Code:
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost]
"NetSvcs"=-
"NetSvcs"=hex(7):36,74,6F,34,00,41,70,70,4D,67,6D,74,00,41,\
75,64,69,6F,53,72,76,00,42,72,6F,77,73,65,72,00,43,72,79,70,74,53,76,\
63,00,44,4D,53,65,72,76,65,72,00,44,48,43,50,00,45,52,53,76,63,00,45,\
76,65,6E,74,53,79,73,74,65,6D,00,46,61,73,74,55,73,65,72,53,77,69,74,\
63,68,69,6E,67,43,6F,6D,70,61,74,69,62,69,6C,69,74,79,00,48,69,64,53,\
65,72,76,00,49,61,73,00,49,70,72,69,70,00,49,72,6D,6F,6E,00,4C,61,6E,\
6D,61,6E,53,65,72,76,65,72,00,4C,61,6E,6D,61,6E,57,6F,72,6B,73,74,61,\
74,69,6F,6E,00,4D,65,73,73,65,6E,67,65,72,00,4E,65,74,6D,61,6E,00,4E,\
6C,61,00,4E,74,6D,73,73,76,63,00,4E,57,43,57,6F,72,6B,73,74,61,74,69,\
6F,6E,00,4E,77,73,61,70,61,67,65,6E,74,00,52,61,73,61,75,74,6F,00,52,\
61,73,6D,61,6E,00,52,65,6D,6F,74,65,61,63,63,65,73,73,00,53,63,68,65,\
64,75,6C,65,00,53,65,63,6C,6F,67,6F,6E,00,53,45,4E,53,00,53,68,61,72,\
65,64,61,63,63,65,73,73,00,53,52,53,65,72,76,69,63,65,00,54,61,70,69,\
73,72,76,00,54,68,65,6D,65,73,00,54,72,6B,57,6B,73,00,57,33,32,54,69,\
6D,65,00,57,5A,43,53,56,43,00,57,6D,69,00,57,6D,64,6D,50,6D,53,70,00,77,\
69,6E,6D,67,6D,74,00,77,73,63,73,76,63,00,78,6D,6C,70,72,6F,76,00,6E,\
61,70,61,67,65,6E,74,00,68,6B,6D,73,76,63,00,42,49,54,53,00,77,75,61,\
75,73,65,72,76,00,53,68,65,6C,6C,48,57,44,65,74,65,63,74,69,6F,6E,00,68,\
65,6C,70,73,76,63,00,57,6D,64,6D,50,6D,53,4E,00,00
Driver::
sqlserveragent
AVCSTRM
websensecamreportserver
vsdatant
zendcoreapache
epson_pm_rpcv2_02
MRESP50a64
ami0nt
UPATC
proxyhostdriver
AlKernel
Xponaut_WBD
beatjammusicstreamingserver
s616mgmt
nod32krn
btfirst
cpqdmi
symantecantibotshim
NWSNS
cachemgr
enodpl
HssTrayService
deventagent
sbcssvc
Sk99202k
useraccess
phc600
ibmpmsvc
FETNDIS
rt73
antivirservice
stllssvr
flashcomadmin
papycpu2
pilogsrv
epsonbidirectionalagent
ibmfilter
lxby_device
sit_flt
EagleNT
mfeapfk
videoacceleratorengine
rslinxng
vmparport
BoiHwsetup
usbatapi2000
igniteservice.exe
bthidenum
ltxred
p2psvc
HPFECP20
IWCA
UDFReadr
wpshelper
serialkeys
cq_mem
fcprintservice
lxcj_device
CAMFLT
MSFWHLPR
pcscnsrv
uhcd
bcm43xx
61883
GT680x
oracleorahome92tnslistener
GTF32BUS
ibmpmdrv
IntelC53
FA312
ZuneWlanCfgSvc
spcsutilityservice
tzontservice
enxpsvc
HpqKbFiltr
3dkeybd
pshost
pdlnctdl
wlluc48
KMW_USB
aksusb
wlancfg
hsf_dp
moufiltr
mks_scan
dktknsrv
aswmon2
dot4print
EIO_XP
SE2Cmdm
snapman
Si3114r5
hidgame
dirms_defragmentation
elnkservice
DM9102
pdlnemsg
dnwhodisp
NCPro
upperdev
npfmntor
aslm75
lusbaudio
bhmonitorservice
SiRemFil
whoisd32
tfsnopio
CBN
se44mgmt
opcenum
ANC
appnnode
dlaudfam
AVerBDA
bglivesvc
ASMMAP
clisvc
snac
pepifilter
dtscsi
sprtsvc_ddoctorv2
NWADI
MSCamSvc
2wirepcp
freepops
USB_RNDIS
sandboxu
BrPar
scarddrv
wmccdsls
lxdm_device
StickyMesger
cmigameport
ixiaendpoint
Machnm32
symantecantibotdriver
bridgemp
driverhardwarev2
TMHIDSRV
dsbrokerservice
DCamUSBMke
ntiopnp
NxSysMon
pdengine
besclient
iaimfp2
pmsveh
SiSRaid2
DritekPortIO
sshrmd
sonytvc
pavdrv
nim32
scsiaccess
admjoy
ofcpfwsvc
ntsyslog
netdevio
mcvsrte
pnrouter
SrvcEPIOMngr
backuplauncher
ltmodem5
sbhooksvc
iaimtv2
HSFHWICH
belgium_id_card_service
ccalib8
tversitymediaserver
winachcf
susbser
In the notepad