Windows Registry Editor Version 5.00 ;Services Startup Configuration Backup 11/9/2012 1:04:49 AM [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdobeARMservice] "DisplayName"="Adobe Acrobat Update Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AeLookupSvc] "DisplayName"="@%SystemRoot%\system32\aelupsvc.dll,-1" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AESTFilters] "DisplayName"="Andrea ST Filters Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG] "DisplayName"="@%SystemRoot%\system32\Alg.exe,-112" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AMD External Events Utility] "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppHostSvc] "DisplayName"="@%windir%\system32\inetsrv\iisres.dll,-30011" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppIDSvc] "DisplayName"="@%systemroot%\system32\appidsvc.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Appinfo] "DisplayName"="@%systemroot%\system32\appinfo.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt] "DisplayName"="@appmgmts.dll,-3250" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspnet_state] "DisplayName"="ASP.NET State Service" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ATTRcAppSvc] "DisplayName"="AT&T RcAppSvc" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder] "DisplayName"="@%SystemRoot%\system32\audiosrv.dll,-204" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv] "DisplayName"="@%SystemRoot%\system32\audiosrv.dll,-200" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Autodesk Content Service] "DisplayName"="Autodesk Content Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Antivirus] "DisplayName"="avast! Antivirus" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AxInstSV] "DisplayName"="@%SystemRoot%\system32\AxInstSV.dll,-103" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BDESVC] "DisplayName"="@%SystemRoot%\system32\bdesvc.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bepldr6PixelPlanetService] "DisplayName"="BCL easyPDF SDK PixelPlanet 6 Loader" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE] "DisplayName"="@%SystemRoot%\system32\bfe.dll,-1001" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS] "DisplayName"="@%SystemRoot%\system32\qmgr.dll,-1000" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bluetooth Device Manager] "DisplayName"="Bluetooth Device Manager" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bluetooth Media Service] "DisplayName"="Bluetooth Media Service" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bluetooth OBEX Service] "DisplayName"="Bluetooth OBEX Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser] "DisplayName"="@%systemroot%\system32\browser.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bthserv] "DisplayName"="@%SystemRoot%\System32\bthserv.dll,-101" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CAATT] "DisplayName"="AT&T Con App Svc" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertPropSvc] "DisplayName"="@%SystemRoot%\System32\certprop.dll,-11" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CLHNServiceForPowerDVD12] "DisplayName"="CLHNServiceForPowerDVD12" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32] "DisplayName"="Microsoft .NET Framework NGEN v2.0.50727_X86" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_64] "DisplayName"="Microsoft .NET Framework NGEN v2.0.50727_X64" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_32] "DisplayName"="Microsoft .NET Framework NGEN v4.0.30319_X86" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_64] "DisplayName"="Microsoft .NET Framework NGEN v4.0.30319_X64" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSysApp] "DisplayName"="@comres.dll,-947" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc] "DisplayName"="@%SystemRoot%\system32\cryptsvc.dll,-1001" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CscService] "DisplayName"="@%systemroot%\system32\cscsvc.dll,-200" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch] "DisplayName"="@oleres.dll,-5012" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\defragsvc] "DisplayName"="@%SystemRoot%\system32\defragsvc.dll,-101" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp] "DisplayName"="@%SystemRoot%\system32\dhcpcore.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache] "DisplayName"="@%SystemRoot%\System32\dnsapi.dll,-101" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dot3svc] "DisplayName"="@%systemroot%\system32\dot3svc.dll,-1102" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DPS] "DisplayName"="@%systemroot%\system32\dps.dll,-500" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost] "DisplayName"="@%systemroot%\system32\eapsvc.dll,-1" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EFS] "DisplayName"="@%SystemRoot%\system32\efssvc.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ehRecvr] "DisplayName"="@%SystemRoot%\ehome\ehrecvr.exe,-101" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ehSched] "DisplayName"="@%SystemRoot%\ehome\ehsched.exe,-101" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eventlog] "DisplayName"="@%SystemRoot%\system32\wevtsvc.dll,-200" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem] "DisplayName"="@comres.dll,-2450" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fabs] "DisplayName"="FABS - Helping agent for MAGIX media database" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fax] "DisplayName"="@%systemroot%\system32\fxsresm.dll,-118" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fdPHost] "DisplayName"="@%systemroot%\system32\fdPHost.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FDResPub] "DisplayName"="@%systemroot%\system32\fdrespub.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FirebirdServerMAGIXInstance] "DisplayName"="Firebird Server - MAGIX Instance" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FLEXnet Licensing Service] "DisplayName"="FLEXnet Licensing Service" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FLEXnet Licensing Service 64] "DisplayName"="FLEXnet Licensing Service 64" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache] "DisplayName"="@%systemroot%\system32\FntCache.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0] "DisplayName"="@%SystemRoot%\system32\PresentationHost.exe,-3309" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gpsvc] "DisplayName"="@gpapi.dll,-112" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hidserv] "DisplayName"="@%SystemRoot%\System32\hidserv.dll,-101" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hkmsvc] "DisplayName"="@%SystemRoot%\system32\kmsvc.dll,-6" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupListener] "DisplayName"="@%SystemRoot%\System32\ListSvc.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HomeGroupProvider] "DisplayName"="@%SystemRoot%\System32\provsvc.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HP Wireless Assistant Service] "DisplayName"="HP Wireless Assistant Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HPDrvMntSvc.exe] "DisplayName"="HP Quick Synchronization Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpqwmiex] "DisplayName"="HP Software Framework Service" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpsrv] "DisplayName"="HP Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IAStorDataMgrSvc] "DisplayName"="Intel(R) Rapid Storage Technology" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\idsvc] "DisplayName"="@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IKEEXT] "DisplayName"="@%SystemRoot%\system32\ikeext.dll,-501" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPBusEnum] "DisplayName"="@%systemroot%\system32\IPBusEnum.dll,-102" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iphlpsvc] "DisplayName"="@%SystemRoot%\system32\iphlpsvc.dll,-500" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iprip] "DisplayName"="@%Systemroot%\system32\iprip.dll,-200" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KeyIso] "DisplayName"="@keyiso.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KMService] "DisplayName"="KMService" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KtmRm] "DisplayName"="KtmRm for Distributed Transaction Coordinator" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer] "DisplayName"="@%systemroot%\system32\srvsvc.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation] "DisplayName"="@%systemroot%\system32\wkssvc.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lltdsvc] "DisplayName"="@%SystemRoot%\system32\lltdres.dll,-1" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lmhosts] "DisplayName"="@%SystemRoot%\system32\lmhsvc.dll,-101" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LMS] "DisplayName"="Intel(R) Management and Security Application Local Management Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mcx2Svc] "DisplayName"="@%SystemRoot%\ehome\ehres.dll,-15501" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft SharePoint Workspace Audit Service] "DisplayName"="Microsoft SharePoint Workspace Audit Service" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS] "DisplayName"="@%systemroot%\system32\mmcss.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MozillaMaintenance] "DisplayName"="Mozilla Maintenance Service" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc] "DisplayName"="Windows Firewall" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC] "DisplayName"="@comres.dll,-2797" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSiSCSI] "DisplayName"="@%SystemRoot%\system32\iscsidsc.dll,-5000" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msiserver] "DisplayName"="@%SystemRoot%\system32\msimsg.dll,-27" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent] "DisplayName"="@%SystemRoot%\system32\qagentrt.dll,-6" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon] "DisplayName"="@%SystemRoot%\System32\netlogon.dll,-102" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman] "DisplayName"="@%SystemRoot%\system32\netman.dll,-109" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetMsmqActivator] "DisplayName"="@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetPipeActivator] "DisplayName"="@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netprofm] "DisplayName"="@%SystemRoot%\system32\netprofm.dll,-202" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetTcpActivator] "DisplayName"="@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing] "DisplayName"="@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8201" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc] "DisplayName"="@%SystemRoot%\System32\nlasvc.dll,-1" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nsi] "DisplayName"="@%SystemRoot%\system32\nsisvc.dll,-200" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ose64] "DisplayName"="Office 64 Source Engine" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\osppsvc] "DisplayName"="Office Software Protection Platform" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\p2pimsvc] "DisplayName"="@%SystemRoot%\system32\pnrpsvc.dll,-8004" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\p2psvc] "DisplayName"="@%SystemRoot%\system32\p2psvc.dll,-8006" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PcaSvc] "DisplayName"="@%SystemRoot%\system32\pcasvc.dll,-1" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PeerDistSvc] "DisplayName"="@%SystemRoot%\system32\peerdistsvc.dll,-9000" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfHost] "DisplayName"="@%systemroot%\sysWow64\perfhost.exe,-2" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pla] "DisplayName"="@%systemroot%\system32\pla.dll,-500" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlay] "DisplayName"="@%SystemRoot%\system32\umpnpmgr.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PNRPAutoReg] "DisplayName"="@%SystemRoot%\system32\pnrpauto.dll,-8002" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PNRPsvc] "DisplayName"="@%SystemRoot%\system32\pnrpsvc.dll,-8000" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent] "DisplayName"="@%SystemRoot%\System32\polstore.dll,-5010" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Power] "DisplayName"="@%SystemRoot%\system32\umpo.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProfSvc] "DisplayName"="@%systemroot%\system32\profsvc.dll,-300" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage] "DisplayName"="@%systemroot%\system32\psbase.dll,-300" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVE] "DisplayName"="@%SystemRoot%\system32\qwave.dll,-1" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto] "DisplayName"="@%Systemroot%\system32\rasauto.dll,-200" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan] "DisplayName"="@%Systemroot%\system32\rasmans.dll,-200" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess] "DisplayName"="@%Systemroot%\system32\mprdim.dll,-200" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry] "DisplayName"="@regsvc.dll,-1" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcEptMapper] "DisplayName"="@%windir%\system32\RpcEpMap.dll,-1001" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator] "DisplayName"="@%systemroot%\system32\Locator.exe,-2" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs] "DisplayName"="@oleres.dll,-5010" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs] "DisplayName"="@%SystemRoot%\system32\samsrv.dll,-1" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr] "DisplayName"="@%SystemRoot%\System32\SCardSvr.dll,-1" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule] "DisplayName"="@%SystemRoot%\system32\schedsvc.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCPolicySvc] "DisplayName"="@%SystemRoot%\System32\certprop.dll,-13" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SDRSVC] "DisplayName"="@%SystemRoot%\system32\sdrsvc.dll,-107" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon] "DisplayName"="@%SystemRoot%\system32\seclogon.dll,-7001" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS] "DisplayName"="@%SystemRoot%\system32\Sens.dll,-200" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SensrSvc] "DisplayName"="@%SystemRoot%\System32\sensrsvc.dll,-1000" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SessionEnv] "DisplayName"="@%SystemRoot%\System32\SessEnv.dll,-1026" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess] "DisplayName"="@%SystemRoot%\system32\ipnathlp.dll,-106" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection] "DisplayName"="@%SystemRoot%\System32\shsvcs.dll,-12288" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SkypeUpdate] "DisplayName"="Skype Updater" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMPTRAP] "DisplayName"="@%SystemRoot%\system32\snmptrap.exe,-3" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sppsvc] "DisplayName"="@%SystemRoot%\system32\sppsvc.exe,-101" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sppuinotify] "DisplayName"="@%SystemRoot%\system32\sppuinotify.dll,-103" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV] "DisplayName"="@%systemroot%\system32\ssdpsrv.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SstpSvc] "DisplayName"="@%SystemRoot%\system32\sstpsvc.dll,-200" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\STacSV] "DisplayName"="@%SystemRoot%\system32\stlang64.dll,-10101" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc] "DisplayName"="@%SystemRoot%\system32\wiaservc.dll,-9" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SwitchBoard] "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swprv] "DisplayName"="@%SystemRoot%\System32\swprv.dll,-103" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysMain] "DisplayName"="@%SystemRoot%\system32\sysmain.dll,-1000" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TabletInputService] "DisplayName"="@%SystemRoot%\system32\TabSvc.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv] "DisplayName"="@%SystemRoot%\system32\tapisrv.dll,-10100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TBS] "DisplayName"="@%SystemRoot%\system32\tbssvc.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService] "DisplayName"="@%SystemRoot%\System32\termsrv.dll,-268" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes] "DisplayName"="@%SystemRoot%\System32\themeservice.dll,-8192" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\THREADORDER] "DisplayName"="@%systemroot%\system32\mmcss.dll,-102" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks] "DisplayName"="@%SystemRoot%\system32\trkwks.dll,-1" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrustedInstaller] "DisplayName"="@%SystemRoot%\servicing\TrustedInstaller.exe,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UmRdpService] "DisplayName"="@%SystemRoot%\system32\umrdp.dll,-1000" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UNS] "DisplayName"="Intel(R) Management and Security Application User Notification Service" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost] "DisplayName"="@%systemroot%\system32\upnphost.dll,-213" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UxSms] "DisplayName"="@%SystemRoot%\system32\dwm.exe,-2000" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VaultSvc] "DisplayName"="@%SystemRoot%\system32\vaultsvc.dll,-1003" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vds] "DisplayName"="@%SystemRoot%\system32\vds.exe,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS] "DisplayName"="@%systemroot%\system32\vssvc.exe,-102" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time] "DisplayName"="@%SystemRoot%\system32\w32time.dll,-200" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WAS] "DisplayName"="@%windir%\system32\inetsrv\iisres.dll,-30001" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WatAdminSvc] "DisplayName"="@%SystemRoot%\system32\Wat\WatUX.exe,-601" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wbengine] "DisplayName"="@%systemroot%\system32\wbengine.exe,-104" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WbioSrvc] "DisplayName"="@%systemroot%\system32\wbiosrvc.dll,-100" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wcncsvc] "DisplayName"="@%SystemRoot%\system32\wcncsvc.dll,-3" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WcsPlugInService] "DisplayName"="@%SystemRoot%\system32\WcsPlugInService.dll,-200" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiServiceHost] "DisplayName"="@%systemroot%\system32\wdi.dll,-502" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiSystemHost] "DisplayName"="@%systemroot%\system32\wdi.dll,-500" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient] "DisplayName"="@%systemroot%\system32\webclnt.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wecsvc] "DisplayName"="@%SystemRoot%\system32\wecsvc.dll,-200" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wercplsupport] "DisplayName"="@%SystemRoot%\System32\wercplsupport.dll,-101" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WerSvc] "DisplayName"="@%SystemRoot%\System32\wersvc.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend] "DisplayName"="@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc] "DisplayName"="@%SystemRoot%\system32\winhttp.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winmgmt] "DisplayName"="@%Systemroot%\system32\wbem\wmisvc.dll,-205" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinRM] "DisplayName"="@%Systemroot%\system32\wsmsvc.dll,-101" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wlansvc] "DisplayName"="@%SystemRoot%\System32\wlansvc.dll,-257" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wmiApSrv] "DisplayName"="@%Systemroot%\system32\wbem\wmiapsrv.exe,-110" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WMPNetworkSvc] "DisplayName"="@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WPCSvc] "DisplayName"="@%SystemRoot%\system32\wpcsvc.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WPDBusEnum] "DisplayName"="@%SystemRoot%\system32\wpdbusenum.dll,-100" "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc] "DisplayName"="@%SystemRoot%\System32\wscsvc.dll,-200" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WSearch] "DisplayName"="@%systemroot%\system32\SearchIndexer.exe,-103" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv] "DisplayName"="@%systemroot%\system32\wuaueng.dll,-105" "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wudfsvc] "DisplayName"="@%SystemRoot%\system32\wudfsvc.dll,-1000" "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WwanSvc] "DisplayName"="@%SystemRoot%\System32\wwansvc.dll,-257" "Start"=dword:00000003