Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Abiosdsk] "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000004 "Tag"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp480n5] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000038 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp480n5\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp480n5\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI] "ErrorControl"=dword:00000001 "Group"="Boot Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Microsoft ACPI Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,43,00,50,00,49,00,2e,00,73,\ 00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI\Parameters] "AMLIMaxCTObjs"=hex:03,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI\Parameters\WakeUp] "FixedEventMask"=hex:20,01 "FixedEventStatus"=hex:00,85 "GenericEventMask"=hex:00,00,00,00 "GenericEventStatus"=hex:00,00,ff,ce [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI\Enum] "0"="ACPI_HAL\\PNP0C08\\0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPIEC] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000006 "Type"=dword:00000001 "DisplayName"="Microsoft Embedded Controller Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,43,00,50,00,49,00,45,00,43,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPIEC\Enum] "0"="ACPI\\PNP0C09\\4&38462492&0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003c "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,65,00,63,00,2e,00,73,00,79,\ 00,73,00,00,00 "DisplayName"="Microsoft Kernel Acoustic Echo Canceller" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD] "DisplayName"="AFD" "Description"="AFD Networking Support Environment" "Group"="TDI" "ImagePath"="\\SystemRoot\\System32\\drivers\\afd.sys" "Start"=dword:00000001 "Type"=dword:00000001 "ErrorControl"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Enum] "0"="Root\\LEGACY_AFD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aha154x] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000006 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aha154x\Parameters] "LegacyAdapterDetection"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aha154x\Parameters\PnpInterface] "1"=dword:00000001 "3"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78u2] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000034 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78u2\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78u2\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000001e "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "DisplayName"="Alerter" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter\Parameters] "AlertNames"=hex(7):00,00 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,6c,00,72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter\Enum] "0"="Root\\LEGACY_ALERTER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG] "Description"="Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall." "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,\ 00,6c,00,67,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Application Layer Gateway Service" "ObjectName"="NT AUTHORITY\\LocalService" "Group"="FirewallGroup" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG\Enum] "0"="Root\\LEGACY_ALG\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AliIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000004 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000024 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt] "Description"="Provides software installation services such as Assign, Publish, and Remove." "DisplayName"="Application Management" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Enum] "0"="Root\\LEGACY_APPMGMT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Arp1394] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000b "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,72,00,70,00,31,00,33,00,39,\ 00,34,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="1394 ARP Client Protocol" "Group"="NDIS" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="1394 ARP Client Protocol" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Arp1394\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Arp1394\Enum] "0"="Root\\LEGACY_ARP1394\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000029 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3350p] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000039 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3350p\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3350p\Parameters\PnpInterface] "1"=dword:00000011 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000002a "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aspi32] "ErrorControl"=dword:00000001 "Type"=dword:00000001 "Start"=dword:00000002 "MatchFlags"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aspi32\Enum] "0"="Root\\LEGACY_ASPI32\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aspi32\Parameters] "ExcludeMiniports"="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AsyncMac] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,73,00,79,00,6e,00,63,00,6d,\ 00,61,00,63,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="RAS Asynchronous Media Driver" "Description"="RAS Asynchronous Media Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AsyncMac\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000000 "Tag"=dword:00000019 "Type"=dword:00000001 "DisplayName"="Standard IDE/ESDI Hard Disk Controller" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,61,00,70,00,69,00,2e,\ 00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi\Parameters] "LegacyDetection"=dword:00000001 "GhostSlave"=hex(7):53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,00,00,00,\ 00 "UseCheckPowerForFlush"=hex(7):53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,20,00,\ 57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,41,00,20,00,28,00,31,\ 00,36,00,30,00,30,00,4d,00,42,00,29,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,41,00,4d,00,53,00,55,\ 00,4e,00,47,00,20,00,57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,\ 41,00,20,00,28,00,31,00,2e,00,36,00,47,00,42,00,29,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,49,00,\ 42,00,4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,54,00,43,00,36,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,\ 4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,54,00,43,00,36,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,\ 2d,00,44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,\ 00,4c,00,38,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,\ 44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,\ 00,38,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,\ 50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,38,\ 00,49,00,41,00,41,00,34,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,\ 43,00,41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,4f,\ 00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,43,00,\ 41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,49,00,41,\ 00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,\ 2d,00,32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,4f,00,41,00,41,\ 00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,2d,00,\ 32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,49,00,41,00,41,00,32,\ 00,41,00,00,00,00,00 "NoFlushDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,5f,00,4c,00,\ 50,00,53,00,35,00,32,00,35,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,43,00,52,00,2d,00,37,00,33,\ 00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00 "PioOnlyDevice"=hex(7):20,00,20,00,20,00,20,00,43,00,6f,00,6e,00,6e,00,65,00,\ 72,00,20,00,50,00,65,00,72,00,69,00,70,00,68,00,65,00,72,00,61,00,6c,00,73,\ 00,20,00,34,00,32,00,35,00,4d,00,42,00,20,00,2d,00,20,00,43,00,46,00,53,00,\ 34,00,32,00,35,00,41,00,20,00,20,00,00,00,4d,00,41,00,54,00,53,00,48,00,49,\ 00,54,00,41,00,20,00,43,00,52,00,2d,00,35,00,38,00,31,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,46,00,58,00,\ 36,00,30,00,30,00,53,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,00,00,43,00,44,00,2d,00,34,00,34,00,45,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,\ 00,54,00,52,00,42,00,38,00,35,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,\ 54,00,55,00,4d,00,20,00,4d,00,41,00,52,00,56,00,45,00,52,00,49,00,43,00,4b,\ 00,20,00,35,00,34,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,20,\ 00,4d,00,41,00,58,00,54,00,4f,00,52,00,20,00,4d,00,58,00,54,00,2d,00,35,00,\ 34,00,30,00,20,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,31,00,32,\ 00,36,00,30,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,\ 20,00,37,00,38,00,35,00,30,00,20,00,41,00,56,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,\ 00,74,00,6f,00,72,00,20,00,37,00,35,00,34,00,30,00,20,00,41,00,56,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,33,00,20,\ 00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,\ 33,00,34,00,35,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,\ 00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,41,00,54,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,\ 61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,\ 31,00,41,00,55,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,\ 00,37,00,31,00,37,00,31,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,44,00,2d,00,\ 33,00,31,00,36,00,45,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,\ 00,53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,5f,00,53,00,43,00,52,00,2d,00,\ 32,00,34,00,33,00,30,00,00,00,43,00,52,00,2d,00,32,00,38,00,30,00,31,00,54,\ 00,45,00,00,00,00,00 "NonRemovableMedia"=hex(7):4b,00,69,00,6e,00,67,00,73,00,74,00,6f,00,6e,00,20,\ 00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,79,00,20,00,44,00,\ 61,00,74,00,61,00,50,00,61,00,6b,00,20,00,33,00,34,00,30,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,\ 73,00,6b,00,20,00,53,00,44,00,50,00,35,00,41,00,2d,00,31,00,30,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,\ 00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,\ 31,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,\ 00,33,00,42,00,2d,00,32,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,\ 20,00,53,00,44,00,50,00,33,00,42,00,2d,00,31,00,37,00,35,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,\ 00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,35,00,2d,00,32,00,2e,00,35,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,\ 43,00,61,00,6c,00,6c,00,75,00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,\ 00,6f,00,6c,00,6f,00,67,00,79,00,20,00,43,00,54,00,32,00,36,00,30,00,4d,00,\ 43,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,00,00,42,00,4e,00,2d,00,53,00,30,00,30,00,34,00,41,00,43,00,\ 2d,00,53,00,20,00,31,00,2e,00,30,00,30,00,00,00,43,00,61,00,6c,00,6c,00,75,\ 00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,\ 79,00,20,00,43,00,54,00,35,00,32,00,30,00,52,00,4d,00,00,00,48,00,69,00,74,\ 00,61,00,63,00,68,00,69,00,20,00,43,00,56,00,20,00,35,00,2e,00,31,00,2e,00,\ 31,00,00,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,41,00,5f,00,46,\ 00,4c,00,41,00,53,00,48,00,20,00,00,00,4d,00,69,00,74,00,73,00,75,00,62,00,\ 69,00,73,00,68,00,69,00,20,00,41,00,54,00,41,00,20,00,43,00,61,00,72,00,64,\ 00,20,00,00,00,4c,00,45,00,58,00,41,00,52,00,20,00,41,00,54,00,41,00,5f,00,\ 46,00,4c,00,41,00,53,00,48,00,00,00,4d,00,69,00,63,00,72,00,6f,00,6e,00,20,\ 00,4d,00,54,00,43,00,46,00,30,00,30,00,34,00,41,00,00,00,4d,00,69,00,63,00,\ 72,00,6f,00,6e,00,20,00,4d,00,54,00,43,00,46,00,30,00,30,00,38,00,41,00,00,\ 00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,33,00,\ 42,00,2d,00,31,00,31,00,30,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,\ 00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,34,00,00,00,42,00,4e,00,2d,00,\ 43,00,41,00,42,00,2d,00,54,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,\ 00,54,00,49,00,43,00,4b,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,00,\ 54,00,49,00,43,00,4b,00,20,00,20,00,20,00,38,00,4d,00,20,00,20,00,38,00,4b,\ 00,00,00,00,00 "NoPowerDownDevice"=hex(7):52,00,44,00,2d,00,44,00,52,00,43,00,30,00,30,00,31,\ 00,2d,00,4d,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,53,00,2d,00,52,00,33,00,\ 37,00,20,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00 "AutoEjectZipDevice"=hex(7):49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,\ 00,49,00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,32,00,33,00,2e,00,44,00,20,00,20,00,\ 20,00,20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,\ 00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,32,00,31,00,2e,00,44,00,20,00,20,00,20,00,\ 20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,\ 00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,\ 54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,32,00,30,00,2e,00,44,00,20,00,20,00,20,00,20,00,\ 00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,\ 00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,\ 41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,39,00,31,00,2e,00,44,00,20,00,20,00,20,00,20,00,00,00,\ 49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,\ 00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,42,00,2e,00,32,00,39,00,20,00,20,00,20,00,20,00,00,00,49,00,\ 4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,00,30,\ 00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,42,00,2e,00,32,00,32,00,20,00,20,00,20,00,20,00,00,00,00,00 "NeedIdentDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,00,46,00,\ 49,00,52,00,45,00,42,00,41,00,4c,00,4c,00,00,00,00,00 "DefaultPioAtapiDevice"=hex(7):54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,\ 44,00,56,00,44,00,2d,00,52,00,4f,00,4d,00,20,00,44,00,52,00,44,00,2d,00,4e,\ 00,32,00,31,00,36,00,00,00,49,00,44,00,45,00,2d,00,43,00,44,00,20,00,52,00,\ 2f,00,52,00,57,00,20,00,32,00,78,00,32,00,78,00,32,00,34,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi\Enum] "0"="PCIIDE\\IDEChannel\\4&de24f37&0&0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="PCIIDE\\IDEChannel\\4&de24f37&0&1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Atdisk] "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000004 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Atmarpc] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000d "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,6d,00,61,00,72,00,70,\ 00,63,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ATM ARP Client Protocol" "Group"="NDIS" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="ATM ARP Client Protocol" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Atmarpc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv] "DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\ 52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Windows Audio" "ErrorControl"=dword:00000001 "Group"="AudioGroup" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,75,00,64,00,69,00,6f,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv\Enum] "0"="Root\\LEGACY_AUDIOSRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\audstub] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,75,00,64,00,73,00,74,00,75,\ 00,62,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Audio Stub Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\audstub\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\audstub\Enum] "0"="Root\\MEDIA\\MS_MMACM" "Count"=dword:00000005 "NextInstance"=dword:00000005 "1"="Root\\MEDIA\\MS_MMDRV" "2"="Root\\MEDIA\\MS_MMMCI" "3"="Root\\MEDIA\\MS_MMVCD" "4"="Root\\MEDIA\\MS_MMVID" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BattC] "MofImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,\ 00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,62,00,61,00,74,00,74,00,63,00,\ 2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep] "ErrorControl"=dword:00000001 "Group"="Base" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep\Enum] "0"="Root\\LEGACY_BEEP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Background Intelligent Transfer Service" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Transfers data between clients and servers in the background. If BITS is disabled, features such as Windows Update will not work correctly." "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,68,e3,0c,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters] "ServiceDll"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,00,6d,00,\ 67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum] "0"="Root\\LEGACY_BITS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Computer Browser" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,4c,00,61,00,6e,00,6d,\ 00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser\Parameters] "IsDomainMaster"="FALSE" "MaintainServerList"="Auto" "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 62,00,72,00,6f,00,77,00,73,00,65,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser\Enum] "0"="Root\\LEGACY_BROWSER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cbidf2k] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000019 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cbidf2k\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cbidf2k\Parameters\PnpInterface] "1"=dword:00000001 "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCDECODE] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000e "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,43,00,43,00,44,00,45,00,43,00,4f,\ 00,44,00,45,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Closed Caption Decoder" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCDECODE\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cd20xrnt] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003a "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cd20xrnt\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cd20xrnt\Parameters\PnpInterface] "1"=dword:00000011 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdaudio] "ErrorControl"=dword:00000000 "Group"="Filter" "Start"=dword:00000001 "Tag"=dword:00000006 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdaudio\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdfs] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,43,00,44,00,52,00,4f,00,\ 4d,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000004 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdfs\Enum] "0"="Root\\LEGACY_CDFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\ 70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="SCSI CDROM Class" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="CD-ROM Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,63,00,64,00,72,00,6f,00,6d,00,2e,\ 00,73,00,79,00,73,00,00,00 "AutoRun"=dword:00000001 "AutoRunAlwaysDisable"=hex(7):4e,00,45,00,43,00,20,00,20,00,20,00,20,00,20,00,\ 4d,00,42,00,52,00,2d,00,37,00,20,00,20,00,20,00,00,00,4e,00,45,00,43,00,20,\ 00,20,00,20,00,20,00,20,00,4d,00,42,00,52,00,2d,00,37,00,2e,00,34,00,20,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,48,00,41,00,4e,\ 00,47,00,52,00,20,00,44,00,52,00,4d,00,2d,00,31,00,38,00,30,00,34,00,58,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,33,00,32,00,34,00,58,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,32,00,34,00,58,00,20,00,\ 00,00,54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,43,00,44,00,52,00,5f,00,43,00,33,00,36,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum] "0"="IDE\\CdRomTSSTcorp_CD/DVDW_TS-L632D_______________TO04____\\5&195506ac&0&0.0.0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Changer] "ErrorControl"=dword:00000000 "Group"="Filter" "Start"=dword:00000001 "Tag"=dword:00000005 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CiSvc] "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Description"="Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language." "DisplayName"="Indexing Service" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\ 00,69,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000120 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv] "DependOnService"=hex(7):4e,00,65,00,74,00,44,00,44,00,45,00,00,00,00,00 "Description"="Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="ClipBook" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\ 00,6c,00,69,00,70,00,73,00,72,00,76,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000010 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv\Enum] "0"="Root\\LEGACY_CLIPSRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmBatt] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,43,00,6d,00,42,00,61,00,74,00,74,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft ACPI Control Method Battery Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmBatt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmBatt\Enum] "0"="ACPI\\ACPI0003\\4&38462492&0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="ACPI\\PNP0C0A\\1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmdIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000004 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Compbatt] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000002 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,63,00,6f,00,6d,00,70,00,62,00,61,\ 00,74,00,74,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Composite Battery Driver" "Group"="System Bus Extender" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Compbatt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Compbatt\Enum] "0"="Root\\COMPOSITE_BATTERY\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSysApp] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6c,00,6c,\ 00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,50,00,72,00,\ 6f,00,63,00,65,00,73,00,73,00,69,00,64,00,3a,00,7b,00,30,00,32,00,44,00,34,\ 00,42,00,33,00,46,00,31,00,2d,00,46,00,44,00,38,00,38,00,2d,00,31,00,31,00,\ 44,00,31,00,2d,00,39,00,36,00,30,00,44,00,2d,00,30,00,30,00,38,00,30,00,35,\ 00,46,00,43,00,37,00,39,00,32,00,33,00,35,00,7d,00,00,00 "DisplayName"="COM+ System Application" "DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "FailureActions"=hex:1e,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,41,00,4d,\ 00,01,00,00,00,e8,03,00,00,01,00,00,00,88,13,00,00,00,00,00,00,e8,03,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSysApp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSysApp\Enum] "0"="Root\\LEGACY_COMSYSAPP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentFilter] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentFilter\Linkage] "Bind"="\\Dummy" "Export"="\\Dummy" "Route"="\\Dummy" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentFilter\Performance] "Close"="DoneFILTERPerformanceData" "Collect"="CollectFILTERPerformanceData" "Open"="InitializeFILTERPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\ 00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:000008c8 "Last Help"=dword:000008c9 "First Counter"=dword:000008c2 "First Help"=dword:000008c3 "Object List"="2242" "WbemAdapFileSignature"=hex:91,57,4d,b0,c7,47,a6,91,95,d7,e5,6a,5c,87,42,6e "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:0015e800 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentIndex] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentIndex\Linkage] "Bind"="\\Dummy" "Export"="\\Dummy" "Route"="\\Dummy" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentIndex\Performance] "Close"="DoneCIPerformanceData" "Collect"="CollectCIPerformanceData" "Open"="InitializeCIPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\ 00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:000008c0 "Last Help"=dword:000008c1 "First Counter"=dword:000008aa "First Help"=dword:000008ab "Object List"="2218" "WbemAdapFileSignature"=hex:91,57,4d,b0,c7,47,a6,91,95,d7,e5,6a,5c,87,42,6e "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:0015e800 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cpqarray] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000100 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cpqarray\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cpqarray\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Cryptographic Services" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 63,00,72,00,79,00,70,00,74,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceMain"="CryptServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Security] "Security"=hex:00,00,0e,00,01 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Enum] "0"="Root\\LEGACY_CRYPTSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac2w2k] "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000020 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac2w2k\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac2w2k\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac960nt] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000020 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac960nt\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac960nt\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch] "Description"="Provides launch functionality for DCOM services." "DisplayName"="DCOM Server Process Launcher" "ErrorControl"=dword:00000001 "Group"="Event Log" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,44,00,63,00,\ 6f,00,6d,00,4c,00,61,00,75,00,6e,00,63,00,68,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,02,00,00,00,60,ea,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,70,00,63,00,73,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch\Security] "Security"=hex:01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,34,00,00,00,02,\ 00,20,00,01,00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,20,02,00,00,02,00,80,00,05,00,00,00,00,03,18,00,8d,00,02,00,01,01,00,\ 00,00,00,00,01,00,00,00,00,00,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,00,\ 00,00,00,05,20,00,00,00,20,02,00,00,00,03,18,00,8f,00,02,00,01,02,00,00,00,\ 00,00,05,20,00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,01,00,00,00,00,\ 00,05,04,00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\ 00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch\Enum] "0"="Root\\LEGACY_DCOMLAUNCH\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="DHCP Client" "Group"="TDI" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,41,00,66,00,64,00,\ 00,00,4e,00,65,00,74,00,42,00,54,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages network configuration by registering and updating IP addresses and DNS names." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Configurations] "Options"=hex:32,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,\ 00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Linkage] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Linkage\Disabled] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,68,00,63,00,70,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "{7F171404-3092-412D-9CA7-FE7A3A5120B4}"=hex:06,00,00,00,00,00,00,00,04,00,00,\ 00,00,00,00,00,db,97,b6,49,c0,a8,01,01,03,00,00,00,00,00,00,00,04,00,00,00,\ 00,00,00,00,db,97,b6,49,c0,a8,01,01,01,00,00,00,00,00,00,00,04,00,00,00,00,\ 00,00,00,db,97,b6,49,ff,ff,ff,00,33,00,00,00,00,00,00,00,04,00,00,00,00,00,\ 00,00,db,97,b6,49,00,01,51,80,36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,\ 00,db,97,b6,49,c0,a8,01,01,35,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,\ db,97,b6,49,05,00,00,00 "{C65ABE47-0D2D-4C3E-8965-C5B62D61BB42}"=hex:06,00,00,00,00,00,00,00,04,00,00,\ 00,00,00,00,00,d4,97,b6,49,c0,a8,01,01,03,00,00,00,00,00,00,00,04,00,00,00,\ 00,00,00,00,d4,97,b6,49,c0,a8,01,01,01,00,00,00,00,00,00,00,04,00,00,00,00,\ 00,00,00,d4,97,b6,49,ff,ff,ff,00,33,00,00,00,00,00,00,00,04,00,00,00,00,00,\ 00,00,d4,97,b6,49,00,01,51,80,36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,\ 00,d4,97,b6,49,c0,a8,01,01,35,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,\ d4,97,b6,49,05,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\1] "KeyType"=dword:00000007 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,\ 65,00,74,00,4d,00,61,00,73,00,6b,00,4f,00,70,00,74,00,00,00,53,00,59,00,53,\ 00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,\ 6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,\ 00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,\ 00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,65,00,74,00,4d,00,61,00,\ 73,00,6b,00,4f,00,70,00,74,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\15] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,\ 69,00,6e,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,49,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,69,\ 00,6e,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\220] "KeyType"=dword:00000003 "VendorType"=dword:00000001 "RegSendLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,\ 72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,\ 00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,\ 54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,\ 00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,\ 65,00,73,00,5c,00,3f,00,5c,00,53,00,6f,00,48,00,52,00,65,00,71,00,75,00,65,\ 00,73,00,74,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\3] "KeyType"=dword:00000007 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,\ 75,00,6c,00,74,00,47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,53,00,59,\ 00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,\ 43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,\ 00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,\ 61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,\ 00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,75,00,6c,00,74,00,\ 47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\44] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\ 63,00,70,00,4e,00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,4c,\ 00,69,00,73,00,74,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,\ 75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,\ 00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,\ 5c,00,4e,00,65,00,74,00,42,00,54,00,5c,00,41,00,64,00,61,00,70,00,74,00,65,\ 00,72,00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,\ 65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\46] "KeyType"=dword:00000004 "RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpNodeType" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\47] "KeyType"=dword:00000001 "RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpScopeID" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\6] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,65,00,\ 53,00,65,00,72,00,76,00,65,00,72,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,\ 00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,\ 72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,\ 61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,4e,\ 00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\DhcpNetbiosOptions] "KeyType"=dword:00000004 "OptionId"=dword:00000001 "VendorType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\ 63,00,70,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,4f,00,70,00,74,00,69,\ 00,6f,00,6e,00,73,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 2c,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Enum] "0"="Root\\LEGACY_DHCP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Disk] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\ 70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="SCSI Class" "Start"=dword:00000000 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="Disk Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,64,00,69,00,73,00,6b,00,2e,00,73,\ 00,79,00,73,00,00,00 "AutoRunAlwaysDisable"=hex(7):42,00,72,00,6f,00,74,00,68,00,65,00,72,00,20,00,\ 52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,44,00,69,00,73,00,6b,\ 00,28,00,55,00,29,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Disk\Enum] "0"="IDE\\DiskTOSHIBA_MK1637GSX_______________________DL030M__\\5&69b5607&0&0.0.0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmadmin] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\ 67,00,50,00,6c,00,61,00,79,00,00,00,44,00,6d,00,53,00,65,00,72,00,76,00,65,\ 00,72,00,00,00,00,00 "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\ 00,6d,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,65,00,78,00,65,00,20,00,2f,00,\ 63,00,6f,00,6d,00,00,00 "DisplayName"="Logical Disk Manager Administrative Service" "ObjectName"="LocalSystem" "Description"="Configures hard disk drives and volumes. The service only runs for configuration processes and then stops." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmadmin\Parameters] "EnableDynamicConversionFor1394"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmboot] "Type"=dword:00000001 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "Group"="Filter" "Tag"=dword:0000000b "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,62,00,6f,00,6f,00,74,\ 00,2e,00,73,00,79,00,73,00,00,00 "VolumeRecoveryNeeded"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmboot\Enum] "0"="Root\\LEGACY_DMBOOT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmio] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Tag"=dword:0000000d "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,69,00,6f,00,2e,00,73,\ 00,79,00,73,00,00,00 "DisplayName"="Logical Disk Manager Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmio\Boot Info] "Boot ID"="e340cdc1-0bfd-11de-a68b-806d6172696f" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmio\Enum] "0"="Root\\dmio\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmload] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Tag"=dword:0000000c "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,6c,00,6f,00,61,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmload\Enum] "0"="Root\\LEGACY_DMLOAD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\ 67,00,50,00,6c,00,61,00,79,00,00,00,00,00 "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Logical Disk Manager" "ObjectName"="LocalSystem" "Description"="Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,6d,00,73,00,65,00,72,00,76,00,65,00,72,00,2e,00,64,00,6c,00,6c,00,00,\ 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver\Enum] "0"="Root\\LEGACY_DMSERVER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DMusic] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,44,00,4d,00,75,00,73,00,69,00,63,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel DLS Syntheiszer" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DMusic\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DMusic\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,65,00,72,00,76,\ 00,69,00,63,00,65,00,00,00 "DisplayName"="DNS Client" "Group"="TDI" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,6e,00,73,00,72,00,73,00,6c,00,76,00,72,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "NegativeCacheTime"=dword:00000000 "NetFailureCacheTime "=dword:00000000 "NegativeSOACacheTime "=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2c,\ 02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,\ 00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Enum] "0"="Root\\LEGACY_DNSCACHE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dot3svc] "DependOnService"=hex(7):4e,00,64,00,69,00,73,00,75,00,69,00,6f,00,00,00,65,00,\ 61,00,70,00,68,00,6f,00,73,00,74,00,00,00,00,00 "Description"="This service performs IEEE 802.1X authentication on Ethernet interfaces" "DisplayName"="Wired AutoConfig" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,64,00,6f,00,74,00,33,00,73,00,76,00,63,00,00,00 "ObjectName"="localSystem" "Type"=dword:00000020 "Start"=dword:00000004 "Group"="TDI" "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dot3svc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,6f,00,74,00,33,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="Dot3SvcMain" "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dot3svc\Enum] "0"="Root\\LEGACY_DOT3SVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dpti2o] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003c "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dpti2o\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dpti2o\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drmkaud] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,72,00,6d,00,6b,00,61,00,75,\ 00,64,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel DRM Audio Descrambler" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drmkaud\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drmkaud\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost] "DisplayName"="Extensible Authentication Protocol Service" "Description"="Provides windows clients Extensible Authentication Protocol Service" "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,65,00,61,00,70,00,73,00,76,00,63,00,73,00,00,00 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "ObjectName"="localSystem" "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 65,00,61,00,70,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceDllUnloadOnStop"=dword:00000001 "PeerInstalled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost\Enum] "0"="Root\\LEGACY_EAPHOST\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Allows error reporting for services and applictions running in non-standard environments." "DisplayName"="Error Reporting Service" "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 65,00,72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Enum] "0"="Root\\LEGACY_ERSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog] "Description"="Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped." "DisplayName"="Event Log" "ErrorControl"=dword:00000001 "Group"="Event log" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "PlugPlayServiceType"=dword:00000003 "Start"=dword:00000002 "Type"=dword:00000020 "ComputerName"="SMAS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application] "DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "DisplayNameID"=dword:00000100 "File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\ 6f,00,6e,00,66,00,69,00,67,00,5c,00,41,00,70,00,70,00,45,00,76,00,65,00,6e,\ 00,74,00,2e,00,45,00,76,00,74,00,00,00 "MaxSize"=dword:00080000 "PrimaryModule"="Application" "Retention"=dword:00093a80 "Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\ 70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,\ 00,00,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,\ 6c,00,6f,00,67,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,\ 00,20,00,50,00,72,00,6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,\ 69,00,76,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,\ 00,77,00,73,00,20,00,33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,\ 74,00,69,00,6f,00,6e,00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,\ 00,74,00,00,00,56,00,53,00,53,00,00,00,56,00,42,00,52,00,75,00,6e,00,74,00,\ 69,00,6d,00,65,00,00,00,55,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,00,\ 00,55,00,73,00,65,00,72,00,65,00,6e,00,76,00,00,00,54,00,6c,00,6e,00,74,00,\ 73,00,76,00,72,00,00,00,53,00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,\ 00,00,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,70,00,6f,00,\ 6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,\ 00,77,00,61,00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,00,\ 74,00,69,00,6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,73,\ 00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,\ 73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,63,\ 00,6c,00,67,00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,\ 76,00,00,00,53,00,63,00,65,00,43,00,6c,00,69,00,00,00,73,00,61,00,66,00,72,\ 00,73,00,6c,00,76,00,00,00,53,00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,\ 52,00,50,00,43,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,41,00,73,\ 00,73,00,69,00,73,00,74,00,61,00,6e,00,63,00,65,00,00,00,50,00,65,00,72,00,\ 66,00,50,00,72,00,6f,00,63,00,00,00,50,00,65,00,72,00,66,00,4f,00,53,00,00,\ 00,50,00,65,00,72,00,66,00,4e,00,65,00,74,00,00,00,50,00,65,00,72,00,66,00,\ 6d,00,6f,00,6e,00,00,00,50,00,65,00,72,00,66,00,6c,00,69,00,62,00,00,00,50,\ 00,65,00,72,00,66,00,44,00,69,00,73,00,6b,00,00,00,50,00,65,00,72,00,66,00,\ 63,00,74,00,72,00,73,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,00,65,00,20,\ 00,46,00,69,00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,65,00,79,00,\ 00,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4d,00,79,00,53,\ 00,51,00,4c,00,00,00,4d,00,53,00,53,00,51,00,4c,00,53,00,45,00,52,00,56,00,\ 45,00,52,00,2f,00,4d,00,53,00,44,00,45,00,00,00,4d,00,53,00,53,00,48,00,41,\ 00,00,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,\ 72,00,00,00,4d,00,53,00,44,00,54,00,43,00,20,00,43,00,6c,00,69,00,65,00,6e,\ 00,74,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,6d,00,6e,00,6d,00,73,00,\ 72,00,76,00,63,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,\ 00,20,00,48,00,2e,00,33,00,32,00,33,00,20,00,54,00,65,00,6c,00,65,00,70,00,\ 68,00,6f,00,6e,00,79,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,20,\ 00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,00,00,4c,00,6f,00,61,00,\ 64,00,50,00,65,00,72,00,66,00,00,00,4a,00,61,00,76,00,61,00,51,00,75,00,69,\ 00,63,00,6b,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,53,00,65,00,72,00,\ 76,00,69,00,63,00,65,00,00,00,48,00,65,00,6c,00,70,00,53,00,76,00,63,00,00,\ 00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,\ 20,00,53,00,74,00,61,00,72,00,74,00,20,00,4d,00,65,00,6e,00,75,00,20,00,53,\ 00,65,00,74,00,74,00,69,00,6e,00,67,00,73,00,00,00,47,00,72,00,6f,00,75,00,\ 70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,53,00,74,00,61,00,6e,\ 00,64,00,61,00,72,00,64,00,20,00,45,00,64,00,69,00,74,00,69,00,6f,00,6e,00,\ 00,00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,\ 00,20,00,53,00,68,00,6f,00,72,00,74,00,63,00,75,00,74,00,73,00,00,00,47,00,\ 72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,53,\ 00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,00,00,47,00,72,00,6f,00,75,00,\ 70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,53,00,63,00,68,00,65,\ 00,64,00,75,00,6c,00,65,00,64,00,20,00,54,00,61,00,73,00,6b,00,73,00,00,00,\ 47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,\ 00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,00,00,00,47,00,72,00,6f,00,\ 75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,52,00,65,00,67,\ 00,69,00,6f,00,6e,00,61,00,6c,00,20,00,4f,00,70,00,74,00,69,00,6f,00,6e,00,\ 73,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,\ 00,79,00,20,00,50,00,72,00,69,00,6e,00,74,00,65,00,72,00,73,00,00,00,47,00,\ 72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,50,\ 00,6f,00,77,00,65,00,72,00,20,00,4f,00,70,00,74,00,69,00,6f,00,6e,00,73,00,\ 00,00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,\ 00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,20,00,53,00,68,00,61,00,\ 72,00,65,00,73,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,\ 00,69,00,63,00,79,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,20,00,\ 4f,00,70,00,74,00,69,00,6f,00,6e,00,73,00,00,00,47,00,72,00,6f,00,75,00,70,\ 00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,4c,00,6f,00,63,00,61,00,\ 6c,00,20,00,55,00,73,00,65,00,72,00,73,00,20,00,61,00,6e,00,64,00,20,00,47,\ 00,72,00,6f,00,75,00,70,00,73,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,\ 50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,49,00,6e,00,74,00,65,00,72,00,6e,\ 00,65,00,74,00,20,00,53,00,65,00,74,00,74,00,69,00,6e,00,67,00,73,00,00,00,\ 47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,\ 00,49,00,6e,00,69,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,00,47,00,72,00,\ 6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,46,00,6f,\ 00,6c,00,64,00,65,00,72,00,73,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,\ 50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,46,00,6f,00,6c,00,64,00,65,00,72,\ 00,20,00,4f,00,70,00,74,00,69,00,6f,00,6e,00,73,00,00,00,47,00,72,00,6f,00,\ 75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,46,00,69,00,6c,\ 00,65,00,73,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,\ 69,00,63,00,79,00,20,00,45,00,6e,00,76,00,69,00,72,00,6f,00,6e,00,6d,00,65,\ 00,6e,00,74,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,\ 69,00,63,00,79,00,20,00,44,00,72,00,69,00,76,00,65,00,20,00,4d,00,61,00,70,\ 00,73,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,\ 63,00,79,00,20,00,44,00,65,00,76,00,69,00,63,00,65,00,20,00,53,00,65,00,74,\ 00,74,00,69,00,6e,00,67,00,73,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,\ 50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,44,00,61,00,74,00,61,00,20,00,53,\ 00,6f,00,75,00,72,00,63,00,65,00,73,00,00,00,47,00,72,00,6f,00,75,00,70,00,\ 20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,20,00,43,00,6c,00,69,00,65,00,6e,\ 00,74,00,00,00,47,00,72,00,6f,00,75,00,70,00,20,00,50,00,6f,00,6c,00,69,00,\ 63,00,79,00,20,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,\ 00,6e,00,73,00,00,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,00,52,00,65,00,\ 64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,46,00,69,00,6c,\ 00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,79,00,6d,00,65,00,6e,00,74,00,\ 00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\ 00,45,00,53,00,45,00,4e,00,54,00,00,00,44,00,72,00,57,00,61,00,74,00,73,00,\ 6f,00,6e,00,00,00,44,00,6f,00,74,00,33,00,53,00,76,00,63,00,00,00,44,00,69,\ 00,73,00,6b,00,51,00,75,00,6f,00,74,00,61,00,00,00,63,00,72,00,79,00,70,00,\ 74,00,33,00,32,00,00,00,43,00,4f,00,4d,00,2b,00,00,00,43,00,4f,00,4d,00,00,\ 00,43,00,69,00,00,00,43,00,68,00,6b,00,64,00,73,00,6b,00,00,00,41,00,75,00,\ 74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,00,65,00,6e,00,74,00,00,\ 00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,41,00,70,00,70,00,6c,00,\ 69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,\ 00,65,00,6d,00,65,00,6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,\ 61,00,74,00,69,00,6f,00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,00,70,\ 00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,72,00,\ 72,00,6f,00,72,00,00,00,41,00,70,00,61,00,63,00,68,00,65,00,20,00,53,00,65,\ 00,72,00,76,00,69,00,63,00,65,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,\ 61,00,74,00,69,00,6f,00,6e,00,00,00,00,00 "RestrictGuestAccess"=dword:00000001 @="mnmsrvc" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Apache Service] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application] "CategoryCount"=dword:00000007 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,64,00,6c,00,\ 6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Error] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Management] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Autochk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\AutoEnrollment] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,61,00,75,00,74,00,6f,00,65,00,6e,00,72,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chkdsk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,6c,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Ci] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryCount"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\COM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\COM+] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypeSupported"=dword:00000007 "CategoryCount"=dword:00000075 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\crypt32] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DiskQuota] "EventMessageFile"="%SystemRoot%\\System32\\dskquota.dll" "TypesSupported"="0x00000007" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dot3Svc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,6f,00,74,00,33,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DrWatson] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,72,00,77,00,74,00,73,00,6e,00,33,00,32,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESENT] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,00,\ 53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,\ 00,53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:00000010 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\EventSystem] "CategoryCount"=dword:00000006 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\File Deployment] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Folder Redirection] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Applications] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Client] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Data Sources] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Device Settings] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Drive Maps] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Environment] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Files] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Folder Options] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Folders] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Ini Files] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Internet Settings] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Local Users and Groups] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Network Options] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Network Shares] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Power Options] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Printers] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Regional Options] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Registry] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Scheduled Tasks] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Services] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Shortcuts] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Standard Edition] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Group Policy Start Menu Settings] "CategoryCount"=dword:00000002 "CategoryMessageFile"="gpprefcl.dll" "EventMessageFile"="gpprefcl.dll" "ParameterMessageFile"="gpprefcl.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HelpSvc] "EventMessageFile"="D:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll" "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\JavaQuickStarterService] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\ 00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,\ 5c,00,6a,00,72,00,65,00,36,00,5c,00,62,00,69,00,6e,00,5c,00,6a,00,71,00,73,\ 00,2e,00,65,00,78,00,65,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LoadPerf] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,6f,00,61,00,64,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft H.323 Telephony Service Provider] "EventMessageFile"="D:\\WINDOWS\\System32\\h323.tsp" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\mnmsrvc] "EventMessageFile"="%SystemRoot%\\System32\\nmevtmsg.dll" "TypeSupported"=hex:07,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDTC] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,3b,00,44,00,3a,00,5c,\ 00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,\ 65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,\ 00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,3b,00,44,00,3a,00,\ 5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,\ 00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,\ 73,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:0000000f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDTC Client] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,3b,00,44,00,3a,00,5c,\ 00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,\ 65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,\ 00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,3b,00,44,00,3a,00,\ 5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,\ 00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,\ 73,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:0000000f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MsiInstaller] "EventMessageFile"="D:\\WINDOWS\\system32\\msimsg.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSHA] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,73,00,73,00,68,00,61,00,76,00,6d,00,73,00,67,00,2e,00,64,00,6c,\ 00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSQLSERVER/MSDE] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MySQL] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,4c,00,69,00,6e,00,6b,00,7a,00,5c,\ 00,77,00,61,00,6d,00,70,00,5c,00,62,00,69,00,6e,00,5c,00,6d,00,79,00,73,00,\ 71,00,6c,00,5c,00,6d,00,79,00,73,00,71,00,6c,00,35,00,2e,00,30,00,2e,00,35,\ 00,31,00,62,00,5c,00,62,00,69,00,6e,00,5c,00,6d,00,79,00,73,00,71,00,6c,00,\ 64,00,2d,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ntbackup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Oakley] "EventMessageFile"="%SystemRoot%\\System32\\oakley.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Offline Files] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,73,00,63,00,75,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"="0x00000007" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perfctrs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfDisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,64,00,69,00,73,00,6b,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perflib] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,72,00,66,00,6c,00,62,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perfmon] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfNet] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,6e,00,65,00,74,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfOS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,4f,00,53,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfProc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,70,00,72,00,6f,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Remote Assistance] "EventMessageFile"="%SystemRoot%\\System32\\xpsp2res.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\RPC] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,33,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SAFrdms] "EventMessageFile"="D:\\WINDOWS\\system32\\safrdm.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\safrslv] "EventMessageFile"="D:\\WINDOWS\\system32\\safrslv.dll" "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SceCli] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SceSrv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,65,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SclgNtfy] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Installation] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,70,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Restriction Policies] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SpoolerCtrs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,73,00,70,00,6f,00,6f,00,6c,00,2e,00,64,00,72,00,76,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Starter] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SysmonLog] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Tlntsvr] "EventMessageFile"="D:\\WINDOWS\\system32\\tlntsvr.exe;D:\\WINDOWS\\system32\\xpsp1res.dll" "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userenv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,73,00,65,00,72,00,65,00,6e,00,76,00,2e,00,64,00,6c,00,6c,00,3b,\ 00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\ 5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,\ 00,70,00,31,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,53,00,\ 79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,\ 00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,\ 72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userinit] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\VBRuntime] "EventMessageFile"="D:\\WINDOWS\\system32\\msvbvm60.dll" "TypesSupported"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSS] "TypesSupported"=dword:00000007 "EventMessageFile"="D:\\WINDOWS\\system32\\vssvc.exe" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WebClient] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows 3.1 Migration] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,64,00,76,00,61,00,70,00,69,00,33,00,32,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Product Activation] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,70,00,63,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinMgmt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,\ 00,52,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,\ 6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,\ 00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,\ 64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WmdmPmSN] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,\ 73,00,50,00,4d,00,53,00,4e,00,53,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WMIAdapter] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,4d,00,49,00,41,00,70,00,52,00,65,\ 00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WSH] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security] "DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "DisplayNameID"=dword:00000101 "File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\ 6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,65,00,63,00,45,00,76,00,65,00,6e,\ 00,74,00,2e,00,45,00,76,00,74,00,00,00 "MaxSize"=dword:00080000 "PrimaryModule"="Security" "Retention"=dword:00093a80 "Sources"=hex(7):53,00,70,00,6f,00,6f,00,6c,00,65,00,72,00,00,00,53,00,65,00,\ 63,00,75,00,72,00,69,00,74,00,79,00,20,00,41,00,63,00,63,00,6f,00,75,00,6e,\ 00,74,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,53,00,43,00,\ 20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,4e,00,65,00,74,00,44,\ 00,44,00,45,00,20,00,4f,00,62,00,6a,00,65,00,63,00,74,00,00,00,4c,00,53,00,\ 41,00,00,00,44,00,53,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,\ 00,00,00,00,00 "RestrictGuestAccess"=dword:00000001 "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS\ObjectNames] "Directory Service Object"=dword:00001e00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames] "PolicyObject"=dword:00001600 "SecretObject"=dword:00001610 "TrustedDomainObject"=dword:00001620 "UserAccountObject"=dword:00001630 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object\ObjectNames] "DDE Share"=dword:00001d00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames] "SC_MANAGER Object"=dword:00001c00 "SERVICE Object"=dword:00001c10 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security] "CategoryCount"=dword:00000009 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,41,00,75,00,64,00,69,00,74,00,45,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "GuidMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,4e,00,74,00,4d,00,61,00,72,00,74,00,61,00,2e,00,64,00,6c,00,6c,00,00,00 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,4d,00,73,00,41,00,75,00,64,00,69,00,74,00,45,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,\ 53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,\ 00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,\ 33,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001c [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames] "Channel"=dword:00001400 "Desktop"=dword:00001a10 "Device"=dword:00001100 "Directory"=dword:00001110 "Event"=dword:00001120 "EventPair"=dword:00001130 "File"=dword:00001140 "IoCompletion"=dword:00001300 "Job"=dword:00001410 "Key"=dword:00001150 "MailSlot"=dword:00001140 "Mutant"=dword:00001160 "NamedPipe"=dword:00001140 "Port"=dword:00001170 "Process"=dword:00001180 "Profile"=dword:00001190 "Section"=dword:000011a0 "Semaphore"=dword:000011b0 "SymbolicLink"=dword:000011c0 "Thread"=dword:000011d0 "Timer"=dword:000011e0 "Token"=dword:000011f0 "Type"=dword:00001200 "WaitablePort"=dword:00001170 "WindowStation"=dword:00001a00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames] "SAM_ALIAS"=dword:00001530 "SAM_DOMAIN"=dword:00001510 "SAM_GROUP"=dword:00001520 "SAM_SERVER"=dword:00001500 "SAM_USER"=dword:00001540 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames] "Document"=dword:00001b20 "Printer"=dword:00001b10 "Server"=dword:00001b00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System] "DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "DisplayNameID"=dword:00000102 "File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\ 6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,79,00,73,00,45,00,76,00,65,00,6e,\ 00,74,00,2e,00,45,00,76,00,74,00,00,00 "MaxSize"=dword:00080000 "PrimaryModule"="System" "Retention"=dword:00093a80 "Sources"=hex(7):57,00,5a,00,43,00,53,00,56,00,43,00,00,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,\ 00,6f,00,77,00,73,00,20,00,55,00,70,00,64,00,61,00,74,00,65,00,20,00,41,00,\ 67,00,65,00,6e,00,74,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,\ 00,53,00,63,00,72,00,69,00,70,00,74,00,20,00,48,00,6f,00,73,00,74,00,00,00,\ 57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,46,00,69,00,6c,00,65,00,20,\ 00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,57,00,\ 69,00,6e,00,33,00,32,00,6b,00,00,00,57,00,33,00,32,00,54,00,69,00,6d,00,65,\ 00,00,00,56,00,6f,00,6c,00,53,00,6e,00,61,00,70,00,00,00,76,00,69,00,61,00,\ 69,00,64,00,65,00,00,00,56,00,67,00,61,00,53,00,61,00,76,00,65,00,00,00,55,\ 00,53,00,45,00,52,00,33,00,32,00,00,00,55,00,50,00,53,00,00,00,75,00,6c,00,\ 74,00,72,00,61,00,00,00,75,00,64,00,66,00,73,00,00,00,74,00,6f,00,73,00,69,\ 00,64,00,65,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,53,00,\ 65,00,73,00,73,00,44,00,69,00,72,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,\ 00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,\ 72,00,76,00,44,00,65,00,76,00,69,00,63,00,65,00,73,00,00,00,54,00,65,00,72,\ 00,6d,00,44,00,44,00,00,00,74,00,64,00,69,00,00,00,54,00,43,00,50,00,4d,00,\ 6f,00,6e,00,00,00,54,00,63,00,70,00,69,00,70,00,00,00,53,00,79,00,73,00,74,\ 00,65,00,6d,00,20,00,45,00,72,00,72,00,6f,00,72,00,00,00,73,00,79,00,6d,00,\ 5f,00,75,00,33,00,00,00,73,00,79,00,6d,00,5f,00,68,00,69,00,00,00,73,00,79,\ 00,6d,00,63,00,38,00,78,00,78,00,00,00,73,00,79,00,6d,00,63,00,38,00,31,00,\ 30,00,00,00,53,00,74,00,69,00,6c,00,6c,00,49,00,6d,00,61,00,67,00,65,00,00,\ 00,53,00,53,00,44,00,50,00,53,00,52,00,56,00,00,00,53,00,72,00,76,00,00,00,\ 73,00,72,00,73,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,73,00,72,00,00,\ 00,73,00,70,00,61,00,72,00,72,00,6f,00,77,00,00,00,73,00,6e,00,64,00,62,00,\ 6c,00,73,00,74,00,00,00,53,00,69,00,6d,00,62,00,61,00,64,00,00,00,53,00,69,\ 00,64,00,65,00,42,00,79,00,53,00,69,00,64,00,65,00,00,00,73,00,66,00,6c,00,\ 6f,00,70,00,70,00,79,00,00,00,53,00,65,00,74,00,75,00,70,00,00,00,53,00,65,\ 00,72,00,76,00,69,00,63,00,65,00,20,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,\ 6c,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,53,00,65,00,72,\ 00,76,00,65,00,72,00,00,00,73,00,65,00,72,00,69,00,61,00,6c,00,00,00,73,00,\ 63,00,73,00,69,00,70,00,6f,00,72,00,74,00,00,00,53,00,63,00,68,00,65,00,64,\ 00,75,00,6c,00,65,00,00,00,53,00,63,00,68,00,61,00,6e,00,6e,00,65,00,6c,00,\ 00,00,53,00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,00,00,53,00,61,00,76,\ 00,65,00,20,00,44,00,75,00,6d,00,70,00,00,00,53,00,41,00,4d,00,00,00,52,00,\ 54,00,4c,00,45,00,38,00,30,00,32,00,33,00,78,00,70,00,00,00,52,00,53,00,56,\ 00,50,00,00,00,72,00,73,00,70,00,6e,00,64,00,72,00,00,00,52,00,65,00,6d,00,\ 6f,00,76,00,61,00,62,00,6c,00,65,00,20,00,53,00,74,00,6f,00,72,00,61,00,67,\ 00,65,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,52,00,65,00,\ 6d,00,6f,00,74,00,65,00,41,00,63,00,63,00,65,00,73,00,73,00,00,00,72,00,65,\ 00,64,00,62,00,6f,00,6f,00,6b,00,00,00,52,00,64,00,62,00,73,00,73,00,00,00,\ 52,00,61,00,73,00,4d,00,61,00,6e,00,00,00,52,00,61,00,73,00,41,00,75,00,74,\ 00,6f,00,00,00,71,00,6c,00,31,00,32,00,38,00,30,00,00,00,71,00,6c,00,31,00,\ 32,00,34,00,30,00,00,00,71,00,6c,00,31,00,32,00,31,00,36,00,30,00,00,00,71,\ 00,6c,00,31,00,30,00,77,00,6e,00,74,00,00,00,71,00,6c,00,31,00,30,00,38,00,\ 30,00,00,00,50,00,53,00,63,00,68,00,65,00,64,00,00,00,50,00,72,00,69,00,6e,\ 00,74,00,00,00,50,00,70,00,74,00,70,00,4d,00,69,00,6e,00,69,00,70,00,6f,00,\ 72,00,74,00,00,00,50,00,6f,00,6c,00,69,00,63,00,79,00,41,00,67,00,65,00,6e,\ 00,74,00,00,00,50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,4d,00,61,00,\ 6e,00,61,00,67,00,65,00,72,00,00,00,70,00,65,00,72,00,63,00,32,00,00,00,70,\ 00,63,00,6d,00,63,00,69,00,61,00,00,00,70,00,63,00,69,00,69,00,64,00,65,00,\ 00,00,70,00,63,00,69,00,00,00,70,00,61,00,72,00,76,00,64,00,6d,00,00,00,70,\ 00,61,00,72,00,74,00,6d,00,67,00,72,00,00,00,70,00,61,00,72,00,70,00,6f,00,\ 72,00,74,00,00,00,4f,00,53,00,50,00,46,00,4d,00,69,00,62,00,00,00,4f,00,53,\ 00,50,00,46,00,00,00,6e,00,76,00,00,00,6e,00,75,00,6c,00,6c,00,00,00,6e,00,\ 74,00,66,00,73,00,00,00,6e,00,70,00,66,00,73,00,00,00,4e,00,6c,00,61,00,00,\ 00,4e,00,49,00,43,00,31,00,33,00,39,00,34,00,00,00,4e,00,45,00,54,00,77,00,\ 34,00,78,00,33,00,32,00,00,00,4e,00,65,00,74,00,6c,00,6f,00,67,00,6f,00,6e,\ 00,00,00,4e,00,65,00,74,00,44,00,44,00,45,00,00,00,4e,00,65,00,74,00,42,00,\ 54,00,00,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,00,00,4e,00,64,00,69,\ 00,73,00,57,00,61,00,6e,00,00,00,4e,00,64,00,69,00,73,00,49,00,50,00,00,00,\ 6e,00,64,00,69,00,73,00,00,00,6e,00,61,00,70,00,69,00,70,00,73,00,65,00,63,\ 00,65,00,6e,00,66,00,00,00,6e,00,61,00,70,00,61,00,67,00,65,00,6e,00,74,00,\ 00,00,4d,00,75,00,70,00,00,00,6d,00,73,00,66,00,73,00,00,00,6d,00,73,00,61,\ 00,64,00,6c,00,69,00,62,00,00,00,4d,00,72,00,78,00,53,00,6d,00,62,00,00,00,\ 4d,00,52,00,78,00,44,00,41,00,56,00,00,00,6d,00,72,00,61,00,69,00,64,00,33,\ 00,35,00,78,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,6d,00,6f,00,\ 75,00,63,00,6c,00,61,00,73,00,73,00,00,00,4d,00,6f,00,64,00,65,00,6d,00,00,\ 00,4c,00,73,00,61,00,53,00,72,00,76,00,00,00,4c,00,6d,00,48,00,6f,00,73,00,\ 74,00,73,00,00,00,4c,00,44,00,4d,00,53,00,00,00,4c,00,44,00,4d,00,00,00,6c,\ 00,62,00,72,00,74,00,66,00,64,00,63,00,00,00,4b,00,65,00,72,00,62,00,65,00,\ 72,00,6f,00,73,00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6b,00,62,\ 00,64,00,63,00,6c,00,61,00,73,00,73,00,00,00,69,00,73,00,61,00,70,00,6e,00,\ 70,00,00,00,49,00,50,00,58,00,53,00,41,00,50,00,00,00,49,00,50,00,58,00,52,\ 00,6f,00,75,00,74,00,65,00,72,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,\ 00,00,49,00,50,00,58,00,52,00,49,00,50,00,00,00,49,00,50,00,58,00,43,00,50,\ 00,00,00,49,00,50,00,53,00,65,00,63,00,00,00,49,00,50,00,52,00,6f,00,75,00,\ 74,00,65,00,72,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,49,00,50,\ 00,52,00,49,00,50,00,32,00,00,00,49,00,50,00,4e,00,41,00,54,00,48,00,4c,00,\ 50,00,00,00,49,00,50,00,4d,00,47,00,4d,00,00,00,49,00,50,00,42,00,4f,00,4f,\ 00,54,00,50,00,00,00,69,00,6e,00,74,00,65,00,6c,00,70,00,70,00,6d,00,00,00,\ 69,00,6e,00,74,00,65,00,6c,00,69,00,64,00,65,00,00,00,69,00,6e,00,69,00,39,\ 00,31,00,30,00,75,00,00,00,49,00,47,00,4d,00,50,00,76,00,32,00,00,00,69,00,\ 38,00,30,00,34,00,32,00,70,00,72,00,74,00,00,00,69,00,32,00,6f,00,6d,00,70,\ 00,00,00,69,00,32,00,6f,00,6d,00,67,00,6d,00,74,00,00,00,48,00,74,00,74,00,\ 70,00,00,00,68,00,70,00,6e,00,00,00,66,00,74,00,64,00,69,00,73,00,6b,00,00,\ 00,66,00,73,00,5f,00,72,00,65,00,63,00,00,00,66,00,6c,00,70,00,79,00,64,00,\ 69,00,73,00,6b,00,00,00,46,00,69,00,70,00,73,00,00,00,66,00,64,00,63,00,00,\ 00,66,00,61,00,73,00,74,00,66,00,61,00,74,00,00,00,65,00,76,00,65,00,6e,00,\ 74,00,6c,00,6f,00,67,00,00,00,65,00,66,00,73,00,00,00,64,00,70,00,74,00,69,\ 00,32,00,6f,00,00,00,44,00,6e,00,73,00,63,00,61,00,63,00,68,00,65,00,00,00,\ 44,00,6e,00,73,00,61,00,70,00,69,00,00,00,64,00,6d,00,69,00,6f,00,00,00,64,\ 00,6d,00,62,00,6f,00,6f,00,74,00,00,00,44,00,69,00,73,00,74,00,72,00,69,00,\ 62,00,75,00,74,00,65,00,64,00,20,00,4c,00,69,00,6e,00,6b,00,20,00,54,00,72,\ 00,61,00,63,00,6b,00,69,00,6e,00,67,00,20,00,43,00,6c,00,69,00,65,00,6e,00,\ 74,00,00,00,64,00,69,00,73,00,6b,00,00,00,44,00,68,00,63,00,70,00,51,00,65,\ 00,63,00,00,00,44,00,68,00,63,00,70,00,00,00,44,00,66,00,73,00,53,00,76,00,\ 63,00,00,00,44,00,66,00,73,00,44,00,72,00,69,00,76,00,65,00,72,00,00,00,44,\ 00,43,00,4f,00,4d,00,00,00,64,00,61,00,63,00,39,00,36,00,30,00,6e,00,74,00,\ 00,00,64,00,61,00,63,00,32,00,77,00,32,00,6b,00,00,00,63,00,70,00,71,00,61,\ 00,72,00,72,00,61,00,79,00,00,00,63,00,6d,00,64,00,69,00,64,00,65,00,00,00,\ 63,00,68,00,61,00,6e,00,67,00,65,00,72,00,00,00,63,00,64,00,72,00,6f,00,6d,\ 00,00,00,43,00,64,00,6d,00,00,00,63,00,64,00,66,00,73,00,00,00,63,00,64,00,\ 61,00,75,00,64,00,69,00,6f,00,00,00,63,00,64,00,32,00,30,00,78,00,72,00,6e,\ 00,74,00,00,00,63,00,62,00,69,00,64,00,66,00,32,00,6b,00,00,00,42,00,72,00,\ 6f,00,77,00,73,00,65,00,72,00,00,00,42,00,49,00,54,00,53,00,00,00,62,00,65,\ 00,65,00,70,00,00,00,41,00,74,00,6d,00,61,00,72,00,70,00,63,00,00,00,61,00,\ 74,00,64,00,69,00,73,00,6b,00,00,00,61,00,74,00,61,00,70,00,69,00,00,00,41,\ 00,73,00,79,00,6e,00,63,00,4d,00,61,00,63,00,00,00,61,00,73,00,63,00,33,00,\ 35,00,35,00,30,00,00,00,61,00,73,00,63,00,33,00,33,00,35,00,30,00,70,00,00,\ 00,61,00,73,00,63,00,00,00,41,00,72,00,70,00,31,00,33,00,39,00,34,00,00,00,\ 41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,50,\ 00,6f,00,70,00,75,00,70,00,00,00,61,00,70,00,70,00,68,00,65,00,6c,00,70,00,\ 00,00,61,00,6d,00,73,00,69,00,6e,00,74,00,00,00,61,00,6d,00,69,00,30,00,6e,\ 00,74,00,00,00,61,00,6c,00,69,00,69,00,64,00,65,00,00,00,41,00,6c,00,65,00,\ 72,00,74,00,65,00,72,00,00,00,61,00,69,00,63,00,37,00,38,00,78,00,78,00,00,\ 00,61,00,69,00,63,00,37,00,38,00,75,00,32,00,00,00,61,00,68,00,61,00,31,00,\ 35,00,34,00,78,00,00,00,61,00,64,00,70,00,75,00,31,00,36,00,30,00,6d,00,00,\ 00,61,00,63,00,70,00,69,00,65,00,63,00,00,00,61,00,63,00,70,00,69,00,00,00,\ 61,00,62,00,70,00,34,00,38,00,30,00,6e,00,35,00,00,00,61,00,62,00,69,00,6f,\ 00,73,00,64,00,73,00,6b,00,00,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,\ 00,00 "RestrictGuestAccess"=dword:00000001 "EventMessageFile"="%systemroot%\\system32\\stisvc.exe" "TypesSupported"=hex:07,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\abiosdsk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\abp480n5] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\acpi] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,63,00,70,00,69,00,2e,00,73,00,\ 79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\acpiec] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,63,00,70,00,69,00,65,00,63,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\adpu160m] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\aha154x] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\aic78u2] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\aic78xx] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Alerter] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\aliide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,41,00,6c,00,69,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ami0nt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\amsint] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\apphelp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,70,00,70,00,68,00,65,00,6c,00,70,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Application Popup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,53,\ 00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,\ 79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,\ 00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Arp1394] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\asc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\asc3350p] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\asc3550] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\AsyncMac] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\atapi] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\atdisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Atmarpc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\beep] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\BITS] "TypesSupported"=dword:00000007 "CategoryCount"=dword:00000001 "CategoryMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,78,00,70,00,6f,00,62,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "EventMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,6f,00,62,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Browser] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cbidf2k] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cd20xrnt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cdaudio] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cdfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Cdm] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cdrom] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\changer] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cmdide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,43,00,6d,00,64,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cpqarray] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dac2w2k] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dac960nt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DCOM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DfsDriver] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DfsSvc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Dhcp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,68,00,63,00,70,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DhcpQec] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,68,00,63,00,70,00,71,00,65,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,64,00,68,00,63,00,70,00,71,00,65,00,63,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\disk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Distributed Link Tracking Client] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dmboot] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,62,00,6f,\ 00,6f,00,74,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dmio] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,69,00,6f,00,2e,00,73,00,\ 79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Dnsapi] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Dnscache] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dpti2o] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\efs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\eventlog] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\fastfat] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\fdc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,64,00,63,00,2e,00,73,00,79,00,\ 73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Fips] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,69,00,70,00,73,\ 00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\flpydisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,6c,00,70,00,79,00,64,00,69,00,\ 73,00,6b,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\fs_rec] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ftdisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,46,00,74,00,44,00,69,00,73,00,6b,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\hpn] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Http] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\i2omgmt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\i2omp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,38,00,30,00,34,00,32,00,70,00,\ 72,00,74,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,67,00,6d,00,70,00,76,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ini910u] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\intelide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,6c,00,49,00,\ 64,00,65,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,6e,00,74,00,65,00,6c,00,70,00,\ 70,00,6d,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,70,00,62,00,6f,00,6f,00,74,00,70,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMGM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,74,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPNATHLP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,70,00,6e,00,61,00,74,00,68,00,6c,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,70,00,72,00,69,00,70,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRouterManager] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPSec] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPXCP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPXRIP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPXRouterManager] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPXSAP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,73,00,61,00,70,00,6e,00,70,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6b,00,62,00,64,00,63,00,6c,00,61,00,\ 73,00,73,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6b,00,62,00,64,00,68,00,69,00,64,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Kerberos] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6b,00,65,00,72,00,62,00,65,00,72,00,6f,00,73,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\lbrtfdc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6c,00,62,00,72,00,74,00,66,00,64,00,\ 63,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\LDM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,6d,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,65,00,78,00,65,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\LDMS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,6d,00,73,00,65,00,72,00,76,00,65,00,72,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\LmHosts] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Modem] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,6f,00,64,00,65,00,6d,00,2e,00,\ 73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6d,00,6f,00,75,00,63,00,6c,00,61,00,\ 73,00,73,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6d,00,6f,00,75,00,68,00,69,00,64,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\mraid35x] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\MRxDAV] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\MrxSmb] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,69,00,6f,\ 00,6c,00,6f,00,67,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\msadlib] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\msfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Mup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\napagent] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,71,00,61,00,67,00,65,00,6e,00,74,00,72,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\napipsecenf] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,61,00,70,00,69,00,70,00,73,00,65,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ndis] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NdisIP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NdisWan] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NetBIOS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,6f,00,6c,00,6f,00,67,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NetBT] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NetDDE] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Netlogon] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NETw4x32] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,4e,00,45,00,54,00,77,00,34,00,78,00,\ 33,00,32,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NIC1394] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Nla] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\npfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ntfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\null] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\nv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6e,00,76,00,34,00,5f,00,6d,00,69,00,\ 6e,00,69,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6f,00,73,00,70,00,66,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6f,00,73,00,70,00,66,00,6d,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\parport] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,61,00,72,00,50,00,6f,00,72,00,\ 74,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\partmgr] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\parvdm] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,61,00,72,00,56,00,64,00,6d,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\pci] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,63,00,69,00,2e,00,73,00,79,00,\ 73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\pciide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,63,00,69,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\perc2] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,6d,00,70,00,6e,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,6f,00,6c,00,61,00,67,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PptpMiniport] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Print] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,70,00,6c,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PSched] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql1080] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql10wnt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql12160] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql1240] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql1280] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RasAuto] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RasMan] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Rdbss] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\redbook] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,72,00,65,00,64,00,62,00,6f,00,6f,00,\ 6b,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RemoteAccess] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,69,00,61,00,73,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Removable Storage Service] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,4e,00,54,00,4d,00,53,00,45,00,56,00,54,00,2e,00,44,00,4c,00,4c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\rspndr] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RSVP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,73,00,76,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RTLE8023xp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,61,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Save Dump] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,53,00,61,00,76,00,65,00,44,00,75,00,6d,00,70,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SCardSvr] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,53,00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Schedule] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\scsiport] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\serial] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,53,00,65,00,72,00,69,00,61,00,6c,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Server] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Setup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,79,00,73,00,73,00,65,00,74,00,75,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sfloppy] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SideBySide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,78,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Simbad] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sndblst] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sparrow] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sr] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,49,00,\ 6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,3b,00,44,\ 00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,\ 73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,\ 00,53,00,5c,00,73,00,72,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\srservice] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,\ 72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Srv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SSDPSRV] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,61,00,73,00,65,00,72,00,76,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\symc810] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\symc8xx] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sym_hi] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sym_u3] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\System] "CategoryCount"=dword:00000007 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,64,00,6c,00,\ 6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\System Error] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Tcpip] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon] "TypesSupported"=dword:00000007 "EventMessageFile"="%SystemRoot%\\System32\\tcpmon.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\tdi] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TermDD] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServDevices] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TermService] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,3b,\ 00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\ 5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,00,74,00,64,\ 00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,74,00,73,00,73,00,64,00,69,00,73,00,2e,00,65,00,78,00,65,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\toside] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,54,00,6f,00,73,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\udfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ultra] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\UPS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\USER32] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,73,00,65,00,72,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\VgaSave] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,76,00,67,00,61,00,2e,00,73,00,79,00,\ 73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\viaide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,56,00,69,00,61,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\VolSnap] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,56,00,6f,00,6c,00,53,00,6e,00,61,00,\ 70,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time] "EventMessageFile"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,\ 33,00,32,00,74,00,69,00,6d,00,65,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Win32k] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,33,00,32,00,6b,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows File Protection] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,66,00,63,00,5f,00,6f,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Script Host] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000018 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Update Agent] "CategoryCount"=dword:00000009 "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,75,00,61,00,75,00,63,00,70,00,6c,00,2e,00,63,00,70,00,6c,00,3b,\ 00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,75,00,61,\ 00,75,00,63,00,70,00,6c,00,2e,00,63,00,70,00,6c,00,2e,00,6d,00,75,00,69,00,\ 00,00 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,77,00,75,00,61,00,75,00,63,00,70,00,6c,00,2e,00,63,00,70,00,6c,00,\ 2e,00,6d,00,75,00,69,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Workstation] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WZCSVC] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,7a,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,\ 00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,\ 6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="COM+ Event System" "Group"="Network" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem\Parameters] "ServiceDll"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,65,00,73,00,\ 2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem\Security] "Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem\Enum] "0"="Root\\LEGACY_EVENTSYSTEM\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fastfat] "ErrorControl"=dword:00000001 "Group"="Boot file system" "Start"=dword:00000004 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fastfat\Enum] "0"="Root\\LEGACY_FASTFAT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Fast User Switching Compatibility" "DependOnService"=hex(7):54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,69,00,\ 63,00,65,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides management for applications that require assistance in a multiple user environment." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="BadApplicationServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Enum] "0"="Root\\LEGACY_FASTUSERSWITCHINGCOMPATIBILITY\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fdc] "ErrorControl"=dword:00000000 "Group"="System Bus Extender" "Start"=dword:00000001 "Tag"=dword:00000000 "Type"=dword:00000001 "SetupDone"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fdc\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fips] "ErrorControl"=dword:00000001 "Start"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fips\Enum] "0"="Root\\LEGACY_FIPS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Flpydisk] "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Flpydisk\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FltMgr] "Type"=dword:00000002 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,66,00,6c,00,74,00,4d,00,67,00,72,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="FltMgr" "Group"="FSFilter Infrastructure" "Description"="File System Filter Manager Driver" "AttachWhenLoaded"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FltMgr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FltMgr\Enum] "0"="Root\\LEGACY_FLTMGR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fs_Rec] "ErrorControl"=dword:00000000 "Group"="Boot file system" "Start"=dword:00000001 "Type"=dword:00000008 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fs_Rec\Enum] "0"="Root\\LEGACY_FS_REC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ftdisk] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000009 "Type"=dword:00000001 "DisplayName"="Volume Manager Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,66,00,74,00,64,00,69,00,73,00,6b,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ftdisk\Enum] "0"="Root\\ftdisk\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gpc] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000006 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,73,00,67,00,70,00,63,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Generic Packet Classifier" "Group"="PNP_TDI" "Description"="Generic Packet Classifier" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gpc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gpc\Enum] "0"="Root\\LEGACY_GPC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HDAudBus] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,48,00,44,00,41,00,75,00,64,00,42,\ 00,75,00,73,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft UAA Bus Driver for High Definition Audio" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HDAudBus\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HDAudBus\Enum] "0"="PCI\\VEN_8086&DEV_27D8&SUBSYS_FF021179&REV_02\\3&b1bfb68&0&D8" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Help and Support" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,05,00,03,\ 00,01,00,00,00,64,00,00,00,01,00,00,00,64,00,00,00,00,00,00,00,64,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc\Parameters] "ServiceDll"=hex(2):25,00,57,00,49,00,4e,00,44,00,49,00,52,00,25,00,5c,00,50,\ 00,43,00,48,00,65,00,61,00,6c,00,74,00,68,00,5c,00,48,00,65,00,6c,00,70,00,\ 43,00,74,00,72,00,5c,00,42,00,69,00,6e,00,61,00,72,00,69,00,65,00,73,00,5c,\ 00,70,00,63,00,68,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc\Enum] "0"="Root\\LEGACY_HELPSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidServ] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="HID Input Service" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidServ\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 68,00,69,00,64,00,73,00,65,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidServ\Enum] "0"="Root\\LEGACY_HIDSERV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hidusb] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "DisplayName"="Microsoft HID Class Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,68,00,69,00,64,00,75,00,73,00,62,\ 00,2e,00,73,00,79,00,73,00,00,00 "Group"="extended base" "Tag"=dword:00000006 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hkmsvc] "DisplayName"="Health Key and Certificate Management Service" "Description"="Manages health certificates and keys (used by NAP)" "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "ObjectName"="localSystem" "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6b,00,6d,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hkmsvc\Enum] "0"="Root\\LEGACY_HKMSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpn] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpn\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpn\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP] "DisplayName"="HTTP" "Description"="This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start." "ErrorControl"=dword:00000001 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,48,00,54,00,54,00,50,00,2e,00,73,\ 00,79,00,73,00,00,00 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\SslBindingInfo] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo] "http://*:2869/"=hex:01,00,04,80,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,\ 00,02,00,1c,00,01,00,00,00,00,00,14,00,00,00,00,20,01,01,00,00,00,00,00,05,\ 13,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Security] "Security"=hex:01,00,14,80,b8,00,00,00,c4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,88,00,06,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,\ 14,00,14,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,14,00,14,00,00,\ 00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Enum] "0"="Root\\LEGACY_HTTP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter] "DependOnService"=hex(7):48,00,54,00,54,00,50,00,00,00,00,00 "Description"="This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="HTTP SSL" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,48,00,54,00,54,00,50,00,46,00,69,00,6c,00,74,00,65,00,72,00,00,\ 00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,33,00,73,00,73,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="HTTPFilterServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter\Security] "Security"=hex:01,00,14,80,b8,00,00,00,c4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,88,00,06,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,\ 14,00,14,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,14,00,14,00,00,\ 00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter\Enum] "0"="Root\\LEGACY_HTTPFILTER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omgmt] "ErrorControl"=dword:00000001 "Group"="SCSI Class" "Start"=dword:00000001 "Tag"=dword:0000002d "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000002d "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt] "Type"=dword:00000001 "Start"=dword:00000001 "Group"="Keyboard Port" "ErrorControl"=dword:00000001 "DisplayName"="i8042 Keyboard and PS/2 Mouse Port Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,38,00,30,00,34,00,32,00,70,\ 00,72,00,74,00,2e,00,73,00,79,00,73,00,00,00 "Tag"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt\Parameters] "LayerDriver JPN"="kbd101.dll" "LayerDriver KOR"="kbd101a.dll" "PollingIterations"=dword:00002ee0 "PollingIterationsMaximum"=dword:00002ee0 "ResendIterations"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt\Enum] "0"="ACPI\\PNP0303\\4&38462492&0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="ACPI\\SYN0705\\4&38462492&0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Imapi] "ErrorControl"=dword:00000001 "Group"="Pnp Filter" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="CD-Burning Filter Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6d,00,61,00,70,00,69,00,2e,\ 00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Imapi\Enum] "0"="IDE\\CdRomTSSTcorp_CD/DVDW_TS-L632D_______________TO04____\\5&195506ac&0&0.0.0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ImapiService] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"="D:\\WINDOWS\\system32\\imapi.exe" "ObjectName"="LocalSystem" "DisplayName"="IMAPI CD-Burning COM Service" "Description"="Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ImapiService\Enum] "0"="Root\\LEGACY_IMAPISERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\inetaccs] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\inetaccs\Parameters] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ini910u] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000030 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ini910u\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ini910u\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Inport] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Inport\Parameters] "HzMode"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IntcAzAudAddService] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,52,00,74,00,6b,00,48,00,44,00,41,\ 00,75,00,64,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Service for Realtek HD Audio (WDM)" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IntcAzAudAddService\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IntcAzAudAddService\Enum] "0"="HDAUDIO\\FUNC_01&VEN_10EC&DEV_0862&SUBSYS_1179010C&REV_1000\\4&d94559&0&0001" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IntelIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000004 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000003 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6e,00,74,00,65,00,6c,00,70,\ 00,70,00,6d,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Intel Processor Driver" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm\Enum] "0"="ACPI\\GenuineIntel_-_x86_Family_6_Model_15\\_0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="ACPI\\GenuineIntel_-_x86_Family_6_Model_15\\_1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ip6Fw] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,49,00,70,00,36,00,46,00,77,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="IPv6 Windows Firewall Driver" "Description"="Provides intrusion prevention service for a home or small office network." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ip6Fw\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpFilterDriver] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,66,00,6c,00,74,00,64,\ 00,72,00,76,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IP Traffic Filter Driver" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="IP Traffic Filter Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpFilterDriver\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpInIp] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,69,00,6e,00,69,00,70,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IP in IP Tunnel Driver" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="IP in IP Tunnel Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpInIp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpNat] "DependOnGroup"=hex(7):00,00 "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "Description"="IP Network Address Translator" "DisplayName"="IP Network Address Translator" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,6e,00,61,00,74,00,2e,\ 00,73,00,79,00,73,00,00,00 "Start"=dword:00000003 "Type"=dword:00000001 "Group"="FirewallGroup" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpNat\Enum] "0"="Root\\LEGACY_IPNAT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSec] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,73,00,65,00,63,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="IPSEC driver" "Group"="PNP_TDI" "Description"="IPSEC driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSec\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSec\Enum] "0"="Root\\LEGACY_IPSEC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRENUM] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,72,00,65,00,6e,00,75,00,6d,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IR Enumerator Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRENUM\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ISAPISearch] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ISAPISearch\Linkage] "Bind"="\\Dummy" "Export"="\\Dummy" "Route"="\\Dummy" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ISAPISearch\Performance] "Close"="DoneCIISAPIPerformanceData" "Collect"="CollectCIISAPIPerformanceData" "Open"="InitializeCIISAPIPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\ 00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:000008de "Last Help"=dword:000008df "First Counter"=dword:000008ca "First Help"=dword:000008cb "Object List"="2250" "WbemAdapFileSignature"=hex:91,57,4d,b0,c7,47,a6,91,95,d7,e5,6a,5c,87,42,6e "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:0015e800 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp] "ErrorControl"=dword:00000003 "Group"="Boot Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000003 "Type"=dword:00000001 "HasBootConfig"=dword:00000000 "DisplayName"="PnP ISA/EISA Bus Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,73,00,61,00,70,00,6e,00,70,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp\Parameters] "ADP1502"=dword:00000001 "ADP1505"=dword:00000001 "ADP1510"=dword:00000001 "ADP1512"=dword:00000001 "ADP1515"=dword:00000001 "ADP1520"=dword:00000001 "ADP1522"=dword:00000001 "ADP3015"=dword:00000001 "ADP3215"=dword:00000001 "ADP6360"=dword:00000001 "ADP6370"=dword:00000001 "USR0014"=dword:00000001 "USR1001"=dword:00000001 "USR1002"=dword:00000001 "USR1003"=dword:00000001 "USR1004"=dword:00000001 "USR6001"=dword:00000001 "USR6002"=dword:00000001 "USR6003"=dword:00000001 "USR6004"=dword:00000001 "USR6005"=dword:00000001 "USR6006"=dword:00000001 "USR6007"=dword:00000001 "USR6008"=dword:00000001 "USR6009"=dword:00000001 "USR600A"=dword:00000001 "USR600B"=dword:00000001 "USR600C"=dword:00000001 "USR600D"=dword:00000001 "USR600E"=dword:00000001 "USR600F"=dword:00000001 "USR6010"=dword:00000001 "USR6011"=dword:00000001 "USR6012"=dword:00000001 "USR6101"=dword:00000001 "USR6020"=dword:00000001 "USR0041"=dword:00000001 "USR002C"=dword:00000001 "AZT4029"=dword:00000001 "AZT4023"=dword:00000001 "USR0040"=dword:00000001 "HAY8601"=dword:00000001 "EQX2400"=dword:00000002 "EQX0900"=dword:00000002 "EQX1B00"=dword:00000002 "EQX1700"=dword:00000002 "EQX0700"=dword:00000002 "EQX0F00"=dword:00000002 "EQX0800"=dword:00000002 "EQX1000"=dword:00000002 "EQX3F00"=dword:00000002 "EQX1200"=dword:00000002 "IBM0001"=dword:00000010 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp\Enum] "0"="PCI\\VEN_8086&DEV_27B9&SUBSYS_00000000&REV_02\\3&b1bfb68&0&F8" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JavaQuickStarterService] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,44,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,5c,\ 00,6a,00,72,00,65,00,36,00,5c,00,62,00,69,00,6e,00,5c,00,6a,00,71,00,73,00,\ 2e,00,65,00,78,00,65,00,22,00,20,00,2d,00,73,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,20,00,2d,00,63,00,6f,00,6e,00,66,00,69,00,67,00,20,00,22,00,44,00,\ 3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,\ 00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,5c,00,6a,00,72,00,65,00,36,00,\ 5c,00,6c,00,69,00,62,00,5c,00,64,00,65,00,70,00,6c,00,6f,00,79,00,5c,00,6a,\ 00,71,00,73,00,5c,00,6a,00,71,00,73,00,2e,00,63,00,6f,00,6e,00,66,00,22,00,\ 00,00 "DisplayName"="Java Quick Starter" "ObjectName"="LocalSystem" "Description"="Prefetches JRE files for faster startup of Java applets and applications" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JavaQuickStarterService\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JavaQuickStarterService\Enum] "0"="Root\\LEGACY_JAVAQUICKSTARTERSERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kbdclass] "ErrorControl"=dword:00000001 "Group"="Keyboard Class" "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Keyboard Class Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6b,00,62,00,64,00,63,00,6c,00,61,\ 00,73,00,73,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kbdclass\Parameters] "ConnectMultiplePorts"=dword:00000000 "KeyboardDataQueueSize"=dword:00000064 "KeyboardDeviceBaseName"="KeyboardClass" "MaximumPortsServiced"=dword:00000003 "SendOutputToAllPorts"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kbdclass\Enum] "0"="Root\\RDP_KBD\\0000" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="ACPI\\PNP0303\\4&38462492&0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid] "Type"=dword:00000001 "Start"=dword:00000001 "Group"="Keyboard Port" "ErrorControl"=dword:00000000 "DisplayName"="Keyboard HID Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6b,00,62,00,64,00,68,00,69,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "Tag"=dword:00000005 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid\Parameters] "WorkNicely"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,6b,00,6d,00,69,00,78,00,65,00,72,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel Wave Audio Mixer" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum] "Count"=dword:00000001 "NextInstance"=dword:00000001 "0"="SW\\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\\{9B365890-165F-11D0-A195-0020AFD156E4}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KSecDD] "ErrorControl"=dword:00000001 "Group"="Base" "Start"=dword:00000000 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KSecDD\Enum] "0"="Root\\LEGACY_KSECDD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Server" "ObjectName"="LocalSystem" "Description"="Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\AutotunedParameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\DefaultSecurity] "SrvsvcConfigInfo"=hex:01,00,04,80,a0,00,00,00,ac,00,00,00,00,00,00,00,14,00,\ 00,00,02,00,8c,00,06,00,00,00,00,00,18,00,17,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,20,02,00,00,00,00,18,00,17,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,25,02,00,00,00,00,14,00,17,00,0f,00,01,01,00,00,00,00,00,05,12,\ 00,00,00,00,00,18,00,03,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,\ 00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,00,00,00,00,00,14,\ 00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcTransportEnum"=hex:01,00,04,80,8c,00,00,00,98,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,78,00,05,00,00,00,00,00,18,00,17,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,17,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,14,00,17,00,0f,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,00,00,18,00,03,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,0b,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcConnection"=hex:01,00,04,80,7c,00,00,00,88,00,00,00,00,00,00,00,14,00,\ 00,00,02,00,68,00,04,00,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,20,02,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,25,02,00,00,00,00,18,00,01,00,00,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,26,02,00,00,00,00,18,00,01,00,00,00,01,02,00,00,00,00,00,05,20,00,\ 00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00 "SrvsvcServerDiskEnum"=hex:01,00,04,80,4c,00,00,00,58,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,38,00,02,00,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\ 00,00,00,05,12,00,00,00 "SrvsvcFile"=hex:01,00,04,80,64,00,00,00,70,00,00,00,00,00,00,00,14,00,00,00,\ 02,00,50,00,03,00,00,00,00,00,18,00,11,00,0f,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,20,02,00,00,00,00,18,00,11,00,0f,00,01,02,00,00,00,00,00,05,20,00,\ 00,00,25,02,00,00,00,00,18,00,11,00,0f,00,01,02,00,00,00,00,00,05,20,00,00,\ 00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00 "SrvsvcSessionInfo"=hex:01,00,04,80,78,00,00,00,84,00,00,00,00,00,00,00,14,00,\ 00,00,02,00,64,00,04,00,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,20,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,25,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,23,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,0b,00,\ 00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,\ 00 "SrvsvcShareFileInfo"=hex:01,00,04,80,8c,00,00,00,98,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,78,00,05,00,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,23,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,\ 00,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcSharePrintInfo"=hex:01,00,04,80,a4,00,00,00,b0,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,90,00,06,00,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,26,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,23,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcShareAdminInfo"=hex:01,00,04,80,8c,00,00,00,98,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,78,00,05,00,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,02,00,00,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,18,00,02,00,00,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,23,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,\ 00,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcShareConnect"=hex:01,00,04,80,8c,00,00,00,98,00,00,00,00,00,00,00,14,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,20,02,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,25,02,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,27,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcShareAdminConnect"=hex:01,00,04,80,64,00,00,00,70,00,00,00,00,00,00,00,\ 14,00,00,00,02,00,50,00,03,00,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,\ 00,00,05,20,00,00,00,20,02,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,25,02,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,27,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\ 00,00,00,05,12,00,00,00 "SrvsvcStatisticsInfo"=hex:01,00,04,80,60,00,00,00,6c,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,4c,00,03,00,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,02,\ 00,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,\ 00,00,00 "AnonymousDescriptorsUpgraded"=dword:00000001 "PreviousAnonymousRestriction"=dword:00000000 "SessionSecurityDescriptorRegenerated"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,\ 2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,\ 00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,\ 42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,\ 7b,00,37,00,46,00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,30,00,39,\ 00,32,00,2d,00,34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,\ 46,00,45,00,37,00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,34,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,\ 42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,00,37,00,38,\ 00,43,00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,00,\ 38,00,37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,00,39,\ 00,33,00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,00,00,5c,00,44,00,\ 65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,\ 00,63,00,70,00,69,00,70,00,5f,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,\ 43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,\ 00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,\ 42,00,45,00,41,00,41,00,37,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,\ 70,00,5f,00,7b,00,35,00,30,00,36,00,30,00,33,00,44,00,37,00,34,00,2d,00,32,\ 00,37,00,41,00,46,00,2d,00,34,00,36,00,45,00,33,00,2d,00,39,00,37,00,39,00,\ 37,00,2d,00,46,00,31,00,36,00,33,00,33,00,38,00,34,00,31,00,46,00,34,00,37,\ 00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,\ 65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,\ 00,41,00,43,00,37,00,44,00,46,00,32,00,45,00,2d,00,45,00,39,00,38,00,39,00,\ 2d,00,34,00,41,00,36,00,33,00,2d,00,38,00,41,00,33,00,41,00,2d,00,46,00,35,\ 00,37,00,45,00,38,00,38,00,39,00,37,00,32,00,38,00,34,00,45,00,7d,00,00,00,\ 00,00 "Route"=hex(7):22,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,\ 00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,\ 63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,43,00,36,00,35,00,41,00,42,\ 00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,\ 45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,\ 00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,22,00,00,00,22,00,4e,00,65,00,\ 74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,\ 00,22,00,7b,00,37,00,46,00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,\ 30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,\ 00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,\ 34,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,\ 00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,34,00,37,00,38,00,\ 43,00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,00,38,\ 00,37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,00,39,00,\ 33,00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,22,00,00,00,22,00,4e,\ 00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,\ 22,00,20,00,22,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,\ 00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,\ 35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,\ 00,41,00,37,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,\ 20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,64,00,69,\ 00,73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,\ 00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,\ 74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,00,00,5c,00,44,00,65,00,76,\ 00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,\ 72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,\ 00,70,00,69,00,70,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,\ 37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,\ 00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,\ 42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,\ 00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,\ 72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,37,00,46,00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,\ 30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,\ 00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,\ 34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,\ 00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,5f,00,4e,00,\ 65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,\ 00,37,00,38,00,43,00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,\ 2d,00,34,00,38,00,37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,\ 00,45,00,39,00,33,00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,00,00,\ 5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,\ 00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,44,00,37,00,42,00,41,\ 00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,\ 39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,\ 00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,\ 00,72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,\ 63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,30,00,36,00,30,00,33,00,44,00,37,\ 00,34,00,2d,00,32,00,37,00,41,00,46,00,2d,00,34,00,36,00,45,00,33,00,2d,00,\ 39,00,37,00,39,00,37,00,2d,00,46,00,31,00,36,00,33,00,33,00,38,00,34,00,31,\ 00,46,00,34,00,37,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,\ 00,72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,\ 70,00,5f,00,7b,00,37,00,41,00,43,00,37,00,44,00,46,00,32,00,45,00,2d,00,45,\ 00,39,00,38,00,39,00,2d,00,34,00,41,00,36,00,33,00,2d,00,38,00,41,00,33,00,\ 41,00,2d,00,46,00,35,00,37,00,45,00,38,00,38,00,39,00,37,00,32,00,38,00,34,\ 00,45,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters] "Size"=dword:00000002 "DisableDos"=dword:00000000 "autodisconnect"=dword:0000000f "enableforcedlogoff"=dword:00000001 "enablesecuritysignature"=dword:00000000 "requiresecuritysignature"=dword:00000000 "NullSessionPipes"=hex(7):43,00,4f,00,4d,00,4e,00,41,00,50,00,00,00,43,00,4f,\ 00,4d,00,4e,00,4f,00,44,00,45,00,00,00,53,00,51,00,4c,00,5c,00,51,00,55,00,\ 45,00,52,00,59,00,00,00,53,00,50,00,4f,00,4f,00,4c,00,53,00,53,00,00,00,4c,\ 00,4c,00,53,00,52,00,50,00,43,00,00,00,62,00,72,00,6f,00,77,00,73,00,65,00,\ 72,00,00,00,00,00 "NullSessionShares"=hex(7):43,00,4f,00,4d,00,43,00,46,00,47,00,00,00,44,00,46,\ 00,53,00,24,00,00,00,00,00 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,72,00,76,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "Lmannounce"=dword:00000000 "Guid"=hex:22,88,c9,72,26,38,e4,44,92,f4,69,50,0e,e6,17,49 "AdjustedNullSessionPipes"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares\Security] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Enum] "0"="Root\\LEGACY_LANMANSERVER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Workstation" "Group"="NetworkProvider" "ObjectName"="LocalSystem" "Description"="Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,\ 2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,\ 00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,\ 42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,\ 7b,00,37,00,46,00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,30,00,39,\ 00,32,00,2d,00,34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,\ 46,00,45,00,37,00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,34,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,\ 42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,00,37,00,38,\ 00,43,00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,00,\ 38,00,37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,00,39,\ 00,33,00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,00,00,5c,00,44,00,\ 65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,\ 00,63,00,70,00,69,00,70,00,5f,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,\ 43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,\ 00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,\ 42,00,45,00,41,00,41,00,37,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,\ 70,00,5f,00,7b,00,35,00,30,00,36,00,30,00,33,00,44,00,37,00,34,00,2d,00,32,\ 00,37,00,41,00,46,00,2d,00,34,00,36,00,45,00,33,00,2d,00,39,00,37,00,39,00,\ 37,00,2d,00,46,00,31,00,36,00,33,00,33,00,38,00,34,00,31,00,46,00,34,00,37,\ 00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,\ 65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,\ 00,41,00,43,00,37,00,44,00,46,00,32,00,45,00,2d,00,45,00,39,00,38,00,39,00,\ 2d,00,34,00,41,00,36,00,33,00,2d,00,38,00,41,00,33,00,41,00,2d,00,46,00,35,\ 00,37,00,45,00,38,00,38,00,39,00,37,00,32,00,38,00,34,00,45,00,7d,00,00,00,\ 00,00 "Route"=hex(7):22,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,\ 00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,\ 63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,43,00,36,00,35,00,41,00,42,\ 00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,\ 45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,\ 00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,22,00,00,00,22,00,4e,00,65,00,\ 74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,\ 00,22,00,7b,00,37,00,46,00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,\ 30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,\ 00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,\ 34,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,\ 00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,34,00,37,00,38,00,\ 43,00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,00,38,\ 00,37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,00,39,00,\ 33,00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,22,00,00,00,22,00,4e,\ 00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,\ 22,00,20,00,22,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,\ 00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,\ 35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,\ 00,41,00,37,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,\ 20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,64,00,69,\ 00,73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,\ 00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,\ 6f,00,6e,00,5f,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,\ 6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,\ 00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,\ 70,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,2d,00,30,\ 00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,00,36,00,\ 35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,42,00,34,\ 00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,\ 61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,\ 00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,\ 70,00,69,00,70,00,5f,00,7b,00,37,00,46,00,31,00,37,00,31,00,34,00,30,00,34,\ 00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,00,2d,00,39,00,\ 43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,35,00,31,00,32,\ 00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,\ 00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,00,37,00,38,00,43,00,46,00,42,\ 00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,00,38,00,37,00,34,00,\ 2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,00,39,00,33,00,34,00,33,\ 00,34,00,38,00,39,00,46,00,33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,\ 00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,44,00,37,00,42,00,41,\ 00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,\ 39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,\ 00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,\ 00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,\ 74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,30,\ 00,36,00,30,00,33,00,44,00,37,00,34,00,2d,00,32,00,37,00,41,00,46,00,2d,00,\ 34,00,36,00,45,00,33,00,2d,00,39,00,37,00,39,00,37,00,2d,00,46,00,31,00,36,\ 00,33,00,33,00,38,00,34,00,31,00,46,00,34,00,37,00,34,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,\ 00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,\ 4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,\ 00,37,00,41,00,43,00,37,00,44,00,46,00,32,00,45,00,2d,00,45,00,39,00,38,00,\ 39,00,2d,00,34,00,41,00,36,00,33,00,2d,00,38,00,41,00,33,00,41,00,2d,00,46,\ 00,35,00,37,00,45,00,38,00,38,00,39,00,37,00,32,00,38,00,34,00,45,00,7d,00,\ 00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\NetworkProvider] "Name"="Microsoft Windows Network" "ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6e,00,74,00,6c,00,61,00,6e,00,6d,00,61,00,6e,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "DeviceName"="\\Device\\LanmanRedirector" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters] "enableplaintextpassword"=dword:00000000 "enablesecuritysignature"=dword:00000001 "requiresecuritysignature"=dword:00000000 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,6b,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "OtherDomains"=hex(7):00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\Enum] "0"="Root\\LEGACY_LANMANWORKSTATION\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lbrtfdc] "ErrorControl"=dword:00000000 "Group"="System Bus Extender" "Start"=dword:00000001 "Tag"=dword:0000000e "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ldap] "ldapclientintegrity"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseService] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseService\FilePrint] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseService\FilePrint\TermService] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "DisplayName"="TCP/IP NetBIOS Helper" "Group"="TDI" "DependOnService"=hex(7):4e,00,65,00,74,00,42,00,54,00,00,00,41,00,66,00,64,00,\ 00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6c,00,6d,00,68,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts\Enum] "0"="Root\\LEGACY_LMHOSTS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Messenger" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,4e,00,65,00,74,00,42,\ 00,49,00,4f,00,53,00,00,00,50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,\ 00,00,52,00,70,00,63,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6d,00,73,00,67,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Enum] "0"="Root\\LEGACY_MESSENGER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmdd] "ErrorControl"=dword:00000000 "Group"="Video Save" "Start"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmdd\Device0] "InstalledDisplayDrivers"=hex(7):6d,00,6e,00,6d,00,64,00,64,00,00,00,00,00 "Device Description"="NetMeeting driver" "VgaCompatible"=dword:00000000 "MirrorDriver"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmdd\Video] "VideoID"="{8B6D7859-A639-4A15-8790-7161976D057A}" "Service"="mnmdd" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmdd\Enum] "0"="Root\\LEGACY_MNMDD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmsrvc] "Type"=dword:00000110 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,6e,00,6d,\ 00,73,00,72,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="NetMeeting Remote Desktop Sharing" "ObjectName"="LocalSystem" "Description"="Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmsrvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Modem] "ErrorControl"=dword:00000000 "Group"="Extended base" "Start"=dword:00000003 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Modem\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mouclass] "ErrorControl"=dword:00000001 "Group"="Pointer Class" "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Mouse Class Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,6f,00,75,00,63,00,6c,00,61,\ 00,73,00,73,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mouclass\Parameters] "ConnectMultiplePorts"=dword:00000000 "MaximumPortsServiced"=dword:00000003 "MouseDataQueueSize"=dword:00000064 "PointerDeviceBaseName"="PointerClass" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mouclass\Enum] "0"="Root\\RDP_MOU\\0000" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="ACPI\\SYN0705\\4&38462492&0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid] "Type"=dword:00000001 "Start"=dword:00000003 "Group"="Pointer Port" "ErrorControl"=dword:00000000 "DisplayName"="Mouse HID Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,6f,00,75,00,68,00,69,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "Tag"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid\Parameters] "UseOnlyMice"=dword:00000000 "TreatAbsoluteAsRelative"=dword:00000000 "TreatAbsolutePointerAsAbsolute"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MountMgr] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000008 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MountMgr\Enum] "0"="Root\\LEGACY_MOUNTMGR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mraid35x] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000002b "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mraid35x\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mraid35x\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV] "Type"=dword:00000002 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,72,00,78,00,64,00,61,00,76,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="WebDav Client Redirector" "Description"="WebDav Client Redirector" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV\Parameters] "FileInformationCacheLifeTimeInSec"=dword:0000003c "FileNotFoundCacheLifeTimeInSec"=dword:0000003c "NameCacheMaxEntries"=dword:0000012c "DAVDebugFlag"=dword:00000000 "UMRxDebugFlag"=dword:00000000 "RequestTimeoutInSec"=dword:00000258 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV\Enum] "0"="Root\\LEGACY_MRXDAV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb] "Type"=dword:00000002 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,72,00,78,00,73,00,6d,00,62,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="MRXSMB" "Group"="Network" "Description"="MRXSMB" "LastLoadStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb\Parameters] "CscEnabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb\Enum] "0"="Root\\LEGACY_MRXSMB\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,64,\ 00,74,00,63,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Distributed Transaction Coordinator" "Group"="MS Transactions" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,53,00,61,00,6d,00,\ 53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC\Performance] "Library"="msdtcuiu.DLL" "Open"="DtcPerfOpen" "Collect"="DtcPerfCollect" "Close"="DtcPerfClose" "Last Counter"=dword:000008a2 "Last Help"=dword:000008a3 "First Counter"=dword:00000888 "First Help"=dword:00000889 "Object List"="2184" "WbemAdapFileSignature"=hex:80,1b,a8,73,02,e1,62,1b,77,52,ed,e6,03,c6,6e,17 "WbemAdapFileTime"=hex:48,4f,b2,40,fb,9f,c9,01 "WbemAdapFileSize"=dword:00027800 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC\Security] "Security"=hex:01,00,14,80,e0,00,00,00,ec,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,b0,00,06,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 02,00,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\ 00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\ 02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,14,00,9d,00,02,\ 00,01,01,00,00,00,00,00,05,14,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC\Enum] "0"="Root\\LEGACY_MSDTC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Msfs] "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000001 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Msfs\Enum] "0"="Root\\LEGACY_MSFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer] "Description"="Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start." "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,69,\ 00,65,00,78,00,65,00,63,00,2e,00,65,00,78,00,65,00,20,00,2f,00,56,00,00,00 "DisplayName"="Windows Installer" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer\Enum] "0"="Root\\LEGACY_MSISERVER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSKSSRV] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000c "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,4b,00,53,00,53,00,52,\ 00,56,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Streaming Service Proxy" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSKSSRV\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPCLOCK] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000009 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,50,00,43,00,4c,00,4f,\ 00,43,00,4b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Streaming Clock Proxy" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPCLOCK\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPQM] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000007 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,50,00,51,00,4d,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Streaming Quality Manager Proxy" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPQM\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,73,00,73,00,6d,00,62,00,69,\ 00,6f,00,73,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft System Management BIOS Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios\Data] "AcpiData"=hex:52,53,44,54,54,00,00,00,01,d1,54,4f,53,43,50,4c,54,4f,53,43,50,\ 4c,30,30,00,00,04,06,20,4c,54,50,00,00,00,00,78,fc,e8,7f,ec,fc,e8,7f,62,fe,\ e8,7f,ca,fe,e8,7f,02,ff,e8,7f,d8,ff,e8,7f,70,ff,e8,7f,c0,8e,e8,7f,2e,88,e8,\ 7f,88,7d,e8,7f,e2,7c,e8,7f,fc,77,e8,7f,46,41,43,50,74,00,00,00,01,8c,54,4f,\ 53,43,50,4c,43,41,4c,49,53,54,47,41,00,00,04,06,4c,4f,48,52,5a,00,00,00,c0,\ 0f,e9,7f,13,95,e8,7f,00,00,09,00,b2,00,00,00,f0,f1,f2,80,00,10,00,00,00,00,\ 00,00,04,10,00,00,00,00,00,00,20,10,00,00,08,10,00,00,28,10,00,00,00,00,00,\ 00,04,02,01,04,08,00,00,85,01,00,39,00,00,00,00,00,01,00,0d,00,32,00,00,00,\ a5,80,00,00,44,53,44,54,65,67,00,00,01,16,54,4f,53,43,50,4c,43,41,4c,49,53,\ 54,47,41,00,00,04,06,49,4e,54,4c,08,06,06,20,53,4c,49,43,76,01,00,00,01,af,\ 54,4f,53,43,50,4c,54,4f,53,43,50,4c,30,30,00,00,04,06,4c,4f,48,52,00,00,00,\ 00,00,00,00,00,9c,00,00,00,06,02,00,00,00,24,00,00,52,53,41,31,00,04,00,00,\ 01,00,01,00,01,d1,f8,e2,2e,9e,56,65,20,b2,3c,d6,8c,a8,ab,ee,e9,1d,d7,45,eb,\ 6b,72,ad,45,b9,29,86,ae,aa,8c,53,39,f4,25,be,b7,d3,f9,d8,f9,c1,90,ab,f9,d4,\ 05,60,a0,72,47,e6,f9,09,15,3f,60,c3,c7,0e,09,c9,d1,bc,1a,6e,af,d4,7d,f3,9d,\ 5f,5a,51,1e,68,c9,f6,3d,90,f5,b0,34,f2,03,c2,9a,7d,dd,e7,52,4c,e8,63,04,6b,\ 00,a7,b5,ab,c0,6f,35,e9,7a,14,d4,f4,4f,29,f1,6a,56,9b,d7,45,81,f3,37,e3,a5,\ 4b,fd,53,5b,3c,e9,a5,01,00,00,00,b6,00,00,00,00,00,02,00,54,4f,53,43,50,4c,\ 54,4f,53,43,50,4c,30,30,57,49,4e,44,4f,57,53,20,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,29,0e,2b,8a,14,a9,04,6f,d0,00,f9,e0,62,8f,\ 77,e0,bb,d5,ce,89,da,72,5d,69,5d,e7,cf,0e,c6,83,6b,38,5b,74,f6,e9,5c,f2,b3,\ 77,2b,ad,5d,91,d5,92,85,5a,1f,e1,31,27,4f,22,7b,11,ac,97,cb,6a,bd,f5,16,41,\ 66,8d,bf,1b,07,65,55,1d,9e,68,d4,b8,ef,8e,21,17,eb,c5,aa,98,e9,23,33,1b,1b,\ 95,7b,12,65,b3,90,fe,54,4b,64,61,c4,35,d1,3a,51,af,a1,ef,2a,fc,8f,c9,9d,f1,\ a8,fc,c3,10,9f,06,ad,50,9e,7b,ee,8a,9f,98,41,50,49,43,68,00,00,00,01,e4,49,\ 4e,54,45,4c,20,43,41,4c,49,53,54,47,41,00,00,04,06,4c,4f,48,52,5a,00,00,00,\ 00,00,e0,fe,01,00,00,00,00,08,00,00,01,00,00,00,00,08,01,01,01,00,00,00,01,\ 0c,01,00,00,00,c0,fe,00,00,00,00,02,0a,00,00,02,00,00,00,00,00,02,0a,00,09,\ 09,00,00,00,0d,00,04,06,00,05,00,01,04,06,01,05,00,01,48,50,45,54,38,00,00,\ 00,01,22,49,4e,54,45,4c,20,43,41,4c,49,53,54,47,41,00,00,04,06,4c,4f,48,52,\ 5a,00,00,00,01,a2,86,80,00,00,00,00,00,00,d0,fe,00,00,00,00,00,80,00,00,4d,\ 43,46,47,3c,00,00,00,01,4a,49,4e,54,45,4c,20,43,41,4c,49,53,54,47,41,00,00,\ 04,06,4c,4f,48,52,5a,00,00,00,00,00,00,00,00,00,00,00,00,00,00,e0,00,00,00,\ 00,00,00,00,ff,00,00,00,00,42,4f,4f,54,28,00,00,00,01,a5,50,54,4c,54,44,20,\ 24,53,42,46,54,42,4c,24,00,00,04,06,20,4c,54,50,01,00,00,00,36,00,00,00,41,\ 50,49,43,68,00,00,00,01,13,50,54,4c,54,44,20,09,20,41,50,49,43,20,20,00,00,\ 04,06,20,4c,54,50,00,00,00,00,00,00,e0,fe,01,00,00,00,00,08,00,00,01,00,00,\ 00,00,08,01,01,01,00,00,00,01,0c,02,00,00,00,c0,fe,00,00,00,00,04,06,00,05,\ 00,01,04,06,01,05,00,01,02,0a,00,00,02,00,00,00,05,00,02,0a,00,09,09,00,00,\ 00,0d,00,53,53,44,54,4f,06,00,00,01,72,53,61,74,61,52,65,53,61,74,61,50,72,\ 69,00,00,10,00,00,49,4e,54,4c,24,06,05,20,53,53,44,54,92,06,00,00,01,2a,53,\ 61,74,61,52,65,53,61,74,61,53,65,63,00,00,10,00,00,49,4e,54,4c,24,06,05,20,\ 53,53,44,54,5f,02,00,00,01,c8,50,6d,52,65,66,00,43,70,75,30,54,73,74,00,00,\ 30,00,00,49,4e,54,4c,24,06,05,20,53,53,44,54,a6,00,00,00,01,6d,50,6d,52,65,\ 66,00,43,70,75,31,54,73,74,00,00,30,00,00,49,4e,54,4c,24,06,05,20,53,53,44,\ 54,e6,04,00,00,01,f8,50,6d,52,65,66,00,43,70,75,50,6d,00,00,00,00,30,00,00,\ 49,4e,54,4c,24,06,05,20 "BiosData"=hex:0a,00,00,00,7e,00,4d,00,48,00,7a,00,00,00,04,00,00,00,04,00,00,\ 00,ca,07,00,00,2c,00,00,00,43,00,6f,00,6d,00,70,00,6f,00,6e,00,65,00,6e,00,\ 74,00,20,00,49,00,6e,00,66,00,6f,00,72,00,6d,00,61,00,74,00,69,00,6f,00,6e,\ 00,00,00,03,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,\ 00,00,26,00,00,00,43,00,6f,00,6e,00,66,00,69,00,67,00,75,00,72,00,61,00,74,\ 00,69,00,6f,00,6e,00,20,00,44,00,61,00,74,00,61,00,00,00,09,00,00,00,10,00,\ 00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,00,00,00,16,00,00,00,49,00,64,\ 00,65,00,6e,00,74,00,69,00,66,00,69,00,65,00,72,00,00,00,01,00,00,00,42,00,\ 00,00,78,00,38,00,36,00,20,00,46,00,61,00,6d,00,69,00,6c,00,79,00,20,00,36,\ 00,20,00,4d,00,6f,00,64,00,65,00,6c,00,20,00,31,00,35,00,20,00,53,00,74,00,\ 65,00,70,00,70,00,69,00,6e,00,67,00,20,00,36,00,00,00,28,00,00,00,50,00,72,\ 00,6f,00,63,00,65,00,73,00,73,00,6f,00,72,00,4e,00,61,00,6d,00,65,00,53,00,\ 74,00,72,00,69,00,6e,00,67,00,00,00,01,00,00,00,60,00,00,00,49,00,6e,00,74,\ 00,65,00,6c,00,28,00,52,00,29,00,20,00,43,00,6f,00,72,00,65,00,28,00,54,00,\ 4d,00,29,00,32,00,20,00,43,00,50,00,55,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,54,00,37,00,32,00,30,00,30,00,20,00,20,00,40,00,20,00,\ 32,00,2e,00,30,00,30,00,47,00,48,00,7a,00,00,00,22,00,00,00,55,00,70,00,64,\ 00,61,00,74,00,65,00,20,00,53,00,69,00,67,00,6e,00,61,00,74,00,75,00,72,00,\ 65,00,00,00,03,00,00,00,08,00,00,00,00,00,00,00,c7,00,00,00,1c,00,00,00,55,\ 00,70,00,64,00,61,00,74,00,65,00,20,00,53,00,74,00,61,00,74,00,75,00,73,00,\ 00,00,04,00,00,00,04,00,00,00,06,00,00,00,22,00,00,00,56,00,65,00,6e,00,64,\ 00,6f,00,72,00,49,00,64,00,65,00,6e,00,74,00,69,00,66,00,69,00,65,00,72,00,\ 00,00,01,00,00,00,1a,00,00,00,47,00,65,00,6e,00,75,00,69,00,6e,00,65,00,49,\ 00,6e,00,74,00,65,00,6c,00,00,00,0c,00,00,00,4d,00,53,00,52,00,38,00,42,00,\ 00,00,0b,00,00,00,08,00,00,00,00,00,00,00,c7,00,00,00,0e,00,00,00,43,00,50,\ 00,55,00,49,00,44,00,31,00,00,00,03,00,00,00,10,00,00,00,f6,06,00,00,00,08,\ 02,01,bd,e3,00,00,ff,fb,eb,bf "SMBiosData"=hex:00,02,04,00,ef,03,00,00,00,18,00,00,01,02,9c,e5,03,07,80,9b,\ 21,7c,00,00,00,00,87,05,01,40,01,40,54,4f,53,48,49,42,41,00,56,31,2e,34,30,\ 00,30,34,2f,32,36,2f,32,30,30,37,00,00,01,1b,01,00,01,02,03,04,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,06,05,06,54,4f,53,48,49,42,41,00,53,41,\ 54,45,4c,4c,49,54,45,20,41,32,30,30,2d,31,42,50,00,50,53,41,45,43,45,2d,30,\ 31,55,30,30,58,54,45,00,20,20,20,20,20,20,20,20,20,00,30,31,32,33,34,35,36,\ 37,38,39,31,32,33,34,35,36,37,38,39,31,32,33,34,35,36,37,38,00,41,42,43,44,\ 45,46,47,48,49,4a,4b,4c,4d,4e,4f,50,51,52,53,54,55,56,57,58,59,5a,00,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,20,00,00,02,08,02,00,01,02,03,04,54,4f,53,48,49,42,41,\ 00,49,53,4b,41,45,00,31,2e,30,30,00,20,20,20,20,20,20,20,20,20,20,20,20,00,\ 00,03,11,03,00,01,0a,02,03,04,03,03,03,03,34,12,00,00,54,4f,53,48,49,42,41,\ 00,4e,2f,41,00,20,20,20,20,00,20,00,20,20,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,00,\ 00,04,23,04,00,01,03,01,02,f6,06,00,00,ff,fb,eb,bf,03,02,00,00,00,08,d0,07,\ 41,04,05,00,06,00,ff,ff,00,00,00,55,32,45,31,00,49,6e,74,65,6c,00,49,6e,74,\ 65,6c,28,52,29,20,43,6f,72,65,28,54,4d,29,32,20,43,50,55,20,20,20,20,20,20,\ 20,20,20,54,37,00,00,07,13,05,00,01,88,01,20,00,20,00,58,00,40,00,00,02,02,\ 02,4c,31,20,43,61,63,68,65,00,00,07,13,06,00,01,a9,01,00,02,00,10,58,00,08,\ 00,00,02,02,02,4c,32,20,43,61,63,68,65,00,00,08,09,07,00,01,00,02,14,0d,4a,\ 33,35,00,4b,65,79,62,6f,61,72,64,00,00,08,09,08,00,01,00,02,14,0d,4a,33,36,\ 00,50,53,2f,32,20,4d,6f,75,73,65,00,00,09,0d,09,00,01,06,05,02,04,00,00,06,\ 00,54,49,37,34,31,32,00,00,0a,06,0a,00,07,01,48,44,2d,41,75,64,69,6f,00,00,\ 0b,05,0b,00,01,2a,00,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,00,00,0c,05,0c,00,01,4a,\ 75,6d,70,65,72,20,73,65,74,74,69,6e,67,73,20,63,61,6e,20,62,65,20,64,65,73,\ 63,72,69,62,65,64,20,68,65,72,65,2e,00,00,10,0f,0d,00,03,03,03,00,00,30,00,\ fe,ff,02,00,00,00,11,1b,0e,00,0d,00,ff,ff,20,00,20,00,00,04,0d,01,01,02,12,\ 80,00,00,00,00,00,00,00,4d,31,00,42,61,6e,6b,20,30,00,00,11,1b,0f,00,0d,00,\ ff,ff,20,00,20,00,00,04,0d,01,01,02,12,80,00,00,00,00,00,00,00,4d,32,00,42,\ 61,6e,6b,20,31,00,00,13,0f,10,00,00,00,00,00,ff,ff,1f,00,0d,00,02,00,00,14,\ 13,11,00,00,00,00,00,ff,ff,0f,00,0e,00,10,00,ff,ff,ff,00,00,14,13,12,00,00,\ 00,10,00,ff,ff,1f,00,0f,00,10,00,ff,ff,ff,00,00,16,1a,13,00,01,02,03,04,05,\ 06,4e,0c,d0,39,00,ff,00,00,00,00,00,0a,00,00,00,00,31,73,74,20,42,61,74,74,\ 65,72,79,00,54,4f,53,48,49,42,41,20,20,20,00,31,32,2f,30,31,2f,32,30,30,35,\ 00,20,20,20,20,20,00,50,41,33,33,39,35,55,20,00,00,20,14,14,00,00,00,00,00,\ 00,00,0c,01,02,03,04,05,06,07,08,09,00,00,7f,04,15,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios\Enum] "0"="Root\\SYSTEM\\0002" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSTEE] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000f "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,54,00,45,00,45,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Streaming Tee/Sink-to-Sink Converter" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSTEE\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mup] "DisplayName"="Mup" "ErrorControl"=dword:00000001 "Group"="Network" "Start"=dword:00000000 "Tag"=dword:00000002 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mup\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mup\Enum] "0"="Root\\LEGACY_MUP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NABTSFEC] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000b "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,4e,00,41,00,42,00,54,00,53,00,46,\ 00,45,00,43,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="NABTS/FEC VBI Codec" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NABTSFEC\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent] "DisplayName"="Network Access Protection Agent" "Description"="Allows windows clients to participate in Network Access Protection" "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "ObjectName"="localSystem" "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\LocalConfig] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\LocalConfig\Enroll] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\LocalConfig\Enroll\HcsGroups] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 71,00,61,00,67,00,65,00,6e,00,74,00,72,00,74,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79617] "Id"=dword:00013701 "Friendly Name"="DHCP Quarantine Enforcement Client" "Description"="Provides DHCP based enforcement for NAP" "Version"="1.0" "Vendor Name"="Microsoft Corporation" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79618] "Id"=dword:00013702 "Description"="Provides the quarantine enforcement for RAS Client" "Friendly Name"="Remote Access Quarantine Enforcement Client" "Vendor Name"="Microsoft Corporation" "Version"="1.0" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79619] "Id"=dword:00013703 "Friendly Name"="IPSec Relying Party" "Description"="Provides IPSec based enforcement for Network Access Protection" "Version"="1.0" "Vendor Name"="Microsoft Corporation" "Component Type"=dword:00000002 "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79620] "Id"=dword:00013704 "Friendly Name"="Wireless Eapol Quarantine Enforcement Client" "Description"="Provides wireless Eapol based enforcement for NAP" "Version"="1.0" "Vendor Name"="Microsoft Corporation" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79621] "Id"=dword:00013705 "Friendly Name"="TS Gateway Quarantine Enforcement Client" "Description"="Provides TS Gateway enforcement for NAP" "Version"="1.0" "Vendor Name"="Microsoft Corporation" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79623] "Id"=dword:00013707 "Enabled"=dword:00000001 "Vendor Name"="Microsoft Corporation" "Version"="1.0" "Friendly Name"="EAP Quarantine Enforcement Client" "Description"="Provides EAP based enforcement for NAP" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Shas] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Shas\79744] "Id"=dword:00013780 "Friendly Name"="Microsoft Out-of-Box System Health Agent" "Description"="Microsoft Out-of-Box System Health Agent" "Version"="1" "Vendor Name"="Microsoft Corporation" "Info Clsid"="{7886B467-66D4-4163-82BA-D9212FDB4CA8}" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\SohCache] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Enum] "0"="Root\\LEGACY_NAPAGENT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS] "DisplayName"="NDIS System Driver" "ErrorControl"=dword:00000001 "Group"="NDIS Wrapper" "Start"=dword:00000000 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\MediaTypes] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\Parameters] "ProcessorAffinityMask"=dword:ffffffff [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\Enum] "0"="Root\\LEGACY_NDIS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisIP] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000c "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,4e,00,64,00,69,00,73,00,49,00,50,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft TV/Video Connection" "Group"="NDIS" "TextModeFlags"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisIP\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,74,00,61,\ 00,70,00,69,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access NDIS TAPI Driver" "Description"="Remote Access NDIS TAPI Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi\Parameters] "AsyncEventQueueSize"=dword:00000300 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi\Enum] "0"="Root\\LEGACY_NDISTAPI\\0000" "Count"=dword:00000004 "NextInstance"=dword:00000004 "1"="Root\\MS_NDISWANIP\\0000" "2"="Root\\MS_PPPOEMINIPORT\\0000" "3"="Root\\MS_PPTPMINIPORT\\0000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000e "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,75,00,69,\ 00,6f,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="NDIS Usermode I/O Protocol" "Group"="NDIS" "Description"="NDIS Usermode I/O Protocol" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,43,00,36,\ 00,35,00,41,00,42,00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,\ 34,00,43,00,33,00,45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,\ 00,36,00,32,00,44,00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,37,00,46,00,31,00,37,00,31,\ 00,34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,\ 44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,\ 00,35,00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,\ 00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,\ 46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,\ 00,41,00,41,00,37,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,2d,\ 00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,00,\ 36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,42,\ 00,34,00,32,00,7d,00,22,00,00,00,22,00,7b,00,37,00,46,00,31,00,37,00,31,00,\ 34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,\ 00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,\ 35,00,31,00,32,00,30,00,42,00,34,00,7d,00,22,00,00,00,22,00,7b,00,44,00,37,\ 00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,\ 34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,\ 00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,00,22,00,00,00,\ 00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,\ 00,73,00,75,00,69,00,6f,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,\ 34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,\ 00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,\ 31,00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,4e,00,64,00,69,00,73,00,75,00,69,00,6f,00,5f,00,7b,00,37,00,\ 46,00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,\ 00,34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,\ 37,00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,75,00,\ 69,00,6f,00,5f,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,\ 00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,\ 35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,\ 00,41,00,37,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio\Enum] "0"="Root\\LEGACY_NDISUIO\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,77,00,61,\ 00,6e,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access NDIS WAN Driver" "Description"="Remote Access NDIS WAN Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,30,00,42,\ 00,31,00,33,00,46,00,34,00,35,00,41,00,2d,00,33,00,38,00,30,00,41,00,2d,00,\ 34,00,36,00,39,00,42,00,2d,00,38,00,46,00,39,00,33,00,2d,00,46,00,38,00,38,\ 00,31,00,36,00,35,00,37,00,42,00,46,00,46,00,30,00,37,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,36,00,35,00,45,00,36,00,37,\ 00,31,00,35,00,30,00,2d,00,42,00,37,00,46,00,45,00,2d,00,34,00,38,00,38,00,\ 46,00,2d,00,39,00,37,00,35,00,38,00,2d,00,34,00,35,00,46,00,35,00,31,00,42,\ 00,42,00,44,00,36,00,41,00,41,00,46,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,37,00,38,00,35,00,35,00,34,00,35,00,39,00,44,\ 00,2d,00,31,00,37,00,44,00,31,00,2d,00,34,00,33,00,43,00,42,00,2d,00,41,00,\ 30,00,32,00,33,00,2d,00,35,00,42,00,32,00,31,00,36,00,38,00,37,00,35,00,42,\ 00,30,00,35,00,44,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,7b,00,41,00,38,00,32,00,36,00,38,00,41,00,38,00,42,00,2d,00,45,00,35,\ 00,38,00,39,00,2d,00,34,00,45,00,39,00,36,00,2d,00,38,00,31,00,42,00,30,00,\ 2d,00,39,00,39,00,38,00,34,00,43,00,36,00,32,00,33,00,30,00,37,00,33,00,37,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,37,00,\ 43,00,41,00,45,00,43,00,32,00,32,00,36,00,2d,00,35,00,35,00,44,00,33,00,2d,\ 00,34,00,39,00,43,00,35,00,2d,00,42,00,33,00,39,00,33,00,2d,00,36,00,42,00,\ 45,00,42,00,42,00,41,00,31,00,35,00,43,00,32,00,33,00,44,00,7d,00,00,00,00,\ 00 "Route"=hex(7):22,00,7b,00,30,00,42,00,31,00,33,00,46,00,34,00,35,00,41,00,2d,\ 00,33,00,38,00,30,00,41,00,2d,00,34,00,36,00,39,00,42,00,2d,00,38,00,46,00,\ 39,00,33,00,2d,00,46,00,38,00,38,00,31,00,36,00,35,00,37,00,42,00,46,00,46,\ 00,30,00,37,00,7d,00,22,00,00,00,22,00,7b,00,36,00,35,00,45,00,36,00,37,00,\ 31,00,35,00,30,00,2d,00,42,00,37,00,46,00,45,00,2d,00,34,00,38,00,38,00,46,\ 00,2d,00,39,00,37,00,35,00,38,00,2d,00,34,00,35,00,46,00,35,00,31,00,42,00,\ 42,00,44,00,36,00,41,00,41,00,46,00,7d,00,22,00,00,00,22,00,7b,00,37,00,38,\ 00,35,00,35,00,34,00,35,00,39,00,44,00,2d,00,31,00,37,00,44,00,31,00,2d,00,\ 34,00,33,00,43,00,42,00,2d,00,41,00,30,00,32,00,33,00,2d,00,35,00,42,00,32,\ 00,31,00,36,00,38,00,37,00,35,00,42,00,30,00,35,00,44,00,7d,00,22,00,00,00,\ 22,00,7b,00,41,00,38,00,32,00,36,00,38,00,41,00,38,00,42,00,2d,00,45,00,35,\ 00,38,00,39,00,2d,00,34,00,45,00,39,00,36,00,2d,00,38,00,31,00,42,00,30,00,\ 2d,00,39,00,39,00,38,00,34,00,43,00,36,00,32,00,33,00,30,00,37,00,33,00,37,\ 00,7d,00,22,00,00,00,22,00,7b,00,37,00,43,00,41,00,45,00,43,00,32,00,32,00,\ 36,00,2d,00,35,00,35,00,44,00,33,00,2d,00,34,00,39,00,43,00,35,00,2d,00,42,\ 00,33,00,39,00,33,00,2d,00,36,00,42,00,45,00,42,00,42,00,41,00,31,00,35,00,\ 43,00,32,00,33,00,44,00,7d,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,\ 00,73,00,57,00,61,00,6e,00,5f,00,7b,00,30,00,42,00,31,00,33,00,46,00,34,00,\ 35,00,41,00,2d,00,33,00,38,00,30,00,41,00,2d,00,34,00,36,00,39,00,42,00,2d,\ 00,38,00,46,00,39,00,33,00,2d,00,46,00,38,00,38,00,31,00,36,00,35,00,37,00,\ 42,00,46,00,46,00,30,00,37,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,00,7b,00,36,00,\ 35,00,45,00,36,00,37,00,31,00,35,00,30,00,2d,00,42,00,37,00,46,00,45,00,2d,\ 00,34,00,38,00,38,00,46,00,2d,00,39,00,37,00,35,00,38,00,2d,00,34,00,35,00,\ 46,00,35,00,31,00,42,00,42,00,44,00,36,00,41,00,41,00,46,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,\ 61,00,6e,00,5f,00,7b,00,37,00,38,00,35,00,35,00,34,00,35,00,39,00,44,00,2d,\ 00,31,00,37,00,44,00,31,00,2d,00,34,00,33,00,43,00,42,00,2d,00,41,00,30,00,\ 32,00,33,00,2d,00,35,00,42,00,32,00,31,00,36,00,38,00,37,00,35,00,42,00,30,\ 00,35,00,44,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,\ 4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,00,7b,00,41,00,38,00,32,00,36,\ 00,38,00,41,00,38,00,42,00,2d,00,45,00,35,00,38,00,39,00,2d,00,34,00,45,00,\ 39,00,36,00,2d,00,38,00,31,00,42,00,30,00,2d,00,39,00,39,00,38,00,34,00,43,\ 00,36,00,32,00,33,00,30,00,37,00,33,00,37,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,\ 00,7b,00,37,00,43,00,41,00,45,00,43,00,32,00,32,00,36,00,2d,00,35,00,35,00,\ 44,00,33,00,2d,00,34,00,39,00,43,00,35,00,2d,00,42,00,33,00,39,00,33,00,2d,\ 00,36,00,42,00,45,00,42,00,42,00,41,00,31,00,35,00,43,00,32,00,33,00,44,00,\ 7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Enum] "0"="Root\\MS_NDISWANIP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDProxy] "DisplayName"=hex(7):4e,00,44,00,49,00,53,00,20,00,50,00,72,00,6f,00,78,00,79,\ 00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="PNP_TDI" "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDProxy\Enum] "0"="Root\\LEGACY_NDPROXY\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS] "Type"=dword:00000002 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,65,00,74,00,62,00,69,00,6f,\ 00,73,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="NetBIOS Interface" "Group"="NetBIOSGroup" "Description"="NetBIOS Interface" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage] "LanaMap"=hex:01,05,01,04,01,00,01,01,00,02,00,03 "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,43,00,36,00,\ 35,00,41,00,42,00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,\ 00,43,00,33,00,45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,\ 36,00,32,00,44,00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,46,00,31,00,37,00,31,00,34,\ 00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,00,\ 2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,35,\ 00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,34,00,37,00,38,00,43,00,46,00,42,00,39,00,37,00,2d,00,\ 36,00,41,00,46,00,45,00,2d,00,34,00,38,00,37,00,34,00,2d,00,41,00,36,00,37,\ 00,33,00,2d,00,38,00,36,00,45,00,39,00,33,00,34,00,33,00,34,00,38,00,39,00,\ 46,00,33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,\ 44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,00,38,\ 00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,\ 44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,00,00,\ 00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,30,00,36,00,30,\ 00,33,00,44,00,37,00,34,00,2d,00,32,00,37,00,41,00,46,00,2d,00,34,00,36,00,\ 45,00,33,00,2d,00,39,00,37,00,39,00,37,00,2d,00,46,00,31,00,36,00,33,00,33,\ 00,38,00,34,00,31,00,46,00,34,00,37,00,34,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,\ 00,70,00,69,00,70,00,5f,00,7b,00,37,00,41,00,43,00,37,00,44,00,46,00,32,00,\ 45,00,2d,00,45,00,39,00,38,00,39,00,2d,00,34,00,41,00,36,00,33,00,2d,00,38,\ 00,41,00,33,00,41,00,2d,00,46,00,35,00,37,00,45,00,38,00,38,00,39,00,37,00,\ 32,00,38,00,34,00,45,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,\ 00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,43,00,36,00,35,00,41,00,42,00,\ 45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,\ 00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,\ 36,00,31,00,42,00,42,00,34,00,32,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,\ 00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,\ 22,00,7b,00,37,00,46,00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,30,\ 00,39,00,32,00,2d,00,34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,00,\ 2d,00,46,00,45,00,37,00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,34,\ 00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,\ 54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,34,00,37,00,38,00,43,\ 00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,00,38,00,\ 37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,00,39,00,33,\ 00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,22,00,00,00,22,00,4e,00,\ 65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,\ 00,20,00,22,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,\ 44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,\ 00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,\ 41,00,37,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,\ 00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,64,00,69,00,\ 73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,\ 63,00,70,00,69,00,70,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,\ 00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,\ 38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,\ 00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,00,74,\ 00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,46,00,\ 31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,\ 00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,\ 41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,4f,00,\ 53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,34,00,37,00,38,00,43,00,46,00,42,00,39,00,37,00,2d,00,36,00,\ 41,00,46,00,45,00,2d,00,34,00,38,00,37,00,34,00,2d,00,41,00,36,00,37,00,33,\ 00,2d,00,38,00,36,00,45,00,39,00,33,00,34,00,33,00,34,00,38,00,39,00,46,00,\ 33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,\ 00,74,00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,\ 00,43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,\ 2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,\ 00,42,00,45,00,41,00,41,00,37,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,\ 00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,\ 30,00,36,00,30,00,33,00,44,00,37,00,34,00,2d,00,32,00,37,00,41,00,46,00,2d,\ 00,34,00,36,00,45,00,33,00,2d,00,39,00,37,00,39,00,37,00,2d,00,46,00,31,00,\ 36,00,33,00,33,00,38,00,34,00,31,00,46,00,34,00,37,00,34,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,\ 4f,00,53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,37,00,41,00,43,00,37,00,44,00,46,00,32,00,45,00,2d,00,\ 45,00,39,00,38,00,39,00,2d,00,34,00,41,00,36,00,33,00,2d,00,38,00,41,00,33,\ 00,41,00,2d,00,46,00,35,00,37,00,45,00,38,00,38,00,39,00,37,00,32,00,38,00,\ 34,00,45,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Parameters] "MaxLana"=dword:00000005 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Parameters\Winsock] "HelperDllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,77,00,73,00,68,00,6e,00,65,00,74,00,62,00,73,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "MaxSockAddrLength"=dword:00000014 "MinSockAddrLength"=dword:00000014 "Mapping"=hex:02,00,00,00,03,00,00,00,11,00,00,00,05,00,00,00,00,00,00,00,11,\ 00,00,00,02,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Enum] "0"="Root\\LEGACY_NETBIOS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,65,00,74,00,62,00,74,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="NetBios over Tcpip" "Group"="PNP_TDI" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="NetBios over Tcpip" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Linkage] "OtherDependencies"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,\ 2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,\ 00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,\ 42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,46,00,31,00,37,00,31,00,\ 34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,\ 00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,\ 35,00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\ 00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,00,37,00,\ 38,00,43,00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,\ 00,38,00,37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,00,\ 39,00,33,00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,\ 7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,\ 00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,\ 43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,\ 69,00,70,00,5f,00,7b,00,35,00,30,00,36,00,30,00,33,00,44,00,37,00,34,00,2d,\ 00,32,00,37,00,41,00,46,00,2d,00,34,00,36,00,45,00,33,00,2d,00,39,00,37,00,\ 39,00,37,00,2d,00,46,00,31,00,36,00,33,00,33,00,38,00,34,00,31,00,46,00,34,\ 00,37,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,41,00,43,00,37,00,44,00,46,\ 00,32,00,45,00,2d,00,45,00,39,00,38,00,39,00,2d,00,34,00,41,00,36,00,33,00,\ 2d,00,38,00,41,00,33,00,41,00,2d,00,46,00,35,00,37,00,45,00,38,00,38,00,39,\ 00,37,00,32,00,38,00,34,00,45,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,43,\ 00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,\ 2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,\ 00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,22,00,\ 00,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,37,00,46,\ 00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,\ 34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,\ 00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,34,00,7d,00,22,00,00,00,\ 22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,34,00,37,00,38,\ 00,43,00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,00,\ 38,00,37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,00,39,\ 00,33,00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,22,00,00,00,22,00,\ 54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,44,00,37,00,42,00,41,\ 00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,\ 39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,\ 00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,00,22,00,00,00,22,00,54,00,\ 63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,64,00,69,00,73,00,57,00,61,\ 00,6e,00,49,00,70,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,43,00,36,00,\ 35,00,41,00,42,00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,\ 00,43,00,33,00,45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,\ 36,00,32,00,44,00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,46,00,31,00,37,00,31,00,34,\ 00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,00,\ 2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,35,\ 00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,34,00,37,00,38,00,43,00,46,00,42,00,39,00,37,00,2d,00,\ 36,00,41,00,46,00,45,00,2d,00,34,00,38,00,37,00,34,00,2d,00,41,00,36,00,37,\ 00,33,00,2d,00,38,00,36,00,45,00,39,00,33,00,34,00,33,00,34,00,38,00,39,00,\ 46,00,33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,\ 44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,00,38,\ 00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,\ 44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,00,00,\ 00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,30,00,36,00,30,\ 00,33,00,44,00,37,00,34,00,2d,00,32,00,37,00,41,00,46,00,2d,00,34,00,36,00,\ 45,00,33,00,2d,00,39,00,37,00,39,00,37,00,2d,00,46,00,31,00,36,00,33,00,33,\ 00,38,00,34,00,31,00,46,00,34,00,37,00,34,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,\ 00,70,00,69,00,70,00,5f,00,7b,00,37,00,41,00,43,00,37,00,44,00,46,00,32,00,\ 45,00,2d,00,45,00,39,00,38,00,39,00,2d,00,34,00,41,00,36,00,33,00,2d,00,38,\ 00,41,00,33,00,41,00,2d,00,46,00,35,00,37,00,45,00,38,00,38,00,39,00,37,00,\ 32,00,38,00,34,00,45,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters] "NbProvider"="_tcp" "NameServerPort"=dword:00000089 "CacheTimeout"=dword:000927c0 "BcastNameQueryCount"=dword:00000003 "BcastQueryTimeout"=dword:000002ee "NameSrvQueryCount"=dword:00000003 "NameSrvQueryTimeout"=dword:000005dc "Size/Small/Medium/Large"=dword:00000001 "SessionKeepAlive"=dword:0036ee80 "TransportBindName"="\\Device\\" "EnableLMHOSTS"=dword:00000001 "EnableProxy"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{478CFB97-6AFE-4874-A673-86E9343489F3}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{50603D74-27AF-46E3-9797-F1633841F474}] "NameServerList"=hex(7):00,00 "RASFlags"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{7AC7DF2E-E989-4A63-8A3A-F57E8897284E}] "NameServerList"=hex(7):00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{7F171404-3092-412D-9CA7-FE7A3A5120B4}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{C65ABE47-0D2D-4C3E-8965-C5B62D61BB42}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{D7BAADC8-DB68-429B-9F56-CD831E7BEAA7}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Security] "Security"=hex:01,00,14,80,e8,00,00,00,f4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,b8,00,08,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\ 00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,14,\ 00,40,00,00,00,01,01,00,00,00,00,00,05,13,00,00,00,00,00,14,00,40,00,00,00,\ 01,01,00,00,00,00,00,05,14,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,\ 00,00,05,20,00,00,00,2c,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Enum] "0"="Root\\LEGACY_NETBT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE] "DependOnService"=hex(7):4e,00,65,00,74,00,44,00,44,00,45,00,44,00,53,00,44,00,\ 4d,00,00,00,00,00 "Description"="Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Network DDE" "ErrorControl"=dword:00000001 "Group"="NetDDEGroup" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,\ 00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE\Enum] "0"="Root\\LEGACY_NETDDE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm] "DependOnService"=hex(7):00,00 "Description"="Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. " "DisplayName"="Network DDE DSDM" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,\ 00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm\Enum] "0"="Root\\LEGACY_NETDDEDSDM\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Net Logon" "Group"="RemoteValidation" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Supports pass-through authentication of account logon events for computers in a domain." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters] "DisablePasswordChange"=dword:00000000 "maximumpasswordage"=dword:0000001e "requiresignorseal"=dword:00000001 "requirestrongkey"=dword:00000000 "sealsecurechannel"=dword:00000001 "signsecurechannel"=dword:00000001 "Update"="no" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Private] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Enum] "0"="Root\\LEGACY_NETLOGON\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections." "DisplayName"="Network Connections" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000120 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6e,00,65,00,74,00,6d,00,61,00,6e,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman\Enum] "0"="Root\\LEGACY_NETMAN\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw4x32] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000010 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,4e,00,45,00,54,00,77,00,34,00,78,\ 00,33,00,32,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Intel(R) Wireless WiFi Link Adapter Driver for Windows XP 32 Bit" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw4x32\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw4x32\Enum] "0"="PCI\\VEN_8086&DEV_4229&SUBSYS_11018086&REV_61\\4&20975680&0&00E1" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIC1394] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000a "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,69,00,63,00,31,00,33,00,39,\ 00,34,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="1394 Net Driver" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIC1394\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIC1394\Enum] "0"="V1394\\NIC1394\\bb40429d23f73" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nla] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Network Location Awareness (NLA)" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,41,00,66,00,64,00,\ 00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Collects and stores network configuration and location information, and notifies applications when this information changes." "Group"="FirewallGroup" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nla\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6d,00,73,00,77,00,73,00,6f,00,63,00,6b,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nla\Security] "Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nla\Enum] "0"="Root\\LEGACY_NLA\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs] "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000001 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs\Aliases] "lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\ 00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\ 67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\ 00,6d,00,72,00,00,00,00,00 "ntsvcs"=hex(7):65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,00,00,73,00,76,\ 00,63,00,63,00,74,00,6c,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs\Enum] "0"="Root\\LEGACY_NPFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ntfs] "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000004 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ntfs\Enum] "0"="Root\\LEGACY_NTFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtLmSsp] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="NT LM Security Support Provider" "ObjectName"="LocalSystem" "Description"="Provides security to remote procedure call (RPC) programs that use transports other than named pipes." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtLmSsp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtLmSsp\Enum] "0"="Root\\LEGACY_NTLMSSP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Removable Storage" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6e,00,74,00,6d,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ShutdownTimeout"=dword:00007530 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Enum] "0"="Root\\LEGACY_NTMSSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Null] "ErrorControl"=dword:00000001 "Group"="Base" "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Null\Enum] "0"="Root\\LEGACY_NULL\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,76,00,34,00,5f,00,6d,00,69,\ 00,6e,00,69,00,2e,00,73,00,79,00,73,00,00,00 "Group"="Video" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Device0] "InstalledDisplayDrivers"=hex(7):6e,00,76,00,34,00,5f,00,64,00,69,00,73,00,70,\ 00,00,00,00,00 "VgaCompatible"=dword:00000000 "UseHWSelectedDevice"=dword:00000001 "VPEEnable"=dword:00000000 "RMMaintainDevs"=dword:00000001 "RMMaintainTVStandard"=dword:00000001 "DualviewMobile"=dword:02000000 "RotateFlag"=dword:00000004 "DevSwitchSuppressMask"=dword:00000005 "MultiFunctionSupported"=dword:00000001 "NV_Modes"=hex(7):7b,00,2a,00,7d,00,53,00,20,00,36,00,34,00,30,00,78,00,34,00,\ 30,00,30,00,3d,00,37,00,46,00,3b,00,33,00,32,00,30,00,78,00,32,00,30,00,30,\ 00,20,00,33,00,32,00,30,00,78,00,32,00,34,00,30,00,20,00,34,00,30,00,30,00,\ 78,00,33,00,30,00,30,00,20,00,34,00,38,00,30,00,78,00,33,00,36,00,30,00,20,\ 00,35,00,31,00,32,00,78,00,33,00,38,00,34,00,3d,00,46,00,3b,00,53,00,48,00,\ 56,00,20,00,37,00,32,00,30,00,78,00,35,00,37,00,36,00,20,00,31,00,32,00,38,\ 00,30,00,78,00,31,00,30,00,32,00,34,00,3d,00,31,00,3b,00,31,00,34,00,30,00,\ 30,00,78,00,31,00,30,00,35,00,30,00,78,00,33,00,32,00,20,00,31,00,36,00,30,\ 00,30,00,78,00,39,00,30,00,30,00,78,00,33,00,32,00,20,00,31,00,36,00,30,00,\ 30,00,78,00,31,00,30,00,32,00,34,00,78,00,33,00,32,00,20,00,31,00,36,00,30,\ 00,30,00,78,00,31,00,32,00,30,00,30,00,78,00,33,00,32,00,20,00,31,00,39,00,\ 32,00,30,00,78,00,31,00,30,00,38,00,30,00,78,00,33,00,32,00,20,00,31,00,39,\ 00,32,00,30,00,78,00,31,00,32,00,30,00,30,00,78,00,33,00,32,00,20,00,31,00,\ 39,00,32,00,30,00,78,00,31,00,34,00,34,00,30,00,20,00,32,00,30,00,34,00,38,\ 00,78,00,31,00,35,00,33,00,36,00,3d,00,31,00,46,00,3b,00,31,00,34,00,30,00,\ 30,00,78,00,31,00,30,00,35,00,30,00,78,00,38,00,2c,00,31,00,36,00,20,00,31,\ 00,36,00,30,00,30,00,78,00,39,00,30,00,30,00,78,00,38,00,2c,00,31,00,36,00,\ 20,00,31,00,36,00,30,00,30,00,78,00,31,00,30,00,32,00,34,00,78,00,38,00,2c,\ 00,31,00,36,00,20,00,31,00,36,00,30,00,30,00,78,00,31,00,32,00,30,00,30,00,\ 78,00,38,00,2c,00,31,00,36,00,20,00,31,00,39,00,32,00,30,00,78,00,31,00,30,\ 00,38,00,30,00,78,00,38,00,2c,00,31,00,36,00,20,00,31,00,39,00,32,00,30,00,\ 78,00,31,00,32,00,30,00,30,00,78,00,38,00,2c,00,31,00,36,00,3d,00,33,00,46,\ 00,3b,00,36,00,34,00,30,00,78,00,34,00,38,00,30,00,20,00,37,00,32,00,30,00,\ 78,00,34,00,38,00,30,00,20,00,38,00,30,00,30,00,78,00,36,00,30,00,30,00,20,\ 00,31,00,30,00,32,00,34,00,78,00,37,00,36,00,38,00,20,00,31,00,30,00,38,00,\ 38,00,78,00,36,00,31,00,32,00,20,00,31,00,31,00,35,00,32,00,78,00,37,00,36,\ 00,38,00,20,00,31,00,31,00,35,00,32,00,78,00,38,00,36,00,34,00,20,00,31,00,\ 32,00,38,00,30,00,78,00,37,00,32,00,30,00,20,00,31,00,32,00,38,00,30,00,78,\ 00,37,00,36,00,38,00,20,00,31,00,32,00,38,00,30,00,78,00,38,00,30,00,30,00,\ 20,00,31,00,32,00,38,00,30,00,78,00,38,00,35,00,34,00,20,00,31,00,32,00,38,\ 00,30,00,78,00,39,00,36,00,30,00,3d,00,37,00,46,00,3b,00,00,00,00,00 "HDTVModePruning"=dword:00000004 "_deko1000.exe:OGL_46574957"=dword:00000003 "_deko1000hd.exe:OGL_46574957"=dword:00000003 "_deko3000.exe:OGL_46574957"=dword:00000003 "_deko3000hd.exe:OGL_46574957"=dword:00000003 "_inflexion3d.exe:OGL_46574957"=dword:00000003 "_oni.exe:OGL_ExtensionStringNVArch"=dword:00000004 "NvCplGfxLib"="nvgfx.dll" "Device Description"="NVIDIA GeForce Go 7300" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Device1] "InstalledDisplayDrivers"=hex(7):6e,00,76,00,34,00,5f,00,64,00,69,00,73,00,70,\ 00,00,00,00,00 "VgaCompatible"=dword:00000000 "UseHWSelectedDevice"=dword:00000001 "VPEEnable"=dword:00000000 "RMMaintainDevs"=dword:00000001 "RMMaintainTVStandard"=dword:00000001 "DualviewMobile"=dword:02000000 "RotateFlag"=dword:00000004 "DevSwitchSuppressMask"=dword:00000005 "MultiFunctionSupported"=dword:00000001 "NV_Modes"=hex(7):7b,00,2a,00,7d,00,53,00,20,00,36,00,34,00,30,00,78,00,34,00,\ 30,00,30,00,3d,00,37,00,46,00,3b,00,33,00,32,00,30,00,78,00,32,00,30,00,30,\ 00,20,00,33,00,32,00,30,00,78,00,32,00,34,00,30,00,20,00,34,00,30,00,30,00,\ 78,00,33,00,30,00,30,00,20,00,34,00,38,00,30,00,78,00,33,00,36,00,30,00,20,\ 00,35,00,31,00,32,00,78,00,33,00,38,00,34,00,3d,00,46,00,3b,00,53,00,48,00,\ 56,00,20,00,37,00,32,00,30,00,78,00,35,00,37,00,36,00,20,00,31,00,32,00,38,\ 00,30,00,78,00,31,00,30,00,32,00,34,00,3d,00,31,00,3b,00,31,00,34,00,30,00,\ 30,00,78,00,31,00,30,00,35,00,30,00,78,00,33,00,32,00,20,00,31,00,36,00,30,\ 00,30,00,78,00,39,00,30,00,30,00,78,00,33,00,32,00,20,00,31,00,36,00,30,00,\ 30,00,78,00,31,00,30,00,32,00,34,00,78,00,33,00,32,00,20,00,31,00,36,00,30,\ 00,30,00,78,00,31,00,32,00,30,00,30,00,78,00,33,00,32,00,20,00,31,00,39,00,\ 32,00,30,00,78,00,31,00,30,00,38,00,30,00,78,00,33,00,32,00,20,00,31,00,39,\ 00,32,00,30,00,78,00,31,00,32,00,30,00,30,00,78,00,33,00,32,00,20,00,31,00,\ 39,00,32,00,30,00,78,00,31,00,34,00,34,00,30,00,20,00,32,00,30,00,34,00,38,\ 00,78,00,31,00,35,00,33,00,36,00,3d,00,31,00,46,00,3b,00,31,00,34,00,30,00,\ 30,00,78,00,31,00,30,00,35,00,30,00,78,00,38,00,2c,00,31,00,36,00,20,00,31,\ 00,36,00,30,00,30,00,78,00,39,00,30,00,30,00,78,00,38,00,2c,00,31,00,36,00,\ 20,00,31,00,36,00,30,00,30,00,78,00,31,00,30,00,32,00,34,00,78,00,38,00,2c,\ 00,31,00,36,00,20,00,31,00,36,00,30,00,30,00,78,00,31,00,32,00,30,00,30,00,\ 78,00,38,00,2c,00,31,00,36,00,20,00,31,00,39,00,32,00,30,00,78,00,31,00,30,\ 00,38,00,30,00,78,00,38,00,2c,00,31,00,36,00,20,00,31,00,39,00,32,00,30,00,\ 78,00,31,00,32,00,30,00,30,00,78,00,38,00,2c,00,31,00,36,00,3d,00,33,00,46,\ 00,3b,00,36,00,34,00,30,00,78,00,34,00,38,00,30,00,20,00,37,00,32,00,30,00,\ 78,00,34,00,38,00,30,00,20,00,38,00,30,00,30,00,78,00,36,00,30,00,30,00,20,\ 00,31,00,30,00,32,00,34,00,78,00,37,00,36,00,38,00,20,00,31,00,30,00,38,00,\ 38,00,78,00,36,00,31,00,32,00,20,00,31,00,31,00,35,00,32,00,78,00,37,00,36,\ 00,38,00,20,00,31,00,31,00,35,00,32,00,78,00,38,00,36,00,34,00,20,00,31,00,\ 32,00,38,00,30,00,78,00,37,00,32,00,30,00,20,00,31,00,32,00,38,00,30,00,78,\ 00,37,00,36,00,38,00,20,00,31,00,32,00,38,00,30,00,78,00,38,00,30,00,30,00,\ 20,00,31,00,32,00,38,00,30,00,78,00,38,00,35,00,34,00,20,00,31,00,32,00,38,\ 00,30,00,78,00,39,00,36,00,30,00,3d,00,37,00,46,00,3b,00,00,00,00,00 "HDTVModePruning"=dword:00000004 "_deko1000.exe:OGL_46574957"=dword:00000003 "_deko1000hd.exe:OGL_46574957"=dword:00000003 "_deko3000.exe:OGL_46574957"=dword:00000003 "_deko3000hd.exe:OGL_46574957"=dword:00000003 "_inflexion3d.exe:OGL_46574957"=dword:00000003 "_oni.exe:OGL_ExtensionStringNVArch"=dword:00000004 "NvCplGfxLib"="nvgfx.dll" "Device Description"="NVIDIA GeForce Go 7300" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Video] "Service"="nv" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Enum] "0"="PCI\\VEN_10DE&DEV_01D7&SUBSYS_FF021179&REV_A1\\4&31b7bfb9&0&0008" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvgts] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvgts\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvgts\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVSvc] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,\ 00,76,00,73,00,76,00,63,00,33,00,32,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="NVIDIA Display Driver Service" "ObjectName"="LocalSystem" "Description"="Provides system and desktop level support to the NVIDIA display driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVSvc\Enum] "0"="Root\\LEGACY_NVSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFlt] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,77,00,6c,00,6e,00,6b,00,66,\ 00,6c,00,74,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IPX Traffic Filter Driver" "DependOnService"=hex(7):4e,00,77,00,6c,00,6e,00,6b,00,46,00,77,00,64,00,00,00,\ 00,00 "DependOnGroup"=hex(7):00,00 "Description"="IPX Traffic Filter Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFlt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFwd] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,77,00,6c,00,6e,00,6b,00,66,\ 00,77,00,64,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IPX Traffic Forwarder Driver" "Description"="IPX Traffic Forwarder Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFwd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ohci1394] "Type"=dword:00000001 "Start"=dword:00000000 "Group"="Boot Bus Extender" "ErrorControl"=dword:00000001 "DisplayName"="Texas Instruments OHCI Compliant IEEE 1394 Host Controller" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6f,00,68,00,63,00,69,00,31,00,33,\ 00,39,00,34,00,2e,00,73,00,79,00,73,00,00,00 "Tag"=dword:00000006 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ohci1394\Enum] "0"="PCI\\VEN_104C&DEV_803A&SUBSYS_FF001179&REV_00\\4&6b16d5b&0&21F0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Parport] "ErrorControl"=dword:00000000 "Group"="Parallel arbitrator" "Start"=dword:00000003 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Parport\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PartMgr] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000007 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PartMgr\Enum] "0"="Root\\LEGACY_PARTMGR\\0000" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="IDE\\DiskTOSHIBA_MK1637GSX_______________________DL030M__\\5&69b5607&0&0.0.0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ParVdm] "DependOnGroup"=hex(7):50,00,61,00,72,00,61,00,6c,00,6c,00,65,00,6c,00,20,00,\ 61,00,72,00,62,00,69,00,74,00,72,00,61,00,74,00,6f,00,72,00,00,00,00,00 "DependOnService"=hex(7):50,00,61,00,72,00,70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000000 "Group"="Extended base" "Start"=dword:00000002 "Tag"=dword:00000002 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ParVdm\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ParVdm\Enum] "0"="Root\\LEGACY_PARVDM\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCI] "ErrorControl"=dword:00000003 "Group"="Boot Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="PCI Bus Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,63,00,69,00,2e,00,73,00,79,\ 00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCI\Parameters] "1045C621"=hex:04,00,00,00,00,00,00,00 "10950640"=hex:04,00,00,00,00,00,00,00 "80861230"=hex:04,00,00,00,00,00,00,00 "80867010"=hex:04,00,00,00,00,00,00,00 "104B0140"=hex:08,00,00,00,00,00,00,00 "11790603"=hex:08,00,00,00,00,00,00,00 "80867113"=hex:08,00,00,00,00,00,00,00 "497884C5"=hex:08,00,00,00,00,00,00,00 "11063040"=hex:08,00,00,00,00,00,00,00 "0E111000"=hex:10,00,00,00,00,00,00,00 "0E112000"=hex:10,00,00,00,00,00,00,00 "10390406"=hex:10,00,00,00,00,00,00,00 "80860482"=hex:00,40,00,00,00,00,00,00 "80860008"=hex:10,00,00,00,00,00,00,00 "10140002"=hex:10,00,00,00,00,00,00,00 "10800600"=hex:20,00,00,00,00,00,00,00 "10131100"=hex:40,00,00,00,00,00,00,00 "10B95219"=hex:80,00,00,00,00,00,00,00 "1C1C0001"=hex:00,01,00,00,00,00,00,00 "10970038"=hex:00,01,00,00,00,00,00,00 "100BD001"=hex:00,04,00,00,00,00,00,00 "808604A3"=hex:00,08,00,00,00,00,00,00 "10AA0000"=hex:00,08,00,00,00,00,00,00 "533388D1"=hex:00,00,00,00,01,00,00,00 "11790605"=hex:00,10,00,00,00,00,00,00 "10131110"=hex:00,20,00,00,00,00,00,00 "11800478"=hex:00,20,00,00,00,00,00,00 "11800475"=hex:00,20,00,00,00,00,00,00 "11800476"=hex:00,20,00,00,00,00,00,00 "10040101"=hex:00,40,00,00,00,00,00,00 "10421000"=hex:00,40,00,00,00,00,00,00 "104CAC12"=hex:00,00,01,00,00,00,00,00 "11800466"=hex:00,00,01,00,00,00,00,00 "10140095"=hex:00,00,04,00,00,00,00,00 "80862418"=hex:00,00,04,00,00,00,00,00 "80862428"=hex:00,00,04,00,00,00,00,00 "8086244E"=hex:00,00,04,00,00,00,00,00 "80862448"=hex:00,00,04,00,00,00,00,00 "8086122E"=hex:00,00,08,00,00,00,00,00 "80867000"=hex:00,00,08,00,00,00,00,00 "80867110"=hex:00,00,08,00,00,00,00,00 "80867600"=hex:00,00,08,00,00,00,00,00 "10024747"=hex:00,00,40,00,00,00,00,00 "10024754"=hex:00,00,00,00,01,00,00,00 "53338901"=hex:00,00,00,00,01,00,00,00 "101300D6"=hex:00,00,40,00,00,00,00,00 "104CAC15"=hex:00,00,40,00,00,00,00,00 "110B0004"=hex:00,00,40,00,00,00,00,00 "1000000F"=hex:00,00,40,00,00,00,00,00 "104CAC17"=hex:00,00,40,00,00,00,00,00 "10239397"=hex:00,00,40,00,00,00,00,00 "10024742"=hex:00,00,40,00,00,00,00,00 "10024744"=hex:00,00,40,00,00,00,00,00 "10024749"=hex:00,00,40,00,00,00,00,00 "10024750"=hex:00,00,40,00,00,00,00,00 "10024751"=hex:00,00,40,00,00,00,00,00 "10024755"=hex:00,00,40,00,00,00,00,00 "10024757"=hex:00,00,40,20,00,00,00,00 "10024759"=hex:00,00,40,20,00,00,00,00 "10024C42"=hex:00,00,40,00,00,00,00,00 "10024C44"=hex:00,00,40,00,00,00,00,00 "10024C47"=hex:00,00,40,00,00,00,00,00 "10024C49"=hex:00,00,40,00,00,00,00,00 "10024C50"=hex:00,00,40,00,00,00,00,00 "10024C51"=hex:00,00,40,00,00,00,00,00 "10025654"=hex:00,00,00,00,01,00,00,00 "10025655"=hex:00,00,40,00,00,00,00,00 "10025656"=hex:00,00,40,00,00,00,00,00 "121A0003"=hex:00,00,40,00,00,00,00,00 "1045C861107B9300"=hex:00,00,40,00,00,00,00,00 "1045C8611045C861"=hex:00,00,40,00,00,00,00,00 "80861231"=hex:00,00,00,01,00,00,00,00 "12730002"=hex:00,00,00,01,00,00,00,00 "1014007D"=hex:00,00,00,01,00,00,00,00 "12850100"=hex:00,00,00,01,00,00,00,00 "12176836"=hex:00,00,00,08,00,00,00,00 "12176832"=hex:00,00,00,08,00,00,00,00 "109107A0"=hex:00,00,00,20,00,00,00,00 "80867800"=hex:00,00,00,20,00,00,00,00 "10c88005"=hex:00,00,00,20,00,00,00,00 "10c88006"=hex:00,00,00,20,00,00,00,00 "10c80005"=hex:00,00,00,20,00,00,00,00 "10c80006"=hex:00,00,00,20,00,00,00,00 "102B1001"=hex:00,00,00,80,00,00,00,00 "10DD0100"=hex:00,00,00,20,00,00,00,00 "10950646"=hex:00,00,00,20,00,00,00,00 "10950670"=hex:00,00,00,20,00,00,00,00 "10950648"=hex:00,00,00,20,00,00,00,00 "10110026"=hex:00,00,00,20,00,00,00,00 "8086B154"=hex:00,00,00,20,00,00,00,00 "53338904"=hex:00,00,00,20,00,00,00,00 "11068598"=hex:00,00,00,20,00,00,00,00 "11068605"=hex:00,00,00,20,00,00,00,00 "11790609"=hex:00,00,00,40,00,00,00,00 "10140047"=hex:00,00,00,40,00,00,00,00 "102B051B"=hex:00,00,00,80,00,00,00,00 "102B0520"=hex:00,00,00,80,00,00,00,00 "102B0521"=hex:00,00,00,80,00,00,00,00 "102B1025"=hex:00,00,00,80,00,00,00,00 "102B0525"=hex:00,00,00,80,00,00,00,00 "80867121"=hex:00,00,00,80,00,00,00,00 "80867123"=hex:00,00,00,80,00,00,00,00 "80867125"=hex:00,00,00,80,00,00,00,00 "80861132"=hex:00,00,00,80,00,00,00,00 "90050050"=hex:00,00,00,80,00,00,00,00 "9005005F"=hex:00,00,00,80,00,00,00,00 "10024752"=hex:00,00,00,80,00,00,00,00 "1002474F"=hex:00,00,00,80,00,00,00,00 "1002474D"=hex:00,00,00,80,00,00,00,00 "10024753"=hex:00,00,00,80,00,00,00,00 "1002474C"=hex:00,00,00,80,00,00,00,00 "1002474E"=hex:00,00,00,80,00,00,00,00 "10024C4D"=hex:00,00,00,80,00,00,00,00 "10024C4E"=hex:00,00,00,80,00,00,00,00 "10024C52"=hex:00,00,00,80,00,00,00,00 "10024C53"=hex:00,00,00,80,00,00,00,00 "10239880"=hex:00,00,00,80,00,00,00,00 "10DE00A0"=hex:00,00,00,80,00,00,00,00 "10DE00A1"=hex:00,00,00,80,00,00,00,00 "10DE00A3"=hex:00,00,00,80,00,00,00,00 "10DE00B0"=hex:00,00,00,80,00,00,00,00 "10DE00B1"=hex:00,00,00,80,00,00,00,00 "10DE00B3"=hex:00,00,00,80,00,00,00,00 "10DE0100"=hex:00,00,00,80,00,00,00,00 "10DE0101"=hex:00,00,00,80,00,00,00,00 "10DE0102"=hex:00,00,00,80,00,00,00,00 "10DE0103"=hex:00,00,00,80,00,00,00,00 "10DE0120"=hex:00,00,00,80,00,00,00,00 "10DE0121"=hex:00,00,00,80,00,00,00,00 "10DE0122"=hex:00,00,00,80,00,00,00,00 "10DE0123"=hex:00,00,00,80,00,00,00,00 "10DE0150"=hex:00,00,00,80,00,00,00,00 "10DE0151"=hex:00,00,00,80,00,00,00,00 "10DE0152"=hex:00,00,00,80,00,00,00,00 "10DE0153"=hex:00,00,00,80,00,00,00,00 "10DE0200"=hex:00,00,00,80,00,00,00,00 "10DE0201"=hex:00,00,00,80,00,00,00,00 "10DE0202"=hex:00,00,00,80,00,00,00,00 "10DE0203"=hex:00,00,00,80,00,00,00,00 "12D20018"=hex:00,00,00,80,00,00,00,00 "12D20019"=hex:00,00,00,80,00,00,00,00 "10136003"=hex:00,00,00,80,00,00,00,00 "3D3D000A"=hex:00,00,00,80,00,00,00,00 "10024158"=hex:00,00,00,00,01,00,00,00 "10024354"=hex:00,00,00,00,01,00,00,00 "10024358"=hex:00,00,00,00,01,00,00,00 "10024554"=hex:00,00,00,00,01,00,00,00 "10024758"=hex:00,00,00,00,01,00,00,00 "10024C54"=hex:00,00,00,00,01,00,00,00 "53338810"=hex:00,00,00,00,01,00,00,00 "53338811"=hex:00,00,00,00,01,00,00,00 "53338812"=hex:00,00,00,00,01,00,00,00 "53338814"=hex:00,00,00,00,01,00,00,00 "53338880"=hex:00,00,00,00,01,00,00,00 "533388B0"=hex:00,00,00,00,01,00,00,00 "533388C0"=hex:00,00,00,00,01,00,00,00 "533388C1"=hex:00,00,00,00,01,00,00,00 "533388D0"=hex:00,00,00,00,01,00,00,00 "533388F0"=hex:00,00,00,00,01,00,00,00 "53338902"=hex:00,00,00,00,01,00,00,00 "0E11B109"=hex:00,00,00,00,02,00,00,00 "10024342"=hex:00,00,00,00,80,00,00,00 "10024362"=hex:00,00,00,00,80,00,00,00 "10024371"=hex:00,00,00,00,80,00,00,00 "100C3202"=hex:00,8a,00,00,00,00,00,00 "10668002"=hex:00,00,30,00,00,00,00,00 "10660002"=hex:00,00,30,00,00,00,00,00 "10040102"=hex:00,40,00,02,00,00,00,00 "1045C814"=hex:00,00,40,20,00,00,00,00 "10024756"=hex:00,00,40,20,00,00,00,00 "1002475A"=hex:00,00,40,20,00,00,00,00 "80861161"=hex:00,00,00,40,10,00,00,00 "80861461"=hex:00,00,00,40,10,00,00,00 "1000000B"=hex:00,00,00,a0,00,00,00,00 "10DE0020"=hex:00,00,00,a0,00,00,00,00 "10DE0028"=hex:00,00,00,a0,00,00,00,00 "10DE0029"=hex:00,00,00,a0,00,00,00,00 "10DE002A"=hex:00,00,00,a0,00,00,00,00 "10DE002B"=hex:00,00,00,a0,00,00,00,00 "10DE002C"=hex:00,00,00,a0,00,00,00,00 "10DE002D"=hex:00,00,00,a0,00,00,00,00 "10DE002E"=hex:00,00,00,a0,00,00,00,00 "10DE002F"=hex:00,00,00,a0,00,00,00,00 "101300D6101880D6"=hex:00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCI\Enum] "0"="ACPI\\PNP0A08\\2&daba3ff&0" "Count"=dword:00000006 "NextInstance"=dword:00000006 "1"="PCI\\VEN_8086&DEV_27A1&SUBSYS_00000000&REV_03\\3&b1bfb68&0&08" "2"="PCI\\VEN_8086&DEV_27D0&SUBSYS_00000000&REV_02\\3&b1bfb68&0&E0" "3"="PCI\\VEN_8086&DEV_27D2&SUBSYS_00000000&REV_02\\3&b1bfb68&0&E1" "4"="PCI\\VEN_8086&DEV_27D4&SUBSYS_00000000&REV_02\\3&b1bfb68&0&E2" "5"="PCI\\VEN_8086&DEV_2448&SUBSYS_00000000&REV_E2\\3&b1bfb68&0&F0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCIDump] "ErrorControl"=dword:00000000 "Group"="PCI Configuration" "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCIIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000003 "Type"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,63,00,69,00,69,00,64,00,65,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCIIde\Enum] "0"="PCI\\VEN_8086&DEV_27C4&SUBSYS_FF001179&REV_02\\3&b1bfb68&0&FA" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pcmcia] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000001 "Type"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,63,00,6d,00,63,00,69,00,61,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pcmcia\Parameters] "SoundsEnabled"=dword:00000000 "IsaIrqRescanComplete"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pcmcia\Enum] "0"="PCI\\VEN_104C&DEV_8039&SUBSYS_FF001179&REV_00\\4&6b16d5b&0&20F0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PDCOMP] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PDFRAME] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PDRELI] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PDRFRAME] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\perc2] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\perc2\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\perc2\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\perc2hib] "ErrorControl"=dword:00000001 "Group"="Filter" "Start"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfDisk] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfDisk\Performance] "Close"="CloseDiskObject" "Collect"="CollectDiskObjectData" "Collect Timeout"=dword:000007d0 "Library"="perfdisk.dll" "Object List"="234 236" "Open"="OpenDiskObject" "Open Timeout"=dword:00001388 "WbemAdapFileSignature"=hex:ab,fb,67,3b,24,a9,b3,28,77,61,d4,97,52,9f,b5,b9 "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00006800 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfNet] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfNet\Performance] "Close"="CloseNetSvcsObject" "Collect"="CollectNetSvcsObjectData" "Collect Timeout"=dword:00001388 "Library"="perfnet.dll" "Object List"="52 262 330 1300" "Open"="OpenNetSvcsObject" "Open Timeout"=dword:00001f40 "WbemAdapFileSignature"=hex:91,3a,f8,8b,02,91,d7,d3,a0,fd,c9,2f,5e,1c,c7,d7 "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00004600 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfOS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfOS\Performance] "Close"="CloseOSObject" "Collect"="CollectOSObjectData" "Collect Timeout"=dword:000007d0 "Library"="perfos.dll" "Object List"="2 4 86 238 260 700" "Open"="OpenOSObject" "Open Timeout"=dword:00001388 "WbemAdapFileSignature"=hex:ac,da,fc,d1,4e,c0,ec,e8,91,98,50,37,46,a5,c1,47 "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00006200 "WbemAdapStatus"=dword:00000000 "Disable Performance Counters"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfProc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfProc\Performance] "Close"="CloseSysProcessObject" "Collect"="CollectSysProcessObjectData" "Collect Timeout"=dword:00001f40 "Library"="perfproc.dll" "Object List"="230 232 786 740 816 1408 1500 1548 1760" "Open"="OpenSysProcessObject" "Open Timeout"=dword:00002710 "WbemAdapFileSignature"=hex:17,93,cc,66,06,05,f6,3b,14,fb,96,c7,70,7f,75,ba "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00008800 "WbemAdapStatus"=dword:00000000 "Disable Performance Counters"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlay] "Description"="Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "DisplayName"="Plug and Play" "ErrorControl"=dword:00000001 "Group"="PlugPlay" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "PlugPlayServiceType"=dword:00000003 "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlay\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="IPSEC Services" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,54,00,63,00,70,00,\ 69,00,70,00,00,00,49,00,50,00,53,00,65,00,63,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver." "PolstoreDllRegisterVersion"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent\Enum] "0"="Root\\LEGACY_POLICYAGENT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PptpMiniport] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,70,00,74,\ 00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="WAN Miniport (PPTP)" "Description"="WAN Miniport (PPTP)" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PptpMiniport\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PptpMiniport\Enum] "0"="Root\\MS_PPTPMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users." "DisplayName"="Protected Storage" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000120 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Enum] "0"="Root\\LEGACY_PROTECTEDSTORAGE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000007 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,73,00,63,00,68,00,65,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="QoS Packet Scheduler" "Group"="PNP_TDI" "DependOnService"=hex(7):47,00,70,00,63,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="QoS Packet Scheduler" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\NdisWanIp] "UpperBindings"="\\Device\\{B28EAB69-7A2C-452D-9C6F-EF1B29158EE8}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{7F171404-3092-412D-9CA7-FE7A3A5120B4}] "UpperBindings"="\\Device\\{E42A9BCC-2644-422F-AC34-812F9005F41A}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{C65ABE47-0D2D-4C3E-8965-C5B62D61BB42}] "UpperBindings"="\\Device\\{D25197A3-11DC-4AD2-B752-E4AD7B6A4134}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Performance] "Library"="pschdprf.dll" "Open"="OpenPschedPerformanceData" "Close"="ClosePschedPerformanceData" "Collect"="CollectPschedPerformanceData" "Last Counter"=dword:000007dc "Last Help"=dword:000007dd "First Counter"=dword:00000790 "First Help"=dword:00000791 "WbemAdapFileSignature"=hex:b4,45,9d,13,47,3d,07,fc,b4,33,65,c0,27,32,de,16 "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00002a00 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Enum] "0"="Root\\MS_PSCHEDMP\\0000" "Count"=dword:00000003 "NextInstance"=dword:00000003 "1"="Root\\MS_PSCHEDMP\\0001" "2"="Root\\MS_PSCHEDMP\\0002" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ptilink] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,74,00,69,00,6c,00,69,00,6e,\ 00,6b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Direct Parallel Link Driver" "Description"="Direct Parallel Link Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ptilink\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ptilink\Enum] "0"="Root\\MS_PTIMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PxHelp20] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,78,00,48,00,65,00,6c,00,70,\ 00,32,00,30,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="PxHelp20" "Group"="Filter" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PxHelp20\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PxHelp20\Enum] "0"="IDE\\CdRomTSSTcorp_CD/DVDW_TS-L632D_______________TO04____\\5&195506ac&0&0.0.0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1080] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003d "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1080\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1080\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ql10wnt] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000023 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ql10wnt\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ql10wnt\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql12160] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003f "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql12160\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql12160\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1240] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000031 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1240\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1240\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1280] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003f "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1280\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1280\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,61,00,63,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access Auto Connection Driver" "Group"="Streams Drivers" "Description"="Remote Access Auto Connection Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd\Enum] "0"="Root\\LEGACY_RASACD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Remote Access Auto Connection Manager" "DependOnService"=hex(7):52,00,61,00,73,00,4d,00,61,00,6e,00,00,00,54,00,61,00,\ 70,00,69,00,73,00,72,00,76,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,61,00,75,00,74,00,6f,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto\Enum] "0"="Root\\LEGACY_RASAUTO\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rasl2tp] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,6c,00,32,00,74,\ 00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="WAN Miniport (L2TP)" "Description"="WAN Miniport (L2TP)" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rasl2tp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rasl2tp\Enum] "0"="Root\\MS_L2TPMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Remote Access Connection Manager" "DependOnService"=hex(7):54,00,61,00,70,00,69,00,73,00,72,00,76,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Creates a network connection." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters] "Medias"=hex(7):72,00,61,00,73,00,74,00,61,00,70,00,69,00,00,00,00,00 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,6d,00,61,00,6e,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "IpOutLowWatermark"=dword:00000001 "IpOutHighWatermark"=dword:00000005 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters\Quarantine] "Enabled"=dword:00000001 "AutoRefreshEnabled"=dword:00000000 "AutoRefreshTimeout"=dword:01808580 "WorkItemTimeout"=dword:00000bb8 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP] "MaxConfigure"=dword:0000000a "MaxFailure"=dword:0000000a "MaxReject"=dword:00000005 "MaxTerminate"=dword:00000002 "Multilink"=dword:00000000 "NegotiateTime"=dword:00000096 "RestartTimer"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\ControlProtocols] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\ControlProtocols\BuiltIn] "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,70,00,70,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\ControlProtocols\Chap] "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP] "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,70,00,70,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13] "RolesSupported"=dword:00000002 "FriendlyName"="Smart Card or other Certificate" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "InvokeUsernameDialog"=dword:00000000 "InvokePasswordDialog"=dword:00000000 "MPPEEncryptionSupported"=dword:00000001 "ConfigCLSID"="{58AB2366-D597-11d1-B90E-00C04FC9B263}" "StandaloneSupported"=dword:00000000 "NoRootRevocationCheck"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\25] "RolesSupported"=dword:0000001a "FriendlyName"="Protected EAP (PEAP)" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "InvokeUsernameDialog"=dword:00000000 "InvokePasswordDialog"=dword:00000000 "MPPEEncryptionSupported"=dword:00000001 "ConfigCLSID"="{58AB2366-D597-11d1-B90E-00C04FC9B263}" "StandaloneSupported"=dword:00000001 "NoRootRevocationCheck"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\26] "FriendlyName"="Secured password (EAP-MSCHAP v2)" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 "ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 "IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 "InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "InvokeUsernameDialog"=dword:00000000 "InvokePasswordDialog"=dword:00000000 "MPPEEncryptionSupported"=dword:00000001 "ConfigCLSID"="{2af6bcaa-f526-4803-aeb8-5777ce386647}" "StandaloneSupported"=dword:00000001 "RolesSupported"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\4] "RolesSupported"=dword:0000000a "FriendlyName"="MD5-Challenge" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 "InvokeUsernameDialog"=dword:00000001 "InvokePasswordDialog"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Security] "Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Enum] "0"="Root\\LEGACY_RASMAN\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,70,00,70,\ 00,6f,00,65,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access PPPOE Driver" "Description"="Remote Access PPPOE Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,43,00,36,\ 00,35,00,41,00,42,00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,\ 34,00,43,00,33,00,45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,\ 00,36,00,32,00,44,00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,37,00,46,00,31,00,37,00,31,\ 00,34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,\ 44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,\ 00,35,00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,\ 00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,\ 46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,\ 00,41,00,41,00,37,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,2d,\ 00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,00,\ 36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,42,\ 00,34,00,32,00,7d,00,22,00,00,00,22,00,7b,00,37,00,46,00,31,00,37,00,31,00,\ 34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,\ 00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,\ 35,00,31,00,32,00,30,00,42,00,34,00,7d,00,22,00,00,00,22,00,7b,00,44,00,37,\ 00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,\ 34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,\ 00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,00,22,00,00,00,\ 00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,52,00,61,00,73,\ 00,50,00,70,00,70,00,6f,00,65,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,\ 45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,\ 00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,\ 36,00,31,00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\ 00,63,00,65,00,5c,00,52,00,61,00,73,00,50,00,70,00,70,00,6f,00,65,00,5f,00,\ 7b,00,37,00,46,00,31,00,37,00,31,00,34,00,30,00,34,00,2d,00,33,00,30,00,39,\ 00,32,00,2d,00,34,00,31,00,32,00,44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,\ 46,00,45,00,37,00,41,00,33,00,41,00,35,00,31,00,32,00,30,00,42,00,34,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,52,00,61,00,73,00,\ 50,00,70,00,70,00,6f,00,65,00,5f,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,\ 00,43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,\ 2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,\ 00,42,00,45,00,41,00,41,00,37,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe\Enum] "0"="Root\\MS_PPPOEMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Raspti] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,74,00,69,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Direct Parallel" "Description"="Direct Parallel" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Raspti\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Raspti\Enum] "0"="Root\\MS_PTIMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rdbss] "Type"=dword:00000002 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,64,00,62,00,73,00,73,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Rdbss" "Group"="Network" "Description"="Rdbss" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rdbss\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rdbss\Enum] "0"="Root\\LEGACY_RDBSS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD] "ErrorControl"=dword:00000000 "Group"="Video Save" "ImagePath"="System32\\DRIVERS\\RDPCDD.sys" "Start"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD\Device0] "Device Description"="RDPDD Chained DD" "InstalledDisplayDrivers"=hex(7):52,00,44,00,50,00,44,00,44,00,00,00,00,00 "MirrorDriver"=dword:00000001 "VgaCompatible"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD\Video] "VideoID"="{DEB039CC-B704-4F53-B43E-9DD4432FA2E9}" "Service"="RDPCDD" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD\Enum] "0"="Root\\LEGACY_RDPCDD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPDD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPDD\Device0] "InstalledDisplayDrivers"=hex(7):52,00,44,00,50,00,44,00,44,00,00,00,00,00 "VgaCompatible"=dword:00000000 "Attach.RelativeX"=dword:00000000 "Attach.RelativeY"=dword:00000000 "Attach.ToDesktop"=dword:00000001 "DefaultSettings.XResolution"=dword:00000320 "DefaultSettings.YResolution"=dword:00000258 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpdr] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,64,00,70,00,64,00,72,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Terminal Server Device Redirector Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpdr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpdr\Enum] "0"="Root\\RDPDR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP\NetworkProvider] "DeviceName"="\\Device\\RdpDr" "Name"="Microsoft Terminal Services" "ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,72,00,70,00,72,00,6f,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP\Enum] "0"="Root\\LEGACY_RDPNP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPWD] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDSessMgr] "Type"=dword:00000010 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,65,00,73,\ 00,73,00,6d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Remote Desktop Help Session Manager" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDSessMgr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDSessMgr\Enum] "0"="Root\\LEGACY_RDSESSMGR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\redbook] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,65,00,64,00,62,00,6f,00,6f,\ 00,6b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Digital CD Audio Playback Filter Driver" "Group"="Pnp Filter" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\redbook\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\redbook\Enum] "0"="IDE\\CdRomTSSTcorp_CD/DVDW_TS-L632D_______________TO04____\\5&195506ac&0&0.0.0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Routing and Remote Access" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,47,00,72,00,\ 6f,00,75,00,70,00,00,00,00,00 "ObjectName"="LocalSystem" "Description"="Offers routing services to businesses in local area and wide area network environments." @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting\Providers] "ActiveProvider"="{1AA7F846-C7F5-11D0-A376-00C04FC9DA04}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting\Providers\{1AA7F840-C7F5-11D0-A376-00C04FC9DA04}] "ConfigClsid"="{1AA7F840-C7F5-11D0-A376-00C04FC9DA04}" "DisplayName"="RADIUS Accounting" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,72,00,61,00,64,00,2e,00,64,00,6c,00,6c,00,00,00 "ProviderTypeGUID"="{76560D80-2BFD-11d2-9539-3078302C2030}" "VendorName"="Microsoft" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting\Providers\{1AA7F846-C7F5-11D0-A376-00C04FC9DA04}] "ConfigClsid"="" "DisplayName"="Windows Accounting" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\ 70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 "ProviderTypeGUID"="{76560D81-2BFD-11d2-9539-3078302C2030}" "VendorName"="Microsoft" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication\Providers] "ActiveProvider"="{1AA7F841-C7F5-11D0-A376-00C04FC9DA04}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication\Providers\{1AA7F83F-C7F5-11D0-A376-00C04FC9DA04}] "ConfigClsid"="{1AA7F83F-C7F5-11D0-A376-00C04FC9DA04}" "DisplayName"="RADIUS Authentication" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,72,00,61,00,64,00,2e,00,64,00,6c,00,6c,00,00,00 "VendorName"="Microsoft" "ProviderTypeGUID"="{76560D00-2BFD-11d2-9539-3078302C2030}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication\Providers\{1AA7F841-C7F5-11D0-A376-00C04FC9DA04}] "ConfigClsid"="" "DisplayName"="Windows Authentication" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\ 70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 "VendorName"="Microsoft" "ProviderTypeGUID"="{76560D01-2BFD-11d2-9539-3078302C2030}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\DemandDialManager] "DllPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,\ 00,70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces] "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\0] "InterfaceName"="Loopback" "Type"=dword:00000005 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\0\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\1] "InterfaceName"="Internal" "Type"=dword:00000004 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\1\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\2] "InterfaceName"="{478CFB97-6AFE-4874-A673-86E9343489F3}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\2\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\3] "InterfaceName"="{7F171404-3092-412D-9CA7-FE7A3A5120B4}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\3\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\4] "InterfaceName"="{C65ABE47-0D2D-4C3E-8965-C5B62D61BB42}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\4\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters] "RouterType"=dword:00000001 "ServerFlags"=dword:00802702 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6d,00,70,00,72,00,64,00,69,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\AppleTalk] "EnableIn"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ip] "AllowClientIpAddresses"=dword:00000000 "AllowNetworkAccess"=dword:00000001 "EnableIn"=dword:00000001 "IpAddress"="0.0.0.0" "IpMask"="0.0.0.0" "UseDhcpAddressing"=dword:00000001 "EnableNetbtBcastFwd"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ip\StaticAddressPool] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ip\StaticAddressPool\0] "From"=dword:00000000 "To"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ipx] "EnableIn"=dword:00000001 "AcceptRemoteNodeNumber"=dword:00000001 "AllowNetworkAccess"=dword:00000001 "AutoWanNetAllocation"=dword:00000001 "FirstWanNet"=dword:00000000 "GlobalWanNet"=dword:00000001 "LastWanNet"=dword:00000000 "WanNetPoolSize"=dword:000003e8 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Nbf] "EnableIn"=dword:00000001 "AllowNetworkAccess"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Performance] "Open"="OpenRasPerformanceData" "Close"="CloseRasPerformanceData" "Collect"="CollectRasPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\ 00,61,00,73,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:00000804 "Last Help"=dword:00000805 "First Counter"=dword:000007de "First Help"=dword:000007df "WbemAdapFileSignature"=hex:b0,b0,d7,90,5a,c7,1b,c2,78,f1,7f,45,5e,18,26,11 "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00002e00 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy] "ProductDir"="D:\\WINDOWS\\system32\\IAS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\01] @="IAS.ProxyPolicyEnforcer" "Requests"="0 1 2" "Responses"="0 1 2 3 4" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\02] @="IAS.NTSamNames" "Providers"="1" "Requests"="0" "Responses"="0 1 3" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\03] @="IAS.BaseCampHost" "Requests"="0 1" "Responses"="0 1 2 4" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\04] @="IAS.RadiusProxy" "Providers"="2" "Responses"="0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\05] @="IAS.NTSamAuthentication" "Providers"="1" "Requests"="0" "Responses"="0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\06] @="IAS.AccountValidation" "Providers"="1" "Requests"="0" "Responses"="0 1" "Reasons"="33" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\07] @="IAS.PolicyEnforcer" "Providers"="1" "Requests"="0" "Responses"="0 1 3" "Reasons"="33" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\08] @="IAS.NTSamPerUser" "Providers"="1" "Requests"="0" "Responses"="0 1 3" "Reasons"="33" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\09] @="IAS.EAP" "Providers"="1" "Requests"="0 2" "Responses"="0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\10] @="IAS.URHandler" "Providers"="0 1" "Requests"="0 2" "Responses"="0 1" "Reasons"="33" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\11] @="IAS.ChangePassword" "Providers"="1" "Requests"="0" "Responses"="0 1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\12] @="IAS.AuthorizationHost" "Requests"="0 1 2" "Responses"="0 1 2 4" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\13] @="IAS.Accounting" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\14] @="IAS.MSChapErrorReporter" "Providers"="0 1" "Requests"="0" "Responses"="2" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers] "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip] "ProtocolId"=dword:00000021 "GlobalInfo"=hex:01,00,00,00,80,00,00,00,02,00,00,00,03,00,ff,ff,08,00,00,00,\ 01,00,00,00,30,00,00,00,06,00,ff,ff,3c,00,00,00,01,00,00,00,38,00,00,00,00,\ 00,00,00,00,00,00,00,01,00,00,00,07,00,00,00,02,00,00,00,01,00,00,00,03,00,\ 00,00,0a,00,00,00,16,27,00,00,03,00,00,00,17,27,00,00,05,00,00,00,12,27,00,\ 00,07,00,00,00,0d,00,00,00,6e,00,00,00,08,00,00,00,78,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "DLLPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,69,\ 00,70,00,72,00,74,00,72,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RoutingTableManager] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RoutingTableManager\Instance 00000] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RoutingTableManager\Instance 00000\AddressFamily 00002] "AddressSize"=dword:00000004 "ViewsSupported"=dword:00000003 "MaxChangeNotifyRegistrations"=dword:00000010 "MaxOpaqueInfoPointers"=dword:00000005 "MaxNextHopsInRoute"=dword:00000003 "MaxHandlesReturnedInEnum"=dword:00000019 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Enum] "0"="Root\\LEGACY_REMOTEACCESS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry] "Description"="Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start." "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DisplayName"="Remote Registry" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Group"="" "Start"=dword:00000004 "Type"=dword:00000020 "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,e0,ad,08,\ 00,01,00,00,00,e8,03,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,65,00,67,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum] "0"="Root\\LEGACY_REMOTEREGISTRY\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,6f,00,63,00,61,00,74,00,6f,00,72,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Remote Procedure Call (RPC) Locator" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Manages the RPC name service database." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator\Parameters] "ExpirationAge"=dword:00000e10 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator\Enum] "0"="Root\\LEGACY_RPCLOCATOR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs] "Description"="Provides the endpoint mapper and other miscellaneous RPC services." "DisplayName"="Remote Procedure Call (RPC)" "ErrorControl"=dword:00000001 "Group"="COM Infrastructure" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,72,00,70,00,\ 63,00,73,00,73,00,00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Start"=dword:00000002 "Type"=dword:00000020 "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,02,00,00,00,60,ea,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,70,00,63,00,73,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Enum] "0"="Root\\LEGACY_RPCSS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rspndr] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "Tag"=dword:0000000f "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,73,00,70,00,6e,00,64,00,72,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Link-Layer Topology Discovery Responder" "Group"="NDIS" "Description"="Allows this PC to be discovered and located on the network." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rspndr\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,43,00,36,\ 00,35,00,41,00,42,00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,\ 34,00,43,00,33,00,45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,\ 00,36,00,32,00,44,00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,37,00,46,00,31,00,37,00,31,\ 00,34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,\ 44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,\ 00,35,00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,\ 00,2d,00,44,00,42,00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,\ 46,00,35,00,36,00,2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,\ 00,41,00,41,00,37,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,2d,\ 00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,00,\ 36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,42,\ 00,34,00,32,00,7d,00,22,00,00,00,22,00,7b,00,37,00,46,00,31,00,37,00,31,00,\ 34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,\ 00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,\ 35,00,31,00,32,00,30,00,42,00,34,00,7d,00,22,00,00,00,22,00,7b,00,44,00,37,\ 00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,00,38,00,2d,00,\ 34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,43,00,44,00,38,\ 00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,00,22,00,00,00,\ 00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,72,00,73,00,70,\ 00,6e,00,64,00,72,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,\ 37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,\ 00,39,00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,\ 42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,\ 00,5c,00,72,00,73,00,70,00,6e,00,64,00,72,00,5f,00,7b,00,37,00,46,00,31,00,\ 37,00,31,00,34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,\ 00,32,00,44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,\ 33,00,41,00,35,00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,\ 00,76,00,69,00,63,00,65,00,5c,00,72,00,73,00,70,00,6e,00,64,00,72,00,5f,00,\ 7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,00,36,\ 00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,2d,00,\ 43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,00,7d,\ 00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rspndr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rspndr\Enum] "0"="Root\\LEGACY_RSPNDR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP] "Type"=dword:00000010 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\ 00,73,00,76,00,70,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="QoS RSVP" "DependOnService"=hex(7):54,00,63,00,70,00,49,00,70,00,00,00,41,00,66,00,64,00,\ 00,00,52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Parameters] "StartBlocker"="" "Requests"="" "Upcalls"="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Performance] "Open"="OpenRsvpPerformanceData" "Close"="CloseRsvpPerformanceData" "Collect"="CollectRsvpPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\ 00,73,00,76,00,70,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:0000078e "Last Help"=dword:0000078f "First Counter"=dword:00000738 "First Help"=dword:00000739 "WbemAdapFileSignature"=hex:f9,dd,79,9e,07,ed,50,28,db,2f,1f,fe,a7,2c,93,57 "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00002600 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Security] "Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Enum] "0"="Root\\LEGACY_RSVP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RTLE8023xp] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000011 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,52,00,74,00,65,00,6e,00,69,00,63,\ 00,78,00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RTLE8023xp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RTLE8023xp\Enum] "0"="PCI\\VEN_10EC&DEV_8136&SUBSYS_813610EC&REV_01\\4&2803e7c1&0&00E2" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs] "Description"="Stores security information for local user accounts." "DisplayName"="Security Accounts Manager" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 "Group"="LocalValidation" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs\Enum] "0"="Root\\LEGACY_SAMSS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,53,\ 00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,2e,00,65,00,78,00,65,00,00,00 "Description"="Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Smart Card" "DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\ 00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Group"="SmartCardGroup" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr\Security] "Security"=hex:01,00,04,80,88,00,00,00,94,00,00,00,00,00,00,00,14,00,00,00,02,\ 00,74,00,05,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,\ 00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,13,00,00,00,00,00,18,\ 00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,00,18,00,\ ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,00,00,00,00,14,00,9d,\ 01,02,00,01,01,00,00,00,00,00,02,00,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule] "Description"="Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start." "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Task Scheduler" "Group"="SchedulerGroup" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,00,00,00,\ 00,01,00,00,00,70,17,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00 "NextAtJobId"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,63,00,68,00,65,00,64,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceMain"="SchedServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\Enum] "0"="Root\\LEGACY_SCHEDULE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,64,00,62,00,75,00,73,00,2e,\ 00,73,00,79,00,73,00,00,00 "Group"="System Bus Extender" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus\Parameters] "SdCmdFlags"=hex:06,01,09,19,0a,19,0d,11,10,01,11,01,12,01,18,05,19,05,19,01,\ 1a,01,1b,01,1c,01,20,05,21,05,26,05,2a,01,34,02,35,02,37,01,38,01,22,01,23,\ 05,24,01,25,01 "SdAppCmdFlags"=hex:06,01,0d,01,16,01,17,01,33,01,12,01,19,01,1a,01,26,01,2b,\ 01,2c,01,2d,01,2e,01,2f,01,30,01,31,01 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus\Enum] "0"="PCI\\VEN_104C&DEV_803C&SUBSYS_FF001179&REV_00\\4&6b16d5b&0&23F0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Secdrv] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,65,00,63,00,64,00,72,00,76,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Secdrv" "Description"="SafeDisc driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Secdrv\Security] "Security"=hex:01,00,14,80,78,00,00,00,84,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,48,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,04,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\ 01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon] "Description"="Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Secondary Logon" "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "Objectname"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000120 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,65,00,63,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceMain"="SvcEntry_Seclogon" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon\Enum] "0"="Root\\LEGACY_SECLOGON\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS] "DependOnService"=hex(7):45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,\ 65,00,6d,00,00,00,00,00 "Description"="Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events." "DisplayName"="System Event Notification" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Group"="Network" "Start"=dword:00000004 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,65,00,6e,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS\Enum] "0"="Root\\LEGACY_SENS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serial] "ErrorControl"=dword:00000000 "Group"="Extended base" "Start"=dword:00000002 "Tag"=dword:00000001 "Type"=dword:00000001 "ForceFifoEnable"=dword:00000001 "RxFIFO"=dword:00000008 "TxFIFO"=dword:0000000e "PermitShare"=dword:00000000 "LogFifo"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serial\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serial\Enum] "0"="Root\\LEGACY_SERIAL\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sfloppy] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\ 70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000001 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sfloppy\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess] "DependOnGroup"=hex(7):00,00 "DependOnService"=hex(7):4e,00,65,00,74,00,6d,00,61,00,6e,00,00,00,57,00,69,00,\ 6e,00,4d,00,67,00,6d,00,74,00,00,00,00,00 "Description"="Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network." "DisplayName"="Windows Firewall/Internet Connection Sharing (ICS)" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 "Group"="FirewallGroup" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch] "Epoch"=dword:0000006b [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 69,00,70,00,6e,00,61,00,74,00,68,00,6c,00,70,00,2e,00,64,00,6c,00,6c,00,00,\ 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=dword:00000000 "DoNotAllowExceptions"=dword:00000000 "DisableNotifications"=dword:00000000 "DisableUnicastResponsesToMulticastBroadcast"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "D:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="D:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call" "D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=dword:00000000 "DoNotAllowExceptions"=dword:00000000 "DisableNotifications"=dword:00000000 "DisableUnicastResponsesToMulticastBroadcast"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "D:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="D:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call" "D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "D:\\Program Files\\Google\\Google Talk\\googletalk.exe"="D:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup] "ServiceUpgrade"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate] "All"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum] "0"="Root\\LEGACY_SHAREDACCESS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Shell Hardware Detection" "Group"="ShellSvcGroup" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides notifications for AutoPlay hardware events." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="HardwareDetectionServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection\Enum] "0"="Root\\LEGACY_SHELLHWDETECTION\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Simbad] "ErrorControl"=dword:00000001 "Group"="Filter" "Start"=dword:00000004 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SLIP] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000a "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,53,00,4c,00,49,00,50,00,2e,00,73,\ 00,79,00,73,00,00,00 "DisplayName"="BDA Slip De-Framer" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SLIP\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sparrow] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000007 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sparrow\Parameters] "LegacyAdapterDetection"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sparrow\Parameters\PnpInterface] "1"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\splitter] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,70,00,6c,00,69,00,74,00,74,\ 00,65,00,72,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel Audio Splitter" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\splitter\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\splitter\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler] "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Description"="Loads files to memory for later printing." "DisplayName"="Print Spooler" "ErrorControl"=dword:00000001 "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,e8,47,0c,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00 "Group"="SpoolerGroup" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,70,00,6f,00,6f,00,6c,00,73,00,76,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000110 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Performance] "Close"="PerfClose" "Collect"="PerfCollect" "Collect Timeout"=dword:000007d0 "Library"="winspool.drv" "Object List"="1450" "Open"="PerfOpen" "Open Timeout"=dword:00000fa0 "WbemAdapFileSignature"=hex:bd,83,ab,a6,1e,8a,cc,c8,d9,ff,b8,69,f2,94,18,ce "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00023c00 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Enum] "0"="Root\\LEGACY_SPOOLER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Type"=dword:00000002 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,72,00,2e,00,73,00,79,00,73,\ 00,00,00 "DisplayName"="System Restore Filter Driver" "Group"="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr\Parameters] "FirstRun"=dword:00000001 "DontBackup"=dword:00000000 "MachineGuid"="{CAABBCF0-E8D9-4E29-81A4-BBE8198C8A46}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr\Enum] "0"="Root\\LEGACY_SR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="System Restore Service" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\Parameters] "ServiceDll"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,72,00,\ 73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\Enum] "0"="Root\\LEGACY_SRSERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Srv] "Type"=dword:00000002 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000006 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,72,00,76,00,2e,00,73,00,79,\ 00,73,00,00,00 "DisplayName"="Srv" "Group"="Network" "Description"="Srv" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Srv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Srv\Enum] "0"="Root\\LEGACY_SRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "DisplayName"="SSDP Discovery Service" "DependOnService"=hex(7):48,00,54,00,54,00,50,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Enables discovery of UPnP devices on your home network." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,73,00,64,00,70,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV\Security] "Security"=hex:01,00,14,80,bc,00,00,00,c8,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,8c,00,06,00,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\ 00,00,00,00,14,00,9d,00,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,14,\ 00,70,00,02,00,01,01,00,00,00,00,00,05,13,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV\Enum] "0"="Root\\LEGACY_SSDPSRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,69,00,6d,00,67,00,73,00,76,00,63,00,00,00 "DisplayName"="Windows Image Acquisition (WIA)" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides image acquisition services for scanners and cameras." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,69,00,61,00,73,00,65,00,72,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc\Enum] "0"="Root\\LEGACY_STISVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\streamip] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000008 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,53,00,74,00,72,00,65,00,61,00,6d,\ 00,49,00,50,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="BDA IPSink" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\streamip\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum] "ErrorControl"=dword:00000001 "Start"=dword:00000003 "Type"=dword:00000001 "DisplayName"="Software Bus Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,77,00,65,00,6e,00,75,00,6d,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{03884cb6-e89a-4deb-b69e-8dc621686e6a}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{03884cb6-e89a-4deb-b69e-8dc621686e6a}\GLOBAL] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{03884cb6-e89a-4deb-b69e-8dc621686e6a}\GLOBAL\{fd0a5af4-b41d-11d2-9c95-00c04f7971e0}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{07dad662-22f1-11d1-a9f4-00c04fbbde8f}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{07dad662-22f1-11d1-a9f4-00c04fbbde8f}\GLOBAL] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{07dad662-22f1-11d1-a9f4-00c04fbbde8f}\GLOBAL\{07dad660-22f1-11d1-a9f4-00c04fbbde8f}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}\{9ea331fa-b91b-45f8-9285-bd2bc77afcde}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{bf963d80-c559-11d0-8a2b-00a0c9255ac1}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{48926476-2cae-4ded-a86e-73ddebed6779}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{48926476-2cae-4ded-a86e-73ddebed6779}\NDISIP] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{48926476-2cae-4ded-a86e-73ddebed6779}\NDISIP\{9aa4a2cc-81e0-4cfd-802f-0f74526d2bd3}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{562370a8-f8dd-11d2-bc64-00a0c95ec22e}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{562370a8-f8dd-11d2-bc64-00a0c95ec22e}\GLOBAL] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{562370a8-f8dd-11d2-bc64-00a0c95ec22e}\GLOBAL\{07dad660-22f1-11d1-a9f4-00c04fbbde8f}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{dff220f3-f70f-11d0-b917-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{70bc06e0-5666-11d3-a184-00105aef9f33}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{70bc06e0-5666-11d3-a184-00105aef9f33}\GLOBAL] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{70bc06e0-5666-11d3-a184-00105aef9f33}\GLOBAL\{07dad660-22f1-11d1-a9f4-00c04fbbde8f}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{dff220f3-f70f-11d0-b917-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196}\{3c0d501a-140b-11d1-b40f-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}\{53172480-4791-11D0-A5D6-28DB04C10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}\{53172480-4791-11D0-A5D6-28DB04C10000}\{53172480-4791-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\{9B365890-165F-11D0-A195-0020AFD156E4}\{a7c7a5b1-5af3-11d1-9ced-00a024bf0407}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{ad809c00-7b88-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}\{9B365890-165F-11D0-A195-0020AFD156E4}\{3e227e76-690d-11d2-8161-0000f8775bf1}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cfd669f1-9bc2-11d0-8299-0000f822fe8a}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cfd669f1-9bc2-11d0-8299-0000f822fe8a}\{0A4252A0-7E70-11D0-A5D6-28DB04C10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cfd669f1-9bc2-11d0-8299-0000f822fe8a}\{0A4252A0-7E70-11D0-A5D6-28DB04C10000}\{0a4252a0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cfd669f1-9bc2-11d0-8299-0000f822fe8a}\{CF1DDA2C-9743-11D0-A3EE-00A0C9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cfd669f1-9bc2-11d0-8299-0000f822fe8a}\{CF1DDA2C-9743-11D0-A3EE-00A0C9223196}\{cf1dda2c-9743-11d0-a3ee-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{d84d449b-62fb-4ebb-b969-5183ed3dfb51}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{d84d449b-62fb-4ebb-b969-5183ed3dfb51}\GLOBAL] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{d84d449b-62fb-4ebb-b969-5183ed3dfb51}\GLOBAL\{71985f4a-1ca1-11d3-9cc8-00c04f7971e0}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196}\{97ebaacb-95bd-11d0-a3ea-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\{ad498944-762f-11d0-8dcb-00c04fc3358c}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{ffbb6e3f-ccfe-4d84-90d9-421418b03a8e}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Enum] "0"="Root\\SYSTEM\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swmidi] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,77,00,6d,00,69,00,64,00,69,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel GS Wavetable Synthesizer" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swmidi\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swmidi\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SwPrv] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):44,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6c,00,6c,\ 00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,50,00,72,00,\ 6f,00,63,00,65,00,73,00,73,00,69,00,64,00,3a,00,7b,00,45,00,42,00,36,00,46,\ 00,39,00,45,00,41,00,45,00,2d,00,41,00,35,00,32,00,35,00,2d,00,34,00,31,00,\ 30,00,30,00,2d,00,39,00,46,00,39,00,36,00,2d,00,31,00,37,00,41,00,30,00,43,\ 00,30,00,45,00,39,00,44,00,46,00,39,00,35,00,7d,00,00,00 "DisplayName"="MS Software Shadow Copy Provider" "DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SwPrv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc810] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000001a "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc810\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc810\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc8xx] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 "Tag"=dword:00000036 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc8xx\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc8xx\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_hi] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 "Tag"=dword:00000037 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_hi\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_hi\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_u3] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 "Tag"=dword:00000037 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_u3\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_u3\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sysaudio] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,79,00,73,00,61,00,75,00,64,\ 00,69,00,6f,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel System Audio Device" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sysaudio\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sysaudio\Enum] "0"="SW\\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\\{9B365890-165F-11D0-A195-0020AFD156E4}" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog] "Description"="Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Performance Logs and Alerts" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="NT Authority\\NetworkService" "Start"=dword:00000003 "Type"=dword:00000010 "DefaultLogFileFolder"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,44,00,\ 72,00,69,00,76,00,65,00,25,00,5c,00,50,00,65,00,72,00,66,00,4c,00,6f,00,67,\ 00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries] "Defaults Installed"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Enum] "0"="Root\\LEGACY_SYSMONLOG\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv] "DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\ 52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service." "DisplayName"="Telephony" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 74,00,61,00,70,00,69,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Performance] "Close"="CloseTapiPerformanceData" "Collect"="CollectTapiPerformanceData" "Library"="tapiperf.dll" "ObjectList"="1150" "Open"="OpenTapiPerformanceData" "WbemAdapFileSignature"=hex:69,51,b8,9b,4f,59,1a,a6,94,04,8a,6c,d0,e5,22,4a "WbemAdapFileTime"=hex:00,d0,18,4d,16,9e,c8,01 "WbemAdapFileSize"=dword:00001600 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Security] "Security"=hex:01,00,14,80,6c,00,00,00,78,00,00,00,14,00,00,00,34,00,00,00,02,\ 00,20,00,01,00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,20,02,00,00,02,00,38,00,02,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,\ 00,00,00,00,05,20,00,00,00,20,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,\ 00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\ 01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Enum] "0"="Root\\LEGACY_TAPISRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000003 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,74,00,63,00,70,00,69,00,70,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="TCP/IP Protocol Driver" "Group"="PNP_TDI" "DependOnService"=hex(7):49,00,50,00,53,00,65,00,63,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="TCP/IP Protocol Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,43,00,36,\ 00,35,00,41,00,42,00,45,00,34,00,37,00,2d,00,30,00,44,00,32,00,44,00,2d,00,\ 34,00,43,00,33,00,45,00,2d,00,38,00,39,00,36,00,35,00,2d,00,43,00,35,00,42,\ 00,36,00,32,00,44,00,36,00,31,00,42,00,42,00,34,00,32,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,37,00,46,00,31,00,37,00,31,\ 00,34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,\ 44,00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,\ 00,35,00,31,00,32,00,30,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,34,00,37,00,38,00,43,00,46,00,42,00,39,00,37,\ 00,2d,00,36,00,41,00,46,00,45,00,2d,00,34,00,38,00,37,00,34,00,2d,00,41,00,\ 36,00,37,00,33,00,2d,00,38,00,36,00,45,00,39,00,33,00,34,00,33,00,34,00,38,\ 00,39,00,46,00,33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,\ 00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,\ 2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,\ 69,00,73,00,57,00,61,00,6e,00,49,00,70,00,00,00,00,00 "Route"=hex(7):22,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,2d,\ 00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,00,\ 36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,42,\ 00,34,00,32,00,7d,00,22,00,00,00,22,00,7b,00,37,00,46,00,31,00,37,00,31,00,\ 34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,\ 00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,\ 35,00,31,00,32,00,30,00,42,00,34,00,7d,00,22,00,00,00,22,00,7b,00,34,00,37,\ 00,38,00,43,00,46,00,42,00,39,00,37,00,2d,00,36,00,41,00,46,00,45,00,2d,00,\ 34,00,38,00,37,00,34,00,2d,00,41,00,36,00,37,00,33,00,2d,00,38,00,36,00,45,\ 00,39,00,33,00,34,00,33,00,34,00,38,00,39,00,46,00,33,00,7d,00,22,00,00,00,\ 22,00,7b,00,44,00,37,00,42,00,41,00,41,00,44,00,43,00,38,00,2d,00,44,00,42,\ 00,36,00,38,00,2d,00,34,00,32,00,39,00,42,00,2d,00,39,00,46,00,35,00,36,00,\ 2d,00,43,00,44,00,38,00,33,00,31,00,45,00,37,00,42,00,45,00,41,00,41,00,37,\ 00,7d,00,22,00,00,00,22,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,49,00,\ 70,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,43,00,36,00,35,00,41,00,42,00,45,00,34,00,37,00,\ 2d,00,30,00,44,00,32,00,44,00,2d,00,34,00,43,00,33,00,45,00,2d,00,38,00,39,\ 00,36,00,35,00,2d,00,43,00,35,00,42,00,36,00,32,00,44,00,36,00,31,00,42,00,\ 42,00,34,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,46,00,31,00,37,00,31,00,\ 34,00,30,00,34,00,2d,00,33,00,30,00,39,00,32,00,2d,00,34,00,31,00,32,00,44,\ 00,2d,00,39,00,43,00,41,00,37,00,2d,00,46,00,45,00,37,00,41,00,33,00,41,00,\ 35,00,31,00,32,00,30,00,