New
#51
Code:Microsoft Windows [Version 6.1.7601] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\Windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\Services\spldr /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\spldr DisplayName REG_SZ Security Processor Loader Driver ErrorControl REG_DWORD 0x3 Start REG_DWORD 0x0 Type REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\spldr\Enum 0 REG_SZ Root\LEGACY_SPLDR\0000 Count REG_DWORD 0x1 NextInstance REG_DWORD 0x1 C:\Windows\system32>REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_SPLDR /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR NextInstance REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR\0000 Service REG_SZ spldr Legacy REG_DWORD 0x1 ConfigFlags REG_DWORD 0x400 Class REG_SZ LegacyDriver ClassGUID REG_SZ {8ECC055D-047F-11D1-A537-0000F8753ED1} DeviceDesc REG_SZ Security Processor Loader Driver Capabilities REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR\0000\Control ActiveService REG_SZ spldr C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servi ces\eventlog\Application\Software Protection Platform Service" /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Softwa re Protection Platform Service EventMessageFile REG_EXPAND_SZ %windir%\system32\sppsvc.exe TypesSupported REG_DWORD 0x7 ProviderGuid REG_SZ {E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156} C:\Windows\system32>REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic es\eventlog\Application\SPP /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\SPP TypesSupported REG_DWORD 0x7 EventMessageFile REG_EXPAND_SZ %systemroot%\system32\sxproxy.dll C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servi ces\eventlog\Key Management Service\KmsRequests" /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Key Management Ser vice\KmsRequests EventMessageFile REG_EXPAND_SZ %windir%\system32\sppsvc.exe TypesSupported REG_DWORD 0x7 ProviderGuid REG_SZ {E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156} C:\Windows\system32>REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic es\sppuinotify /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\sppuinotify DisplayName REG_SZ @%SystemRoot%\system32\sppuinotify.dll,-103 ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k LocalServ ice Description REG_SZ @%SystemRoot%\system32\sppuinotify.dll,-102 ObjectName REG_SZ NT AUTHORITY\LocalService ErrorControl REG_DWORD 0x1 Start REG_DWORD 0x3 Type REG_DWORD 0x20 DependOnService REG_MULTI_SZ EventSystem ServiceSidType REG_DWORD 0x1 RequiredPrivileges REG_MULTI_SZ SeChangeNotifyPrivilege\0SeImpersonate Privilege FailureActions REG_BINARY 80510100000000000000000003000000140000000100 0000E093040001000000E09304000000000000000000 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\sppuinotify\Parameters ServiceDll REG_EXPAND_SZ %SystemRoot%\system32\sppuinotify.dll ServiceDllUnloadOnStop REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\sppuinotify\Security Security REG_BINARY 01001480C8000000D4000000140000003000000002001C0001 00000002801400FF010F00010100000000000100000000020098000600000000001400FD01020001 010000000000051200000000002800FD010200010600000000000550000000F05B5807C3438C9AC7 8A72DD8F8CB4DF4447E7F800001800FF010F0001020000000000052000000020020000000014008D 010200010100000000000504000000000014008D0102000101000000000005060000000000140000 01000001010000000000050B000000010100000000000512000000010100000000000512000000 C:\Windows\system32>REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic es\VSS\Diag\SPP /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\SPP SppGetSnapshots (Enter) REG_BINARY 4000000000000000BC046BCF3FA6CD01001 50000B40E0000D207000000000000000000000000000000000000000000000000000000000000000 0000000000000 SppGetSnapshots (Leave) REG_BINARY 40000000000000001BA57DCF3FA6CD01001 50000B40E0000D207000001000000000000000000000000000000000000000000000000000000000 0000000000000 SppEnumGroups (Enter) REG_BINARY 400000000000000041CB7DCF3FA6CD0100150 000B40E0000D10700000000000000000000000000000000000000000000000000000000000000000 00000000000 SppEnumGroups (Leave) REG_BINARY 40000000000000000FD3FAD43FA6CD0100150 000B40E0000D10700000100000000000000010000000000000000000000000000000000000000000 00000000000 SppCreate (Enter) REG_BINARY 40000000000000008262AD1161A6CD01C8030000E 8100000D007000000000000000000000000000000000000000000000000000000000000000000000 0000000 SppGatherWriterMetadata (Enter) REG_BINARY 40000000000000009089B41161A 6CD01C8030000E8100000D3070000000000000000000000000000000000000000000000000000000 000000000000000000000 SppGatherWriterMetadata (Leave) REG_BINARY 4000000000000000DD1BA31461A 6CD01C8030000E8100000D3070000010000000000000000000000000000000000000000000000000 000000000000000000000 SppAddInterestingComponents (Enter) REG_BINARY 40000000000000000342A31 461A6CD01C8030000E8100000D407000000000000000000000000000000000000000000000000000 0000000000000000000000000 SppAddInterestingComponents (Leave) REG_BINARY 40000000000000007C52CE1 461A6CD01C8030000E8100000D407000001000000000000000000000000000000000000000000000 0000000000000000000000000 SppCreate (Leave) REG_BINARY 40000000000000009883411861A6CD01C8030000E 8100000D007000001000000000000000000000000000000000000000000000000000000000000000 0000000 C:\Windows\system32>