HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
. ImagePath
under a driver's corresponding registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\driverName
. svchost.exe
can be started with -k xyz
. In such cases, xyz
seems to correspond to a value and a registry key below the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost