Hej
Loggen fra FSS
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\swprv]
“DisplayName”=”@%SystemRoot%\\System32\\swprv.dll,-103”
“ImagePath”=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,73,00,77,00,70,00,72,00,76,00,00,00
“Description”=”@%SystemRoot%\\System32\\swprv.dll,-102”
“ObjectName”=“LocalSystem”
“ErrorControl”=dword:00000001
“Start”=dword:00000004
“Type”=dword:00000010
“DependOnService”=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
“ServiceSidType”=dword:00000001
“RequiredPrivileges”=hex(7):53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,\
68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,\
00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,\
65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,65,00,\
61,00,74,00,65,00,50,00,65,00,72,00,6d,00,61,00,6e,00,65,00,6e,00,74,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\
6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,56,00,6f,00,6c,00,75,00,6d,00,65,00,50,00,72,00,69,00,76,\
00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,74,00,\
6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,\
00,53,00,65,00,49,00,6e,00,63,00,72,00,65,00,61,00,73,00,65,00,42,00,61,00,\
73,00,65,00,50,00,72,00,69,00,6f,00,72,00,69,00,74,00,79,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,56,00,6f,00,6c,00,75,00,6d,00,65,00,50,00,72,00,69,00,76,\
00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,74,00,\
6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,\
00,53,00,65,00,54,00,63,00,62,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
67,00,65,00,00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\swprv\Parameters]
“ServiceDll”=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,77,00,70,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS]
“DisplayName”=”@%systemroot%\\system32\\vssvc.exe,-102”
“ImagePath”=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,76,\
00,73,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00
“Description”=”@%systemroot%\\system32\\vssvc.exe,-101”
“ObjectName”=“LocalSystem”
“ErrorControl”=dword:00000001
“Start”=dword:00000003
“Type”=dword:00000010
“DependOnService”=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
“ServiceSidType”=dword:00000001
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\SPP]
“SppGetSnapshots (Enter)”=hex:48,00,00,00,00,00,00,00,d3,90,cc,8e,b6,c1,cc,01,\
e8,05,00,00,1c,07,00,00,d2,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
“SppGetSnapshots (Leave)”=hex:48,00,00,00,00,00,00,00,d3,90,cc,8e,b6,c1,cc,01,\
e8,05,00,00,1c,07,00,00,d2,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
“SppEnumGroups (Enter)”=hex:48,00,00,00,00,00,00,00,d3,90,cc,8e,b6,c1,cc,01,e8,\
05,00,00,1c,07,00,00,d1,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00
“SppEnumGroups (Leave)”=hex:48,00,00,00,00,00,00,00,d3,90,cc,8e,b6,c1,cc,01,e8,\
05,00,00,1c,07,00,00,d1,07,00,00,01,00,00,00,00,00,00,00,01,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00
“SppCreate (Enter)”=hex:48,00,00,00,00,00,00,00,d0,3c,7c,21,9e,c1,cc,01,4c,06,\
00,00,30,07,00,00,d0,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
“SppGatherWriterMetadata (Enter)”=hex:48,00,00,00,00,00,00,00,a7,69,9d,bc,29,\
bd,cc,01,84,01,00,00,6c,16,00,00,d3,07,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00
“SppGatherWriterMetadata (Leave)”=hex:48,00,00,00,00,00,00,00,1d,c8,4e,c2,29,\
bd,cc,01,84,01,00,00,6c,16,00,00,d3,07,00,00,01,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00
“SppAddInterestingComponents (Enter)”=hex:48,00,00,00,00,00,00,00,1d,c8,4e,c2,\
29,bd,cc,01,84,01,00,00,6c,16,00,00,d4,07,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00
“SppAddInterestingComponents (Leave)”=hex:48,00,00,00,00,00,00,00,3f,9e,62,c2,\
29,bd,cc,01,84,01,00,00,6c,16,00,00,d4,07,00,00,01,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00
“SppCreate (Leave)”=hex:48,00,00,00,00,00,00,00,d0,3c,7c,21,9e,c1,cc,01,4c,06,\
00,00,30,07,00,00,d0,07,00,00,01,00,00,00,00,00,00,00,02,23,04,80,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\SystemRestore]
“SrCreateRp (Enter)”=hex:48,00,00,00,00,00,00,00,d0,3c,7c,21,9e,c1,cc,01,4c,06,\
00,00,30,07,00,00,d5,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
“SrCreateRp (Leave)”=hex:48,00,00,00,00,00,00,00,d0,3c,7c,21,9e,c1,cc,01,4c,06,\
00,00,30,07,00,00,d5,07,00,00,01,00,00,00,00,00,00,00,02,23,04,80,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\ASR Writer]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\COM+ REGDB Writer]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\Registry Writer]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\Shadow Copy Optimization Writer]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\VolSnap]
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}DiscoverSnapshots (Enter)”=hex:48,\
00,00,00,00,00,00,00,da,d9,76,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,20,00,\
00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}Activate (Enter)”=hex:48,00,00,00,\
00,00,00,00,da,d9,76,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,08,00,00,00,01,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}ActivateLoop (Enter)”=hex:48,00,\
00,00,00,00,00,00,da,d9,76,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,1a,00,00,\
00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}ActivateLoop (Leave)”=hex:48,00,\
00,00,00,00,00,00,3f,51,9f,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,1b,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}ComputeIgnorableProduct (Enter)”=hex:48,\
00,00,00,00,00,00,00,9f,b2,a1,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,0c,00,\
00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}ComputeIgnorableProduct (Leave)”=hex:48,\
00,00,00,00,00,00,00,25,4e,d1,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,0d,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}DeleteProcess (Enter)”=hex:48,00,\
00,00,00,00,00,00,25,4e,d1,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,12,00,00,\
00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}Activate (Leave)”=hex:48,00,00,00,\
00,00,00,00,25,4e,d1,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,09,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}DiscoverSnapshots (Leave)”=hex:48,\
00,00,00,00,00,00,00,25,4e,d1,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,21,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}SetIgnorable (Enter)”=hex:48,00,\
00,00,00,00,00,00,25,4e,d1,b7,b3,c1,cc,01,00,00,00,00,00,00,00,00,0a,00,00,\
00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}SetIgnorable (Leave)”=hex:48,00,\
00,00,00,00,00,00,25,d7,9b,c1,b3,c1,cc,01,00,00,00,00,00,00,00,00,0b,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}AdjustBitmap (Enter)”=hex:48,00,\
00,00,00,00,00,00,25,d7,9b,c1,b3,c1,cc,01,00,00,00,00,00,00,00,00,04,00,00,\
00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}ValidateDiffAreaFiles (Enter)”=hex:48,\
00,00,00,00,00,00,00,25,d7,9b,c1,b3,c1,cc,01,00,00,00,00,00,00,00,00,1c,00,\
00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“VolumesSafeForWrite (Enter)”=hex:48,00,00,00,00,00,00,00,25,d7,9b,c1,b3,c1,cc,\
01,00,00,00,00,00,00,00,00,1e,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00
“VolumesSafeForWrite (Leave)”=hex:48,00,00,00,00,00,00,00,25,d7,9b,c1,b3,c1,cc,\
01,00,00,00,00,00,00,00,00,1f,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}ValidateDiffAreaFiles (Leave)”=hex:48,\
00,00,00,00,00,00,00,25,d7,9b,c1,b3,c1,cc,01,00,00,00,00,00,00,00,00,1d,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}AdjustBitmap (Leave)”=hex:48,00,\
00,00,00,00,00,00,25,d7,9b,c1,b3,c1,cc,01,00,00,00,00,00,00,00,00,05,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
“Volume{ffd637c8-feb6-11df-bfe9-806e6f6e6963}DeleteProcess (Leave)”=hex:48,00,\
00,00,00,00,00,00,25,d7,9b,c1,b3,c1,cc,01,00,00,00,00,00,00,00,00,13,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\VssapiPublisher]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Diag\WMI Writer]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Providers]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}]
@=“Microsoft Software Shadow Copy provider 1.0”
“Type”=dword:00000001
“Version”=“1.0.0.7”
“VersionId”=”{00000001-0000-0000-0007-000000000001}”
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}\CLSID]
@=”{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}”
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Settings]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\Settings\WritersBlockingRevert]
“{2707761B-2324-473D-88EB-EB007A359533}”=“DFS-R Writer”
“{D76F5A28-3092-4589-BA48-2958FB88CE29}”=“FRS Writer”
“{B2014C9E-8711-4C5C-A5A9-3CF384484757}”=“AD Writer”
“{DD846AAA-A1B6-42a8-AAF8-03DCB6114BFD}”=“ADAM Writer”
“TornComponentsBlockRevert”=dword:00000001
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VSS\VssAccessControl]
“NT Authority\\NetworkService”=dword:00000001
Jeg sætter virkelig pris på jeres hjælp.
Kh Jette