Registro de HijackThis - ayudar a eliminar la mala troyano
- bmd5782
- Born


- Registrado: May 06, 2009
- Mensajes: 3
- Status: Offline
Hola, acabo de apuntar, no sé mucho acerca de la programación a todos y fue la esperanza de que alguien podría ayudarme a entender mi registro de HijackThis. Estoy tratando de eliminar troyano Rootkit-Agent.DL desde un PC corriendo XP y mi investigación en Internet indica que este es un muy mala. el registro es similar al siguiente:
Plataforma: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Modo de arranque: Normal
Procesos que se están ejecutando:
C: \ WINDOWS \ System32 \ SMS. exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ Explorer.EXE
C: \ Archivos de programa \ Lavasoft \ Ad-Aware \ AAWService.exe
C: \ WINDOWS \ system32 \ Spoolsv.exe
C: \ WINDOWS \ system32 \ hkcmd.exe
C: \ Archivos de programa \ Microsoft Office \ Office12 \ GrooveMonitor.exe
C: \ Archivos de programa \ Lavasoft \ Ad-Aware \ AAWTray.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgtray. exe
C: \ WINDOWS \ system32 \ Ctfmon.exe
C: \ Archivos de programa \ ADN \ btdna.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgam.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgrsx.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgnsx.exe
C: \ Archivos de programa \ AVG \ AVG8 \ avgcsrvx.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ NOTEPAD.EXE
C: \ Archivos de programa \ AIM \ aim.exe
C: \ Archivos de programa \ Microsoft Office \ Office12 \ WINWORD.EXE
C: \ Archivos de programa \ AVG \ AVG8 \ avgcsrvx.exe
C: \ Archivos de programa \ Winamp \ winampa. exe
C: \ Archivos de programa \ Winamp \ winamp.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Archivos de programa \ AVG \ AVG8 \ avgcsrvx.exe
C: \ Archivos de programa \ Mozilla Firefox \ firefox.exe
C: \ WINDOWS \ system32 \ Taskmgr.exe
C: \ Archivos de programa \ Trend Micro \ HijackThis \ HijackThis. exe
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://google.atcomet.com/b/
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main Local Page =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main Local Page =
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyServer = http = localhost: 7171
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyOverride = *. local; <local>
R3 - URLSearchHook: Yahoo! Barra de Herramientas - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Archivos de programa \ Yahoo! \ Compañía \ instala \ CPN \ yt.dll
O2 - BHO: & Yahoo! Barra de Herramientas de Ayuda - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ Archivos de programa \ Yahoo! \ Compañía \ instala \ CPN \ yt.dll
O2 - BHO: BitComet ClickCapture - (39F7E362-828A-4B5A-BCAF-5B79BFDFEA60) - C: \ Archivos de programa \ BitComet \ tools \ BitCometBHO_1.3.3.2.dll
O3 - Toolbar: Yahoo! Barra de Herramientas - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Archivos de programa \ Yahoo! \ Compañía \ instala \ CPN \ yt.dll
O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ system32 \ igfxtray.exe
O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ system32 \ hkcmd.exe
O4 - HKLM \ .. \ Run: [Windows Defender] "C: \ Archivos de programa \ Windows Defender \ MSASCui.exe"-ocultar
O4 - HKLM \ .. \ Run: [GrooveMonitor] "C: \ Archivos de programa \ Microsoft Office \ Office12 \ GrooveMonitor.exe"
O4 - HKLM \ .. \ Run: [QuickTime Tarea] "C: \ Archivos de programa \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ Run: [TrojanScanner] C: \ Archivos de programa \ Trojan Remover \ Trjscan.exe / boot
O4 - HKLM \ .. \ Run: [Ad-Watch] C: \ Archivos de programa \ Lavasoft \ Ad-Aware \ AAWTray.exe
O4 - HKLM \ .. \ Run: [AVG8_TRAY] C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgtray.exe
O4 - HKLM \ .. \ Run: [WinampAgent] "C: \ Archivos de programa \ Winamp \ winampa.exe"
O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe
O4 - HKCU \ .. \ Run: [BitTorrent ADN] "C: \ Archivos de programa \ ADN \ btdna.exe"
O4 - de inicio: santa. murciélago
O8 - Extra menú contextual artículo: + D + ownload y con BitComet -- res://C : \ Archivos de programa \ BitComet \ BitComet.exe / AddLink.htm
O8 - Extra menú contextual artículo: + D + ownload video con todos los BitComet -- res://C : \ Archivos de programa \ BitComet \ BitComet.exe / AddVideo.htm
O8 - Extra menú contextual artículo: + D + ownload todos con BitComet -- res://C : \ Archivos de programa \ BitComet \ BitComet.exe / AddAllLink. htm
O8 - Extra menú contextual tema: E & xport a Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000
O9 - Extra botón: Enviar a OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra "Herramientas" menuitem: S & fin a OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE. dll
O9 - Extra botón: Investigación - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL
O9 - Extra botón: AIM - (AC9E2541-2814-11d5-BC6D-00B0D0A1DE45) - C: \ Archivos de programa \ AIM \ aim.exe
O9 - Extra botón: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) -- res://C : \ Archivos de programa \ BitComet \ tools \ BitCometBHO_1.3.3.2. dll/206 (archivo de desaparecidos)
O9 - Extra botón: (sin nombre) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Red de diagnóstico \ xpnetdiag.exe
O9 - Extra "Herramientas" menuitem: @ Xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Red de diagnóstico \ xpnetdiag.exe
O9 - Extra botón: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Archivos de programa \ Messenger \ msmsgs. exe
O9 - Extra "Herramientas" menuitem: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Archivos de programa \ Messenger \ msmsgs.exe
O18 - Protocolo: grooveLocalGWS - (88FED34C-F0CA-4636-A375-3CB6248B04CD) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ GR99D3 ~ 1.DLL
O18 - Protocolo: linkscanner - (F274614C-63F8-47D5-A4D1-FBDDE494F8D1) - C: \ Archivos de programa \ AVG \ AVG8 \ avgpp.dll
O20 - Winlogon Notificar: avgrsstarter - C: \ WINDOWS \ SYSTEM32 \ avgrsstx. dll
O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - (C2BA40A1-74F3-42BD-F434-12345A2C8953) - (no file)
O23 - Servicio: AVG8 WatchDog (avg8wd) - AVG Tecnologías CZ, sro - C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe
O23 - Servicio: Servicio de transferencia inteligente en segundo plano (BITS) - Desconocido propietario - C: \ WINDOWS \
O23 - Servicio: getPlus (R) de Ayuda - NOS Microsystems Ltd. - C: \ Archivos de programa \ NOS \ bin \ getPlus_HelperSvc. exe
O23 - Servicio: Lavasoft Ad-Aware Service (Lavasoft Ad-Aware de servicio) - Lavasoft - C: \ Archivos de programa \ Lavasoft \ Ad-Aware \ AAWService. exe
O23 - Servicio: Actualizaciones automáticas (wuauserv) - Desconocido propietario - C: \ WINDOWS \
ar ya ejecutar varias cosas como TrojanRemover, RegCure, un par de antivirus diferentes progs...pero yo realmente no tienen una comprensión suficiente de saber sobre la programación de HijackThis mirando un registro de lo que es lo que, y lo que está bien para eliminar vs lo que no, y appare notly este prog es el único ahí fuera que pueden matar a severa - riesgo de troyanos como este. si alguien puede ayudar a ser itd oleaje! gracias de antemano
Plataforma: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Modo de arranque: Normal
Procesos que se están ejecutando:
C: \ WINDOWS \ System32 \ SMS. exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ Explorer.EXE
C: \ Archivos de programa \ Lavasoft \ Ad-Aware \ AAWService.exe
C: \ WINDOWS \ system32 \ Spoolsv.exe
C: \ WINDOWS \ system32 \ hkcmd.exe
C: \ Archivos de programa \ Microsoft Office \ Office12 \ GrooveMonitor.exe
C: \ Archivos de programa \ Lavasoft \ Ad-Aware \ AAWTray.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgtray. exe
C: \ WINDOWS \ system32 \ Ctfmon.exe
C: \ Archivos de programa \ ADN \ btdna.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgam.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgrsx.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgnsx.exe
C: \ Archivos de programa \ AVG \ AVG8 \ avgcsrvx.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ NOTEPAD.EXE
C: \ Archivos de programa \ AIM \ aim.exe
C: \ Archivos de programa \ Microsoft Office \ Office12 \ WINWORD.EXE
C: \ Archivos de programa \ AVG \ AVG8 \ avgcsrvx.exe
C: \ Archivos de programa \ Winamp \ winampa. exe
C: \ Archivos de programa \ Winamp \ winamp.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Archivos de programa \ AVG \ AVG8 \ avgcsrvx.exe
C: \ Archivos de programa \ Mozilla Firefox \ firefox.exe
C: \ WINDOWS \ system32 \ Taskmgr.exe
C: \ Archivos de programa \ Trend Micro \ HijackThis \ HijackThis. exe
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://google.atcomet.com/b/
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main Local Page =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main Local Page =
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyServer = http = localhost: 7171
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyOverride = *. local; <local>
R3 - URLSearchHook: Yahoo! Barra de Herramientas - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Archivos de programa \ Yahoo! \ Compañía \ instala \ CPN \ yt.dll
O2 - BHO: & Yahoo! Barra de Herramientas de Ayuda - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ Archivos de programa \ Yahoo! \ Compañía \ instala \ CPN \ yt.dll
O2 - BHO: BitComet ClickCapture - (39F7E362-828A-4B5A-BCAF-5B79BFDFEA60) - C: \ Archivos de programa \ BitComet \ tools \ BitCometBHO_1.3.3.2.dll
O3 - Toolbar: Yahoo! Barra de Herramientas - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Archivos de programa \ Yahoo! \ Compañía \ instala \ CPN \ yt.dll
O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ system32 \ igfxtray.exe
O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ system32 \ hkcmd.exe
O4 - HKLM \ .. \ Run: [Windows Defender] "C: \ Archivos de programa \ Windows Defender \ MSASCui.exe"-ocultar
O4 - HKLM \ .. \ Run: [GrooveMonitor] "C: \ Archivos de programa \ Microsoft Office \ Office12 \ GrooveMonitor.exe"
O4 - HKLM \ .. \ Run: [QuickTime Tarea] "C: \ Archivos de programa \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ Run: [TrojanScanner] C: \ Archivos de programa \ Trojan Remover \ Trjscan.exe / boot
O4 - HKLM \ .. \ Run: [Ad-Watch] C: \ Archivos de programa \ Lavasoft \ Ad-Aware \ AAWTray.exe
O4 - HKLM \ .. \ Run: [AVG8_TRAY] C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgtray.exe
O4 - HKLM \ .. \ Run: [WinampAgent] "C: \ Archivos de programa \ Winamp \ winampa.exe"
O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe
O4 - HKCU \ .. \ Run: [BitTorrent ADN] "C: \ Archivos de programa \ ADN \ btdna.exe"
O4 - de inicio: santa. murciélago
O8 - Extra menú contextual artículo: + D + ownload y con BitComet -- res://C : \ Archivos de programa \ BitComet \ BitComet.exe / AddLink.htm
O8 - Extra menú contextual artículo: + D + ownload video con todos los BitComet -- res://C : \ Archivos de programa \ BitComet \ BitComet.exe / AddVideo.htm
O8 - Extra menú contextual artículo: + D + ownload todos con BitComet -- res://C : \ Archivos de programa \ BitComet \ BitComet.exe / AddAllLink. htm
O8 - Extra menú contextual tema: E & xport a Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000
O9 - Extra botón: Enviar a OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra "Herramientas" menuitem: S & fin a OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE. dll
O9 - Extra botón: Investigación - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL
O9 - Extra botón: AIM - (AC9E2541-2814-11d5-BC6D-00B0D0A1DE45) - C: \ Archivos de programa \ AIM \ aim.exe
O9 - Extra botón: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) -- res://C : \ Archivos de programa \ BitComet \ tools \ BitCometBHO_1.3.3.2. dll/206 (archivo de desaparecidos)
O9 - Extra botón: (sin nombre) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Red de diagnóstico \ xpnetdiag.exe
O9 - Extra "Herramientas" menuitem: @ Xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Red de diagnóstico \ xpnetdiag.exe
O9 - Extra botón: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Archivos de programa \ Messenger \ msmsgs. exe
O9 - Extra "Herramientas" menuitem: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Archivos de programa \ Messenger \ msmsgs.exe
O18 - Protocolo: grooveLocalGWS - (88FED34C-F0CA-4636-A375-3CB6248B04CD) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ GR99D3 ~ 1.DLL
O18 - Protocolo: linkscanner - (F274614C-63F8-47D5-A4D1-FBDDE494F8D1) - C: \ Archivos de programa \ AVG \ AVG8 \ avgpp.dll
O20 - Winlogon Notificar: avgrsstarter - C: \ WINDOWS \ SYSTEM32 \ avgrsstx. dll
O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - (C2BA40A1-74F3-42BD-F434-12345A2C8953) - (no file)
O23 - Servicio: AVG8 WatchDog (avg8wd) - AVG Tecnologías CZ, sro - C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe
O23 - Servicio: Servicio de transferencia inteligente en segundo plano (BITS) - Desconocido propietario - C: \ WINDOWS \
O23 - Servicio: getPlus (R) de Ayuda - NOS Microsystems Ltd. - C: \ Archivos de programa \ NOS \ bin \ getPlus_HelperSvc. exe
O23 - Servicio: Lavasoft Ad-Aware Service (Lavasoft Ad-Aware de servicio) - Lavasoft - C: \ Archivos de programa \ Lavasoft \ Ad-Aware \ AAWService. exe
O23 - Servicio: Actualizaciones automáticas (wuauserv) - Desconocido propietario - C: \ WINDOWS \
ar ya ejecutar varias cosas como TrojanRemover, RegCure, un par de antivirus diferentes progs...pero yo realmente no tienen una comprensión suficiente de saber sobre la programación de HijackThis mirando un registro de lo que es lo que, y lo que está bien para eliminar vs lo que no, y appare notly este prog es el único ahí fuera que pueden matar a severa - riesgo de troyanos como este. si alguien puede ayudar a ser itd oleaje! gracias de antemano
- Anonymous
- Bot


- Registrado: 25 Feb 2008
- Mensajes: ?
- Loc: Ozzuland
- Status: Online
Mayo 6th, 2009, 3:20 pm
- Don2007
- Web Master


- Registrado: Nov 21, 2006
- Mensajes: 4924
- Loc: NY
- Status: Offline
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyServer = http = localhost: 7171
¿Te ha establecido que los representantes y puerto ^ ^?
O4 - de inicio: santa.bat
O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - (C2BA40A1-74F3-42BD-F434-12345A2C8953) - (no file)
Si no utiliza bits torrente, que unistall.
¿Te ha establecido que los representantes y puerto ^ ^?
O4 - de inicio: santa.bat
O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - (C2BA40A1-74F3-42BD-F434-12345A2C8953) - (no file)
Si no utiliza bits torrente, que unistall.
How do you know when a politician is lying? His mouth is moving.
- bmd5782
- Born


- Registrado: May 06, 2009
- Mensajes: 3
- Status: Offline
- Don2007
- Web Master


- Registrado: Nov 21, 2006
- Mensajes: 4924
- Loc: NY
- Status: Offline
- bmd5782
- Born


- Registrado: May 06, 2009
- Mensajes: 3
- Status: Offline
i ha descargado jv16 Power Tools
Ive es el asesoramiento recibido de un foro:
"Si no se está ejecutando svchost.exe de c: \ winnt \ system32 en Win NT 4.0 y
2k ganar o c: \ windows \ system32 Win XP y Win 2K3, es un troyano y como es
simple como eso. "
este es un registro que guardan la ejecución de una búsqueda de Power Tools svchost.exe:
HKLM \ SYSTEM \ ControlSet001 \ Services \ xmlprov \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ wzcsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ wudfsvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k WudfServiceGroup, 07/04/2009, 17:52
HKLM \ SYSTEM \ ControlSet001 \ Services \ wuauserv \, ImagePath,% fystemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ wscsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ WMI \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ wmdmpmsn \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ winmgmt \, ImagePath,% systemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ WebClient \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06. 05.2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ W32Time \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ upnphost \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ trkwks \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ temas \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06. 05.2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ tapisrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ stisvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k imgsvc, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ ssdpsrv \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ srservice \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ shellhwdetection \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ SharedAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ sentido \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ seclogon \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ Schedule \ ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ remoteregistry \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ RemoteAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:54
HKLM \ SYSTEM \ ControlSet001 \ Services \ RasMan \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ rasauto \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ ntmssvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ NLA \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ netman \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ napagent \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ ControlSet001 \ Services \ Messenger \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ lmhosts \ ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06. 05.2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ lanmanworkstation \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ LanmanServer \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ httpfilter \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k HTTPFilter, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ hkmsvc \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ ControlSet001 \ Services \ hidserv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ helpsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ fastuserswitchingcompatibility \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ eventsystem \ ImagePath, C: \ WINDOWS \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ ersvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ eaphost \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k eapsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ ControlSet001 \ Services \ dot3svc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k dot3svc, 07.04. 2009, 15:49
HKLM \ SYSTEM \ ControlSet001 \ Services \ Dnscache \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k NetworkService, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ dmserver \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ dhcp \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ cryptsvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06. 05.2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ Browser \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ services \ bits \, ImagePath,% fystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ audiosrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ appmgmt \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ alerta \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ xmlprov \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wzcsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wudfsvc \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k WudfServiceGroup, 07/04/2009, 17:52
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wuauserv \, ImagePath,% fystemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wscsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ WMI \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wmdmpmsn \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ winmgmt \, ImagePath,% systemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ WebClient \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ W32Time \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ upnphost \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ trkwks \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ temas \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ tapisrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ stisvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k imgsvc, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ ssdpsrv \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ srservice \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ shellhwdetection \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ SharedAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ sentido \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ seclogon \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ calendario \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ remoteregistry \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ RemoteAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:54
HKLM \ SYSTEM \ CurrentControlSet \ Services \ RasMan \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ rasauto \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ ntmssvc \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ NLA \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ netman \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ napagent \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:49
HKLM \ SYSTEM \ CurrentControlSet \ Services \ Messenger \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ lmhosts \ ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ lanmanworkstation \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ lanmanserver \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ httpfilter \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k HTTPFilter, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ hkmsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ CurrentControlSet \ Services \ hidserv \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ helpsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ fastuserswitchingcompatibility \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ eventsystem \ ImagePath, C: \ WINDOWS \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ ersvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ eaphost \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k eapsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ CurrentControlSet \ Services \ dot3svc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k dot3svc, 07/04/2009, 15:49
HKLM \ SYSTEM \ CurrentControlSet \ Services \ Dnscache \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k NetworkService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ dmserver \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ dhcp \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ cryptsvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ navegador, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ bits \, ImagePath,% fystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ audiosrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ appmgmt \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ alerta \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ xmlprov \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ wzcsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ wudfsvc \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k WudfServiceGroup, 07/04/2009, 17:52
HKLM \ system \ controlset003 \ Services \ wuauserv \, ImagePath,% fystemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ wscsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ WMI \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ system \ controlset003 \ services \ wmdmpmsn \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ winmgmt \, ImagePath,% systemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ WebClient \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ W32Time \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ system \ controlset003 \ services \ upnphost \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ trkwks \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ temas \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ tapisrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06. 05.2009, 11:29
HKLM \ system \ controlset003 \ services \ stisvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k imgsvc, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ ssdpsrv \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ srservice \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ shellhwdetection \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ SharedAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ sentido \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ seclogon \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ Schedule \ ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ remoteregistry \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ RemoteAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:54
HKLM \ system \ controlset003 \ Services \ RasMan \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ system \ controlset003 \ services \ rasauto \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ ntmssvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ NLA \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ netman \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ system \ controlset003 \ services \ napagent \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:49
HKLM \ system \ controlset003 \ Services \ Messenger \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ lmhosts \ ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ lanmanworkstation \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ LanmanServer \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ httpfilter \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k HTTPFilter, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ hkmsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:49
HKLM \ system \ controlset003 \ services \ hidserv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ helpsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ fastuserswitchingcompatibility \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ eventsystem \ ImagePath, C: \ WINDOWS \ system32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ ersvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ eaphost \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k eapsvcs, 07/04/2009, 15:49
HKLM \ system \ controlset003 \ services \ dot3svc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k dot3svc, 07/04/2009, 15:49
HKLM \ system \ controlset003 \ Services \ Dnscache \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k NetworkService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ dmserver \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ dhcp \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ cryptsvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ system \ controlset003 \ Services \ Browser \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ bits \, ImagePath,% fystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ audiosrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ appmgmt \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ system \ controlset003 \ services \ alerta \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 07/04/2009, 15:37
HKCR \ CLSID \ (e9376cc6-121a-447e-81cf-d8bcc200007c) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 07/04/2009, 01:35
HKLM \ SOFTWARE \ Classes \ CLSID \ (e9376cc6-121a-447e-81cf-d8bcc200007c) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 07-04. 2009, 01:35
HKLM \ SOFTWARE \ Classes \ CLSID \ (a1f4e726-8cf1-11d1-bf92-0060081ed811) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 06/04/2009, 21:24
HKLM \ SOFTWARE \ Classes \ CLSID \ (a1e75357-881a-419e-83e2-bb16db197c68) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 06/04/2009, 21:24
HKCR \ CLSID \ (a1f4e726-8cf1-11d1-bf92-0060081ed811) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 06.04. 2009, 21:24
HKCR \ CLSID \ (a1e75357-881a-419e-83e2-bb16db197c68) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 06/04/2009, 21:24
como pueden ver, tengo una gran cantidad de los ingresos derivados de esa búsqueda de mi registro, y sólo los últimos son de la carpeta C: \ WINDOWS \ system32...significa esto debo borrar todos los otros procesos? Hay, evidentemente, mucho, sin duda más que ver Im que se ejecuta en el Administrador de tareas...
Ive es el asesoramiento recibido de un foro:
"Si no se está ejecutando svchost.exe de c: \ winnt \ system32 en Win NT 4.0 y
2k ganar o c: \ windows \ system32 Win XP y Win 2K3, es un troyano y como es
simple como eso. "
este es un registro que guardan la ejecución de una búsqueda de Power Tools svchost.exe:
HKLM \ SYSTEM \ ControlSet001 \ Services \ xmlprov \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ wzcsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ wudfsvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k WudfServiceGroup, 07/04/2009, 17:52
HKLM \ SYSTEM \ ControlSet001 \ Services \ wuauserv \, ImagePath,% fystemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ wscsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ WMI \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ wmdmpmsn \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ winmgmt \, ImagePath,% systemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ WebClient \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06. 05.2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ W32Time \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ upnphost \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ trkwks \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ temas \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06. 05.2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ tapisrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ stisvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k imgsvc, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ ssdpsrv \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ srservice \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ shellhwdetection \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ SharedAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ sentido \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ seclogon \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ Schedule \ ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ remoteregistry \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ RemoteAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:54
HKLM \ SYSTEM \ ControlSet001 \ Services \ RasMan \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ rasauto \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ ntmssvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ NLA \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ netman \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ napagent \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ ControlSet001 \ Services \ Messenger \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ lmhosts \ ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06. 05.2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ lanmanworkstation \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ LanmanServer \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ httpfilter \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k HTTPFilter, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ hkmsvc \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ ControlSet001 \ Services \ hidserv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ helpsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ fastuserswitchingcompatibility \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ eventsystem \ ImagePath, C: \ WINDOWS \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ ersvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ eaphost \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k eapsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ ControlSet001 \ Services \ dot3svc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k dot3svc, 07.04. 2009, 15:49
HKLM \ SYSTEM \ ControlSet001 \ Services \ Dnscache \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k NetworkService, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ dmserver \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ dhcp \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ cryptsvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06. 05.2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ Browser \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ services \ bits \, ImagePath,% fystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ audiosrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ ControlSet001 \ Services \ appmgmt \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ SYSTEM \ ControlSet001 \ Services \ alerta \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ xmlprov \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wzcsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wudfsvc \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k WudfServiceGroup, 07/04/2009, 17:52
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wuauserv \, ImagePath,% fystemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wscsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ WMI \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ wmdmpmsn \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ winmgmt \, ImagePath,% systemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ WebClient \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ W32Time \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ upnphost \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ trkwks \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ temas \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ tapisrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ stisvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k imgsvc, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ ssdpsrv \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ srservice \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ shellhwdetection \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ SharedAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ sentido \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ seclogon \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ calendario \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ remoteregistry \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ RemoteAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:54
HKLM \ SYSTEM \ CurrentControlSet \ Services \ RasMan \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ rasauto \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ ntmssvc \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ NLA \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ netman \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ napagent \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:49
HKLM \ SYSTEM \ CurrentControlSet \ Services \ Messenger \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ lmhosts \ ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ lanmanworkstation \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ lanmanserver \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ httpfilter \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k HTTPFilter, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ hkmsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ CurrentControlSet \ Services \ hidserv \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ helpsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ fastuserswitchingcompatibility \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ eventsystem \ ImagePath, C: \ WINDOWS \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ ersvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ eaphost \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k eapsvcs, 07/04/2009, 15:49
HKLM \ SYSTEM \ CurrentControlSet \ Services \ dot3svc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k dot3svc, 07/04/2009, 15:49
HKLM \ SYSTEM \ CurrentControlSet \ Services \ Dnscache \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k NetworkService, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ dmserver \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ dhcp \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ cryptsvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ navegador, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ bits \, ImagePath,% fystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ audiosrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ SYSTEM \ CurrentControlSet \ Services \ appmgmt \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k netsvcs, 07/04/2009, 15:37
HKLM \ SYSTEM \ CurrentControlSet \ Services \ alerta \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ xmlprov \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ wzcsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ wudfsvc \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k WudfServiceGroup, 07/04/2009, 17:52
HKLM \ system \ controlset003 \ Services \ wuauserv \, ImagePath,% fystemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ wscsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ WMI \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ system \ controlset003 \ services \ wmdmpmsn \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ winmgmt \, ImagePath,% systemroot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ WebClient \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ W32Time \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ system \ controlset003 \ services \ upnphost \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ trkwks \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ temas \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ tapisrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06. 05.2009, 11:29
HKLM \ system \ controlset003 \ services \ stisvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k imgsvc, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ ssdpsrv \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ srservice \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ shellhwdetection \, ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ SharedAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ sentido \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ seclogon \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ Schedule \ ImagePath,% SystemRoot% \ System32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ remoteregistry \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ RemoteAccess \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:54
HKLM \ system \ controlset003 \ Services \ RasMan \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ system \ controlset003 \ services \ rasauto \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ ntmssvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ NLA \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ netman \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ system \ controlset003 \ services \ napagent \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:49
HKLM \ system \ controlset003 \ Services \ Messenger \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ lmhosts \ ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ lanmanworkstation \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ Services \ LanmanServer \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ httpfilter \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k HTTPFilter, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ hkmsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:49
HKLM \ system \ controlset003 \ services \ hidserv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ helpsvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ fastuserswitchingcompatibility \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ eventsystem \ ImagePath, C: \ WINDOWS \ system32 \ svchost. exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ ersvc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ eaphost \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k eapsvcs, 07/04/2009, 15:49
HKLM \ system \ controlset003 \ services \ dot3svc \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k dot3svc, 07/04/2009, 15:49
HKLM \ system \ controlset003 \ Services \ Dnscache \, ImagePath,% SystemRoot% \ system32 \ svchost. exe-k NetworkService, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ dmserver \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 07/04/2009, 15:37
HKLM \ system \ controlset003 \ services \ dhcp \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ cryptsvc \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06.05. 2009, 11:29
HKLM \ system \ controlset003 \ Services \ Browser \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ bits \, ImagePath,% fystemRoot% \ system32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ audiosrv \, ImagePath,% SystemRoot% \ System32 \ svchost.exe-k netsvcs, 06/05/2009, 11:29
HKLM \ system \ controlset003 \ services \ appmgmt \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k netsvcs, 07-04. 2009, 15:37
HKLM \ system \ controlset003 \ services \ alerta \, ImagePath,% SystemRoot% \ system32 \ svchost.exe-k LocalService, 07/04/2009, 15:37
HKCR \ CLSID \ (e9376cc6-121a-447e-81cf-d8bcc200007c) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 07/04/2009, 01:35
HKLM \ SOFTWARE \ Classes \ CLSID \ (e9376cc6-121a-447e-81cf-d8bcc200007c) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 07-04. 2009, 01:35
HKLM \ SOFTWARE \ Classes \ CLSID \ (a1f4e726-8cf1-11d1-bf92-0060081ed811) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 06/04/2009, 21:24
HKLM \ SOFTWARE \ Classes \ CLSID \ (a1e75357-881a-419e-83e2-bb16db197c68) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 06/04/2009, 21:24
HKCR \ CLSID \ (a1f4e726-8cf1-11d1-bf92-0060081ed811) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 06.04. 2009, 21:24
HKCR \ CLSID \ (a1e75357-881a-419e-83e2-bb16db197c68) \ LocalServer32 \, @, C: \ WINDOWS \ system32 \ svchost.exe, 06/04/2009, 21:24
como pueden ver, tengo una gran cantidad de los ingresos derivados de esa búsqueda de mi registro, y sólo los últimos son de la carpeta C: \ WINDOWS \ system32...significa esto debo borrar todos los otros procesos? Hay, evidentemente, mucho, sin duda más que ver Im que se ejecuta en el Administrador de tareas...
- grinch2171
- Moderator


- Registrado: Feb 11, 2004
- Mensajes: 6740
- Loc: Martinsburg, WV
- Status: Offline
Página 1 de 1
Para responder a este tema que necesita para ingresar o registrarse. Es gratis.
Publicar Información
- Total de mensajes en este tema: 6 mensajes
- Usuarios navegando por este Foro: No hay usuarios registrados visitando el Foro y 133 invitados
- No puede abrir nuevos temas en este Foro
- No puede responder a temas en este Foro
- No puede editar sus mensajes en este Foro
- No puede borrar sus mensajes en este Foro
- No puede enviar adjuntos en este Foro
