查杀新变种3448的办法 及 查杀后不能进入安全模式的修复办法
Sm w3L7. oZ_
YB-F$ f_zr()QN ~Ozr;sH8 最近两天来新变种3448爆发,病毒特征:不能安装360安全卫士。
oD"8SV$ WKc.Z]l3 修复工具:1、System Repair Engineer(SREng)的扫描报告;
@FVRh 2、unlocker 用于删除病毒文件。
oudO:`&pt 3-$,y{ aO1[O oH. 在 System Repair Engineer(SREng)的扫描报告中查找病毒文件的办法:
G75ZnxDA x>KEXaQNKQ 在“正在运行的进程”下面查找注入到进程的dll文件:以★嘎嘎★的报告为例(比较典型)
[H.ra#0R| 9Dg>E)" [PID: 532][C:\WINDOWS\system32\k6s.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
iU@MYo0r1 [C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
`R;/Z)THY [C:\WINDOWS\system32\rdzl7.dll] [N/A, N/A]
t4*DI4# '`;4Y4J\t 这个进程和附带的两个文件就是病毒。一般nmprt.sys是昨天发现的共有名称,但今天的报告中发现了随机名字的sys文件。但这3个病毒文件的存放路径是固定的。
2L(ORl!(4 exe文件的名字和位数不固定,特征是包含数字。
I/|z
l< dll文件是5位包含数字的随机名字。
VdTM|xK? 这个exe进程下可能还寄生其他的dll文件,最典型的就是cnnic的dll文件。本文不讨论cnnic.
%j;jbCd dll文件的特征是同时注入到其他进程下,几乎每个进程都有他们的踪迹:比如C:\WINDOWS\Explorer.EXE进程、rundll32.exe、ctfmon.exe下肯定有。
6/qalUPG 0BVu#X( R 快速判定以上病毒文件的办法是用百度搜索一下文件名字,一般不会有搜索结果的定是病毒无疑。
ot93 CVR AQZ>0WK 删除病毒文件不用到安全模式(也进不去),用unlocker即可删除。一次删除不了请重新安装unlocker或重起,多试几次就删掉了。
?EGb0 EJ 具体下载地址和教程:
http://btbaicai.com/read-htm-tid-661.html c&8I5se Gy
o .2 }.F[v\| 删除病毒文件后的后遗症是不能进安全模式,原因是病毒文件吧关键的安全模式需要加载的注册表项删除了,请下载以下文件解压后双击,导入注册表即可。
~^w1>C? 请把下面内容另存为任意reg文件,然后双击导入注册表即可.
hj(gd^9* JrQVecEf V!R^D9/( p;z@E&. Windows Registry Editor Version 5.00
t|Q3Z ')A{Ai [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
sX[lZy* "AlternateShell"="cmd.exe"
GGhSI~ :wID&SU [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal]
QX_@nBS~ ,a03C]U [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
OQr[p @="Service"
H-p*h &MwRs, [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
*!ww"v1 @="Driver Group"
SJ~Iy!qPps bZsBbfq= [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
Ws$-rFnzV @="Driver Group"
- H,<zkQ: /t|z"']4 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
F}^pL(,-`a @="Driver Group"
^BEF;4J=D uOn?X8.g. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
s{c!=," @="Service"
DMW:0b3 (p-~.B;), [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
cb~+{f<1| @="Service"
s-b(?o0. P:(bsh,l [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin]
bUuSx'Js @="Service"
147Oy wy?x`F|| [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys]
@.ZN1 ;9J @="Driver"
h?>TApO ?vY!$\ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys]
j5 @T$6N @="Driver"
0>VNZ
:,P @Nx~ &[: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys]
`"W.'xn&C @="Driver"
5O@-nnC+ xj;Pq'gTL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver]
DM\mg[s, @="Service"
'w0'D] NHxVWaR [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
.r}(&^Krd @="Service"
O}qi<- m;!-V= [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
Czm8
fM:M @="Driver Group"
&Ku
m45 LoX()M [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
uM&b*skCO5 @="Driver Group"
y%@p~qZaK *c9[OoD" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
~_fm=4m~ @="Service"
awz_p& N;Hc'%+I [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
11nmPf @="Service"
i=~c997; \dTqb%AN [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
\b#@2$t @="Driver Group"
3~6Ls6 pb_-%Q.C [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
MAXCZzcXW @="Service"
+{D<"Q l8a&?5TVM [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
PGLi(D;XT @="Driver Group"
C7Ky.3I6J 4 $|yv1r [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
P
*GtQ @="Driver Group"
_E 4eJZ|L jG3Cu|RA [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
uV=DWw`W @="Service"
(rh;;ci|K r=A5F~6w [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
D+@g|)/" @="Driver Group"
`fh$ocM#< b4CgG]}v [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
+.$_RTsIf @="Driver"
y=l'86s^ *OHG;Z2 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
k0A3B-^x @="FSFilter System Recovery"
~P,3E&
,ME>|{W [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
VF>M<ZY1 @="Service"
RbA`t7eC >\Wm~V# [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
L-WH @="Driver Group"
O%$z*1zL JK0Ym@d(^W [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys]
r[j1Tiu@ @="Driver"
$FY<"MoG CTVpp'a{ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
KC[zhsB @="Driver"
k*xeIW
m ,FNF@qfk [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
:~kn%W @="Service"
K~5W"O/ >&iG5fU
a [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
"EUH5,
\ @="Universal Serial Bus controllers"
l
Cl+4d ZQ6m)P3$l [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
Ky5hl @="CD-ROM Drive"
C1z[@}Tr WndDjM~a [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
rf?eGG{8Eh @="DiskDrive"
sE?.WWU] Yrj+d7 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
Pz0~j{ ){y @="Standard floppy disk controller"
G oyjxQ+ . re{,(W [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
LYgowT-,X @="Hdc"
R3`DXg iykt [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
p\]'zxa @="Keyboard"
J5C') - \nqR]mX [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
v(
w%u# @="Mouse"
z<1Z(ym O4l9a6*gU [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
g^P+ndE)- @="PCMCIA Adapters"
h F5}?v@* bUI=1GAMh [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
=OcPbxT x @="SCSIAdapter"
Y0&5*)<~ $iF@R [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
;rM06buk @="System"
|L5M#qOvb h#= [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
DWax)*q}C` @="Floppy disk drive"
s{j8o[:+ p`%`<W [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
~mQz~E: @="Volume"
vlG-+9^ %U59.4a [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
Bj}`!=^u/ @="Human Interface Devices"
\pV{<v6 z!~@Eek=R [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network]
"A*x4_(/ @+QO2%6/ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD]
8SqAJo}E @="Service"
9Zyp3$ o2\ffv] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt]
lmEd{ppf @="Service"
h"|Uyv),s <J/_Opnh [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base]
[LsX^+ @="Driver Group"
dQ":]8q" x{R]-- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender]
u7YlKpf @="Driver Group"
:fvK$$f# }z|IdPm [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system]
7[kmQq;" @="Driver Group"
&T-{S
TG \DhD e [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser]
I~[tv`$? @="Service"
s?G
bfMo "aG:P36x! [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc]
%T(7|R)@ @="Service"
f%\H_s .isaDkqE [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch]
L0(4EaCP\ @="Service"
n 5\3iA9~ 9\2J-]ZJ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp]
YJ}u$lc @="Service"
>Gd3W}2\J kaH/q$7. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadmin]
rCv>.$ l @="Service"
>tI-y(Px kDuXZUS~M [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sys]
5<C|p)5 @="Driver"
q8)2}# C20q| [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sys]
`~Dl6mOh @="Driver"
vaQ:{5L9> hyxnyIP%E [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sys]
=nH/!9z @="Driver"
^u 'wP' }{4,?E7h9 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserver]
d;r#y5) @="Service"
hggB7? dk]|vEs [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache]
@Pr2&<TM @="Service"
C Ybdh"S 'fi*'&H [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog]
J3EL1|:F @="Service"
>?KXJ&l@ Q,7'%Jkp* [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system]
1v}14D @="Driver Group"
@Rp(`miK hs*J{pr@_ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter]
(yM/c)Gs @="Driver Group"
DUO}:&63z C9#VAzHPX [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc]
;(&rU/Uh @="Service"
"Z 4%ra1+> |bo1Z? [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sys]
*$,H @="Driver"
NXs<j}qC< V&kW&z* [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys]
kc\O!v\Q @="Driver"
=#d9jP, uuO)k> [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer]
) qP anus @="Service"
Bcl$~N :L(T"lHL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation]
CbZh5)/ @="Service"
8ae]: Iq5j? [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts]
q_nGVn @="Service"
_O{-;y1h) VTtk* I [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger]
$y4{r[PGt @="Service"
Oy!]4r)wg E#=6)2e2xi [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS]
D0?aJz]-BU @="Driver Group"
HCRl
iE= ga+TbyV`8 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper]
E<Lo
}b3 @="Driver Group"
Bu}X#<:wt mvS e8)p [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio]
xY*;as |VU @="Service"
pOzr0< w~+Mwm [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS]
-[eQ_R[X! @="Service"
2)xaN S<lxgrc [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup]
`R'8^", @="Driver Group"
l?`dga9B _Zqxx'QZ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT]
$Kg>kKI% @="Service"
rR9N(>.71 $canzN0t` [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup]
oo$&u% @="Driver Group"
/df-X\UAT I=yA8bB [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon]
*0}bjE(vu @="Service"
gk#Qm@F zRNL Te\ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan]
cD g,ym@R @="Service"
NCb;ub$ r+: LvNS [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network]
F)[9L<<# @="Driver Group"
v>)]- x| c8HP;j [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider]
Fj2f]LO @="Driver Group"
69f5&|!!V .ybS+w7d; [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSsp]
$UTms8u @="Service"
}BCmO8WLo c-DG.UZK [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration]
R"Duu'A @="Driver Group"
PPg1:d~_u s50CoSa(O [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay]
\[U[[{/y @="Service"
Uj#K~9Cf R<\+mN [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter]
-P]<ME 5 @="Driver Group"
8`H R:r ^:j"s8w7 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI]
-'^i#O1+j @="Driver Group"
J^yp:c6bIu O1Nfm V-q [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk]
`&b\1^7 @="Driver Group"
f\K;-x]/ :^Gb2C: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sys]
l?[~=zY, @="Driver"
XuY4t$w <BWuBP,H [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sys]
bCFH(7K @="Driver"
D~7.62, /<0%a: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sys]
fY
DYU> @="Driver"
7h_hlg3 \@]u15 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr]
Ws4"_'vaM @="Service"
!!GzGY6L .J[]8P2KQ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs]
xm=eQSdc @="Service"
8?x<cwW>:g
n%.86Vi? [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class]
Ci8T$" @="Driver Group"
WyFRC:E! s;]mFM?3< [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys]
-Ttw,d @="Driver"
"wpDrU;Y*X itm/(]W [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess]
gDDyM4 @="Service"
a "U5SO 7K%(-azY [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sys]
ugv{ ]D\q @="FSFilter System Recovery"
Q8d4a\~G 7y/rd8#;GT [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRService]
:Gm0Q[1I @="Service"
Y2Ub6Xm( k(a*2G9 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers]
rZn3.pQ @="Driver Group"
5q/pBTXeq1 !@Fv5s$w' [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender]
C&{D.p@p @="Driver Group"
2
a$|a k7+6FkEO* [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip]
J6knAo$b @="Service"
9[I?LJK`D :#]`-Nj [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI]
)Syw5w,c @="Driver Group"
N[T&)}od #XpP><^*%# [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sys]
8rq P+- @="Driver"
NpMTY9 '*t8/P [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sys]
;tS+9Zy @="Driver"
gQ']tkf`' 5Y/k] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termservice]
$uEWk @="Service"
tI,_r;<d4& ^- ]W*dkN@ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys]
n/XOn)}8z @="Driver"
1Q}Xh>iP p=fT!O?F [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys]
kb`unKmZ @="Driver"
P=e 58Wn ED_cECu [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt]
"PQ[ "vX4_ @="Service"
;K^C8IP c@At0od| [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVC]
}KUtj6'KO@ @="Service"
t34j ){S'G}J+ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
%#-76R @="Universal Serial Bus controllers"
P3;]V|E)p _
?L(!dm3 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
_DSy$rE% @="CD-ROM Drive"
Y?CJ:Wb l8*eD1}g [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
>)=(<He @="DiskDrive"
hIA?K%G A==/{SH [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
SX5;&Eo! @="Standard floppy disk controller"
'kF$rX *- Qv{ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
9/*oEdAy% @="Hdc"
F :q<A!i FW7F= uq [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
w%)$PP2KF @="Keyboard"
k\(+(a vh>s`15o [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
#R9=]BA" @="Mouse"
,9rrTM8 h"UO-c&j [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
FUO
;i<#^ @="Net"
$)Ib ,O x^bj [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
KmEK:4 @="NetClient"
rwuuf9M .&Ca-:V [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
YEJEyWQ @="NetService"
8lAH?D &4>1: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
:&Q{O#
dH1 @="NetTrans"
SOh V|G .Ho&epZJ` [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
1AdD,zj @="PCMCIA Adapters"
ba.WA : 3i6HK7l= [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
MUvL~. @="SCSIAdapter"
(FLCPBQ: 6a7wM/! [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
V,B;{U>J_ @="System"
ET(S=BI? zUI`*I!3
> [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
H9)S9rjlg @="Floppy disk drive"
$dul.!- -|&P_-Z) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
1`*l'{1 @="Volume"
f9Gu [+$| 3{1U7Ke [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
36Fp^1dG} @="Human Interface Devices"
7v_fVR"M2%