: %systemroot%\system32\svchost.exe -k LocalService -p (autostart)
@%SystemRoot%\system32\drivers\nsiproxy.sys,-2: system32\drivers\nsiproxy.sys (system)
@nvdimm.inf,%nvdimm.SvcDesc%;Microsoft NVDIMM device driver: \SystemRoot\System32\drivers\nvdimm.sys (manual start)
@oem1.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver: \SystemRoot\system32\drivers\nvhda64v.sys (manual start)
nvlddmkm: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_827405c7c65146ab\nvlddmkm.sys (manual start)
nvraid: System32\drivers\nvraid.sys (system)
nvstor: System32\drivers\nvstor.sys (system)
@msports.inf,%Parport.SVCDESC%;Parallel port driver: \SystemRoot\System32\drivers\parport.sys (manual start)
@%SystemRoot%\system32\drivers\partmgr.sys,-100: System32\drivers\partmgr.sys (system)
Program Compatibility Assistant Service: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (disabled)
@pci.inf,%pci_svcdesc%;PCI Bus Driver: System32\drivers\pci.sys (system)
pciide: System32\drivers\pciide.sys (system)
Performance Counters for Windows Driver: System32\drivers\pcw.sys (system)
@%SystemRoot%\system32\drivers\pdc.sys,-100: system32\drivers\pdc.sys (system)
PEAUTH: system32\drivers\peauth.sys (autostart)
percsas2i: System32\drivers\percsas2i.sys (system)
percsas3i: System32\drivers\percsas3i.sys (system)
@%systemroot%\sysWow64\perfhost.exe,-2: %SystemRoot%\SysWow64\perfhost.exe (manual start)
@%systemroot%\system32\pla.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork -p (manual start)
@%SystemRoot%\system32\umpnpmgr.dll,-200: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (manual start)
@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver: \SystemRoot\System32\drivers\pmem.sys (manual start)
@memory.inf,%PNPMEM.SvcDesc%;Microsoft Memory Module Driver: \SystemRoot\System32\drivers\pnpmem.sys (manual start)
@%SystemRoot%\System32\polstore.dll,-5010: %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted -p (manual start)
@%SystemRoot%\system32\umpo.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%systemroot%\system32\mprmsg.dll,-32006: \SystemRoot\System32\drivers\raspptp.sys (manual start)
@C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll,-1: %SystemRoot%\system32\svchost.exe -k print (manual start)
@cpu.inf,%Processor.SvcDesc%;Processor Driver: \SystemRoot\System32\drivers\processr.sys (manual start)
@%systemroot%\system32\profsvc.dll,-300: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
Windows RAM Disk Driver: system32\DRIVERS\ramdisk.sys (system)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (manual start)
@netavpna.inf,%Svc-Mp-AgileVpn-DispName%;WAN Miniport (IKEv2): \SystemRoot\System32\drivers\AgileVpn.sys (manual start)
@%Systemroot%\system32\rasauto.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs -p (manual start)
@%systemroot%\system32\mprmsg.dll,-32005: \SystemRoot\System32\drivers\rasl2tp.sys (manual start)
@%Systemroot%\system32\rasmans.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
@%systemroot%\system32\mprmsg.dll,-32007: System32\DRIVERS\raspppoe.sys (manual start)
@%systemroot%\system32\sstpsvc.dll,-202: \SystemRoot\System32\drivers\rassstp.sys (manual start)
@%systemroot%\system32\wkssvc.dll,-1000: system32\DRIVERS\rdbss.sys (system)
@rdpbus.inf,%rdpbus_svcdesc%;Remote Desktop Device Redirector Bus Driver: \SystemRoot\System32\drivers\rdpbus.sys (manual start)
@%SystemRoot%\System32\DRIVERS\rdpdr.sys,-100: System32\drivers\rdpdr.sys (manual start)
Remote Desktop Video Miniport Driver: System32\drivers\rdpvideominiport.sys (manual start)
ReadyBoost: System32\drivers\rdyboost.sys (system)
@%Systemroot%\system32\mprdim.dll,-200: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI): \SystemRoot\System32\drivers\rfcomm.sys (manual start)
@rhproxy.inf,%rhproxy.SVCDESC%;Resource Hub proxy driver: \SystemRoot\System32\drivers\rhproxy.sys (manual start)
@%windir%\system32\RpcEpMap.dll,-1001: %SystemRoot%\system32\svchost.exe -k RPCSS -p (autostart)
@%systemroot%\system32\Locator.exe,-2: %SystemRoot%\system32\locator.exe (manual start)
@combase.dll,-5010: %SystemRoot%\system32\svchost.exe -k rpcss -p (autostart)
@%SystemRoot%\system32\samsrv.dll,-1: %SystemRoot%\system32\lsass.exe (disabled)
@%SystemRoot%\System32\SCardSvr.dll,-1: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation (disabled)
@%SystemRoot%\System32\ScDeviceEnum.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (disabled)
@%SystemRoot%\System32\drivers\scfilter.sys,-11: System32\DRIVERS\scfilter.sys (manual start)
@%SystemRoot%\system32\schedsvc.dll,-100: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver: System32\drivers\scmbus.sys (system)
@%SystemRoot%\System32\certprop.dll,-13: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
sdbus: \SystemRoot\System32\drivers\sdbus.sys (manual start)
@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector: \SystemRoot\System32\drivers\SDFRd.sys (manual start)
@sdstor.inf,%sdstor_ServiceDesc%;SD Storage Port Driver: \SystemRoot\System32\drivers\sdstor.sys (manual start)
@%SystemRoot%\system32\seclogon.dll,-7001: %windir%\system32\svchost.exe -k netsvcs -p (disabled)
@%SystemRoot%\system32\Sens.dll,-200: %SystemRoot%\system32\svchost.exe -k netsvcs -p (autostart)
Serial UART Support Library: system32\drivers\SerCx.sys (manual start)
Serial UART Support Library: system32\drivers\SerCx2.sys (manual start)
@msports.inf,%Serenum.SVCDESC%;Serenum Filter Driver: \SystemRoot\System32\drivers\serenum.sys (manual start)
@msports.inf,%Serial.SVCDESC%;Serial port driver: \SystemRoot\System32\drivers\serial.sys (manual start)
@msmouse.inf,%sermouse.SvcDesc%;Serial Mouse Driver: \SystemRoot\System32\drivers\sermouse.sys (manual start)
@%SystemRoot%\System32\SessEnv.dll,-1026: %SystemRoot%\System32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\system32\ipnathlp.dll,-106: %SystemRoot%\System32\svchost.exe -k netsvcs -p (disabled)
@%SystemRoot%\System32\shsvcs.dll,-12288: %SystemRoot%\System32\svchost.exe -k netsvcs -p (autostart)
SiSRaid2: System32\drivers\SiSRaid2.sys (system)
SiSRaid4: System32\drivers\sisraid4.sys (system)
SmartSAMD: System32\drivers\SmartSAMD.sys (system)
smbdirect: System32\DRIVERS\smbdirect.sys (manual start)
@%SystemRoot%\System32\SmsRouterSvc.dll,-10001: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@firewallapi.dll,-50323: %SystemRoot%\System32\snmptrap.exe (manual start)
Simple Peripheral Bus Support Library: system32\drivers\SpbCx.sys (manual start)
@%systemroot%\system32\spoolsv.exe,-1: %SystemRoot%\System32\spoolsv.exe (disabled)
@%SystemRoot%\system32\sppsvc.exe,-101: %SystemRoot%\system32\sppsvc.exe (autostart)
@%systemroot%\system32\srvsvc.dll,-104: System32\DRIVERS\srv2.sys (manual start)
srvnet: System32\DRIVERS\srvnet.sys (manual start)
@%systemroot%\system32\ssdpsrv.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p (disabled)
@%SystemRoot%\system32\sstpsvc.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService -p (manual start)
@oem37.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.): \SystemRoot\system32\DRIVERS\ssudmdm.sys (manual start)
SAMSUNG Mobile Connectivity Service: "C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe" (disabled)
@%SystemRoot%\system32\windows.staterepository.dll,-1: %SystemRoot%\system32\svchost.exe -k appmodel -p (manual start)
Steam Client Service: "C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService (manual start)
stexstor: System32\drivers\stexstor.sys (system)
@%SystemRoot%\system32\wiaservc.dll,-9: %SystemRoot%\system32\svchost.exe -k imgsvc (disabled)
@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver: System32\drivers\storahci.sys (system)
@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver: System32\drivers\stornvme.sys (system)
@%SystemRoot%\System32\StorSvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@storufs.inf,sServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver: System32\drivers\storufs.sys (system)
@swenum.inf,%SWENUM.SVCDESC%;Software Bus Driver: \SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_31f554b660026323\swenum.sys (manual start)
Synth3dVsc: \SystemRoot\System32\drivers\Synth3dVsc.sys (manual start)
@%SystemRoot%\system32\sysmain.dll,-1000: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (disabled)
@%windir%\system32\SystemEventsBrokerServer.dll,-1001: %SystemRoot%\system32\svchost.exe -k DcomLaunch -p (autostart)
@%SystemRoot%\system32\tapisrv.dll,-10100: %SystemRoot%\System32\svchost.exe -k NetworkService -p (disabled)
@%SystemRoot%\system32\drivers\tcpip.sys,-10001: System32\drivers\tcpip.sys (system)
@todo.dll,-100;Microsoft IPv6 Protocol Driver: System32\drivers\tcpip.sys (manual start)
TCP/IP Registry Compatibility: System32\drivers\tcpipreg.sys (autostart)
@%SystemRoot%\system32\tcpipcfg.dll,-50004: \SystemRoot\system32\DRIVERS\tdx.sys (system)
@termmou.inf,%TermInpt.SVCDESC%;Microsoft Remote Desktop Input Driver: \SystemRoot\System32\drivers\terminpt.sys (manual start)
@%SystemRoot%\System32\termsrv.dll,-268: %SystemRoot%\System32\svchost.exe -k NetworkService (disabled)
@%SystemRoot%\System32\themeservice.dll,-8192: %SystemRoot%\System32\svchost.exe -k netsvcs -p (autostart)
@%windir%\system32\TimeBrokerServer.dll,-1001: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%systemroot%\system32\tokenbroker.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@tpm.inf,%TPM%;TPM: \SystemRoot\System32\drivers\tpm.sys (manual start)
@%SystemRoot%\system32\trkwks.dll,-1: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (autostart)
@%SystemRoot%\servicing\TrustedInstaller.exe,-100: %SystemRoot%\servicing\TrustedInstaller.exe (manual start)
@%SystemRoot%\system32\drivers\tsusbflt.sys,-1000: system32\drivers\tsusbflt.sys (manual start)
@tsgenericusbdriver.inf,%TsUsbGD.DeviceDesc.Generic%;Remote Desktop Generic USB Device: \SystemRoot\System32\drivers\TsUsbGD.sys (manual start)
@tsusbhub.inf,%tsusbhub.SVCDESC%;Remote Desktop USB Hub: \SystemRoot\System32\drivers\tsusbhub.sys (manual start)
@%SystemRoot%\System32\drivers\tunnel.sys,-500: System32\drivers\tunnel.sys (manual start)
@%SystemRoot%\system32\tzautoupdate.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService -p (disabled)
@uaspstor.inf, SPortName%;USB Attached SCSI (UAS) Driver: \SystemRoot\System32\drivers\uaspstor.sys (manual start)
USB Connector Manager KMDF Class Extension: System32\Drivers\UcmCx.sys (manual start)
UCM-TCPCI KMDF Class Extension: System32\Drivers\UcmTcpciCx.sys (manual start)
@UcmUcsi.inf,mUcsi.ServiceName%;USB Connector Manager UCSI Client: \SystemRoot\System32\drivers\UcmUcsi.sys (manual start)
@UcmUcsiAcpiClient.inf,mUcsiAcpiClient.ServiceName%;UCM-UCSI ACPI Client: \SystemRoot\System32\drivers\UcmUcsiAcpiClient.sys (manual start)
UCM-UCSI KMDF Class Extension: System32\Drivers\UcmUcsiCx.sys (manual start)
USB Host Support Library: system32\drivers\ucx01000.sys (manual start)
USB Device Emulation Support Library: system32\drivers\udecx.sys (manual start)
udfs: system32\DRIVERS\udfs.sys (disabled)
@uefi.inf,ïI.SvcDesc%;Microsoft UEFI Driver: \SystemRoot\System32\drivers\UEFI.sys (manual start)
USB Function Class Extension: system32\drivers\ufx01000.sys (manual start)
@ufxchipidea.inf,xChipidea.ServiceName%;USB Chipidea Controller: \SystemRoot\System32\drivers\UfxChipidea.sys (manual start)
@ufxsynopsys.inf,xsynopsys.ServiceName%;USB Synopsys Controller: \SystemRoot\System32\drivers\ufxsynopsys.sys (manual start)
@umbus.inf,%umbus.SVCDESC%;UMBus Enumerator Driver: \SystemRoot\System32\drivers\umbus.sys (manual start)
@umpass.inf,%UmPass.SVCDESC%;Microsoft UMPass Driver: \SystemRoot\System32\drivers\umpass.sys (manual start)
@%SystemRoot%\system32\umrdp.dll,-1000: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%systemroot%\system32\upnphost.dll,-213: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation -p (manual start)
@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver: \SystemRoot\System32\drivers\urschipidea.sys (manual start)
USB Role-Switch Support Library: system32\drivers\urscx01000.sys (manual start)
@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver: \SystemRoot\System32\drivers\urssynopsys.sys (manual start)
@usb.inf,%GenericParent.SvcDesc%;Microsoft USB Generic Parent Driver: \SystemRoot\System32\drivers\usbccgp.sys (manual start)
@usbcir.inf,%usbcir.SVCDESC%;eHome Infrared Receiver (USBCIR): \SystemRoot\System32\drivers\usbcir.sys (manual start)
@usbport.inf,%EHCIMP.SvcDesc%;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: \SystemRoot\System32\drivers\usbehci.sys (manual start)
@usbport.inf,%ROOTHUB.SvcDesc%;Microsoft USB Standard Hub Driver: \SystemRoot\System32\drivers\usbhub.sys (manual start)
@usbhub3.inf,%UsbHub3.SVCDESC%;SuperSpeed Hub: \SystemRoot\System32\drivers\UsbHub3.sys (manual start)
@usbport.inf,%OHCIMP.SvcDesc%;Microsoft USB Open Host Controller Miniport Driver: \SystemRoot\System32\drivers\usbohci.sys (manual start)
@usbprint.inf,%USBPRINT.SvcDesc%;Microsoft USB PRINTER Class: \SystemRoot\System32\drivers\usbprint.sys (manual start)
@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver: \SystemRoot\system32\DRIVERS\usbser.sys (manual start)
@usbstor.inf,%USBSTOR.SvcDesc%;USB Mass Storage Driver: \SystemRoot\System32\drivers\USBSTOR.SYS (manual start)
@usbport.inf,%UHCIMP.SvcDesc%;Microsoft USB Universal Host Controller Miniport Driver: \SystemRoot\System32\drivers\usbuhci.sys (manual start)
@usbxhci.inf,%PCI\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller: \SystemRoot\System32\drivers\USBXHCI.SYS (manual start)
@%systemroot%\system32\usermgr.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (autostart)
@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator: System32\drivers\vdrvroot.sys (system)
@%SystemRoot%\system32\vds.exe,-100: %SystemRoot%\System32\vds.exe (manual start)
@%SystemRoot%\System32\drivers\VerifierExt.sys,-1000: System32\drivers\VerifierExt.sys (disabled)
vhdmp: \SystemRoot\System32\drivers\vhdmp.sys (manual start)
@hidvhf.inf,%VhfService%;Virtual HID Framework (VHF) Driver: \SystemRoot\System32\drivers\vhf.sys (manual start)
@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver: System32\drivers\volmgr.sys (system)
@%SystemRoot%\system32\drivers\volmgrx.sys,-100: System32\drivers\volmgrx.sys (system)
@volume.inf,%VolumeServiceDesc%;Volume driver: System32\drivers\volume.sys (system)
vsmraid: System32\drivers\vsmraid.sys (system)
@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver: System32\drivers\vstxraid.sys (system)
@%SystemRoot%\System32\drivers\vwifibus.sys,-257: \SystemRoot\System32\drivers\vwifibus.sys (manual start)
@%SystemRoot%\System32\drivers\vwififlt.sys,-259: System32\drivers\vwififlt.sys (system)
@%SystemRoot%\system32\w32time.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
@hiddigi.inf,%WacomPen.SVCDESC%;Wacom Serial Pen HID Driver: \SystemRoot\System32\drivers\wacompen.sys (manual start)
@%systemroot%\system32\mprmsg.dll,-32011: System32\DRIVERS\wanarp.sys (autostart)
@%systemroot%\system32\mprmsg.dll,-32012: System32\DRIVERS\wanarp.sys (manual start)
@%SystemRoot%\System32\wcmsvc.dll,-4097: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (autostart)
@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000: system32\drivers\Wdf01000.sys (system)
WDI Driver Framework: system32\DRIVERS\wdiwifi.sys (manual start)
@%SystemRoot%\system32\drivers\WdmCompanionFilter.sys,-1000: system32\drivers\WdmCompanionFilter.sys (manual start)
@%SystemRoot%\System32\wfdsconmgrsvc.dll,-9000: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000: System32\drivers\wfplwfs.sys (system)
@%SystemRoot%\system32\wiarpc.dll,-2: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%SystemRoot%\system32\drivers\wimmount.sys,-101: system32\drivers\wimmount.sys (manual start)
Windows Trusted Execution Environment Class Extension: system32\drivers\WindowsTrustedRT.sys (system)
@WindowsTrustedRTProxy.inf,%WindowsTrustedRTProxy.SVCDESC%;Microsoft Windows Trusted Runtime Secure Service: System32\drivers\WindowsTrustedRTProxy.sys (system)
@%SystemRoot%\system32\winhttp.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@mlx4_bus.inf,%WinMad.ServiceDesc%;WinMad Service: \SystemRoot\System32\drivers\winmad.sys (manual start)
@%Systemroot%\system32\wbem\wmisvc.dll,-205: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@%SystemRoot%\system32\drivers\winnat.sys,-10001: system32\drivers\winnat.sys (manual start)
@%SystemRoot%\system32\drivers\winquic.sys,-1: system32\drivers\winquic.sys (manual start)
@winusb.inf,%WINUSB_SvcName%;WinUsb Driver: \SystemRoot\System32\drivers\WinUSB.SYS (manual start)
@mlx4_bus.inf,%WinVerbs.ServiceDesc%;WinVerbs Service: \SystemRoot\System32\drivers\winverbs.sys (manual start)
@%SystemRoot%\System32\wlansvc.dll,-257: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%SystemRoot%\system32\wlidsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@%SystemRoot%\system32\lpasvc.dll,-1000: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted -p (manual start)
@%systemroot%\system32\Windows.Management.Service.dll,-100: %systemroot%\system32\svchost.exe -k netsvcs -p (manual start)
@wmiacpi.inf,%WMIMAP.SvcDesc%;Microsoft Windows Management Interface for ACPI: \SystemRoot\System32\drivers\wmiacpi.sys (manual start)
@%Systemroot%\system32\wbem\wmiapsrv.exe,-110: %systemroot%\system32\wbem\WmiApSrv.exe (disabled)
@%SystemRoot%\system32\wpdbusenum.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start)
@%systemroot%\System32\drivers\WpdUpFltr.sys,-100: System32\drivers\WpdUpFltr.sys (manual start)
@%SystemRoot%\system32\wpnservice.dll,-1: %systemroot%\system32\svchost.exe -k netsvcs -p (autostart)
@%SystemRoot%\system32\WpnUserService.dll,-1: %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup (autostart)
Windows Push Notifications User Service_21363: C:\Windows\system32\svchost.exe -k UnistackSvcGroup (autostart)
@%systemroot%\System32\drivers\ws2ifsl.sys,-1000: \SystemRoot\system32\drivers\ws2ifsl.sys (disabled)
Windows Search: %systemroot%\system32\SearchIndexer.exe /Embedding (disabled)
Windows Update: %systemroot%\system32\svchost.exe -k netsvcs -p (disabled)
@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000: system32\drivers\WudfPf.sys (manual start)
@wpdfs.inf,%WPDFS_SvcName%;WPD File System driver: \SystemRoot\system32\DRIVERS\WUDFRd.sys (manual start)
WUDFWpdMtp: \SystemRoot\system32\DRIVERS\WUDFRd.sys (manual start)
@%SystemRoot%\System32\wwansvc.dll,-257: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted -p (manual start)
@%systemroot%\system32\xboxgipsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs -p (manual start)
@xinputhid.inf,%xinputhid.SvcDesc%;XINPUT HID Filter Driver: \SystemRoot\System32\drivers\xinputhid.sys (manual start)
--------------------------------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute =
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\Users\Doido\AppData\Local\Temp\20341483-971d-4583-9782-762070da52c9.tmp||C:\Users\Doido\AppData\Local\Temp\GoogleUpdate.execc60cd||C:\Users\Doido\AppData\Local\Temp\goopdate.dllcc60cd
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
*Registry key not found*
--------------------------------------------------
End of report, 59,132 bytes
Report generated in 0.063 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
PS: I have that file from autoruns, dont know where to upload
Edited by HiagoVieira, 23 October 2019 - 05:59 AM.



This topic is locked
Back to top







