Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Data] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Data\Linkage] "Export"="2e,00,4e,00,45,00,54,00,20,00,43,00,4c,00,52,00,20,00,44,00,61,00,74,00,61,00,00,00,00,00" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Data\Performance] "Open"="OpenPerformanceData" "Collect"="CollectPerformanceData" "Close"="ClosePerformanceData" "Library"="netfxperf.dll" "Counter Types"=hex:36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,\ 00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,\ 36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,\ 00,00,00,00,00 "Counter Names"=hex:53,00,71,00,6c,00,43,00,6c,00,69,00,65,00,6e,00,74,00,3a,\ 00,20,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,20,00,23,00,20,00,70,00,\ 6f,00,6f,00,6c,00,65,00,64,00,20,00,61,00,6e,00,64,00,20,00,6e,00,6f,00,6e,\ 00,70,00,6f,00,6f,00,6c,00,65,00,64,00,20,00,63,00,6f,00,6e,00,6e,00,65,00,\ 63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,53,00,71,00,6c,00,43,00,6c,00,69,\ 00,65,00,6e,00,74,00,3a,00,20,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,\ 20,00,23,00,20,00,70,00,6f,00,6f,00,6c,00,65,00,64,00,20,00,63,00,6f,00,6e,\ 00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,53,00,71,00,6c,00,\ 43,00,6c,00,69,00,65,00,6e,00,74,00,3a,00,20,00,43,00,75,00,72,00,72,00,65,\ 00,6e,00,74,00,20,00,23,00,20,00,63,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,\ 69,00,6f,00,6e,00,20,00,70,00,6f,00,6f,00,6c,00,73,00,00,00,53,00,71,00,6c,\ 00,43,00,6c,00,69,00,65,00,6e,00,74,00,3a,00,20,00,50,00,65,00,61,00,6b,00,\ 20,00,23,00,20,00,70,00,6f,00,6f,00,6c,00,65,00,64,00,20,00,63,00,6f,00,6e,\ 00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,53,00,71,00,6c,00,\ 43,00,6c,00,69,00,65,00,6e,00,74,00,3a,00,20,00,54,00,6f,00,74,00,61,00,6c,\ 00,20,00,23,00,20,00,66,00,61,00,69,00,6c,00,65,00,64,00,20,00,63,00,6f,00,\ 6e,00,6e,00,65,00,63,00,74,00,73,00,00,00,53,00,71,00,6c,00,43,00,6c,00,69,\ 00,65,00,6e,00,74,00,3a,00,20,00,54,00,6f,00,74,00,61,00,6c,00,20,00,23,00,\ 20,00,66,00,61,00,69,00,6c,00,65,00,64,00,20,00,63,00,6f,00,6d,00,6d,00,61,\ 00,6e,00,64,00,73,00,00,00,00,00 "Last Counter"=dword:000009fc "Last Help"=dword:000009fd "First Counter"=dword:000009f0 "First Help"=dword:000009f1 "Object List"="2544" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:ffffffff "CategoryOptions"=dword:00000001 "IsMultiInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Linkage] "Export"="2e,00,4e,00,45,00,54,00,20,00,43,00,4c,00,52,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,69,00,6e,00,67,00,00,00,00,00" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance] "Open"="OpenPerformanceData" "Collect"="CollectPerformanceData" "Close"="ClosePerformanceData" "Library"="netfxperf.dll" "Counter Types"=hex:36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,37,00,39,\ 00,32,00,00,00,36,00,35,00,37,00,39,00,32,00,00,00,36,00,35,00,35,00,33,00,\ 36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,00,00 "Counter Names"=hex:43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,\ 00,73,00,20,00,45,00,73,00,74,00,61,00,62,00,6c,00,69,00,73,00,68,00,65,00,\ 64,00,00,00,42,00,79,00,74,00,65,00,73,00,20,00,52,00,65,00,63,00,65,00,69,\ 00,76,00,65,00,64,00,00,00,42,00,79,00,74,00,65,00,73,00,20,00,53,00,65,00,\ 6e,00,74,00,00,00,44,00,61,00,74,00,61,00,67,00,72,00,61,00,6d,00,73,00,20,\ 00,52,00,65,00,63,00,65,00,69,00,76,00,65,00,64,00,00,00,44,00,61,00,74,00,\ 61,00,67,00,72,00,61,00,6d,00,73,00,20,00,53,00,65,00,6e,00,74,00,00,00,00,\ 00 "Last Counter"=dword:00000a08 "Last Help"=dword:00000a09 "First Counter"=dword:000009fe "First Help"=dword:000009ff "Object List"="2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558 2558" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:ffffffff "IsMultiInstance"=dword:00000001 "FileMappingSize"=dword:00020000 "CategoryOptions"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET Data Provider for Oracle] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET Data Provider for Oracle\Linkage] "Export"="2e,00,4e,00,45,00,54,00,20,00,44,00,61,00,74,00,61,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,20,00,66,00,6f,00,72,00,20,00,4f,00,72,00,61,00,63,00,6c,00,65,00,00,00,00,00" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET Data Provider for Oracle\Performance] "CategoryOptions"=dword:00000003 "IsMultiInstance"=dword:00000001 "Counter Types"=hex:32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,\ 00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,32,00,37,00,\ 32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,32,00,37,00,32,00,36,00,39,\ 00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,\ 35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,\ 00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,\ 35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,\ 00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,\ 33,00,36,00,00,00,00,00 "Library"="netfxperf.dll" "Collect"="CollectPerformanceData" "FileMappingSize"=dword:00020000 "Counter Names"=hex:48,00,61,00,72,00,64,00,43,00,6f,00,6e,00,6e,00,65,00,63,\ 00,74,00,73,00,50,00,65,00,72,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,\ 48,00,61,00,72,00,64,00,44,00,69,00,73,00,63,00,6f,00,6e,00,6e,00,65,00,63,\ 00,74,00,73,00,50,00,65,00,72,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,\ 53,00,6f,00,66,00,74,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,73,00,50,\ 00,65,00,72,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,53,00,6f,00,66,00,\ 74,00,44,00,69,00,73,00,63,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,73,00,50,\ 00,65,00,72,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,4e,00,75,00,6d,00,\ 62,00,65,00,72,00,4f,00,66,00,4e,00,6f,00,6e,00,50,00,6f,00,6f,00,6c,00,65,\ 00,64,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,\ 00,00,4e,00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,50,00,6f,00,6f,00,6c,\ 00,65,00,64,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,\ 73,00,00,00,4e,00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,41,00,63,00,74,\ 00,69,00,76,00,65,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,\ 6e,00,50,00,6f,00,6f,00,6c,00,47,00,72,00,6f,00,75,00,70,00,73,00,00,00,4e,\ 00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,49,00,6e,00,61,00,63,00,74,00,\ 69,00,76,00,65,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,\ 00,50,00,6f,00,6f,00,6c,00,47,00,72,00,6f,00,75,00,70,00,73,00,00,00,4e,00,\ 75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,41,00,63,00,74,00,69,00,76,00,65,\ 00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,50,00,6f,00,\ 6f,00,6c,00,73,00,00,00,4e,00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,49,\ 00,6e,00,61,00,63,00,74,00,69,00,76,00,65,00,43,00,6f,00,6e,00,6e,00,65,00,\ 63,00,74,00,69,00,6f,00,6e,00,50,00,6f,00,6f,00,6c,00,73,00,00,00,4e,00,75,\ 00,6d,00,62,00,65,00,72,00,4f,00,66,00,41,00,63,00,74,00,69,00,76,00,65,00,\ 43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,4e,\ 00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,46,00,72,00,65,00,65,00,43,00,\ 6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,4e,00,75,\ 00,6d,00,62,00,65,00,72,00,4f,00,66,00,53,00,74,00,61,00,73,00,69,00,73,00,\ 43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,4e,\ 00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,52,00,65,00,63,00,6c,00,61,00,\ 69,00,6d,00,65,00,64,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,\ 00,6e,00,73,00,00,00,00,00 "Close"="ClosePerformanceData" "Open"="OpenPerformanceData" "Last Counter"=dword:00000f1e "Last Help"=dword:00000f1f "First Counter"=dword:00000f02 "First Help"=dword:00000f03 "Object List"="3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842 3842" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET Data Provider for SqlServer] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET Data Provider for SqlServer\Linkage] "Export"="2e,00,4e,00,45,00,54,00,20,00,44,00,61,00,74,00,61,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,20,00,66,00,6f,00,72,00,20,00,53,00,71,00,6c,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET Data Provider for SqlServer\Performance] "FileMappingSize"=dword:00020000 "CategoryOptions"=dword:00000003 "IsMultiInstance"=dword:00000001 "Counter Names"=hex:48,00,61,00,72,00,64,00,43,00,6f,00,6e,00,6e,00,65,00,63,\ 00,74,00,73,00,50,00,65,00,72,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,\ 48,00,61,00,72,00,64,00,44,00,69,00,73,00,63,00,6f,00,6e,00,6e,00,65,00,63,\ 00,74,00,73,00,50,00,65,00,72,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,\ 53,00,6f,00,66,00,74,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,73,00,50,\ 00,65,00,72,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,53,00,6f,00,66,00,\ 74,00,44,00,69,00,73,00,63,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,73,00,50,\ 00,65,00,72,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,4e,00,75,00,6d,00,\ 62,00,65,00,72,00,4f,00,66,00,4e,00,6f,00,6e,00,50,00,6f,00,6f,00,6c,00,65,\ 00,64,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,\ 00,00,4e,00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,50,00,6f,00,6f,00,6c,\ 00,65,00,64,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,\ 73,00,00,00,4e,00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,41,00,63,00,74,\ 00,69,00,76,00,65,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,\ 6e,00,50,00,6f,00,6f,00,6c,00,47,00,72,00,6f,00,75,00,70,00,73,00,00,00,4e,\ 00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,49,00,6e,00,61,00,63,00,74,00,\ 69,00,76,00,65,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,\ 00,50,00,6f,00,6f,00,6c,00,47,00,72,00,6f,00,75,00,70,00,73,00,00,00,4e,00,\ 75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,41,00,63,00,74,00,69,00,76,00,65,\ 00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,50,00,6f,00,\ 6f,00,6c,00,73,00,00,00,4e,00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,49,\ 00,6e,00,61,00,63,00,74,00,69,00,76,00,65,00,43,00,6f,00,6e,00,6e,00,65,00,\ 63,00,74,00,69,00,6f,00,6e,00,50,00,6f,00,6f,00,6c,00,73,00,00,00,4e,00,75,\ 00,6d,00,62,00,65,00,72,00,4f,00,66,00,41,00,63,00,74,00,69,00,76,00,65,00,\ 43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,4e,\ 00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,46,00,72,00,65,00,65,00,43,00,\ 6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,4e,00,75,\ 00,6d,00,62,00,65,00,72,00,4f,00,66,00,53,00,74,00,61,00,73,00,69,00,73,00,\ 43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,4e,\ 00,75,00,6d,00,62,00,65,00,72,00,4f,00,66,00,52,00,65,00,63,00,6c,00,61,00,\ 69,00,6d,00,65,00,64,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,\ 00,6e,00,73,00,00,00,00,00 "Counter Types"=hex:32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,\ 00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,32,00,37,00,\ 32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,32,00,37,00,32,00,36,00,39,\ 00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,\ 35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,\ 00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,\ 35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,\ 00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,\ 33,00,36,00,00,00,00,00 "Library"="netfxperf.dll" "Close"="ClosePerformanceData" "Collect"="CollectPerformanceData" "Open"="OpenPerformanceData" "Last Counter"=dword:00000f3c "Last Help"=dword:00000f3d "First Counter"=dword:00000f20 "First Help"=dword:00000f21 "Object List"="3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872 3872" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NETFramework] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NETFramework\Performance] "Close"="CloseCtrs" "Collect"="CollectCtrs" "Open"="OpenCtrs" "Library"="mscoree.dll" "Last Counter"=dword:00000ad2 "Last Help"=dword:00000ad3 "First Counter"=dword:00000a24 "First Help"=dword:00000a25 "WbemAdapFileSignature"=hex:c9,92,48,b9,69,a7,99,b7,71,f4,84,cd,68,bc,b9,6e "WbemAdapFileTime"=hex:00,61,3d,30,37,ee,c8,01 "WbemAdapFileSize"=dword:00044e00 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Abiosdsk] "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000004 "Tag"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp480n5] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000038 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp480n5\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp480n5\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Accelerometer] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000014 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,63,00,63,00,65,00,6c,00,65,\ 00,72,00,6f,00,6d,00,65,00,74,00,65,00,72,00,2e,00,73,00,79,00,73,00,00,00 "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Accelerometer\Parameters] "ShockEventDurationLong"=dword:00004e20 "ShockEventDurationShort"=dword:000007d0 "ClearInterruptInSoftware"=dword:00000001 "CreateErrorLogEntries"=dword:00000000 "ErrorLogLimit"=dword:0000000a "Enabled"=dword:00000001 "DisableFastParkOnLidOpen"=dword:00000001 "UseStandardModeOnly"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Accelerometer\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Accelerometer\Statistics] "ShocksDetected"=dword:0002b3bd [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Accelerometer\Enum] "0"="ACPI\\HPQ0004\\3&b1bfb68&0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI] "ErrorControl"=dword:00000001 "Group"="Boot Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Microsoft ACPI Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,43,00,50,00,49,00,2e,00,73,\ 00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI\Parameters] "AMLIMaxCTObjs"=hex:25,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI\Parameters\WakeUp] "FixedEventMask"=hex:20,01 "FixedEventStatus"=hex:00,04 "GenericEventMask"=hex:00,20,00,00 "GenericEventStatus"=hex:00,00,01,20 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPI\Enum] "0"="ACPI_HAL\\PNP0C08\\0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPIEC] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000006 "Type"=dword:00000001 "DisplayName"="Microsoft Embedded Controller Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,43,00,50,00,49,00,45,00,43,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACPIEC\Enum] "0"="ACPI\\PNP0C09\\4&374ccb25&0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ADIHdAudAddService] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,41,00,44,00,49,00,48,00,64,00,41,\ 00,75,00,64,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ADI UAA Function Driver for High Definition Audio Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ADIHdAudAddService\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ADIHdAudAddService\Enum] "0"="HDAUDIO\\FUNC_01&VEN_11D4&DEV_1981&SUBSYS_103C30C5&REV_1002\\4&1d8c0f4e&0&0001" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003c "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AEAudio] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,41,00,45,00,41,00,75,00,64,00,69,\ 00,6f,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AE Audio Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AEAudio\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AEAudio\Enum] "0"="HDAUDIO\\FUNC_01&VEN_11D4&DEV_1981&SUBSYS_103C30C5&REV_1002\\4&1d8c0f4e&0&0001" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,65,00,63,00,2e,00,73,00,79,\ 00,73,00,00,00 "DisplayName"="Microsoft Kernel Acoustic Echo Canceller" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD] "DisplayName"="AFD" "Description"="AFD Networking Support Environment" "Group"="TDI" "ImagePath"="\\SystemRoot\\System32\\drivers\\afd.sys" "Start"=dword:00000001 "Type"=dword:00000001 "ErrorControl"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Enum] "0"="Root\\LEGACY_AFD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aha154x] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000006 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aha154x\Parameters] "LegacyAdapterDetection"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aha154x\Parameters\PnpInterface] "1"=dword:00000001 "3"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78u2] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000034 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78u2\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78u2\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000001e "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "DisplayName"="Alerter" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter\Parameters] "AlertNames"=hex(7):00,00 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,6c,00,72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG] "Description"="Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall." "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,\ 00,6c,00,67,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Application Layer Gateway Service" "ObjectName"="NT AUTHORITY\\LocalService" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG\Enum] "0"="Root\\LEGACY_ALG\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AliIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000004 "Type"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,6c,00,69,00,69,00,64,00,65,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AliIde\Enum] "0"="Root\\LEGACY_ALIIDE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000024 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt] "Description"="Provides software installation services such as Assign, Publish, and Remove." "DisplayName"="Application Management" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Enum] "0"="Root\\LEGACY_APPMGMT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Arp1394] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000f "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,72,00,70,00,31,00,33,00,39,\ 00,34,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="1394 ARP Client Protocol" "Group"="NDIS" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="1394 ARP Client Protocol" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Arp1394\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Arp1394\Enum] "0"="Root\\LEGACY_ARP1394\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000029 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3350p] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000039 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3350p\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3350p\Parameters\PnpInterface] "1"=dword:00000011 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000002a "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET\Performance] "Library"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_perf.dll" "Open"="OpenPerfCommonData" "Close"="ClosePerfCommonData" "Collect"="CollectPerfCommonData" "WbemAdapFileSignature"=hex:f1,43,0f,5d,20,f4,bb,71,a0,03,20,9c,3d,b3,ad,df "WbemAdapFileTime"=hex:00,cc,82,25,37,ee,c8,01 "WbemAdapFileSize"=dword:00008408 "WbemAdapStatus"=dword:00000000 "Last Counter"=dword:0000260c "Last Help"=dword:0000260d "First Counter"=dword:00002540 "First Help"=dword:00002541 "Object List"="9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538 9536 9538" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET_1.1.4322] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET_1.1.4322\Names] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET_1.1.4322\Performance] "Library"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.1.4322\\aspnet_isapi.dll" "Open"="OpenVersionedPerfData" "Close"="CloseVersionedPerfData" "Collect"="CollectVersionedPerfData" "Last Counter"=dword:00000c30 "Last Help"=dword:00000c31 "First Counter"=dword:00000baa "First Help"=dword:00000bab "Object List"="2986 2988" "WbemAdapFileSignature"=hex:4b,42,3d,db,78,ab,25,bc,d2,ef,9b,b2,f2,64,cb,d7 "WbemAdapFileTime"=hex:00,21,72,9f,51,c0,c8,01 "WbemAdapFileSize"=dword:0003f000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET_2.0.50727] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET_2.0.50727\Names] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET_2.0.50727\Performance] "Library"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_perf.dll" "Open"="OpenVersionedPerfData" "Close"="CloseVersionedPerfData" "Collect"="CollectVersionedPerfData" "Last Counter"=dword:0000253e "Last Help"=dword:0000253f "First Counter"=dword:00002472 "First Help"=dword:00002473 "Object List"="9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332 9330 9332" "WbemAdapFileSignature"=hex:f1,43,0f,5d,20,f4,bb,71,a0,03,20,9c,3d,b3,ad,df "WbemAdapFileTime"=hex:00,cc,82,25,37,ee,c8,01 "WbemAdapFileSize"=dword:00008408 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspnet_state] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,\ 00,4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,\ 6b,00,5c,00,76,00,32,00,2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,5c,\ 00,61,00,73,00,70,00,6e,00,65,00,74,00,5f,00,73,00,74,00,61,00,74,00,65,00,\ 2e,00,65,00,78,00,65,00,00,00 "DisplayName"="ASP.NET State Service" "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspnet_state\Parameters] "Port"=dword:0000a5b8 "AllowRemoteConnection"=dword:00000000 "DontResetOnUpgradeAllowRemoteConnection"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspnet_state\Performance] "Library"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_perf.dll" "Open"="OpenStateServicePerfData" "Close"="CloseStateServicePerfData" "Collect"="CollectStateServicePerfData" "WbemAdapFileSignature"=hex:f1,43,0f,5d,20,f4,bb,71,a0,03,20,9c,3d,b3,ad,df "WbemAdapFileTime"=hex:00,cc,82,25,37,ee,c8,01 "WbemAdapFileSize"=dword:00008408 "WbemAdapStatus"=dword:00000000 "Last Counter"=dword:00002470 "Last Help"=dword:00002471 "First Counter"=dword:0000239c "First Help"=dword:0000239d "Object List"="9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116 9116" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspnet_state\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AsyncMac] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,73,00,79,00,6e,00,63,00,6d,\ 00,61,00,63,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="RAS Asynchronous Media Driver" "Description"="RAS Asynchronous Media Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AsyncMac\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000000 "Tag"=dword:00000019 "Type"=dword:00000001 "DisplayName"="Standard IDE/ESDI Hard Disk Controller" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,61,00,70,00,69,00,2e,\ 00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi\Parameters] "LegacyDetection"=dword:00000001 "GhostSlave"=hex(7):53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,00,00,00,\ 00 "UseCheckPowerForFlush"=hex(7):53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,20,00,\ 57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,41,00,20,00,28,00,31,\ 00,36,00,30,00,30,00,4d,00,42,00,29,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,41,00,4d,00,53,00,55,\ 00,4e,00,47,00,20,00,57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,\ 41,00,20,00,28,00,31,00,2e,00,36,00,47,00,42,00,29,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,49,00,\ 42,00,4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,54,00,43,00,36,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,\ 4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,54,00,43,00,36,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,\ 2d,00,44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,\ 00,4c,00,38,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,\ 44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,\ 00,38,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,\ 50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,38,\ 00,49,00,41,00,41,00,34,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,\ 43,00,41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,4f,\ 00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,43,00,\ 41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,49,00,41,\ 00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,\ 2d,00,32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,4f,00,41,00,41,\ 00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,2d,00,\ 32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,49,00,41,00,41,00,32,\ 00,41,00,00,00,00,00 "NoFlushDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,5f,00,4c,00,\ 50,00,53,00,35,00,32,00,35,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,43,00,52,00,2d,00,37,00,33,\ 00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00 "PioOnlyDevice"=hex(7):20,00,20,00,20,00,20,00,43,00,6f,00,6e,00,6e,00,65,00,\ 72,00,20,00,50,00,65,00,72,00,69,00,70,00,68,00,65,00,72,00,61,00,6c,00,73,\ 00,20,00,34,00,32,00,35,00,4d,00,42,00,20,00,2d,00,20,00,43,00,46,00,53,00,\ 34,00,32,00,35,00,41,00,20,00,20,00,00,00,4d,00,41,00,54,00,53,00,48,00,49,\ 00,54,00,41,00,20,00,43,00,52,00,2d,00,35,00,38,00,31,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,46,00,58,00,\ 36,00,30,00,30,00,53,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,00,00,43,00,44,00,2d,00,34,00,34,00,45,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,\ 00,54,00,52,00,42,00,38,00,35,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,\ 54,00,55,00,4d,00,20,00,4d,00,41,00,52,00,56,00,45,00,52,00,49,00,43,00,4b,\ 00,20,00,35,00,34,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,20,\ 00,4d,00,41,00,58,00,54,00,4f,00,52,00,20,00,4d,00,58,00,54,00,2d,00,35,00,\ 34,00,30,00,20,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,31,00,32,\ 00,36,00,30,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,\ 20,00,37,00,38,00,35,00,30,00,20,00,41,00,56,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,\ 00,74,00,6f,00,72,00,20,00,37,00,35,00,34,00,30,00,20,00,41,00,56,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,33,00,20,\ 00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,\ 33,00,34,00,35,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,\ 00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,41,00,54,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,\ 61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,\ 31,00,41,00,55,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,\ 00,37,00,31,00,37,00,31,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,44,00,2d,00,\ 33,00,31,00,36,00,45,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,\ 00,53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,5f,00,53,00,43,00,52,00,2d,00,\ 32,00,34,00,33,00,30,00,00,00,43,00,52,00,2d,00,32,00,38,00,30,00,31,00,54,\ 00,45,00,00,00,00,00 "NonRemovableMedia"=hex(7):4b,00,69,00,6e,00,67,00,73,00,74,00,6f,00,6e,00,20,\ 00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,79,00,20,00,44,00,\ 61,00,74,00,61,00,50,00,61,00,6b,00,20,00,33,00,34,00,30,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,\ 73,00,6b,00,20,00,53,00,44,00,50,00,35,00,41,00,2d,00,31,00,30,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,\ 00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,\ 31,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,\ 00,33,00,42,00,2d,00,32,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,\ 20,00,53,00,44,00,50,00,33,00,42,00,2d,00,31,00,37,00,35,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,\ 00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,35,00,2d,00,32,00,2e,00,35,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,\ 43,00,61,00,6c,00,6c,00,75,00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,\ 00,6f,00,6c,00,6f,00,67,00,79,00,20,00,43,00,54,00,32,00,36,00,30,00,4d,00,\ 43,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,00,00,42,00,4e,00,2d,00,53,00,30,00,30,00,34,00,41,00,43,00,\ 2d,00,53,00,20,00,31,00,2e,00,30,00,30,00,00,00,43,00,61,00,6c,00,6c,00,75,\ 00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,\ 79,00,20,00,43,00,54,00,35,00,32,00,30,00,52,00,4d,00,00,00,48,00,69,00,74,\ 00,61,00,63,00,68,00,69,00,20,00,43,00,56,00,20,00,35,00,2e,00,31,00,2e,00,\ 31,00,00,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,41,00,5f,00,46,\ 00,4c,00,41,00,53,00,48,00,20,00,00,00,4d,00,69,00,74,00,73,00,75,00,62,00,\ 69,00,73,00,68,00,69,00,20,00,41,00,54,00,41,00,20,00,43,00,61,00,72,00,64,\ 00,20,00,00,00,4c,00,45,00,58,00,41,00,52,00,20,00,41,00,54,00,41,00,5f,00,\ 46,00,4c,00,41,00,53,00,48,00,00,00,4d,00,69,00,63,00,72,00,6f,00,6e,00,20,\ 00,4d,00,54,00,43,00,46,00,30,00,30,00,34,00,41,00,00,00,4d,00,69,00,63,00,\ 72,00,6f,00,6e,00,20,00,4d,00,54,00,43,00,46,00,30,00,30,00,38,00,41,00,00,\ 00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,33,00,\ 42,00,2d,00,31,00,31,00,30,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,\ 00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,34,00,00,00,42,00,4e,00,2d,00,\ 43,00,41,00,42,00,2d,00,54,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,\ 00,54,00,49,00,43,00,4b,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,00,\ 54,00,49,00,43,00,4b,00,20,00,20,00,20,00,38,00,4d,00,20,00,20,00,38,00,4b,\ 00,00,00,00,00 "NoPowerDownDevice"=hex(7):52,00,44,00,2d,00,44,00,52,00,43,00,30,00,30,00,31,\ 00,2d,00,4d,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,53,00,2d,00,52,00,33,00,\ 37,00,20,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00 "AutoEjectZipDevice"=hex(7):49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,\ 00,49,00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,32,00,33,00,2e,00,44,00,20,00,20,00,\ 20,00,20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,\ 00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,32,00,31,00,2e,00,44,00,20,00,20,00,20,00,\ 20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,\ 00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,\ 54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,32,00,30,00,2e,00,44,00,20,00,20,00,20,00,20,00,\ 00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,\ 00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,\ 41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,39,00,31,00,2e,00,44,00,20,00,20,00,20,00,20,00,00,00,\ 49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,\ 00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,42,00,2e,00,32,00,39,00,20,00,20,00,20,00,20,00,00,00,49,00,\ 4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,00,30,\ 00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,42,00,2e,00,32,00,32,00,20,00,20,00,20,00,20,00,00,00,00,00 "NeedIdentDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,00,46,00,\ 49,00,52,00,45,00,42,00,41,00,4c,00,4c,00,00,00,00,00 "DefaultPioAtapiDevice"=hex(7):54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,\ 44,00,56,00,44,00,2d,00,52,00,4f,00,4d,00,20,00,44,00,52,00,44,00,2d,00,4e,\ 00,32,00,31,00,36,00,00,00,49,00,44,00,45,00,2d,00,43,00,44,00,20,00,52,00,\ 2f,00,52,00,57,00,20,00,32,00,78,00,32,00,78,00,32,00,34,00,00,00,00,00 "EnableBigLba"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi\Enum] "0"="PCIIDE\\IDEChannel\\4&3543be6&0&0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="PCIIDE\\IDEChannel\\4&3543be6&0&1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Atdisk] "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000004 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Atmarpc] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000a "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,6d,00,61,00,72,00,70,\ 00,63,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ATM ARP Client Protocol" "Group"="NDIS" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="ATM ARP Client Protocol" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Atmarpc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ATMsrvc] "ErrorControl"=dword:00000001 "Type"=dword:00000010 "DisplayName"="ATM Service" "ObjectName"="LocalSystem" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,41,\ 00,54,00,4d,00,73,00,72,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ATSWPDRV] "WatchdogTimerInterval"=dword:00000000 "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,54,00,53,00,77,00,70,00,44,\ 00,72,00,76,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="(****DEBUG****) AuthenTec TruePrint USB Driver (SwipeSensor)" "DriverVersion"="7.7.1.2" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ATSWPDRV\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ATSWPDRV\Enum] "0"="USB\\Vid_08ff&Pid_2580\\5&570f764&0&2" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv] "DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\ 52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Windows Audio" "ErrorControl"=dword:00000001 "Group"="AudioGroup" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,75,00,64,00,69,00,6f,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv\Enum] "0"="Root\\LEGACY_AUDIOSRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\audstub] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,75,00,64,00,73,00,74,00,75,\ 00,62,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Audio Stub Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\audstub\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\audstub\Enum] "0"="Root\\MEDIA\\MS_MMACM" "Count"=dword:00000005 "NextInstance"=dword:00000005 "1"="Root\\MEDIA\\MS_MMDRV" "2"="Root\\MEDIA\\MS_MMMCI" "3"="Root\\MEDIA\\MS_MMVCD" "4"="Root\\MEDIA\\MS_MMVID" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVG] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVG\AVG9] "AvgDir"="C:\\Program Files\\AVG\\AVG9" "AvgAllUsersDir"="C:\\Documents and Settings\\All Users\\Application Data\\avg9" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avg9wd] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,56,00,47,00,5c,00,41,\ 00,56,00,47,00,39,00,5c,00,61,00,76,00,67,00,77,00,64,00,73,00,76,00,63,00,\ 2e,00,65,00,78,00,65,00,22,00,00,00 "DisplayName"="AVG WatchDog" "ObjectName"="LocalSystem" "FailureActions"=hex:0a,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,01,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avg9wd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avg9wd\Enum] "0"="Root\\LEGACY_AVG9WD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwdx] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,76,00,67,00,66,00,77,00,64,\ 00,78,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwdx\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwdx\Enum] "0"="Root\\GR_AVGFWMP\\0000" "Count"=dword:00000007 "NextInstance"=dword:00000007 "1"="Root\\GR_AVGFWMP\\0001" "2"="Root\\GR_AVGFWMP\\0002" "3"="Root\\GR_AVGFWMP\\0003" "4"="Root\\GR_AVGFWMP\\0004" "5"="Root\\GR_AVGFWMP\\0005" "6"="Root\\GR_AVGFWMP\\0006" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000b "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,76,00,67,00,66,00,77,00,64,\ 00,78,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AVG network filter service" "Group"="PNP_TDI" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\NdisWanIp] "UpperBindings"="\\Device\\{6371804C-E555-431D-9123-9C41B878F2CB}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\{2937DCE5-1AB6-4454-A75A-347564768FC5}] "UpperBindings"="\\Device\\{46E7D318-CD50-463B-AA32-911FBE262DC4}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}] "UpperBindings"="\\Device\\{56A31BB1-B383-47D5-949B-7596D4759E30}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}] "UpperBindings"="\\Device\\{BD5D29EE-7911-4CD1-98B2-5F0886B33708}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}] "UpperBindings"="\\Device\\{A73F83D7-A6AA-4F3E-AFE0-941716E6F351}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}] "UpperBindings"="\\Device\\{6699A4AD-0E95-46CC-9E7A-B10E0C6B7138}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\{AFE45985-028E-4E55-A932-232847605B83}] "UpperBindings"="\\Device\\{D3CE85C4-44D8-4778-878F-51DC994E35F3}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgfwfd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avgfws9] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,56,00,47,00,5c,00,41,\ 00,56,00,47,00,39,00,5c,00,61,00,76,00,67,00,66,00,77,00,73,00,39,00,2e,00,\ 65,00,78,00,65,00,22,00,00,00 "DisplayName"="AVG Firewall" "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avgfws9\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avgfws9\Enum] "0"="Root\\LEGACY_AVGFWS9\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgLdx86] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000002 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,6c,00,64,00,78,00,\ 38,00,36,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AVG AVI Loader Driver x86" "Group"="AVG" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgLdx86\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgLdx86\Enum] "0"="Root\\LEGACY_AVGLDX86\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgMfx86] "Type"=dword:00000002 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,6d,00,66,00,78,00,\ 38,00,36,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AVG On-access Scanner Minifilter Driver x86" "Group"="AVG" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgMfx86\Instances] "DefaultInstance"="Avgmfx86 Instance" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgMfx86\Instances\AvgMfx86 Instance] "Altitude"="325000" "Flags"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgMfx86\Parameters] "Params"=dword:00008403 "Extensions"=hex:36,69,c4,8b,53,68,0c,c8,f7,fa,2a,09,15,f2,ab,88,44,3a,ca,67,\ e6,cf,eb,95,e5,93,34,f4,36,6a,c4,8b,53,3c,4d,8a,28,33,ed,c5,ca,2d,74,57,44,\ 74,83,55,39,40,67,0b,3a,4c,eb,2b,36,3a,89,c9,8c,b7,d3,17,f7,ec,32,1a,ca,62,\ 3b,15,9b,e5,15,c8,e6,9f,b8,d4,3a,01,a3,68,e9,b5,1b,54,53,68,0c,c8,f7,ad,7e,\ 59,15,f2,ab,88,44,3a,ca,17,b5,de,f4,97,e5,93,34,f4,36,6a,c4,8b,53,2c,41,8b,\ 28,33,ed,c5,ca,2d,74,57,44,77,84,54,39,40,67,0b,3a,4c,eb,2b,36,27,8b,c8,8c,\ b7,d3,17,f7,ec,32,1a,ca,61,24,14,9b,e5,15,c8,e6,9f,b8,d4,3a,1a,ae,6f,e9,b5,\ 1b,54,53,68,0c,c8,f7,a0,7e,5e,15,f2,ab,88,44,3a,ca,17,e6,9f,f7,90,3a,4c,34,\ f4,36,6a,c4,8b,53,3e,5e,8c,28,33,ed,c5,ca,2d,74,57,44,76,87,52,39,40,67,0b,\ 3a,4c,eb,2b,36,2f,9c,ce,8c,b7,d3,17,f7,ec,32,1a,ca,6b,3d,10,9b,e5,15,c8,e6,\ 9f,b8,d4,3a,1c,a7,63,e9,b5,1b,54,53,68,0c,c8,f7,ec,66,52,ca,2d,ab,88,44,3a,\ ca,17,e6,d9,f6,9d,e5,93,34,f4,36,6a,c4,8b,53,21,42,81,28,33,ed,c5,ca,2d,74,\ 57,03,7f,9a,5d,39,40,67,0b,3a,4c,eb,2b,36,2d,94,c1,8c,b7,d3,17,f7,ec,32,1a,\ ca,2d,27,1d,44,3a,15,c8,e6,9f,b8,d4,3a,07,a5,67,e9,b5,1b,54,53,68,0c,c8,f7,\ ec,76,57,ca,2d,ab,88,44,3a,ca,17,e6,d8,eb,99,e5,93,34,f4,36,6a,c4,8b,53,3b,\ 5b,86,28,33,ed,c5,ca,2d,74,57,44,62,89,58,39,40,67,0b,3a,4c,eb,2b,36,6a,92,\ c4,53,68,d3,17,f7,ec,32,1a,ca,75,37,07,9b,e5,15,c8,e6,9f,b8,d4,3a,0a,af,7b,\ e9,b5,1b,54,53,68,0c,c8,f7,a1,75,4a,15,f2,ab,88,44,3a,ca,17,e6,cf,f0,84,3a,\ 93,34,f4,36,6a,c4,8b,53,2e,45,98,28,33,ed,c5,ca,2d,74,57,44,3a,86,47,e6,9f,\ 67,0b,3a,4c,eb,2b,36,2d,8a,db,8c,b7,d3,17,f7,ec,32,1a,ca,79,3b,07,9b,e5,15,\ c8,e6,9f,b8,d4,3a,4c,bb,7b,36,6a,1b,54,53,68,0c,c8,f7,be,71,49,15,f2,ab,88,\ 44,3a,ca,17,e6,cc,f0,87,e5,93,34,f4,36,6a,c4,8b,53,25,41,9b,28,33,ed,c5,ca,\ 2d,74,57,44,7c,9d,44,39,40,67,0b,3a,4c,eb,2b,36,39,9d,d8,8c,b7,d3,17,f7,ec,\ 32,1a,ca,6b,3d,03,9b,e5,15,c8,e6,9f,b8,d4,3a,09,a9,7d,e9,b5,1b,54,53,68,0c,\ c8,f7,bf,70,4c,15,f2,ab,88,44,3a,ca,17,e6,c7,fa,82,e5,93,34,f4,36,6a,c4,8b,\ 53,2c,54,9e,28,33,ed,c5,ca,2d,74,57,44,7c,87,40,39,40,67,0b,3a,4c,eb,2b,36,\ 6a,88,d3,53,68,d3,17,f7,ec,32,1a,ca,61,39,0f,9b,e5,15,c8,e6,9f,b8,d4,3a,4c,\ a7,71,36,6a,1b,54,53,68,0c,c8,08,13,cd,e5,ca,2d,74,57,44,3a,ca,17,19,60,47,\ 2b,3a,4c,eb,2b,36,6a,c4,8b,ac,97,f3,37,f7,ec,32,1a,ca,2d,74,57,bb,c5,35,e8,\ e6,9f,b8,d4,3a,4c,eb,2b,c9,95,3b,74,53,68,0c,c8,f7,ec,32,1a,35,d2,8b,a8,44,\ 3a,ca,17,e6,9f,b8,d4,c5,b3,14,d4,36,6a,c4,8b,53,68,0c,c8,08,13,cd,e5,ca,2d,\ 74,57,44,3a,ca,17,22,13 "Security"=hex:01,00,04,90,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,02,\ 00,20,00,01,00,00,00,00,03,18,00,ff,01,1f,00,01,02,00,00,00,00,00,05,20,00,\ 00,00,20,02,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgMfx86\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgMfx86\Enum] "0"="Root\\LEGACY_AVGMFX86\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgRkx86] "Type"=dword:00000002 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,72,00,6b,00,78,\ 00,38,00,36,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="avgrkx86.sys" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgRkx86\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgRkx86\Enum] "0"="Root\\LEGACY_AVGRKX86\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgTdiX] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,74,00,64,00,69,00,\ 78,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AVG Network Redirector" "Group"="PNP_TDI" "Tag"=dword:00000056 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgTdiX\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgTdiX\Enum] "0"="Root\\LEGACY_AVGTDIX\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BattC] "MofImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,\ 00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,62,00,61,00,74,00,74,00,63,00,\ 2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep] "ErrorControl"=dword:00000001 "Group"="Base" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep\Enum] "0"="Root\\LEGACY_BEEP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Background Intelligent Transfer Service" "DependOnService"=hex(7):52,00,70,00,63,00,73,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled." "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,68,e3,0c,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters] "ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,00,6d,00,\ 67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum] "0"="Root\\LEGACY_BITS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Computer Browser" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,4c,00,61,00,6e,00,6d,\ 00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser\Parameters] "IsDomainMaster"="FALSE" "MaintainServerList"="Auto" "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 62,00,72,00,6f,00,77,00,73,00,65,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser\Enum] "0"="Root\\LEGACY_BROWSER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btaudio] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,62,00,74,00,61,00,75,00,64,00,69,\ 00,6f,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Bluetooth Audio Device" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btaudio\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btaudio\Enum] "0"="{95C7A0A0-3094-11D7-A202-00508B9D7D5A}\\BTAUDIO\\1&30ee4ad&0&1000000030000" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="{95C7A0A0-3094-11D7-A202-00508B9D7D5A}\\BTWAUDIO\\1&30ee4ad&0&1000000030001" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTDriver] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,62,00,74,00,70,00,6f,00,72,00,74,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Bluetooth Virtual Communications Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTDriver\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTDriver\Enum] "0"="{95C7A0A0-3094-11D7-A202-00508B9D7D5A}\\BLUETOOTHPORT\\1&30ee4ad&0&1000000000000" "Count"=dword:00000003 "NextInstance"=dword:00000003 "1"="{95C7A0A0-3094-11D7-A202-00508B9D7D5A}\\BLUETOOTHPORT\\1&30ee4ad&0&1000000000001" "2"="{95C7A0A0-3094-11D7-A202-00508B9D7D5A}\\BLUETOOTHPORT\\1&30ee4ad&0&1000000000002" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTKRNL] "WiFiChannelRange"=dword:0000000b "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000d "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,62,00,74,00,6b,00,72,00,6e,00,6c,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Bluetooth Bus Enumerator" "Group"="Extended Base" "BDAddress"=hex:00,21,86,69,61,2b "DevName"=hex:45,57,49,31,32,39,39,00,1c,01,00,00,00,01,00,00,01,00,00,00,00,\ 00,00,00,90,2b,cb,cc,15,12,c9,01,00,00,00,00,04,00,00,00,00,00,00,00,18,5a,\ 50,89,00,00,00,00,b0,2a,53,8a,d8,37,95,89,d8,37,95,89,00,00,00,00,00,00,00,\ 00,01,00,00,00,03,00,00,00,04,00,00,00,36,02,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,48,4c,54,89,00,00,00,00,78,90,5d,86,78,90,5d,86,08,\ 90,5d,86,f8,2d,9c,89,08,91,5d,86,8c,90,5d,86,8c,90,5d,86,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,6d,04,3d,c0,5c,00,44,00,72,00,69,00,76,00,65,\ 00,72,00,5c,00,41,00,43,00,50,00,49,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 88,58,46,8a,88,58,46,8a,01,00,00,00,88,58,46,0a,00,00,00,00,00,00,00,00,04,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00 "DevClass"=hex:00,01,0c "ScanParams"=hex:02,00,00,00,00,00,01,00,00,00,00,00,01,00,01,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTKRNL\bus] "1000000000000"=hex(7):7b,00,39,00,35,00,43,00,37,00,41,00,30,00,41,00,30,00,\ 2d,00,33,00,30,00,39,00,34,00,2d,00,31,00,31,00,44,00,37,00,2d,00,41,00,32,\ 00,30,00,32,00,2d,00,30,00,30,00,35,00,30,00,38,00,42,00,39,00,44,00,37,00,\ 44,00,35,00,41,00,7d,00,5c,00,42,00,4c,00,55,00,45,00,54,00,4f,00,4f,00,54,\ 00,48,00,50,00,4f,00,52,00,54,00,00,00,00,00 "1000000020000"=hex(7):7b,00,39,00,35,00,43,00,37,00,41,00,30,00,41,00,30,00,\ 2d,00,33,00,30,00,39,00,34,00,2d,00,31,00,31,00,44,00,37,00,2d,00,41,00,32,\ 00,30,00,32,00,2d,00,30,00,30,00,35,00,30,00,38,00,42,00,39,00,44,00,37,00,\ 44,00,35,00,41,00,7d,00,5c,00,42,00,54,00,57,00,44,00,4e,00,44,00,49,00,53,\ 00,00,00,00,00 "1000000030000"=hex(7):7b,00,39,00,35,00,43,00,37,00,41,00,30,00,41,00,30,00,\ 2d,00,33,00,30,00,39,00,34,00,2d,00,31,00,31,00,44,00,37,00,2d,00,41,00,32,\ 00,30,00,32,00,2d,00,30,00,30,00,35,00,30,00,38,00,42,00,39,00,44,00,37,00,\ 44,00,35,00,41,00,7d,00,5c,00,42,00,54,00,41,00,55,00,44,00,49,00,4f,00,00,\ 00,00,00 "1000000030001"=hex(7):7b,00,39,00,35,00,43,00,37,00,41,00,30,00,41,00,30,00,\ 2d,00,33,00,30,00,39,00,34,00,2d,00,31,00,31,00,44,00,37,00,2d,00,41,00,32,\ 00,30,00,32,00,2d,00,30,00,30,00,35,00,30,00,38,00,42,00,39,00,44,00,37,00,\ 44,00,35,00,41,00,7d,00,5c,00,42,00,54,00,57,00,41,00,55,00,44,00,49,00,4f,\ 00,00,00,00,00 "2c07035d81d00"=hex(7):7b,00,39,00,35,00,43,00,37,00,41,00,30,00,41,00,30,00,\ 2d,00,33,00,30,00,39,00,34,00,2d,00,31,00,31,00,44,00,37,00,2d,00,41,00,32,\ 00,30,00,32,00,2d,00,30,00,30,00,35,00,30,00,38,00,42,00,39,00,44,00,37,00,\ 44,00,35,00,41,00,7d,00,5c,00,48,00,49,00,44,00,5f,00,4d,00,4f,00,55,00,53,\ 00,45,00,00,00,7b,00,39,00,35,00,43,00,37,00,41,00,30,00,41,00,30,00,2d,00,\ 33,00,30,00,39,00,34,00,2d,00,31,00,31,00,44,00,37,00,2d,00,41,00,32,00,30,\ 00,32,00,2d,00,30,00,30,00,35,00,30,00,38,00,42,00,39,00,44,00,37,00,44,00,\ 35,00,41,00,7d,00,5c,00,7b,00,30,00,30,00,30,00,30,00,31,00,31,00,32,00,34,\ 00,2d,00,30,00,30,00,30,00,30,00,2d,00,31,00,30,00,30,00,30,00,2d,00,38,00,\ 30,00,30,00,30,00,2d,00,30,00,30,00,38,00,30,00,35,00,66,00,39,00,62,00,33,\ 00,34,00,66,00,62,00,7d,00,26,00,56,00,49,00,44,00,5f,00,30,00,34,00,35,00,\ 45,00,26,00,50,00,49,00,44,00,5f,00,30,00,37,00,30,00,31,00,00,00,00,00 "1000000000001"=hex(7):7b,00,39,00,35,00,43,00,37,00,41,00,30,00,41,00,30,00,\ 2d,00,33,00,30,00,39,00,34,00,2d,00,31,00,31,00,44,00,37,00,2d,00,41,00,32,\ 00,30,00,32,00,2d,00,30,00,30,00,35,00,30,00,38,00,42,00,39,00,44,00,37,00,\ 44,00,35,00,41,00,7d,00,5c,00,42,00,4c,00,55,00,45,00,54,00,4f,00,4f,00,54,\ 00,48,00,50,00,4f,00,52,00,54,00,00,00,00,00 "1000000000002"=hex(7):7b,00,39,00,35,00,43,00,37,00,41,00,30,00,41,00,30,00,\ 2d,00,33,00,30,00,39,00,34,00,2d,00,31,00,31,00,44,00,37,00,2d,00,41,00,32,\ 00,30,00,32,00,2d,00,30,00,30,00,35,00,30,00,38,00,42,00,39,00,44,00,37,00,\ 44,00,35,00,41,00,7d,00,5c,00,42,00,4c,00,55,00,45,00,54,00,4f,00,4f,00,54,\ 00,48,00,50,00,4f,00,52,00,54,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTKRNL\Locale] "BT_FAX_MODEM_STR"="Bluetooth Fax Modem" "BT_SERIAL_PORT_STR"="Bluetooth Communications Port" "BT_AUDIO_STR"="Bluetooth Hands-free Audio" "BT_HQ_AUDIO_STR"="Bluetooth Stereo Audio" "BT_NDIS_STR"="Bluetooth LAN Access Server Driver" "BT_KEYB_STR"="Bluetooth Virtual HID Device" "BT_MOUSE_STR"="Bluetooth Virtual HID Device" "BT_AVCONTROL_STR"="Bluetooth Remote Control" "BT_USB_STR"="Bluetooth Devices" "BT_MODEM_STR"="Bluetooth Modem" "BT_KRNL_STR"="Bluetooth Bus Enumerator" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTKRNL\ports] "NextBusNo"=hex:03,00,00,00,00,00,01,00 "Bluetooth Communications Port (COM4)"=hex:00,00,00,00,00,00,01,00 "Bluetooth Communications Port (COM15)"=hex:01,00,00,00,00,00,01,00 "Bluetooth Communications Port (COM16)"=hex:02,00,00,00,00,00,01,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTKRNL\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTKRNL\Enum] "0"="Root\\BTW\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwdins] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,\ 20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,57,00,49,00,44,00,43,00,4f,00,4d,\ 00,4d,00,5c,00,42,00,6c,00,75,00,65,00,74,00,6f,00,6f,00,74,00,68,00,20,00,\ 53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,62,00,69,00,6e,00,5c,\ 00,62,00,74,00,77,00,64,00,69,00,6e,00,73,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Bluetooth Service" "Group"="PlugPlay" "ObjectName"="LocalSystem" "Description"="Handles installation and removal of Bluetooth devices." "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,45,00,57,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,60,ea,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwdins\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwdins\Enum] "0"="Root\\LEGACY_BTWDINS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTWDNDIS] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000012 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,62,00,74,00,77,00,64,00,6e,00,64,\ 00,69,00,73,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Bluetooth LAN Access Server" "Group"="NDIS" "TextModeFlags"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTWDNDIS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTWDNDIS\Enum] "0"="{95C7A0A0-3094-11D7-A202-00508B9D7D5A}\\BTWDNDIS\\1&30ee4ad&0&1000000020000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwhid] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,62,00,74,00,77,00,68,00,69,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwhid\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwhid\Enum] "0"="{95C7A0A0-3094-11D7-A202-00508B9D7D5A}\\HID_MOUSE\\1&30ee4ad&0&2c07035d81d00" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTWUSB] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000012 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,62,00,74,00,77,00,75,00,73,00,62,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="WIDCOMM USB Bluetooth Driver" "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTWUSB\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTWUSB\Enum] "0"="USB\\Vid_03f0&Pid_171d\\5&183c0cee&0&1" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cbidf2k] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000019 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cbidf2k\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cbidf2k\Parameters\PnpInterface] "1"=dword:00000001 "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cd20xrnt] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003a "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cd20xrnt\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cd20xrnt\Parameters\PnpInterface] "1"=dword:00000011 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdaudio] "ErrorControl"=dword:00000000 "Group"="Filter" "Start"=dword:00000001 "Tag"=dword:00000006 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdaudio\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdfs] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,43,00,44,00,52,00,4f,00,\ 4d,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000004 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdfs\Enum] "0"="Root\\LEGACY_CDFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\ 70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="SCSI CDROM Class" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="CD-ROM Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,63,00,64,00,72,00,6f,00,6d,00,2e,\ 00,73,00,79,00,73,00,00,00 "AutoRun"=dword:00000000 "AutoRunAlwaysDisable"=hex(7):4e,00,45,00,43,00,20,00,20,00,20,00,20,00,20,00,\ 4d,00,42,00,52,00,2d,00,37,00,20,00,20,00,20,00,00,00,4e,00,45,00,43,00,20,\ 00,20,00,20,00,20,00,20,00,4d,00,42,00,52,00,2d,00,37,00,2e,00,34,00,20,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,48,00,41,00,4e,\ 00,47,00,52,00,20,00,44,00,52,00,4d,00,2d,00,31,00,38,00,30,00,34,00,58,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,33,00,32,00,34,00,58,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,32,00,34,00,58,00,20,00,\ 00,00,54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,43,00,44,00,52,00,5f,00,43,00,33,00,36,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum] "0"="IDE\\CdRomOptiarc_DVD_RW_AD-7560A_________________DH10____\\3033343638373034312039393838323531513131" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="SCSI\\CdRom&Ven_Generic&Prod_DVD-ROM&Rev_1.0\\2&12b1de20&1&000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cebal] @="" "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,63,00,65,00,62,00,61,00,6c,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Cebal Driver (cebal.sys)" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cebal\Parameters] @="" "PowerStateOnOpen"=dword:00000000 "PowerStateOnClose"=dword:00000000 "MinPowerStateUsed"=dword:00000003 "MinPowerStateUnused"=dword:00000003 "EnableRemoteWakeup"=dword:00000001 "AbortPipesOnPowerDown"=dword:00000001 "UnconfigureOnClose"=dword:00000001 "ResetDeviceOnClose"=dword:00000000 "MaxIsoPackets"=dword:00000200 "ShortTransferOk"=dword:00000001 "RequestTimeout"=dword:000003e8 "SuppressPnPRemoveDlg"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cebal\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertPropSvc] "Start"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Changer] "ErrorControl"=dword:00000000 "Group"="Filter" "Start"=dword:00000001 "Tag"=dword:00000005 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CiSvc] "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Description"="Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language." "DisplayName"="Indexing Service" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\ 00,69,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000120 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv] "DependOnService"=hex(7):4e,00,65,00,74,00,44,00,44,00,45,00,00,00,00,00 "Description"="Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="ClipBook" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\ 00,6c,00,69,00,70,00,73,00,72,00,76,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000010 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,4e,00,45,\ 00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,00,5c,00,\ 76,00,32,00,2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,5c,00,6d,00,73,\ 00,63,00,6f,00,72,00,73,00,76,00,77,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"=".NET Runtime Optimization Service v2.0.50727_X86" "ObjectName"="LocalSystem" "Description"="Microsoft .NET Framework NGEN" "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,04,00,00,00,35,00,30,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,00,a6,0e,00,01,00,00,00,00,60,ea,00,\ 00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32\Enum] "0"="Root\\LEGACY_CLR_OPTIMIZATION_V2.0.50727_32\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmBatt] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,43,00,6d,00,42,00,61,00,74,00,74,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft ACPI Control Method Battery Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmBatt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmBatt\Enum] "0"="ACPI\\PNP0C0A\\1" "Count"=dword:00000003 "NextInstance"=dword:00000003 "1"="ACPI\\PNP0C0A\\2" "2"="ACPI\\ACPI0003\\2&daba3ff&0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CmdIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000004 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CO80211] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Compbatt] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000002 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,63,00,6f,00,6d,00,70,00,62,00,61,\ 00,74,00,74,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Composite Battery Driver" "Group"="System Bus Extender" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Compbatt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Compbatt\Enum] "0"="Root\\COMPOSITE_BATTERY\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSysApp] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6c,00,6c,\ 00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,50,00,72,00,\ 6f,00,63,00,65,00,73,00,73,00,69,00,64,00,3a,00,7b,00,30,00,32,00,44,00,34,\ 00,42,00,33,00,46,00,31,00,2d,00,46,00,44,00,38,00,38,00,2d,00,31,00,31,00,\ 44,00,31,00,2d,00,39,00,36,00,30,00,44,00,2d,00,30,00,30,00,38,00,30,00,35,\ 00,46,00,43,00,37,00,39,00,32,00,33,00,35,00,7d,00,00,00 "DisplayName"="COM+ System Application" "DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "FailureActions"=hex:1e,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,04,00,03,\ 00,01,00,00,00,e8,03,00,00,01,00,00,00,88,13,00,00,00,00,00,00,e8,03,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSysApp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSysApp\Enum] "0"="Root\\LEGACY_COMSYSAPP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentFilter] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentFilter\Linkage] "Bind"="\\Dummy" "Export"="\\Dummy" "Route"="\\Dummy" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentFilter\Performance] "Close"="DoneFILTERPerformanceData" "Collect"="CollectFILTERPerformanceData" "Open"="InitializeFILTERPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\ 00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "WbemAdapFileSignature"=hex:43,e4,75,89,53,f4,54,09,0c,ad,65,c3,03,79,6e,d5 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:0015e800 "WbemAdapStatus"=dword:00000000 "Last Counter"=dword:0000142e "Last Help"=dword:0000142f "First Counter"=dword:00001428 "First Help"=dword:00001429 "Object List"="5160" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentIndex] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentIndex\Linkage] "Bind"="\\Dummy" "Export"="\\Dummy" "Route"="\\Dummy" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentIndex\Performance] "Close"="DoneCIPerformanceData" "Collect"="CollectCIPerformanceData" "Open"="InitializeCIPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\ 00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "WbemAdapFileSignature"=hex:43,e4,75,89,53,f4,54,09,0c,ad,65,c3,03,79,6e,d5 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:0015e800 "WbemAdapStatus"=dword:00000000 "Last Counter"=dword:00001426 "Last Help"=dword:00001427 "First Counter"=dword:00001410 "First Help"=dword:00001411 "Object List"="5136" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cpqarray] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000100 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cpqarray\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cpqarray\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Cryptographic Services" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 63,00,72,00,79,00,70,00,74,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceMain"="CryptServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Security] "Security"=hex:00,00,0e,00,01 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Enum] "0"="Root\\LEGACY_CRYPTSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVirtA] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000010 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,43,00,56,00,69,00,72,00,74,00,41,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Cisco Systems VPN Adapter" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVirtA\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVirtA\Enum] "0"="Root\\NET\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVPND] "EventMessageFile"="C:\\Program Files\\UT-EWI\\VPN Connector\\cvpnd.exe" "TypesSupported"=dword:00000007 "Type"=dword:00000110 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,55,00,54,00,2d,00,45,00,57,\ 00,49,00,5c,00,56,00,50,00,4e,00,20,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,\ 74,00,6f,00,72,00,5c,00,63,00,76,00,70,00,6e,00,64,00,2e,00,65,00,78,00,65,\ 00,22,00,00,00 "DisplayName"="Cisco Systems, Inc. VPN Service" "DependOnService"=hex(7):54,00,43,00,50,00,49,00,50,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVPND\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVPND\Enum] "0"="Root\\LEGACY_CVPND\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVPNDRVA] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\ 44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,43,00,56,00,50,00,\ 4e,00,44,00,52,00,56,00,41,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Cisco Systems Inc. IPSec Driver" "DependOnService"=hex(7):44,00,4e,00,45,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVPNDRVA\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVPNDRVA\Enum] "0"="Root\\LEGACY_CVPNDRVA\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347bus] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000008 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,64,00,33,00,34,00,37,00,62,00,75,\ 00,73,00,2e,00,73,00,79,00,73,00,00,00 "Group"="Boot Bus Extender" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347bus\Cfg] "khjeh"=hex:14,01,00,00,82,9c,16,a1,9e,7f,e1,44,60,2e,30,c3,8d,85,49,4a,10,cd,\ c7,f0,df,1e,cd,81,ca,f7,43,4f,8c,3a,89,fd,41,4a,7f,93,6c,d9,33,65,5f,c9,48,\ 31,06,fd,e2,f4,31,7a,f0,28,00,8e,93,d5,a3,5d,10,8a,9a,f5,63,8e,65,e7,2c,fd,\ 64,29,aa,19,f7,0d,fc,f8,5e,32,ff,01,e9,0c,b2,e0,98,65,4d,2f,5b,4c,be,b7,52,\ c6,f4,18,5d,3f,52,e3,7c,80,c0,32,6f,45,07,00,96,55,97,88,41,82,e7,36,10,b4,\ dc,90,73,e5,96,c1,6a,65,82,00,b5,b1,86,5d,74,c6,cd,6a,87,d7,78,ed,2e,28,a9,\ 5d,39,52,15,b7,e8,51,cb,f8,6b,81,d2,aa,22,ab,28,e5,ed,b7,e8,a1,4c,c3,a2,c6,\ 3f,25,64,f8,66,a2,9c,f3,91,dd,d6,02,60,36,88,16,03,90,c8,97,fa,88,8d,fc,c5,\ 90,16,70,44,77,66,9e,57,8e,e9,65,be,9a,58,be,49,74,11,34,f8,21,e8,da,3b,6a,\ 5a,94,b2,dc,3e,76,3d,bc,0b,8b,5c,a2,a9,1d,cf,69,39,a8,f6,f2,4c,10,21,7d,d1,\ 9f,70,14,a7,38,d3,77,68,92,4a,70,50,20,15,7b,46,bc,54,44,6c,b4,67,28,bd,c4,\ 0e,89,76,8e [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347bus\Cfg\Device0] "Name"="d347prt" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347bus\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347bus\Enum] "0"="Root\\SYSTEM\\0003" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,33,00,34,00,37,00,70,00,72,\ 00,74,00,2e,00,73,00,79,00,73,00,00,00 "Group"="SCSI miniport" "Tag"=dword:00000040 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg] "khjeh"=hex:90,01,00,00,9e,39,03,94,43,0d,ba,b4,bb,97,4e,4d,73,2b,e1,a3,8c,33,\ 46,b7,dc,2d,60,43,4f,6f,b1,8a,76,e2,42,f2,a1,76,1b,85,b7,2a,d3,4c,21,a4,1e,\ c5,8e,89,5a,12,c7,db,fc,42,f4,97,75,93,c7,7d,b7,05,8f,17,7f,a1,28,d5,e3,6e,\ 48,f9,2b,26,4b,8d,04,7d,82,11,60,aa,cd,0e,9b,af,6b,e5,1f,bb,6d,ee,a4,63,82,\ 40,aa,b0,a3,f5,f5,24,e0,41,5f,e3,43,10,9e,6c,5b,a4,b6,9c,14,cd,95,ac,24,78,\ b7,b6,b7,43,1b,20,1e,33,e5,d9,a9,14,e3,c0,1f,04,56,5c,69,47,6c,57,56,c5,b3,\ 05,4f,cc,4b,1e,1c,5f,a7,73,0f,23,6c,9c,57,c0,0f,a0,30,7c,7c,a2,d0,df,06,cb,\ 33,cf,71,d6,2a,9a,8b,b2,75,4e,26,80,73,00,e6,87,35,4f,20,3f,aa,af,84,b2,ab,\ a5,2a,af,88,8c,8e,98,0b,53,3f,cc,e3,af,fd,e1,9c,a5,29,92,0c,0a,24,10,ff,f3,\ db,cb,26,5b,bf,61,51,3e,92,38,67,cc,6a,32,b1,e3,73,be,fe,cb,79,b4,d7,f3,19,\ 18,24,46,8a,bf,37,cc,10,0f,7f,bb,4c,2c,38,b2,88,8a,b8,cc,38,d0,fb,74,29,46,\ 72,4a,42,b8,fd,20,b9,c6,5b,5c,55,91,fd,3e,2d,7f,f2,2d,7a,8d,b3,22,f9,f9,10,\ ff,56,84,b3,59,15,58,0b,aa,9b,e9,e4,19,96,c3,14,7b,0a,19,27,9e,5b,09,ce,fa,\ e0,7c,59,0a,b4,d2,cf,a5,78,ff,f9,78,ed,f0,86,d1,fe,2b,5f,0e,af,99,4c,2c,d4,\ f1,7f,38,b1,90,07,67,12,8d,00,cf,ce,b6,00,61,7d,e6,a3,9c,ae,e2,9a,c0,bd,04,\ 65,be,ab,bb,23,d9,86,b6,85,55,0d,d4,1a,6b,77,a6,bb,04,7a,c6,b8,b8,49,9e,7b,\ 43,84,cf [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Parameters\PnpInterface] "0"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Enum] "0"="PCI\\d347prt\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac2w2k] "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000020 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac2w2k\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac2w2k\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac960nt] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000020 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac960nt\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dac960nt\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch] "Description"="Provides launch functionality for DCOM services." "DisplayName"="DCOM Server Process Launcher" "ErrorControl"=dword:00000001 "Group"="Event Log" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,44,00,63,00,\ 6f,00,6d,00,4c,00,61,00,75,00,6e,00,63,00,68,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,02,00,00,00,60,ea,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,70,00,63,00,73,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch\Security] "Security"=hex:01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,34,00,00,00,02,\ 00,20,00,01,00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,20,02,00,00,02,00,80,00,05,00,00,00,00,03,18,00,8d,00,02,00,01,01,00,\ 00,00,00,00,01,00,00,00,00,00,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,00,\ 00,00,00,05,20,00,00,00,20,02,00,00,00,03,18,00,8f,00,02,00,01,02,00,00,00,\ 00,00,05,20,00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,01,00,00,00,00,\ 00,05,04,00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\ 00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DcomLaunch\Enum] "0"="Root\\LEGACY_DCOMLAUNCH\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DgiVecp] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\ 44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,44,00,67,00,69,00,\ 56,00,65,00,63,00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="DgiVecp" "TurnAroundDelay"=dword:00000032 "PreTurnAroundDelay"=dword:00000032 "MinimumStallTime"=dword:00001f40 "CurrentInUse"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DgiVecp\LPT1] "Irq"=dword:00000008 "BaseAddress"=dword:00000378 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DgiVecp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DgiVecp\Enum] "0"="Root\\LEGACY_DGIVECP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="DHCP Client" "Group"="TDI" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,41,00,66,00,64,00,\ 00,00,4e,00,65,00,74,00,42,00,54,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages network configuration by registering and updating IP addresses and DNS names." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Configurations] "Options"=hex:32,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,\ 00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Linkage] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Linkage\Disabled] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,68,00,63,00,70,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "{BA3CCE32-43A8-49EB-ABC0-C4F4B2AE089F}"=hex:03,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,d3,19,ce,47,0f,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ d3,19,ce,47,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,d3,19,ce,47,33,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,d3,19,ce,47,36,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,d3,19,ce,47,35,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,d3,19,ce,47 "{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}"=hex:36,00,00,00,00,00,00,00,04,00,00,\ 00,00,00,00,00,4d,7e,a2,4b,0a,07,0a,c1,33,00,00,00,00,00,00,00,04,00,00,00,\ 00,00,00,00,4d,7e,a2,4b,00,00,1c,20,06,00,00,00,00,00,00,00,08,00,00,00,00,\ 00,00,00,4d,7e,a2,4b,3e,8c,8a,ed,3e,8c,8c,fa,03,00,00,00,00,00,00,00,04,00,\ 00,00,00,00,00,00,4d,7e,a2,4b,0a,07,0a,c1,01,00,00,00,00,00,00,00,04,00,00,\ 00,00,00,00,00,4d,7e,a2,4b,ff,ff,ff,f8,0c,00,00,00,00,00,00,00,07,00,00,00,\ 00,00,00,00,4d,7e,a2,4b,65,77,69,31,32,39,39,00,35,00,00,00,00,00,00,00,01,\ 00,00,00,00,00,00,00,4d,7e,a2,4b,05,00,00,00 "{2937DCE5-1AB6-4454-A75A-347564768FC5}"=hex:fc,00,00,00,00,00,00,00,1f,00,00,\ 00,00,00,00,00,04,47,1b,4c,68,74,74,70,3a,2f,2f,77,77,77,2e,75,74,77,65,6e,\ 74,65,2e,6e,6c,2f,70,72,6f,78,79,2e,70,61,63,00,2e,00,00,00,00,00,00,00,01,\ 00,00,00,00,00,00,00,04,47,1b,4c,08,00,00,00,2c,00,00,00,00,00,00,00,10,00,\ 00,00,00,00,00,00,04,47,1b,4c,82,59,0a,0a,82,59,0a,12,82,59,04,15,82,59,04,\ 16,06,00,00,00,00,00,00,00,08,00,00,00,00,00,00,00,04,47,1b,4c,82,59,02,02,\ 82,59,02,03,03,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,04,47,1b,4c,82,\ 59,91,01,0f,00,00,00,00,00,00,00,0d,00,00,00,00,00,00,00,04,47,1b,4c,63,73,\ 2e,75,74,77,65,6e,74,65,2e,6e,6c,00,00,00,01,00,00,00,00,00,00,00,04,00,00,\ 00,00,00,00,00,04,47,1b,4c,ff,ff,ff,00,36,00,00,00,00,00,00,00,04,00,00,00,\ 00,00,00,00,04,47,1b,4c,82,59,01,91,35,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,04,47,1b,4c,05,00,00,00,33,00,00,00,00,00,00,00,04,00,00,00,00,00,\ 00,00,04,47,1b,4c,00,00,1c,20 "{AFE45985-028E-4E55-A932-232847605B83}"=hex:2e,00,00,00,00,00,00,00,01,00,00,\ 00,00,00,00,00,f9,31,1b,4c,02,00,00,00,2c,00,00,00,00,00,00,00,08,00,00,00,\ 00,00,00,00,f9,31,1b,4c,82,59,04,15,82,59,04,16,06,00,00,00,00,00,00,00,08,\ 00,00,00,00,00,00,00,f9,31,1b,4c,82,59,02,02,82,59,02,03,03,00,00,00,00,00,\ 00,00,04,00,00,00,00,00,00,00,f9,31,1b,4c,82,59,e0,01,01,00,00,00,00,00,00,\ 00,04,00,00,00,00,00,00,00,f9,31,1b,4c,ff,ff,f0,00,33,00,00,00,00,00,00,00,\ 04,00,00,00,00,00,00,00,f9,31,1b,4c,00,00,07,08,36,00,00,00,00,00,00,00,04,\ 00,00,00,00,00,00,00,f9,31,1b,4c,01,01,01,01,35,00,00,00,00,00,00,00,01,00,\ 00,00,00,00,00,00,f9,31,1b,4c,05,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\1] "KeyType"=dword:00000007 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,\ 65,00,74,00,4d,00,61,00,73,00,6b,00,4f,00,70,00,74,00,00,00,53,00,59,00,53,\ 00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,\ 6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,\ 00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,\ 00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,65,00,74,00,4d,00,61,00,\ 73,00,6b,00,4f,00,70,00,74,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\15] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,\ 69,00,6e,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,49,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,69,\ 00,6e,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\220] "KeyType"=dword:00000003 "VendorType"=dword:00000001 "RegSendLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,\ 72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,\ 00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,\ 54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,\ 00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,\ 65,00,73,00,5c,00,3f,00,5c,00,53,00,6f,00,48,00,52,00,65,00,71,00,75,00,65,\ 00,73,00,74,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\3] "KeyType"=dword:00000007 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,\ 75,00,6c,00,74,00,47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,53,00,59,\ 00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,\ 43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,\ 00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,\ 61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,\ 00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,75,00,6c,00,74,00,\ 47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\44] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\ 63,00,70,00,4e,00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,4c,\ 00,69,00,73,00,74,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,\ 75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,\ 00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,\ 5c,00,4e,00,65,00,74,00,42,00,54,00,5c,00,41,00,64,00,61,00,70,00,74,00,65,\ 00,72,00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,\ 65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\46] "KeyType"=dword:00000004 "RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpNodeType" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\47] "KeyType"=dword:00000001 "RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpScopeID" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\6] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,65,00,\ 53,00,65,00,72,00,76,00,65,00,72,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,\ 00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,\ 72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,\ 61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,4e,\ 00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\DhcpNetbiosOptions] "KeyType"=dword:00000004 "OptionId"=dword:00000001 "VendorType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\ 63,00,70,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,4f,00,70,00,74,00,69,\ 00,6f,00,6e,00,73,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 2c,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Enum] "0"="Root\\LEGACY_DHCP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Disk] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\ 70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="SCSI Class" "Start"=dword:00000000 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="Disk Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,64,00,69,00,73,00,6b,00,2e,00,73,\ 00,79,00,73,00,00,00 "AutoRunAlwaysDisable"=hex(7):42,00,72,00,6f,00,74,00,68,00,65,00,72,00,20,00,\ 52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,44,00,69,00,73,00,6b,\ 00,28,00,55,00,29,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Disk\Enum] "0"="IDE\\DiskST9200420AS_____________________________3.AHC___\\533530483547304b202020202020202020202020" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmadmin] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\ 67,00,50,00,6c,00,61,00,79,00,00,00,44,00,6d,00,53,00,65,00,72,00,76,00,65,\ 00,72,00,00,00,00,00 "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\ 00,6d,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,65,00,78,00,65,00,20,00,2f,00,\ 63,00,6f,00,6d,00,00,00 "DisplayName"="Logical Disk Manager Administrative Service" "ObjectName"="LocalSystem" "Description"="Configures hard disk drives and volumes. The service only runs for configuration processes and then stops." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmadmin\Parameters] "EnableDynamicConversionFor1394"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmadmin\Enum] "0"="Root\\LEGACY_DMADMIN\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmboot] "Type"=dword:00000001 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "Group"="Filter" "Tag"=dword:0000000b "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,62,00,6f,00,6f,00,74,\ 00,2e,00,73,00,79,00,73,00,00,00 "VolumeRecoveryNeeded"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmboot\Enum] "0"="Root\\LEGACY_DMBOOT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmio] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Tag"=dword:0000000d "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,69,00,6f,00,2e,00,73,\ 00,79,00,73,00,00,00 "DisplayName"="Logical Disk Manager Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmio\Boot Info] "Boot ID"="cc6d1e41-29df-11da-8d3a-806d6172696f" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmio\Enum] "0"="Root\\dmio\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmload] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Tag"=dword:0000000c "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,6c,00,6f,00,61,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmload\Enum] "0"="Root\\LEGACY_DMLOAD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\ 67,00,50,00,6c,00,61,00,79,00,00,00,00,00 "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Logical Disk Manager" "ObjectName"="LocalSystem" "Description"="Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,6d,00,73,00,65,00,72,00,76,00,65,00,72,00,2e,00,64,00,6c,00,6c,00,00,\ 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver\Enum] "0"="Root\\LEGACY_DMSERVER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DMusic] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,44,00,4d,00,75,00,73,00,69,00,63,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel DLS Syntheiszer" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DMusic\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DMusic\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000009 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,64,00,6e,00,65,00,32,00,30,00,30,\ 00,30,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Deterministic Network Enhancer Miniport" "Group"="PNP_TDI" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters] "MaximumPlugins"=dword:0000001d "MtuAdjustment"=dword:00000000 "PacketPoolSize"=dword:00000300 "FragmentPoolSize"=dword:00000600 "FilterAttachLimit"=dword:00004e20 "VerifyBindings"=dword:00000001 "LockBinding"=dword:00000000 "MtuAdjustmentWan"=dword:00000000 "ForcePluginDetach"=dword:00000000 "DisableTaskOffload"=dword:00000000 "IndicatePacket"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\NdisWanIp] "UpperBindings"="\\Device\\{EB2D1957-8151-41BF-90CA-45F3B120FDAF}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{145638C9-949D-4442-A865-9819E776B889}] "UpperBindings"="\\Device\\{E65DE57D-DA64-433C-A571-A1FBFCF168D5}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{2937DCE5-1AB6-4454-A75A-347564768FC5}] "UpperBindings"="\\Device\\{F33DD8A2-0B16-45FE-B140-D79F2D5DBC3B}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{2B8DDB41-2379-4992-B9F8-DC7F41EC4817}] "UpperBindings"="\\Device\\{E072C260-8861-4F8F-A78D-C358D4F7D55C}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{3223DA9C-4B2F-46F1-96EA-45C158827B15}] "UpperBindings"="\\Device\\{19A9B0BB-9783-453E-8DC0-A1FC600FE480}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}] "UpperBindings"="\\Device\\{16744DAB-C4B4-4AA6-B342-199D8B4AB5F9}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}] "UpperBindings"="\\Device\\{053F8CB5-5CD7-4B55-9DBD-B86D4CEF6BA0}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}] "UpperBindings"="\\Device\\{D8E959E3-E8A9-46C8-995B-AD2052C27A48}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}] "UpperBindings"="\\Device\\{7B0E195E-AE57-451B-9945-4DF2AEEAC30C}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{AFE45985-028E-4E55-A932-232847605B83}] "UpperBindings"="\\Device\\{4A97213A-5A0C-4030-AA1B-FC6620E95AAC}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{B57AD90D-90AA-474A-A4F3-051BE53F591A}] "UpperBindings"="\\Device\\{42CF73CB-BF16-4A3E-A40B-1F59D99E4D68}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Adapters\{F6483FC5-D0F5-49BA-9DE0-CE505408BC40}] "UpperBindings"="\\Device\\{691D04DD-026E-44FD-A9DA-1C85DA907874}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order] "DBVersion"="1.3" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\BJIPF] "Type"=dword:00000000 "Order"=dword:40020100 "Name"="BJIPF" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\CVPNDRV] "Name"="CVPNDRV" "Order"=dword:80040100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\CYPHRCST] "Name"="CYPHRCST" "Order"=dword:800a0100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\d] "Order"=dword:60020100 "Type"=dword:00000000 "Name"="d" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\dnlace] "Name"="dnlace" "Order"=dword:c0020100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\dnvad] "Name"="dnvad" "Order"=dword:60020100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\EPDD] "Name"="EPDD" "Order"=dword:20020100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\Gatekpr] "Type"=dword:00000000 "Order"=dword:40080100 "Name"="Gatekpr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\highway] "Name"="highway" "Type"=dword:00000000 "Order"=dword:40060100 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\Hybplug] "Type"=dword:00000000 "Order"=dword:e0040100 "Name"="Hybplug" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\I] "Name"="I" "Order"=dword:60020100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\IPSecDrv] "Name"="IPSecDrv" "Type"=dword:00000000 "Order"=dword:b0020100 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\IPUMIPVA] "Name"="IPUMIPVA" "Order"=dword:60020100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\Meter] "Name"="Meter" "Order"=dword:400a0100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\nat] "Name"="nat" "Order"=dword:60040100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\netpost] "Name"="netpost" "Order"=dword:40040100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\obqos] "Name"="obqos" "Type"=dword:00000000 "Order"=dword:60060100 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\others] "Order"=dword:55555555 "Type"=dword:00000001 "Name"="others" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\PPPOE] "Order"=dword:e0020100 "Type"=dword:00000000 "Name"="PPPOE" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\RCFox] "Name"="RCFox" "Order"=dword:80060100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\rcvad] "Order"=dword:80080100 "Name"="rcvad" "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\W] "Name"="W" "Type"=dword:00000000 "Order"=dword:a0020100 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Parameters\Order\WGW] "Name"="WGW" "Order"=dword:a0020100 "Type"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNE\Enum] "0"="Root\\DNI_DNEMP\\0000" "Count"=dword:00000007 "NextInstance"=dword:00000007 "1"="Root\\DNI_DNEMP\\0001" "2"="Root\\DNI_DNEMP\\0002" "3"="Root\\DNI_DNEMP\\0003" "4"="Root\\DNI_DNEMP\\0004" "5"="Root\\DNI_DNEMP\\0006" "6"="Root\\DNI_DNEMP\\0007" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,65,00,72,00,76,\ 00,69,00,63,00,65,00,00,00 "DisplayName"="DNS Client" "Group"="TDI" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,6e,00,73,00,72,00,73,00,6c,00,76,00,72,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServerPriorityTimeLimit"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2c,\ 02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,\ 00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Enum] "0"="Root\\LEGACY_DNSCACHE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dot3svc] "DependOnService"=hex(7):4e,00,64,00,69,00,73,00,75,00,69,00,6f,00,00,00,65,00,\ 61,00,70,00,68,00,6f,00,73,00,74,00,00,00,00,00 "Description"="This service performs IEEE 802.1X authentication on Ethernet interfaces" "DisplayName"="Wired AutoConfig" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,64,00,6f,00,74,00,33,00,73,00,76,00,63,00,00,00 "ObjectName"="LocalSystem" "Type"=dword:00000020 "Group"="TDI" "FailureActions"=hex:5a,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,65,00,79,\ 00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00 "Start"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dot3svc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,6f,00,74,00,33,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="Dot3SvcMain" "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dpti2o] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003c "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dpti2o\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dpti2o\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DriverX] "ErrorControl"=dword:00000001 "Start"=dword:00000002 "Type"=dword:00000001 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,72,00,69,00,76,00,65,00,72,00,\ 78,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="DriverX" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DriverX\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DriverX\Parameters\FET] "IgnoreConflicts"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DriverX\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DriverX\Enum] "0"="Root\\LEGACY_DRIVERX\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drmkaud] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,72,00,6d,00,6b,00,61,00,75,\ 00,64,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel DRM Audio Descrambler" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drmkaud\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drmkaud\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\e1express] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000c "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,65,00,31,00,65,00,35,00,31,00,33,\ 00,32,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Intel(R) PRO/1000 PCI Express Network Connection Driver" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\e1express\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\e1express\Enum] "0"="PCI\\VEN_8086&DEV_1049&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&C8" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost] "DisplayName"="Extensible Authentication Protocol Service" "Description"="Provides windows clients Extensible Authentication Protocol Service" "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,65,00,61,00,70,00,73,00,76,00,63,00,73,00,00,00 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "ObjectName"="localSystem" "FailureActions"=hex:5a,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,65,00,79,\ 00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost\Methods] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 65,00,61,00,70,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceDllUnloadOnStop"=dword:00000001 "PeerInstalled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Allows error reporting for services and applictions running in non-standard environments." "DisplayName"="Error Reporting Service" "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 65,00,72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Enum] "0"="Root\\LEGACY_ERSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog] "Description"="Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped." "DisplayName"="Event Log" "ErrorControl"=dword:00000001 "Group"="Event log" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "PlugPlayServiceType"=dword:00000003 "Start"=dword:00000002 "Type"=dword:00000020 "ComputerName"="ewi1299" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application] "DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "DisplayNameID"=dword:00000100 "File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\ 6f,00,6e,00,66,00,69,00,67,00,5c,00,41,00,70,00,70,00,45,00,76,00,65,00,6e,\ 00,74,00,2e,00,45,00,76,00,74,00,00,00 "MaxSize"=dword:00080000 "PrimaryModule"="Application" "Retention"=dword:00093a80 "Sources"=hex(7):58,00,4c,00,69,00,76,00,65,00,00,00,57,00,53,00,48,00,00,00,\ 57,00,4d,00,49,00,41,00,64,00,61,00,70,00,74,00,65,00,72,00,00,00,57,00,4d,\ 00,49,00,2e,00,4e,00,45,00,54,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,\ 65,00,72,00,20,00,45,00,78,00,74,00,65,00,6e,00,73,00,69,00,6f,00,6e,00,00,\ 00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,00,00,00,57,00,69,00,6e,00,\ 4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,\ 00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,50,00,72,00,6f,00,\ 64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,69,00,76,00,61,00,74,00,69,\ 00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,33,00,\ 2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,74,00,69,00,6f,00,6e,00,00,\ 00,57,00,67,00,61,00,53,00,65,00,74,00,75,00,70,00,00,00,57,00,65,00,62,00,\ 43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,56,00,53,00,53,00,00,00,56,00,73,\ 00,4a,00,49,00,54,00,44,00,65,00,62,00,75,00,67,00,67,00,65,00,72,00,00,00,\ 56,00,4d,00,43,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,56,00,69,\ 00,73,00,75,00,61,00,6c,00,20,00,53,00,74,00,75,00,64,00,69,00,6f,00,20,00,\ 32,00,30,00,30,00,38,00,20,00,52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,44,\ 00,65,00,62,00,75,00,67,00,67,00,65,00,72,00,00,00,56,00,69,00,73,00,75,00,\ 61,00,6c,00,20,00,53,00,74,00,75,00,64,00,69,00,6f,00,20,00,2d,00,20,00,56,\ 00,73,00,54,00,65,00,6d,00,70,00,6c,00,61,00,74,00,65,00,00,00,56,00,42,00,\ 52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,00,00,55,00,73,00,65,00,72,00,69,\ 00,6e,00,69,00,74,00,00,00,55,00,73,00,65,00,72,00,65,00,6e,00,76,00,00,00,\ 54,00,72,00,75,00,65,00,56,00,65,00,63,00,74,00,6f,00,72,00,20,00,53,00,65,\ 00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,\ 72,00,00,00,53,00,79,00,73,00,74,00,65,00,6d,00,2e,00,53,00,65,00,72,00,76,\ 00,69,00,63,00,65,00,4d,00,6f,00,64,00,65,00,6c,00,2e,00,49,00,6e,00,73,00,\ 74,00,61,00,6c,00,6c,00,20,00,33,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,\ 00,53,00,79,00,73,00,74,00,65,00,6d,00,2e,00,53,00,65,00,72,00,76,00,69,00,\ 63,00,65,00,4d,00,6f,00,64,00,65,00,6c,00,20,00,33,00,2e,00,30,00,2e,00,30,\ 00,2e,00,30,00,00,00,53,00,79,00,73,00,74,00,65,00,6d,00,2e,00,52,00,75,00,\ 6e,00,74,00,69,00,6d,00,65,00,2e,00,53,00,65,00,72,00,69,00,61,00,6c,00,69,\ 00,7a,00,61,00,74,00,69,00,6f,00,6e,00,20,00,33,00,2e,00,30,00,2e,00,30,00,\ 2e,00,30,00,00,00,53,00,79,00,73,00,74,00,65,00,6d,00,2e,00,49,00,4f,00,2e,\ 00,4c,00,6f,00,67,00,20,00,33,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,\ 53,00,79,00,73,00,74,00,65,00,6d,00,2e,00,49,00,64,00,65,00,6e,00,74,00,69,\ 00,74,00,79,00,4d,00,6f,00,64,00,65,00,6c,00,20,00,33,00,2e,00,30,00,2e,00,\ 30,00,2e,00,30,00,00,00,53,00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,\ 00,00,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,51,00,4c,00,\ 57,00,72,00,69,00,74,00,65,00,72,00,00,00,53,00,51,00,4c,00,57,00,45,00,50,\ 00,00,00,53,00,51,00,4c,00,56,00,44,00,49,00,00,00,53,00,51,00,4c,00,4e,00,\ 43,00,4c,00,49,00,00,00,53,00,51,00,4c,00,44,00,75,00,6d,00,70,00,65,00,72,\ 00,00,00,53,00,51,00,4c,00,43,00,54,00,52,00,24,00,53,00,51,00,4c,00,45,00,\ 58,00,50,00,52,00,45,00,53,00,53,00,00,00,53,00,51,00,4c,00,42,00,72,00,6f,\ 00,77,00,73,00,65,00,72,00,00,00,53,00,70,00,79,00,62,00,6f,00,74,00,20,00,\ 2d,00,20,00,53,00,65,00,61,00,72,00,63,00,68,00,20,00,26,00,20,00,44,00,65,\ 00,73,00,74,00,72,00,6f,00,79,00,20,00,32,00,00,00,53,00,70,00,6f,00,6f,00,\ 6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,00,77,\ 00,61,00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,00,74,00,\ 69,00,6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,73,00,00,\ 00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,73,00,\ 74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,4e,00,4c,\ 00,20,00,48,00,69,00,76,00,65,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,\ 00,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,4d,00,6f,00,64,00,65,00,6c,\ 00,20,00,41,00,75,00,64,00,69,00,74,00,20,00,33,00,2e,00,30,00,2e,00,30,00,\ 2e,00,30,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,43,00,65,\ 00,6e,00,74,00,65,00,72,00,00,00,53,00,63,00,6c,00,67,00,4e,00,74,00,66,00,\ 79,00,00,00,53,00,63,00,65,00,53,00,72,00,76,00,00,00,53,00,63,00,65,00,43,\ 00,6c,00,69,00,00,00,73,00,61,00,66,00,72,00,73,00,6c,00,76,00,00,00,53,00,\ 41,00,46,00,72,00,64,00,6d,00,73,00,00,00,52,00,50,00,43,00,00,00,52,00,65,\ 00,6d,00,6f,00,74,00,65,00,20,00,41,00,73,00,73,00,69,00,73,00,74,00,61,00,\ 6e,00,63,00,65,00,00,00,50,00,65,00,72,00,66,00,50,00,72,00,6f,00,63,00,00,\ 00,50,00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,65,00,72,00,66,00,4e,00,\ 65,00,74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,00,00,50,00,65,\ 00,72,00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,72,00,66,00,44,00,69,00,\ 73,00,6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,00,00,4f,\ 00,76,00,69,00,53,00,75,00,69,00,74,00,65,00,00,00,4f,00,75,00,74,00,6c,00,\ 6f,00,6f,00,6b,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,00,65,00,20,00,46,\ 00,69,00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,65,00,79,00,00,00,\ 6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4e,00,6f,00,6b,00,69,\ 00,61,00,20,00,4d,00,20,00,50,00,6c,00,61,00,74,00,66,00,6f,00,72,00,6d,00,\ 00,00,4e,00,44,00,50,00,31,00,2e,00,31,00,73,00,70,00,31,00,2d,00,4b,00,42,\ 00,39,00,35,00,33,00,32,00,39,00,37,00,2d,00,58,00,38,00,36,00,00,00,4d,00,\ 53,00,53,00,51,00,4c,00,53,00,65,00,72,00,76,00,65,00,72,00,41,00,44,00,48,\ 00,65,00,6c,00,70,00,65,00,72,00,00,00,4d,00,53,00,53,00,51,00,4c,00,53,00,\ 45,00,52,00,56,00,45,00,52,00,2f,00,4d,00,53,00,44,00,45,00,00,00,4d,00,53,\ 00,53,00,51,00,4c,00,24,00,53,00,51,00,4c,00,45,00,58,00,50,00,52,00,45,00,\ 53,00,53,00,00,00,4d,00,53,00,53,00,4f,00,41,00,50,00,00,00,4d,00,53,00,53,\ 00,48,00,41,00,00,00,4d,00,53,00,4d,00,51,00,54,00,72,00,69,00,67,00,67,00,\ 65,00,72,00,73,00,00,00,4d,00,53,00,4d,00,51,00,00,00,4d,00,73,00,69,00,49,\ 00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,\ 54,00,43,00,20,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,\ 00,54,00,43,00,00,00,4d,00,53,00,44,00,4d,00,69,00,6e,00,65,00,00,00,4d,00,\ 6f,00,62,00,69,00,6c,00,65,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,00,\ 00,6d,00,6e,00,6d,00,73,00,72,00,76,00,63,00,00,00,4d,00,69,00,63,00,72,00,\ 6f,00,73,00,6f,00,66,00,74,00,2e,00,54,00,72,00,61,00,6e,00,73,00,61,00,63,\ 00,74,00,69,00,6f,00,6e,00,73,00,2e,00,42,00,72,00,69,00,64,00,67,00,65,00,\ 20,00,33,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,4d,00,69,00,63,00,72,\ 00,6f,00,73,00,6f,00,66,00,74,00,20,00,56,00,69,00,73,00,75,00,61,00,6c,00,\ 20,00,53,00,74,00,75,00,64,00,69,00,6f,00,00,00,4d,00,69,00,63,00,72,00,6f,\ 00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,00,66,00,69,00,63,00,65,00,20,00,\ 44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,20,00,49,00,6d,00,61,00,67,\ 00,69,00,6e,00,67,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\ 74,00,20,00,4f,00,66,00,66,00,69,00,63,00,65,00,20,00,31,00,31,00,00,00,4d,\ 00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,48,00,2e,00,33,00,\ 32,00,33,00,20,00,54,00,65,00,6c,00,65,00,70,00,68,00,6f,00,6e,00,79,00,20,\ 00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,\ 69,00,64,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\ 00,74,00,20,00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,20,00,45,00,\ 78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,6f,\ 00,73,00,6f,00,66,00,74,00,20,00,28,00,52,00,29,00,20,00,56,00,69,00,73,00,\ 75,00,61,00,6c,00,20,00,43,00,23,00,20,00,32,00,30,00,30,00,35,00,20,00,43,\ 00,6f,00,6d,00,70,00,69,00,6c,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,\ 6f,00,73,00,6f,00,66,00,74,00,20,00,28,00,52,00,29,00,20,00,56,00,69,00,73,\ 00,75,00,61,00,6c,00,20,00,42,00,61,00,73,00,69,00,63,00,20,00,43,00,6f,00,\ 6d,00,70,00,69,00,6c,00,65,00,72,00,00,00,4d,00,44,00,4d,00,00,00,4c,00,6f,\ 00,61,00,64,00,50,00,65,00,72,00,66,00,00,00,4c,00,69,00,67,00,68,00,74,00,\ 53,00,63,00,72,00,69,00,62,00,65,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\ 00,00,00,4a,00,61,00,76,00,61,00,51,00,75,00,69,00,63,00,6b,00,53,00,74,00,\ 61,00,72,00,74,00,65,00,72,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,\ 00,49,00,53,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,49,00,4a,00,\ 50,00,4c,00,4d,00,53,00,56,00,43,00,00,00,48,00,6f,00,74,00,46,00,69,00,78,\ 00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,00,00,48,00,65,00,\ 6c,00,70,00,53,00,76,00,63,00,00,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,\ 00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,\ 46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,79,00,6d,00,65,\ 00,6e,00,74,00,00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,\ 65,00,6d,00,00,00,45,00,53,00,45,00,4e,00,54,00,00,00,44,00,72,00,57,00,61,\ 00,74,00,73,00,6f,00,6e,00,00,00,44,00,6f,00,74,00,33,00,53,00,76,00,63,00,\ 00,00,44,00,69,00,73,00,6b,00,51,00,75,00,6f,00,74,00,61,00,00,00,64,00,65,\ 00,76,00,65,00,6e,00,76,00,00,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,\ 00,00,43,00,4f,00,4d,00,2b,00,00,00,43,00,4f,00,4d,00,00,00,43,00,69,00,00,\ 00,43,00,68,00,6b,00,64,00,73,00,6b,00,00,00,43,00,61,00,72,00,64,00,53,00,\ 70,00,61,00,63,00,65,00,20,00,33,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,\ 00,42,00,6f,00,6e,00,6a,00,6f,00,75,00,72,00,20,00,53,00,65,00,72,00,76,00,\ 69,00,63,00,65,00,00,00,41,00,76,00,67,00,39,00,41,00,6c,00,72,00,74,00,00,\ 00,41,00,75,00,74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,00,65,00,\ 6e,00,74,00,00,00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,41,00,53,\ 00,50,00,2e,00,4e,00,45,00,54,00,20,00,32,00,2e,00,30,00,2e,00,35,00,30,00,\ 37,00,32,00,37,00,2e,00,30,00,00,00,41,00,53,00,50,00,2e,00,4e,00,45,00,54,\ 00,20,00,31,00,2e,00,31,00,2e,00,34,00,33,00,32,00,32,00,2e,00,30,00,00,00,\ 41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,4d,\ 00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,6e,00,74,00,00,00,41,00,70,00,\ 70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,48,00,61,00,6e,\ 00,67,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,\ 6e,00,20,00,45,00,72,00,72,00,6f,00,72,00,00,00,61,00,70,00,70,00,68,00,65,\ 00,6c,00,70,00,00,00,2e,00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,00,\ 69,00,6d,00,65,00,20,00,4f,00,70,00,74,00,69,00,6d,00,69,00,7a,00,61,00,74,\ 00,69,00,6f,00,6e,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,\ 2e,00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,20,\ 00,32,00,2e,00,30,00,20,00,45,00,72,00,72,00,6f,00,72,00,20,00,52,00,65,00,\ 70,00,6f,00,72,00,74,00,69,00,6e,00,67,00,00,00,2e,00,4e,00,45,00,54,00,20,\ 00,52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,00,00,41,00,70,00,70,00,6c,00,\ 69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,00 "RestrictGuestAccess"=dword:00000001 @="mnmsrvc" "AutoBackupLogFiles"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime] "TypesSupported"=dword:00000007 "EventMessageFile"="c:\\WINDOWS\\system32\\mscoree.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime 2.0 Error Reporting] "EventMessageFile"="c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\.NET Runtime Optimization Service] "EventMessageFile"="c:\\WINDOWS\\system32\\mscoree.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\apphelp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,70,00,70,00,68,00,65,00,6c,00,70,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application] "CategoryCount"=dword:00000007 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,64,00,6c,00,\ 6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Error] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Hang] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Management] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 1.1.4322.0] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,\ 4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,\ 00,5c,00,76,00,31,00,2e,00,31,00,2e,00,34,00,33,00,32,00,32,00,5c,00,61,00,\ 73,00,70,00,6e,00,65,00,74,00,5f,00,72,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "CategoryCount"=dword:00000002 "CategoryMessageFile"=hex(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,\ 00,4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,\ 6b,00,5c,00,76,00,31,00,2e,00,31,00,2e,00,34,00,33,00,32,00,32,00,5c,00,61,\ 00,73,00,70,00,6e,00,65,00,74,00,5f,00,72,00,63,00,2e,00,64,00,6c,00,6c,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ASP.NET 2.0.50727.0] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,\ 4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,\ 00,5c,00,76,00,32,00,2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,5c,00,\ 61,00,73,00,70,00,6e,00,65,00,74,00,5f,00,72,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "CategoryCount"=dword:00000005 "CategoryMessageFile"=hex(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,\ 00,4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,\ 6b,00,5c,00,76,00,32,00,2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,5c,\ 00,61,00,73,00,70,00,6e,00,65,00,74,00,5f,00,72,00,63,00,2e,00,64,00,6c,00,\ 6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Autochk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\AutoEnrollment] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,61,00,75,00,74,00,6f,00,65,00,6e,00,72,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Avg9Alrt] "EventMessageFile"="C:\\PROGRA~1\\AVG\\AVG9\\avgameh.dll" "CategoryMessageFile"="C:\\PROGRA~1\\AVG\\AVG9\\avgameh.dll" "CategoryCount"=dword:00000001 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\ 00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,42,00,6f,00,6e,00,6a,00,\ 6f,00,75,00,72,00,5c,00,6d,00,44,00,4e,00,53,00,52,00,65,00,73,00,70,00,6f,\ 00,6e,00,64,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\CardSpace 3.0.0.0] "CategoryCount"=dword:00000001 "CategoryMessageFile"="c:\\WINDOWS\\system32\\icardres.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui;c:\\WINDOWS\\system32\\icardres.dll.mui" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chkdsk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,6c,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Ci] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryCount"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\COM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\COM+] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypeSupported"=dword:00000007 "CategoryCount"=dword:00000075 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\crypt32] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\devenv] "EventMessageFile"="C:\\Program Files\\Microsoft Visual Studio 9.0\\Common7\\IDE\\devenv.exe" "TypesSupported"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DiskQuota] "EventMessageFile"="%SystemRoot%\\System32\\dskquota.dll" "TypesSupported"="0x00000007" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Dot3Svc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,6f,00,74,00,33,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DrWatson] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,72,00,77,00,74,00,73,00,6e,00,33,00,32,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESENT] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,00,\ 53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,\ 00,53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:00000010 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\EventSystem] "CategoryCount"=dword:00000006 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\File Deployment] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Folder Redirection] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HelpSvc] "EventMessageFile"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll" "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HotFixInstaller] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,\ 00,7e,00,31,00,5c,00,43,00,4f,00,4d,00,4d,00,4f,00,4e,00,7e,00,31,00,5c,00,\ 4d,00,49,00,43,00,52,00,4f,00,53,00,7e,00,31,00,5c,00,44,00,57,00,5c,00,44,\ 00,57,00,32,00,30,00,2e,00,45,00,58,00,45,00,00,00,10,02,10,02,10,02,10,02,\ 14,02,14,02,10,02,12,03,10,02,10,02,10,02,14,02,12,03,10,02,10,02,10,02,10,\ 02,10,02,01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,\ 01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,01,03,10,\ 02,01,03,01,03,01,03,01,03,01,03,01,03,01,03,02,03,02,03,02,03,02,03,02,03,\ 02,03,02,03,02,03,02,03,02,03,02,03,02,03,02,03,02,03,02,03,02,03,02,03,02,\ 03,02,03,02,03,02,03,02,03,02,03,02,03,10,02,02,03,02,03,02,03,02,03,02,03,\ 02,03,02,03,02,03,20,01,02,03,04,05,06,07,08,09,0a,0b,0c,0d,0e,0f,10,11,12,\ 13,14,15,16,17,18,19,1a,1b,1c,1d,1e,1f,20,21,22,23,24,25,26,27,28,29,2a,2b,\ 2c,2d,2e,2f,30,31,32,33,34,35,36,37,38,39,3a,3b,3c,3d,3e,3f,40,41,42,43,14,\ fc,12,00,00,00,15,00,02,02,91,7c,20,fc,12,00,00,00,15,00,02,02,91,7c,05,00,\ 00,00,78,07,15,00,00,00,15,00,00,00,00,00,f8,fb,12,00,99,01,00,00,3c,fe,12,\ 00,00,e9,90,7c,94,01,00,00,4c,fe,12,00,08,10,91,7c,66,10,91,7c,bb,01,91,7c,\ 24,4c,44,00,10,4c,44,00,00,00,00,00,28,fc,12,00,a0,a1,a2,a3,98,fc,12,00,00,\ e9,90,7c,60,2d,91,7c,ff,ff,ff,ff,58,2d,91,7c,4e,b5,80,7c,01,00,00,00,0e,00,\ 14,06,fe,b4,80,7c,04,01,00,00,00,fd,12,00,0c,fd,12,00,c0,1e,25,00,6c,d9,90,\ 7c,4d,ba,80,7c,ff,ff,ff,ff,7c,80,c2,77,00,00,00,00,c4,fc,12,00,1c,00,00,00,\ a8,fc,12,00,ac,fc,12,00,76,ba,80,7c,ff,ff,ff,ff,7c,80,c2,77,c4,fc,12,00,1c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IJPLMSVC] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ISService] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,\ 00,7e,00,31,00,5c,00,53,00,59,00,4d,00,41,00,4e,00,54,00,7e,00,31,00,5c,00,\ 53,00,59,00,4d,00,41,00,4e,00,54,00,7e,00,31,00,5c,00,49,00,53,00,53,00,56,\ 00,43,00,2e,00,65,00,78,00,65,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\JavaQuickStarterService] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\ 00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,\ 5c,00,6a,00,72,00,65,00,36,00,5c,00,62,00,69,00,6e,00,5c,00,6a,00,71,00,73,\ 00,2e,00,65,00,78,00,65,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LightScribeService] @="" "EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\ 00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\ 6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4c,00,69,00,67,00,68,\ 00,74,00,53,00,63,00,72,00,69,00,62,00,65,00,5c,00,4c,00,53,00,53,00,4d,00,\ 73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LoadPerf] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,6f,00,61,00,64,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MDM] "EventMessageFile"="C:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft (R) Visual Basic Compiler] "EventMessageFile"="C:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft (R) Visual C# 2005 Compiler] "EventMessageFile"="c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Document Explorer] "EventMessageFile"="C:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft H.323 Telephony Service Provider] "EventMessageFile"="C:\\WINDOWS\\System32\\h323.tsp" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Office 11] "EventMessageFile"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\DW20.EXE" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Office Document Imaging] "CategoryMessageFile"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MODI\\11.0\\MSPFILT.DLL" "TypesSupported"=dword:00000007 "LoggingLevel"=dword:00000000 "EventMessageFile"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MODI\\11.0\\MSPFILT.DLL" "CategoryCount"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft Visual Studio] "EventMessageFile"="C:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft.Transactions.Bridge 3.0.0.0] "CategoryCount"=dword:0000000e "CategoryMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\mnmsrvc] "EventMessageFile"="%SystemRoot%\\System32\\nmevtmsg.dll" "TypeSupported"=hex:07,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MobileConnect] "EventMessageFile"=hex(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,\ 4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,\ 00,5c,00,76,00,32,00,2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,5c,00,\ 45,00,76,00,65,00,6e,00,74,00,4c,00,6f,00,67,00,4d,00,65,00,73,00,73,00,61,\ 00,67,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDMine] "EventMessageFile"="C:\\PROGRA~1\\COMMON~1\\SYSTEM\\OLEDB~1\\MSDMINE.DLL" "TypesSupported"=hex:00,12,b8,58 "CategoryCount"=dword:00000002 "CategoryMessageFile"="C:\\PROGRA~1\\COMMON~1\\SYSTEM\\OLEDB~1\\MSDMINE.DLL" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDTC] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,6f,00,6d,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,3b,00,25,\ 00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,\ 53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,\ 00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,3b,00,43,00,3a,00,\ 5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,\ 00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,\ 73,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:0000000f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDTC Client] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,6f,00,6d,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,3b,00,25,\ 00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,\ 53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,\ 00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,3b,00,43,00,3a,00,\ 5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,\ 00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,\ 73,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:0000000f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MsiInstaller] "EventMessageFile"="C:\\WINDOWS\\system32\\msi.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSMQ] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\ 71,00,75,00,74,00,69,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,\ 00,71,00,75,00,74,00,69,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSMQTriggers] "EventMessageFile"="C:\\WINDOWS\\system32\\mqutil.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSHA] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,73,00,73,00,68,00,61,00,76,00,6d,00,73,00,67,00,2e,00,64,00,6c,\ 00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSOAP] "TypesSupported"=dword:00000001 "CategoryCount"=dword:00000004 "EventMessageFile"="C:\\Program Files\\Common Files\\Microsoft Shared\\OFFICE11\\MSSOAP30.DLL" "CategoryMessageFile"="C:\\Program Files\\Common Files\\Microsoft Shared\\OFFICE11\\MSSOAP30.DLL" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSQL$SQLEXPRESS] "CategoryCount"=dword:00000008 "CategoryMessageFile"="C:\\Program Files\\Microsoft SQL Server\\MSSQL.1\\MSSQL\\Binn\\Resources\\1033\\sqlevn70.rll" "EventMessageFile"="C:\\Program Files\\Microsoft SQL Server\\MSSQL.1\\MSSQL\\Binn\\Resources\\1033\\sqlevn70.rll" "TypesSupported"=dword:000000ff [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSQLSERVER/MSDE] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSQLServerADHelper] "EventMessageFile"="C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\Resources\\1033\\sqladevn90.rll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\NDP1.1sp1-KB953297-X86] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,\ 00,7e,00,31,00,5c,00,43,00,4f,00,4d,00,4d,00,4f,00,4e,00,7e,00,31,00,5c,00,\ 4d,00,49,00,43,00,52,00,4f,00,53,00,7e,00,31,00,5c,00,44,00,57,00,5c,00,44,\ 00,57,00,32,00,30,00,2e,00,45,00,58,00,45,00,00,00,4d,00,00,00,49,00,00,00,\ 43,00,00,00,52,00,00,00,4f,00,00,00,53,00,00,00,7e,00,00,00,31,00,00,00,5c,\ 00,00,00,44,00,00,00,57,00,00,00,5c,00,00,00,44,00,00,00,57,00,00,00,32,00,\ 00,00,30,00,00,00,2e,00,00,00,45,00,00,00,58,00,00,00,45,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,79,00,4c,\ 00,a8,00,7d,00,ac,00,fe,00,06,00,00,00,fd,00,7e,00,01,00,01,00,14,00,3d,00,\ 03,00,01,00,dc,02,3a,00,00,00,01,00,3c,00,38,00,00,00,01,00,c4,00,3c,00,03,\ 00,00,00,5d,00,4c,00,a8,00,7d,00,e0,00,fe,00,06,00,00,00,68,00,6e,00,01,00,\ 01,00,00,00,00,00,00,00,00,00,c4,00,3c,00,03,00,01,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,04,00,ff,00,06,00,00,00,cb,00,75,00,01,00,01,00,4c,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,08,00,00,\ 00,00,00,00,00,20,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,10,00,28,00,\ 53,00,00,00,28,00,ff,00,06,00,00,00,b5,00,67,00,00,00,01,00,5e,00,23,00,09,\ 00,00,00,24,00,ff,00,06,00,00,00,28,00,0a,00,00,00,00,00,02,00,00,00,00,00,\ 00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,c0,00,ff,00,06,00,00,00,5e,00,6c,00,00,00,01,00,00,00,00,00,00,00,01,00,\ 00,00,00,00,00,00,00,00,5e,00,23,00,09,00,00,00,0a,00,00,00,00,00,00,00,2d,\ 00,4d,00,a8,00,7d,00,3a,20,01,00,18,20,7c,00,db,00,01,00,18,20,7c,00,00,00,\ e0,00,fd,00,7f,00,44,00,00,00,00,00,00,00,20,00,5c,00,09,00,00,00,38,00,5e,\ 00,09,00,00,00,48,00,5e,00,09,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,ff,00,ff,00,ff,00,ff,\ 00,ff,00,ff,00,ff,00,ff,00,ff,00,ff,00,ff,00,ff,00,bc,00,ff,00,06,00,00,00,\ 01,00,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,3a,\ 20,01,00,18,20,7c,00,40,00,ff,00,06,00,00,00,0a,00,90,00,b6,00,43,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Nokia M Platform] "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ntbackup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Oakley] "EventMessageFile"="%SystemRoot%\\System32\\oakley.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Offline Files] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,73,00,63,00,75,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"="0x00000007" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Outlook] "TypesSupported"=dword:00000007 "Version"=dword:0000000d "EventMessageFile"="C:\\PROGRA~1\\COMMON~1\\SYSTEM\\MSMAPI\\1033\\MAPIR.DLL" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\OviSuite] "EventMessageFile"="C:\\DOCUME~1\\bosch\\LOCALS~1\\Temp\\NOSEventMessages.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perfctrs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfDisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,64,00,69,00,73,00,6b,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perflib] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,72,00,66,00,6c,00,62,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perfmon] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfNet] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,6e,00,65,00,74,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfOS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,4f,00,53,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfProc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,70,00,72,00,6f,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Remote Assistance] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\RPC] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,33,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SAFrdms] "EventMessageFile"="C:\\WINDOWS\\system32\\safrdm.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\safrslv] "EventMessageFile"="C:\\WINDOWS\\system32\\safrslv.dll" "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SceCli] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SceSrv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,65,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SclgNtfy] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SecurityCenter] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ServiceModel Audit 3.0.0.0] "TypesSupported"=dword:0000001f "CategoryCount"=dword:00000002 "CategoryMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SNL HiveManager] "EventMessageFile"=hex(2):00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):00,00 "CategoryCount"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Installation] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,70,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Restriction Policies] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SpoolerCtrs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,73,00,70,00,6f,00,6f,00,6c,00,2e,00,64,00,72,00,76,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Spybot - Search & Destroy 2] "EventMessageFile"=hex(2):53,00,44,00,45,00,76,00,65,00,6e,00,74,00,73,00,2e,\ 00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):53,00,44,00,45,00,76,00,65,00,6e,00,74,00,73,00,\ 2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLBrowser] "EventMessageFile"="C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\Resources\\1033\\sbevent.rll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLCTR$SQLEXPRESS] "EventMessageFile"="C:\\Program Files\\Microsoft SQL Server\\MSSQL.1\\MSSQL\\Binn\\Resources\\1033\\sqlevn70.rll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLDumper] "TypesSupported"=dword:00000007 "EventMessageFile"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\DW20.EXE" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLNCLI] "EventMessageFile"="c:\\WINDOWS\\system32\\sqlncli.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLVDI] @="Microsoft SQL Server Virtual Device Interface" "TypesSupported"=dword:00000007 "EventMessageFile"="c:\\Program Files\\Microsoft SQL Server\\80\\COM\\sqlvdi.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLWEP] @="Microsoft SQL Server WMI Event Provider" "EventMessageFile"="C:\\Program Files\\Microsoft SQL Server\\90\\COM\\sqlwep.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SQLWriter] "EventMessageFile"="c:\\Program Files\\Microsoft SQL Server\\90\\Shared\\Resources\\1033\\sqlwriter.rll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Starter] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SysmonLog] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IdentityModel 3.0.0.0] "CategoryCount"=dword:0000000e "CategoryMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.IO.Log 3.0.0.0] "CategoryCount"=dword:0000000e "CategoryMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.Runtime.Serialization 3.0.0.0] "CategoryCount"=dword:0000000e "CategoryMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel 3.0.0.0] "CategoryCount"=dword:0000000e "CategoryMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\System.ServiceModel.Install 3.0.0.0] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,\ 4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,\ 00,5c,00,76,00,32,00,2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,5c,00,\ 45,00,76,00,65,00,6e,00,74,00,4c,00,6f,00,67,00,4d,00,65,00,73,00,73,00,61,\ 00,67,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Tlntsvr] "EventMessageFile"="C:\\WINDOWS\\system32\\tlntsvr.exe;C:\\WINDOWS\\system32\\xpsp1res.dll" "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TrueVector Service] "EventMessageFile"="C:\\WINDOWS\\system32\\VSINIT.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userenv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,73,00,65,00,72,00,65,00,6e,00,76,00,2e,00,64,00,6c,00,6c,00,3b,\ 00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\ 5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,\ 00,70,00,31,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,53,00,\ 79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,\ 00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,\ 72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userinit] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\VBRuntime] "EventMessageFile"="C:\\WINDOWS\\system32\\msvbvm60.dll" "TypesSupported"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Visual Studio - VsTemplate] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\ 00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\ 6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,\ 00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,\ 5c,00,56,00,53,00,41,00,5c,00,39,00,2e,00,30,00,5c,00,56,00,73,00,61,00,45,\ 00,6e,00,76,00,5c,00,6d,00,73,00,65,00,6e,00,76,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Visual Studio 2008 Remote Debugger] "EventMessageFile"="C:\\Program Files\\Microsoft Visual Studio 9.0\\Common7\\IDE\\Remote Debugger\\x86\\msvsmon.exe" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\VMCService] "EventMessageFile"=hex(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,\ 4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,\ 00,5c,00,76,00,32,00,2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,5c,00,\ 45,00,76,00,65,00,6e,00,74,00,4c,00,6f,00,67,00,4d,00,65,00,73,00,73,00,61,\ 00,67,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\VsJITDebugger] "EventMessageFile"="C:\\WINDOWS\\system32\\vsjitdebugger.exe" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\VSS] "TypesSupported"=dword:00000007 "EventMessageFile"="C:\\WINDOWS\\system32\\vssvc.exe" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WebClient] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup] "TypesSupported"=dword:00000007 "EventMessageFile"="C:\\WINDOWS\\system32\\KB905474\\wgasetup.exe" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows 3.1 Migration] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,64,00,76,00,61,00,70,00,69,00,33,00,32,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows Product Activation] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,70,00,63,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinMgmt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,\ 00,52,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,\ 6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,\ 00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,\ 64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WmdmPmSN] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,\ 73,00,50,00,4d,00,53,00,4e,00,53,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WMI.NET Provider Extension] "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\EventLogMessages.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WMIAdapter] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,4d,00,49,00,41,00,70,00,52,00,65,\ 00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WSH] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\XLive] "EventMessageFile"="C:\\WINDOWS\\system32\\xlive.dll" "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Internet Explorer] "Sources"=hex(7):49,00,6e,00,74,00,65,00,72,00,6e,00,65,00,74,00,20,00,45,00,\ 78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security] "DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "DisplayNameID"=dword:00000101 "File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\ 6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,65,00,63,00,45,00,76,00,65,00,6e,\ 00,74,00,2e,00,45,00,76,00,74,00,00,00 "MaxSize"=dword:00080000 "PrimaryModule"="Security" "Retention"=dword:00093a80 "Sources"=hex(7):53,00,70,00,6f,00,6f,00,6c,00,65,00,72,00,00,00,53,00,65,00,\ 72,00,76,00,69,00,63,00,65,00,4d,00,6f,00,64,00,65,00,6c,00,20,00,33,00,2e,\ 00,30,00,2e,00,30,00,2e,00,30,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,\ 74,00,79,00,20,00,41,00,63,00,63,00,6f,00,75,00,6e,00,74,00,20,00,4d,00,61,\ 00,6e,00,61,00,67,00,65,00,72,00,00,00,53,00,43,00,20,00,4d,00,61,00,6e,00,\ 61,00,67,00,65,00,72,00,00,00,4e,00,65,00,74,00,44,00,44,00,45,00,20,00,4f,\ 00,62,00,6a,00,65,00,63,00,74,00,00,00,4c,00,53,00,41,00,00,00,44,00,53,00,\ 00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,00,00,00,00 "RestrictGuestAccess"=dword:00000001 "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS\ObjectNames] "Directory Service Object"=dword:00001e00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames] "PolicyObject"=dword:00001600 "SecretObject"=dword:00001610 "TrustedDomainObject"=dword:00001620 "UserAccountObject"=dword:00001630 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object\ObjectNames] "DDE Share"=dword:00001d00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames] "SC_MANAGER Object"=dword:00001c00 "SERVICE Object"=dword:00001c10 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security] "CategoryCount"=dword:00000009 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,41,00,75,00,64,00,69,00,74,00,45,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "GuidMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,4e,00,74,00,4d,00,61,00,72,00,74,00,61,00,2e,00,64,00,6c,00,6c,00,00,00 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,4d,00,73,00,41,00,75,00,64,00,69,00,74,00,45,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,\ 53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,\ 00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,\ 33,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001c [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames] "Channel"=dword:00001400 "Desktop"=dword:00001a10 "Device"=dword:00001100 "Directory"=dword:00001110 "Event"=dword:00001120 "EventPair"=dword:00001130 "File"=dword:00001140 "IoCompletion"=dword:00001300 "Job"=dword:00001410 "Key"=dword:00001150 "MailSlot"=dword:00001140 "Mutant"=dword:00001160 "NamedPipe"=dword:00001140 "Port"=dword:00001170 "Process"=dword:00001180 "Profile"=dword:00001190 "Section"=dword:000011a0 "Semaphore"=dword:000011b0 "SymbolicLink"=dword:000011c0 "Thread"=dword:000011d0 "Timer"=dword:000011e0 "Token"=dword:000011f0 "Type"=dword:00001200 "WaitablePort"=dword:00001170 "WindowStation"=dword:00001a00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames] "SAM_ALIAS"=dword:00001530 "SAM_DOMAIN"=dword:00001510 "SAM_GROUP"=dword:00001520 "SAM_SERVER"=dword:00001500 "SAM_USER"=dword:00001540 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0] "TypesSupported"=dword:0000001f "CategoryMessageFile"="%SystemRoot%\\System32\\MsAuditE.dll" "CategoryCount"=dword:00000003 "ParameterMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventSourceFlags"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames] "Document"=dword:00001b20 "Printer"=dword:00001b10 "Server"=dword:00001b00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System] "DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "DisplayNameID"=dword:00000102 "File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\ 6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,79,00,73,00,45,00,76,00,65,00,6e,\ 00,74,00,2e,00,45,00,76,00,74,00,00,00 "MaxSize"=dword:00080000 "PrimaryModule"="System" "Retention"=dword:00093a80 "Sources"=hex(7):5a,00,54,00,45,00,75,00,73,00,62,00,6e,00,65,00,74,00,00,00,\ 57,00,5a,00,43,00,53,00,56,00,43,00,00,00,57,00,75,00,64,00,66,00,30,00,31,\ 00,30,00,30,00,37,00,00,00,57,00,75,00,64,00,66,00,30,00,31,00,30,00,30,00,\ 35,00,00,00,57,00,75,00,64,00,66,00,30,00,31,00,30,00,30,00,30,00,00,00,57,\ 00,70,00,64,00,55,00,73,00,62,00,00,00,57,00,50,00,44,00,4d,00,54,00,50,00,\ 44,00,72,00,69,00,76,00,65,00,72,00,00,00,57,00,50,00,44,00,43,00,6c,00,61,\ 00,73,00,73,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,00,00,\ 57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,\ 00,4d,00,50,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,76,00,63,00,\ 00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,4d,00,65,00,64,00,69,00,61,\ 00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,55,00,70,00,64,00,\ 61,00,74,00,65,00,20,00,41,00,67,00,65,00,6e,00,74,00,00,00,57,00,69,00,6e,\ 00,64,00,6f,00,77,00,73,00,20,00,53,00,63,00,72,00,69,00,70,00,74,00,20,00,\ 48,00,6f,00,73,00,74,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,\ 00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,20,00,33,00,2e,00,\ 31,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,46,00,69,00,6c,\ 00,65,00,20,00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,\ 00,00,57,00,69,00,6e,00,33,00,32,00,6b,00,00,00,57,00,67,00,61,00,4e,00,6f,\ 00,74,00,69,00,66,00,79,00,00,00,57,00,47,00,41,00,00,00,57,00,64,00,66,00,\ 30,00,31,00,30,00,30,00,37,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,\ 00,35,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,00,00,00,57,00,\ 33,00,32,00,54,00,69,00,6d,00,65,00,00,00,56,00,6f,00,6c,00,53,00,6e,00,61,\ 00,70,00,00,00,76,00,69,00,61,00,69,00,64,00,65,00,00,00,56,00,67,00,61,00,\ 53,00,61,00,76,00,65,00,00,00,55,00,53,00,45,00,52,00,33,00,32,00,00,00,55,\ 00,50,00,53,00,00,00,55,00,6c,00,74,00,72,00,61,00,4d,00,6f,00,6e,00,4d,00,\ 69,00,72,00,72,00,6f,00,72,00,00,00,75,00,6c,00,74,00,72,00,61,00,00,00,75,\ 00,64,00,66,00,73,00,00,00,74,00,6f,00,73,00,69,00,64,00,65,00,00,00,54,00,\ 65,00,72,00,6d,00,53,00,65,00,72,00,76,00,53,00,65,00,73,00,73,00,44,00,69,\ 00,72,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,69,00,63,00,\ 65,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,44,00,65,00,76,\ 00,69,00,63,00,65,00,73,00,00,00,54,00,65,00,72,00,6d,00,44,00,44,00,00,00,\ 74,00,64,00,69,00,00,00,54,00,43,00,50,00,4d,00,6f,00,6e,00,00,00,54,00,63,\ 00,70,00,69,00,70,00,00,00,53,00,79,00,73,00,74,00,65,00,6d,00,20,00,45,00,\ 72,00,72,00,6f,00,72,00,00,00,53,00,79,00,6e,00,54,00,50,00,00,00,73,00,79,\ 00,6d,00,5f,00,75,00,33,00,00,00,73,00,79,00,6d,00,5f,00,68,00,69,00,00,00,\ 73,00,79,00,6d,00,63,00,38,00,78,00,78,00,00,00,73,00,79,00,6d,00,63,00,38,\ 00,31,00,30,00,00,00,53,00,74,00,69,00,6c,00,6c,00,49,00,6d,00,61,00,67,00,\ 65,00,00,00,53,00,53,00,44,00,50,00,53,00,52,00,56,00,00,00,53,00,72,00,76,\ 00,00,00,73,00,72,00,73,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,73,00,\ 72,00,00,00,73,00,70,00,74,00,64,00,00,00,73,00,70,00,61,00,72,00,72,00,6f,\ 00,77,00,00,00,73,00,6e,00,64,00,62,00,6c,00,73,00,74,00,00,00,53,00,4d,00,\ 53,00,76,00,63,00,48,00,6f,00,73,00,74,00,20,00,33,00,2e,00,30,00,2e,00,30,\ 00,2e,00,30,00,00,00,53,00,69,00,6d,00,62,00,61,00,64,00,00,00,53,00,69,00,\ 64,00,65,00,42,00,79,00,53,00,69,00,64,00,65,00,00,00,73,00,66,00,6c,00,6f,\ 00,70,00,70,00,79,00,00,00,53,00,65,00,74,00,75,00,70,00,00,00,53,00,65,00,\ 72,00,76,00,69,00,63,00,65,00,20,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,\ 00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,53,00,65,00,72,00,\ 76,00,65,00,72,00,00,00,73,00,65,00,72,00,6d,00,6f,00,75,00,73,00,65,00,00,\ 00,73,00,65,00,72,00,69,00,61,00,6c,00,00,00,73,00,63,00,73,00,69,00,70,00,\ 6f,00,72,00,74,00,00,00,53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,00,\ 00,53,00,63,00,68,00,61,00,6e,00,6e,00,65,00,6c,00,00,00,53,00,43,00,61,00,\ 72,00,64,00,53,00,76,00,72,00,00,00,53,00,61,00,76,00,65,00,20,00,44,00,75,\ 00,6d,00,70,00,00,00,53,00,41,00,4d,00,00,00,52,00,53,00,56,00,50,00,00,00,\ 72,00,69,00,73,00,6d,00,63,00,33,00,32,00,00,00,52,00,65,00,6d,00,6f,00,76,\ 00,61,00,62,00,6c,00,65,00,20,00,53,00,74,00,6f,00,72,00,61,00,67,00,65,00,\ 20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,52,00,65,00,6d,00,6f,\ 00,74,00,65,00,41,00,63,00,63,00,65,00,73,00,73,00,00,00,72,00,65,00,64,00,\ 62,00,6f,00,6f,00,6b,00,00,00,52,00,64,00,62,00,73,00,73,00,00,00,52,00,61,\ 00,73,00,4d,00,61,00,6e,00,00,00,52,00,61,00,73,00,41,00,75,00,74,00,6f,00,\ 00,00,71,00,6c,00,31,00,32,00,38,00,30,00,00,00,71,00,6c,00,31,00,32,00,34,\ 00,30,00,00,00,71,00,6c,00,31,00,32,00,31,00,36,00,30,00,00,00,71,00,6c,00,\ 31,00,30,00,77,00,6e,00,74,00,00,00,71,00,6c,00,31,00,30,00,38,00,30,00,00,\ 00,50,00,53,00,63,00,68,00,65,00,64,00,00,00,50,00,72,00,69,00,6e,00,74,00,\ 46,00,69,00,6c,00,74,00,65,00,72,00,50,00,69,00,70,00,65,00,6c,00,69,00,6e,\ 00,65,00,53,00,76,00,63,00,00,00,50,00,72,00,69,00,6e,00,74,00,00,00,50,00,\ 70,00,74,00,70,00,4d,00,69,00,6e,00,69,00,70,00,6f,00,72,00,74,00,00,00,50,\ 00,6f,00,6c,00,69,00,63,00,79,00,41,00,67,00,65,00,6e,00,74,00,00,00,50,00,\ 6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,4d,00,61,00,6e,00,61,00,67,00,65,\ 00,72,00,00,00,70,00,65,00,72,00,63,00,32,00,00,00,70,00,63,00,6d,00,63,00,\ 69,00,61,00,00,00,70,00,63,00,69,00,69,00,64,00,65,00,00,00,70,00,63,00,69,\ 00,00,00,70,00,61,00,72,00,76,00,64,00,6d,00,00,00,70,00,61,00,72,00,74,00,\ 6d,00,67,00,72,00,00,00,70,00,61,00,72,00,70,00,6f,00,72,00,74,00,00,00,4f,\ 00,53,00,50,00,46,00,4d,00,69,00,62,00,00,00,4f,00,53,00,50,00,46,00,00,00,\ 6e,00,76,00,00,00,6e,00,75,00,6c,00,6c,00,00,00,4e,00,74,00,53,00,65,00,72,\ 00,76,00,69,00,63,00,65,00,50,00,61,00,63,00,6b,00,00,00,6e,00,74,00,66,00,\ 73,00,00,00,6e,00,70,00,66,00,73,00,00,00,4e,00,6c,00,61,00,00,00,4e,00,49,\ 00,43,00,31,00,33,00,39,00,34,00,00,00,4e,00,45,00,54,00,77,00,34,00,78,00,\ 33,00,32,00,00,00,4e,00,65,00,74,00,6c,00,6f,00,67,00,6f,00,6e,00,00,00,4e,\ 00,65,00,74,00,44,00,44,00,45,00,00,00,4e,00,65,00,74,00,42,00,54,00,00,00,\ 4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,00,00,4e,00,64,00,69,00,73,00,57,\ 00,61,00,6e,00,00,00,6e,00,64,00,69,00,73,00,00,00,6e,00,61,00,70,00,69,00,\ 70,00,73,00,65,00,63,00,65,00,6e,00,66,00,00,00,6e,00,61,00,70,00,61,00,67,\ 00,65,00,6e,00,74,00,00,00,4d,00,75,00,70,00,00,00,6d,00,73,00,66,00,73,00,\ 00,00,4d,00,53,00,44,00,54,00,43,00,20,00,57,00,53,00,2d,00,41,00,54,00,20,\ 00,50,00,72,00,6f,00,74,00,6f,00,63,00,6f,00,6c,00,00,00,4d,00,53,00,44,00,\ 54,00,43,00,20,00,47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,6d,00,73,\ 00,61,00,64,00,6c,00,69,00,62,00,00,00,4d,00,72,00,78,00,53,00,6d,00,62,00,\ 00,00,4d,00,52,00,78,00,44,00,41,00,56,00,00,00,6d,00,72,00,61,00,69,00,64,\ 00,33,00,35,00,78,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,6d,00,\ 6f,00,75,00,63,00,6c,00,61,00,73,00,73,00,00,00,4d,00,6f,00,64,00,65,00,6d,\ 00,00,00,4c,00,73,00,61,00,53,00,72,00,76,00,00,00,4c,00,6d,00,48,00,6f,00,\ 73,00,74,00,73,00,00,00,4c,00,44,00,4d,00,53,00,00,00,4c,00,44,00,4d,00,00,\ 00,6c,00,62,00,72,00,74,00,66,00,64,00,63,00,00,00,4b,00,65,00,72,00,62,00,\ 65,00,72,00,6f,00,73,00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6b,\ 00,62,00,64,00,63,00,6c,00,61,00,73,00,73,00,00,00,69,00,73,00,61,00,70,00,\ 6e,00,70,00,00,00,49,00,50,00,58,00,53,00,41,00,50,00,00,00,49,00,50,00,58,\ 00,52,00,6f,00,75,00,74,00,65,00,72,00,4d,00,61,00,6e,00,61,00,67,00,65,00,\ 72,00,00,00,49,00,50,00,58,00,52,00,49,00,50,00,00,00,49,00,50,00,58,00,43,\ 00,50,00,00,00,49,00,50,00,53,00,65,00,63,00,00,00,49,00,50,00,52,00,6f,00,\ 75,00,74,00,65,00,72,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,49,\ 00,50,00,52,00,49,00,50,00,32,00,00,00,49,00,50,00,4e,00,41,00,54,00,48,00,\ 4c,00,50,00,00,00,49,00,50,00,4d,00,47,00,4d,00,00,00,49,00,50,00,42,00,4f,\ 00,4f,00,54,00,50,00,00,00,49,00,6e,00,74,00,65,00,72,00,6e,00,65,00,74,00,\ 20,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,20,00,38,00,00,00,49,\ 00,6e,00,74,00,65,00,72,00,6e,00,65,00,74,00,20,00,45,00,78,00,70,00,6c,00,\ 6f,00,72,00,65,00,72,00,20,00,37,00,20,00,44,00,69,00,73,00,6b,00,00,00,69,\ 00,6e,00,74,00,65,00,6c,00,70,00,70,00,6d,00,00,00,69,00,6e,00,74,00,65,00,\ 6c,00,69,00,64,00,65,00,00,00,69,00,6e,00,69,00,39,00,31,00,30,00,75,00,00,\ 00,49,00,47,00,4d,00,50,00,76,00,32,00,00,00,49,00,46,00,58,00,54,00,50,00,\ 4d,00,00,00,49,00,45,00,37,00,2d,00,4d,00,55,00,49,00,00,00,69,00,61,00,53,\ 00,74,00,6f,00,72,00,00,00,69,00,38,00,30,00,34,00,32,00,70,00,72,00,74,00,\ 00,00,69,00,32,00,6f,00,6d,00,70,00,00,00,69,00,32,00,6f,00,6d,00,67,00,6d,\ 00,74,00,00,00,48,00,74,00,74,00,70,00,00,00,68,00,70,00,6e,00,00,00,68,00,\ 70,00,64,00,73,00,6b,00,66,00,6c,00,74,00,00,00,48,00,42,00,74,00,6e,00,4b,\ 00,65,00,79,00,00,00,66,00,74,00,64,00,69,00,73,00,6b,00,00,00,66,00,73,00,\ 5f,00,72,00,65,00,63,00,00,00,66,00,6c,00,70,00,79,00,64,00,69,00,73,00,6b,\ 00,00,00,46,00,69,00,70,00,73,00,00,00,66,00,64,00,63,00,00,00,66,00,61,00,\ 73,00,74,00,66,00,61,00,74,00,00,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,\ 00,67,00,00,00,65,00,66,00,73,00,00,00,65,00,61,00,62,00,75,00,73,00,62,00,\ 00,00,65,00,61,00,62,00,66,00,69,00,6c,00,74,00,72,00,00,00,65,00,31,00,65,\ 00,78,00,70,00,72,00,65,00,73,00,73,00,00,00,44,00,72,00,69,00,76,00,65,00,\ 72,00,58,00,00,00,64,00,70,00,74,00,69,00,32,00,6f,00,00,00,44,00,6e,00,73,\ 00,63,00,61,00,63,00,68,00,65,00,00,00,44,00,6e,00,73,00,61,00,70,00,69,00,\ 00,00,64,00,6d,00,69,00,6f,00,00,00,64,00,6d,00,62,00,6f,00,6f,00,74,00,00,\ 00,44,00,69,00,73,00,74,00,72,00,69,00,62,00,75,00,74,00,65,00,64,00,20,00,\ 4c,00,69,00,6e,00,6b,00,20,00,54,00,72,00,61,00,63,00,6b,00,69,00,6e,00,67,\ 00,20,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,64,00,69,00,73,00,6b,00,\ 00,00,44,00,68,00,63,00,70,00,51,00,65,00,63,00,00,00,44,00,68,00,63,00,70,\ 00,00,00,44,00,66,00,73,00,53,00,76,00,63,00,00,00,44,00,66,00,73,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,00,00,44,00,43,00,4f,00,4d,00,00,00,64,00,61,\ 00,63,00,39,00,36,00,30,00,6e,00,74,00,00,00,64,00,61,00,63,00,32,00,77,00,\ 32,00,6b,00,00,00,64,00,33,00,34,00,37,00,62,00,75,00,73,00,00,00,63,00,72,\ 00,79,00,70,00,74,00,73,00,76,00,63,00,00,00,63,00,70,00,71,00,61,00,72,00,\ 72,00,61,00,79,00,00,00,63,00,6d,00,64,00,69,00,64,00,65,00,00,00,63,00,68,\ 00,61,00,6e,00,67,00,65,00,72,00,00,00,63,00,65,00,62,00,61,00,6c,00,00,00,\ 63,00,64,00,72,00,6f,00,6d,00,00,00,43,00,64,00,6d,00,00,00,63,00,64,00,66,\ 00,73,00,00,00,63,00,64,00,61,00,75,00,64,00,69,00,6f,00,00,00,63,00,64,00,\ 32,00,30,00,78,00,72,00,6e,00,74,00,00,00,63,00,62,00,69,00,64,00,66,00,32,\ 00,6b,00,00,00,42,00,54,00,57,00,44,00,4e,00,44,00,49,00,53,00,00,00,42,00,\ 54,00,44,00,72,00,69,00,76,00,65,00,72,00,00,00,42,00,72,00,6f,00,77,00,73,\ 00,65,00,72,00,00,00,42,00,49,00,54,00,53,00,00,00,62,00,65,00,65,00,70,00,\ 00,00,62,00,61,00,73,00,65,00,63,00,73,00,70,00,00,00,41,00,54,00,53,00,57,\ 00,50,00,44,00,52,00,56,00,00,00,41,00,74,00,6d,00,61,00,72,00,70,00,63,00,\ 00,00,61,00,74,00,64,00,69,00,73,00,6b,00,00,00,61,00,74,00,61,00,70,00,69,\ 00,00,00,41,00,73,00,79,00,6e,00,63,00,4d,00,61,00,63,00,00,00,61,00,73,00,\ 63,00,33,00,35,00,35,00,30,00,00,00,61,00,73,00,63,00,33,00,33,00,35,00,30,\ 00,70,00,00,00,61,00,73,00,63,00,00,00,41,00,72,00,70,00,31,00,33,00,39,00,\ 34,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,\ 00,20,00,50,00,6f,00,70,00,75,00,70,00,00,00,61,00,6d,00,73,00,69,00,6e,00,\ 74,00,00,00,61,00,6d,00,69,00,30,00,6e,00,74,00,00,00,61,00,6c,00,69,00,69,\ 00,64,00,65,00,00,00,41,00,6c,00,65,00,72,00,74,00,65,00,72,00,00,00,61,00,\ 69,00,63,00,37,00,38,00,78,00,78,00,00,00,61,00,69,00,63,00,37,00,38,00,75,\ 00,32,00,00,00,61,00,68,00,61,00,31,00,35,00,34,00,78,00,00,00,61,00,64,00,\ 70,00,75,00,31,00,36,00,30,00,6d,00,00,00,61,00,63,00,70,00,69,00,65,00,63,\ 00,00,00,61,00,63,00,70,00,69,00,00,00,61,00,62,00,70,00,34,00,38,00,30,00,\ 6e,00,35,00,00,00,61,00,62,00,69,00,6f,00,73,00,64,00,73,00,6b,00,00,00,53,\ 00,79,00,73,00,74,00,65,00,6d,00,00,00,00,00 "RestrictGuestAccess"=dword:00000001 "EventMessageFile"="%systemroot%\\system32\\stisvc.exe" "TypesSupported"=hex:07,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\abiosdsk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\abp480n5] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\acpi] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,63,00,70,00,69,00,2e,00,73,00,\ 79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\acpiec] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,63,00,70,00,69,00,65,00,63,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\adpu160m] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\aha154x] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\aic78u2] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\aic78xx] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Alerter] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\aliide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,41,00,6c,00,69,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ami0nt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\amsint] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Application Popup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,53,\ 00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,\ 79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,00,32,\ 00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Arp1394] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\asc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\asc3350p] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\asc3550] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\AsyncMac] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\atapi] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\atdisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Atmarpc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ATSWPDRV] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,41,00,54,00,53,00,77,00,70,00,44,00,\ 72,00,76,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\basecsp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\beep] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\BITS] "TypesSupported"=dword:00000007 "CategoryCount"=dword:00000001 "CategoryMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,78,00,70,00,6f,00,62,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "EventMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,6f,00,62,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Browser] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\BTDriver] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,62,00,74,00,70,00,6f,00,72,00,74,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\BTWDNDIS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cbidf2k] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cd20xrnt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cdaudio] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cdfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Cdm] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cdrom] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cebal] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,63,00,65,00,62,00,61,00,6c,00,2e,00,\ 73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\changer] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cmdide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,43,00,6d,00,64,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cpqarray] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\cryptsvc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,72,00,79,00,70,00,74,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\d347bus] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dac2w2k] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dac960nt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DCOM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DfsDriver] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DfsSvc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Dhcp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,68,00,63,00,70,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DhcpQec] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,68,00,63,00,70,00,71,00,65,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,64,00,68,00,63,00,70,00,71,00,65,00,63,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\disk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Distributed Link Tracking Client] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dmboot] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,62,00,6f,\ 00,6f,00,74,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dmio] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,69,00,6f,00,2e,00,73,00,\ 79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Dnsapi] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Dnscache] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\dpti2o] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\DriverX] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,44,00,72,00,69,00,76,00,65,00,72,00,\ 58,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\e1express] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,31,00,65,00,35,00,31,00,33,00,\ 32,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\eabfiltr] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\eabusb] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\efs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\eventlog] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\fastfat] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\fdc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,64,00,63,00,2e,00,73,00,79,00,\ 73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Fips] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,69,00,70,00,73,\ 00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\flpydisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,6c,00,70,00,79,00,64,00,69,00,\ 73,00,6b,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\fs_rec] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ftdisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,46,00,74,00,44,00,69,00,73,00,6b,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\HBtnKey] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\hpdskflt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,68,00,70,00,64,00,73,\ 00,6b,00,66,00,6c,00,74,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\hpn] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Http] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,78,00,70,00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\i2omgmt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\i2omp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\i8042prt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,38,00,30,00,34,00,32,00,70,00,\ 72,00,74,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\iaStor] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,61,00,53,00,74,00,6f,00,72,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IE7-MUI] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IFXTPM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,49,00,66,00,78,00,74,00,70,00,6d,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IGMPv2] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,67,00,6d,00,70,00,76,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ini910u] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\intelide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,6c,00,49,00,\ 64,00,65,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\intelppm] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,6e,00,74,00,65,00,6c,00,70,00,\ 70,00,6d,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 7 Disk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Internet Explorer 8] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPBOOTP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,70,00,62,00,6f,00,6f,00,74,00,70,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPMGM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,74,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPNATHLP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,70,00,6e,00,61,00,74,00,68,00,6c,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRIP2] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,70,00,72,00,69,00,70,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPRouterManager] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPSec] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPXCP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPXRIP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPXRouterManager] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\IPXSAP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\isapnp] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,73,00,61,00,70,00,6e,00,70,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdclass] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6b,00,62,00,64,00,63,00,6c,00,61,00,\ 73,00,73,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\kbdhid] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6b,00,62,00,64,00,68,00,69,00,64,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Kerberos] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6b,00,65,00,72,00,62,00,65,00,72,00,6f,00,73,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\lbrtfdc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6c,00,62,00,72,00,74,00,66,00,64,00,\ 63,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\LDM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,6d,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,65,00,78,00,65,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\LDMS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,6d,00,73,00,65,00,72,00,76,00,65,00,72,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\LmHosts] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\LsaSrv] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Modem] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,6f,00,64,00,65,00,6d,00,2e,00,\ 73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\mouclass] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6d,00,6f,00,75,00,63,00,6c,00,61,00,\ 73,00,73,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\mouhid] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6d,00,6f,00,75,00,68,00,69,00,64,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\mraid35x] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\MRxDAV] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\MrxSmb] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,69,00,6f,\ 00,6c,00,6f,00,67,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\msadlib] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\MSDTC Gateway] "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\EventLogMessages.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\MSDTC WS-AT Protocol] "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\EventLogMessages.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\msfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Mup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\napagent] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,71,00,61,00,67,00,65,00,6e,00,74,00,72,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\napipsecenf] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,61,00,70,00,69,00,70,00,73,00,65,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ndis] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NdisWan] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NetBIOS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,69,00,6f,00,6c,00,6f,00,67,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NetBT] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NetDDE] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Netlogon] "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NETw4x32] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,4e,00,45,00,54,00,77,00,34,00,78,00,\ 33,00,32,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NIC1394] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Nla] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\npfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ntfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\null] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\nv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,6e,00,76,00,34,00,5f,00,6d,00,69,00,\ 6e,00,69,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPF] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6f,00,73,00,70,00,66,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\OSPFMib] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6f,00,73,00,70,00,66,00,6d,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\parport] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,70,00,61,00,72,00,70,00,6f,00,72,00,\ 74,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\partmgr] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\parvdm] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,61,00,72,00,56,00,64,00,6d,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\pci] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,63,00,69,00,2e,00,73,00,79,00,\ 73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\pciide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,63,00,69,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\pcmcia] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\perc2] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PlugPlayManager] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,6d,00,70,00,6e,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PolicyAgent] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,6f,00,6c,00,61,00,67,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PptpMiniport] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Print] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,70,00,6c,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PrintFilterPipelineSvc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,50,00,72,00,69,00,6e,00,74,00,46,00,69,00,6c,00,74,00,65,00,72,00,50,\ 00,69,00,70,00,65,00,6c,00,69,00,6e,00,65,00,53,00,76,00,63,00,2e,00,65,00,\ 78,00,65,00,00,00 "TypesSupported"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PSched] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql1080] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql10wnt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql12160] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql1240] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ql1280] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RasAuto] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RasMan] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,3b,00,25,\ 00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,\ 53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,00,70,\ 00,33,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Rdbss] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\redbook] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,72,00,65,00,64,00,62,00,6f,00,6f,00,\ 6b,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RemoteAccess] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,69,00,61,00,73,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "TypesSupported"=dword:0000001f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Removable Storage Service] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,4e,00,54,00,4d,00,53,00,45,00,56,00,54,00,2e,00,44,00,4c,00,4c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\rismc32] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,72,00,69,00,73,00,6d,00,63,00,33,00,\ 32,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\RSVP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,73,00,76,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAM] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,61,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Save Dump] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,53,00,61,00,76,00,65,00,44,00,75,00,6d,00,70,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SCardSvr] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,53,00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Schedule] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\scsiport] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\serial] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,53,00,65,00,72,00,69,00,61,00,6c,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sermouse] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,65,00,72,00,6d,00,6f,00,75,00,\ 73,00,65,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Server] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Service Control Manager] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Setup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,79,00,73,00,73,00,65,00,74,00,75,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sfloppy] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SideBySide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,78,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Simbad] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SMSvcHost 3.0.0.0] "CategoryCount"=dword:0000000e "CategoryMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" "EventMessageFile"="c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelEvents.dll.mui" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sndblst] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sparrow] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sptd] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sr] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,49,00,\ 6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,3b,00,43,\ 00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,\ 73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,\ 00,53,00,5c,00,73,00,72,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\srservice] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,\ 72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Srv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SSDPSRV] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\StillImage] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,61,00,73,00,65,00,72,00,76,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\symc810] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\symc8xx] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sym_hi] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\sym_u3] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SynTP] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,53,00,79,00,6e,00,54,00,50,00,2e,00,\ 73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\System] "CategoryCount"=dword:00000007 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,64,00,6c,00,\ 6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\System Error] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Tcpip] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,\ 00,73,00,70,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TCPMon] "TypesSupported"=dword:00000007 "EventMessageFile"="%SystemRoot%\\System32\\tcpmon.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\tdi] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TermDD] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServDevices] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TermService] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,3b,\ 00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\ 5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,00,74,00,64,\ 00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\TermServSessDir] "TypesSupported"=dword:00000007 "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,74,00,73,00,73,00,64,00,69,00,73,00,2e,00,65,00,78,00,65,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\toside] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,54,00,6f,00,73,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\udfs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ultra] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\UltraMonMirror] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,55,00,6c,00,74,00,72,00,61,00,4d,00,\ 6f,00,6e,00,4d,00,69,00,72,00,72,00,6f,00,72,00,2e,00,73,00,79,00,73,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\UPS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\USER32] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,73,00,65,00,72,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\VgaSave] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,76,00,67,00,61,00,2e,00,73,00,79,00,\ 73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\viaide] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,56,00,69,00,61,00,49,00,64,00,65,00,\ 2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\VolSnap] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\ 25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,56,00,6f,00,6c,00,53,00,6e,00,61,00,\ 70,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\W32Time] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,\ 33,00,32,00,74,00,69,00,6d,00,65,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Wdf01000] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,77,00,64,00,66,00,30,\ 00,31,00,30,00,30,00,30,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Wdf01005] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Wdf01007] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,58,00,50,00,5f,00,32,00,6b,00,33,00,2e,\ 00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WGA] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WgaNotify] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Win32k] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,33,00,32,00,6b,00,2e,00,73,00,79,00,73,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows File Protection] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,66,00,63,00,5f,00,6f,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Installer 3.1] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Script Host] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000018 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Update Agent] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,75,00,61,00,75,00,63,00,70,00,6c,00,2e,00,63,00,70,00,6c,00,3b,\ 00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,75,00,61,\ 00,75,00,63,00,70,00,6c,00,2e,00,63,00,70,00,6c,00,2e,00,6d,00,75,00,69,00,\ 00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,77,00,75,00,61,00,75,00,63,00,70,00,6c,00,2e,00,63,00,70,00,6c,00,\ 2e,00,6d,00,75,00,69,00,00,00 "CategoryCount"=dword:00000009 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WindowsMedia] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WMPNetworkSvc] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\ 00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,57,00,69,00,6e,00,64,00,\ 6f,00,77,00,73,00,20,00,4d,00,65,00,64,00,69,00,61,00,20,00,50,00,6c,00,61,\ 00,79,00,65,00,72,00,5c,00,57,00,4d,00,50,00,4e,00,65,00,74,00,77,00,6b,00,\ 2e,00,65,00,78,00,65,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Workstation] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WPDClassInstaller] "CategoryCount"=dword:00000003 "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,\ 70,00,64,00,5f,00,63,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,\ 00,70,00,64,00,5f,00,63,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WPDMTPDriver] "CategoryCount"=dword:00000003 "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,6d,00,64,00,66,00,5c,00,77,\ 00,70,00,64,00,6d,00,74,00,70,00,64,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,\ 00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,6d,00,64,00,66,00,5c,00,\ 77,00,70,00,64,00,6d,00,74,00,70,00,64,00,72,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WpdUsb] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01000] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01005] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Wudf01007] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WZCSVC] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,7a,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\ZTEusbnet] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,\ 00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,\ 6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="COM+ Event System" "Group"="Network" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem\Parameters] "ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,65,00,73,00,\ 2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem\Security] "Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem\Enum] "0"="Root\\LEGACY_EVENTSYSTEM\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fastfat] "ErrorControl"=dword:00000001 "Group"="Boot file system" "Start"=dword:00000004 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fastfat\Enum] "0"="Root\\LEGACY_FASTFAT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Fast User Switching Compatibility" "DependOnService"=hex(7):54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,69,00,\ 63,00,65,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides management for applications that require assistance in a multiple user environment." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="BadApplicationServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Enum] "0"="Root\\LEGACY_FASTUSERSWITCHINGCOMPATIBILITY\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fdc] "ErrorControl"=dword:00000000 "Group"="System Bus Extender" "Start"=dword:00000001 "Tag"=dword:00000000 "Type"=dword:00000001 "SetupDone"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fdc\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fips] "ErrorControl"=dword:00000001 "Start"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fips\Enum] "0"="Root\\LEGACY_FIPS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FLEXnet Licensing Service] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,\ 00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,61,00,63,00,72,00,\ 6f,00,76,00,69,00,73,00,69,00,6f,00,6e,00,20,00,53,00,68,00,61,00,72,00,65,\ 00,64,00,5c,00,46,00,4c,00,45,00,58,00,6e,00,65,00,74,00,20,00,50,00,75,00,\ 62,00,6c,00,69,00,73,00,68,00,65,00,72,00,5c,00,46,00,4e,00,50,00,4c,00,69,\ 00,63,00,65,00,6e,00,73,00,69,00,6e,00,67,00,53,00,65,00,72,00,76,00,69,00,\ 63,00,65,00,2e,00,65,00,78,00,65,00,22,00,00,00 "DisplayName"="FLEXnet Licensing Service" "ObjectName"="LocalSystem" "Description"="This service performs licensing functions on behalf of FLEXnet enabled products." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FLEXnet Licensing Service\Security] "Security"=hex:01,00,14,80,a4,00,00,00,b0,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,74,00,05,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 01,00,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\ 00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\ 02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FLEXnet Licensing Service\Enum] "0"="Root\\LEGACY_FLEXNET_LICENSING_SERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Flpydisk] "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Flpydisk\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FltMgr] "Type"=dword:00000002 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,6c,00,74,00,6d,00,67,00,72,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="FltMgr" "Group"="FSFilter Infrastructure" "Description"="File System Filter Manager Driver" "AttachWhenLoaded"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FltMgr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FltMgr\Enum] "0"="Root\\LEGACY_FLTMGR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):63,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,4e,00,45,\ 00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,00,5c,00,\ 76,00,33,00,2e,00,30,00,5c,00,57,00,50,00,46,00,5c,00,50,00,72,00,65,00,73,\ 00,65,00,6e,00,74,00,61,00,74,00,69,00,6f,00,6e,00,46,00,6f,00,6e,00,74,00,\ 43,00,61,00,63,00,68,00,65,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Windows Presentation Foundation Font Cache 3.0.0.0" "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications." "FailureActions"=hex:00,a5,ff,ff,01,00,00,00,01,00,00,00,03,00,00,00,45,00,57,\ 00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0\Security] "Security"=hex:01,00,14,80,a4,00,00,00,b0,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,74,00,05,00,00,00,00,00,14,00,10,00,00,00,01,01,00,00,00,00,00,\ 05,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\ 00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\ 02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0\Enum] "0"="Root\\LEGACY_FONTCACHE3.0.0.0\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fs_Rec] "ErrorControl"=dword:00000000 "Group"="Boot file system" "Start"=dword:00000001 "Type"=dword:00000008 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fs_Rec\Enum] "0"="Root\\LEGACY_FS_REC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTD2XX] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000016 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,46,00,54,00,44,00,32,00,58,00,58,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="FTD2XX.SYS FT8U2XX device driver" "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTD2XX\Parameters] "MaximumTransferSize"=dword:00001000 "DebugLevel"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTD2XX\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTDIBUS] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000001b "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,74,00,64,00,69,00,62,00,75,\ 00,73,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="USB Serial Converter Driver" "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTDIBUS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTDIBUS\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ftdisk] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000009 "Type"=dword:00000001 "DisplayName"="Volume Manager Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,66,00,74,00,64,00,69,00,73,00,6b,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ftdisk\Enum] "0"="Root\\ftdisk\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTSER2K] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000001c "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,74,00,73,00,65,00,72,00,32,\ 00,6b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="USB Serial Port Driver" "Group"="Base" "ForceFifoEnable"=dword:00000001 "RxFIFO"=dword:00000008 "TxFIFO"=dword:0000000e "PermitShare"=dword:00000000 "LogFifo"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTSER2K\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTSER2K\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gpc] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000006 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,73,00,67,00,70,00,63,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Generic Packet Classifier" "Group"="PNP_TDI" "Description"="Generic Packet Classifier" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gpc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Gpc\Enum] "0"="Root\\LEGACY_GPC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HBtnKey] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "Tag"=dword:0000000b "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,63,00,70,00,71,00,62,00,74,00,74,\ 00,6e,00,2e,00,73,00,79,00,73,00,00,00 "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HBtnKey\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HBtnKey\Enum] "0"="ACPI\\HPQ0006\\2&daba3ff&0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HDAudBus] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000007 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,48,00,44,00,41,00,75,00,64,00,42,\ 00,75,00,73,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft UAA Bus Driver for High Definition Audio" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HDAudBus\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HDAudBus\Enum] "0"="PCI\\VEN_8086&DEV_284B&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&D8" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Help and Support" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,05,00,03,\ 00,01,00,00,00,64,00,00,00,01,00,00,00,64,00,00,00,00,00,00,00,64,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc\Parameters] "ServiceDll"=hex(2):25,00,57,00,49,00,4e,00,44,00,49,00,52,00,25,00,5c,00,50,\ 00,43,00,48,00,65,00,61,00,6c,00,74,00,68,00,5c,00,48,00,65,00,6c,00,70,00,\ 43,00,74,00,72,00,5c,00,42,00,69,00,6e,00,61,00,72,00,69,00,65,00,73,00,5c,\ 00,70,00,63,00,68,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc\Enum] "0"="Root\\LEGACY_HELPSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidServ] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="HID Input Service" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidServ\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 68,00,69,00,64,00,73,00,65,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidServ\Enum] "0"="Root\\LEGACY_HIDSERV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidUsb] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "Tag"=dword:0000000c "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,68,00,69,00,64,00,75,00,73,00,62,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft HID Class Driver" "Group"="extended base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidUsb\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidUsb\Enum] "0"="USB\\Vid_046d&Pid_c03d\\6&1633edb3&0&3" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="USB\\Vid_046d&Pid_c312\\6&1633edb3&0&4" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hkmsvc] "DisplayName"="Health Key and Certificate Management Service" "Description"="Manages health certificates and keys (used by NAP)" "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "ObjectName"="localSystem" "FailureActions"=hex:5a,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,65,00,79,\ 00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6b,00,6d,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpdskflt] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000003 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,68,00,70,00,64,00,73,00,6b,00,66,\ 00,6c,00,74,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="HP Disk Filter Driver" "Group"="PnP Filter" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpdskflt\Parameters] "SecondDriveNotSupported"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpdskflt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpdskflt\Enum] "0"="IDE\\DiskST9200420AS_____________________________3.AHC___\\533530483547304b202020202020202020202020" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpn] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpn\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpn\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HpqKbFiltr] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "Tag"=dword:00000006 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,48,00,70,00,71,00,4b,00,62,00,46,\ 00,69,00,6c,00,74,00,72,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="HpqKbFilter Driver" "Group"="Keyboard Port" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HpqKbFiltr\Parameters] "MaxButtons"=dword:0000000c "Buttons"=hex:01,e0,00,00,31,01,00,00,20,e0,00,00,ea,03,00,00,2e,e0,00,00,e9,\ 03,00,00,30,e0,00,00,e8,03,00,00,23,e0,00,00,f5,01,00,00,1f,e0,00,00,f6,01,\ 00,00,1a,e0,00,00,91,01,00,00,1e,e0,00,00,92,01,00,00,13,e0,00,00,f7,01,00,\ 00,14,e0,00,00,f8,01,00,00,15,e0,00,00,f9,01,00,00,1b,e0,00,00,fa,01,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HpqKbFiltr\Parameters\Wdf] "KmdfLibraryVersion"="1.5" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HpqKbFiltr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpqwmiex] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,\ 20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,48,00,65,00,77,00,6c,00,65,00,74,\ 00,74,00,2d,00,50,00,61,00,63,00,6b,00,61,00,72,00,64,00,5c,00,53,00,68,00,\ 61,00,72,00,65,00,64,00,5c,00,68,00,70,00,71,00,57,00,6d,00,69,00,45,00,78,\ 00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="hpqwmiex" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,57,00,69,00,6e,00,\ 4d,00,67,00,6d,00,74,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpqwmiex\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpqwmiex\Enum] "0"="Root\\LEGACY_HPQWMIEX\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HSFHWAZL] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,48,00,53,00,46,00,48,00,57,00,41,\ 00,5a,00,4c,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HSFHWAZL\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HSFHWAZL\Enum] "0"="HDAUDIO\\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_103C1379&REV_1000\\4&1d8c0f4e&0&0102" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HSF_DPV] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,48,00,53,00,46,00,5f,00,44,00,50,\ 00,56,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HSF_DPV\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HSF_DPV\Enum] "0"="HDAUDIO\\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_103C1379&REV_1000\\4&1d8c0f4e&0&0102" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP] "DisplayName"="HTTP" "Description"="This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start." "ErrorControl"=dword:00000001 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,48,00,54,00,54,00,50,00,2e,00,73,\ 00,79,00,73,00,00,00 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\SslBindingInfo] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo] "http://*:2869/"=hex:01,00,04,80,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,\ 00,02,00,1c,00,01,00,00,00,00,00,14,00,00,00,00,20,01,01,00,00,00,00,00,05,\ 13,00,00,00 "http://+:10243/WMPNSSv3/"=hex:01,00,04,80,00,00,00,00,00,00,00,00,00,00,00,00,\ 14,00,00,00,02,00,1c,00,01,00,00,00,00,03,14,00,3f,00,0f,00,01,01,00,00,00,\ 00,00,05,14,00,00,00 "http://+:8731/Design_Time_Addresses/"=hex:01,00,04,80,00,00,00,00,00,00,00,00,\ 00,00,00,00,14,00,00,00,02,00,1c,00,01,00,00,00,00,00,14,00,00,00,00,20,01,\ 01,00,00,00,00,00,05,04,00,00,00 "http://+:80/Temporary_Listen_Addresses/"=hex:01,00,04,80,00,00,00,00,00,00,00,\ 00,00,00,00,00,14,00,00,00,02,00,1c,00,01,00,00,00,00,00,14,00,00,00,00,20,\ 01,01,00,00,00,00,00,01,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Security] "Security"=hex:01,00,14,80,b8,00,00,00,c4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,88,00,06,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,\ 14,00,14,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,14,00,14,00,00,\ 00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Enum] "0"="Root\\LEGACY_HTTP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter] "DependOnService"=hex(7):48,00,54,00,54,00,50,00,00,00,00,00 "Description"="This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="HTTP SSL" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,48,00,54,00,54,00,50,00,46,00,69,00,6c,00,74,00,65,00,72,00,00,\ 00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,33,00,73,00,73,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="HTTPFilterServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter\Security] "Security"=hex:01,00,14,80,b8,00,00,00,c4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,88,00,06,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,\ 14,00,14,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,14,00,14,00,00,\ 00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter\Enum] "0"="Root\\LEGACY_HTTPFILTER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omgmt] "ErrorControl"=dword:00000001 "Group"="SCSI Class" "Start"=dword:00000001 "Tag"=dword:0000002d "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000002d "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt] "Type"=dword:00000001 "Start"=dword:00000001 "Group"="Keyboard Port" "ErrorControl"=dword:00000001 "DisplayName"="i8042 Keyboard and PS/2 Mouse Port Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,38,00,30,00,34,00,32,00,70,\ 00,72,00,74,00,2e,00,73,00,79,00,73,00,00,00 "Tag"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt\Parameters] "PollingIterations"=dword:00002ee0 "PollingIterationsMaximum"=dword:00002ee0 "ResendIterations"=dword:00000003 "MouseDataQueueSize"=dword:00000084 "LayerDriver JPN"="kbd101.dll" "LayerDriver KOR"="kbd101a.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt\Enum] "0"="ACPI\\PNP0303\\4&374ccb25&0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="ACPI\\SYN0136\\4&374ccb25&0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iaStor] "Type"=dword:00000001 "Start"=dword:00000000 "Tag"=dword:00000019 "ErrorControl"=dword:00000001 "DisplayName"="Intel AHCI Controller" "LoadOrderGroup"="SCSI Miniport" "Security"="" "Description"="" "ImagePath"="System32\\DRIVERS\\iaStor.sys" "Group"="SCSI Miniport" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iaStor\Parameters] "queuePriorityEnable"=dword:00000000 "BusType"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iaStor\Parameters\Port0] "AN"=dword:00000000 "LPM"=dword:00000001 "LPMSTATE"=dword:00000000 "LPMDSTATE"=dword:00000001 "GTF"=dword:00000001 "DIPM"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iaStor\Parameters\Port1] "AN"=dword:00000000 "LPM"=dword:00000001 "LPMSTATE"=dword:00000000 "LPMDSTATE"=dword:00000001 "GTF"=dword:00000001 "DIPM"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iaStor\Parameters\Port2] "AN"=dword:00000000 "LPM"=dword:00000001 "LPMSTATE"=dword:00000000 "LPMDSTATE"=dword:00000001 "GTF"=dword:00000001 "DIPM"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iaStor\Enum] "0"="Root\\LEGACY_IASTOR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IDriverT] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,\ 00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,49,00,6e,00,73,00,74,00,\ 61,00,6c,00,6c,00,53,00,68,00,69,00,65,00,6c,00,64,00,5c,00,44,00,72,00,69,\ 00,76,00,65,00,72,00,5c,00,31,00,30,00,35,00,30,00,5c,00,49,00,6e,00,74,00,\ 65,00,6c,00,20,00,33,00,32,00,5c,00,49,00,44,00,72,00,69,00,76,00,65,00,72,\ 00,54,00,2e,00,65,00,78,00,65,00,22,00,00,00 "DisplayName"="InstallDriver Table Manager" "ObjectName"="LocalSystem" "Description"="Provides support for the Running Object Table for InstallShield Drivers" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IDriverT\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IDriverT\Enum] "0"="Root\\LEGACY_IDRIVERT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\idsvc] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,\ 53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,4e,\ 00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,00,\ 5c,00,76,00,33,00,2e,00,30,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,\ 00,20,00,43,00,6f,00,6d,00,6d,00,75,00,6e,00,69,00,63,00,61,00,74,00,69,00,\ 6f,00,6e,00,20,00,46,00,6f,00,75,00,6e,00,64,00,61,00,74,00,69,00,6f,00,6e,\ 00,5c,00,69,00,6e,00,66,00,6f,00,63,00,61,00,72,00,64,00,2e,00,65,00,78,00,\ 65,00,22,00,00,00 "DisplayName"="Windows CardSpace" "ObjectName"="LocalSystem" "Description"="Securely enables the creation, management, and disclosure of digital identities." "FailureActions"=hex:84,03,00,00,00,00,00,00,00,00,00,00,03,00,00,00,45,00,57,\ 00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\idsvc\Security] "Security"=hex:01,00,14,80,b8,00,00,00,c4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,88,00,06,00,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,03,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,\ 14,00,14,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,14,00,14,00,00,\ 00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IFXTPM] "InitHW"=dword:00000000 "InterruptModus"=dword:00000000 "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,49,00,46,00,58,00,54,00,50,00,4d,\ 00,2e,00,53,00,59,00,53,00,00,00 "DisplayName"="IFXTPM" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IFXTPM\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IFXTPM\Enum] "0"="ACPI\\IFX0102\\4&374ccb25&0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Imapi] "ErrorControl"=dword:00000001 "Group"="Pnp Filter" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="CD-Burning Filter Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6d,00,61,00,70,00,69,00,2e,\ 00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Imapi\Enum] "0"="IDE\\CdRomOptiarc_DVD_RW_AD-7560A_________________DH10____\\3033343638373034312039393838323531513131" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ImapiService] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,\ 53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,69,00,6d,\ 00,61,00,70,00,69,00,2e,00,65,00,78,00,65,00,22,00,00,00 "ObjectName"="LocalSystem" "DisplayName"="IMAPI CD-Burning COM Service" "Description"="Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ImapiService\Enum] "0"="Root\\LEGACY_IMAPISERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\inetaccs] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\inetaccs\Parameters] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ini910u] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000030 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ini910u\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ini910u\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Inport] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Inport\Parameters] "HzMode"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IntelIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000004 "Type"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6e,00,74,00,65,00,6c,00,69,\ 00,64,00,65,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IntelIde\Enum] "0"="Root\\LEGACY_INTELIDE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000006 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6e,00,74,00,65,00,6c,00,70,\ 00,70,00,6d,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Intel Processor Driver" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm\Enum] "0"="ACPI\\GenuineIntel_-_x86_Family_6_Model_23\\_0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="ACPI\\GenuineIntel_-_x86_Family_6_Model_23\\_1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ip6Fw] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,70,00,36,00,66,00,77,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="IPv6 Windows Firewall Driver" "Description"="Provides intrusion prevention service for a home or small office network." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ip6Fw\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpFilterDriver] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,66,00,6c,00,74,00,64,\ 00,72,00,76,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IP Traffic Filter Driver" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="IP Traffic Filter Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpFilterDriver\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpInIp] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,69,00,6e,00,69,00,70,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IP in IP Tunnel Driver" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="IP in IP Tunnel Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpInIp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpNat] "DependOnGroup"=hex(7):00,00 "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "Description"="IP Network Address Translator" "DisplayName"="IP Network Address Translator" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,6e,00,61,00,74,00,2e,\ 00,73,00,79,00,73,00,00,00 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpNat\Enum] "0"="Root\\LEGACY_IPNAT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSec] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,73,00,65,00,63,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="IPSEC driver" "Group"="PNP_TDI" "Description"="IPSEC driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSec\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSec\Enum] "0"="Root\\LEGACY_IPSEC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRENUM] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,72,00,65,00,6e,00,75,00,6d,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IR Enumerator Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRENUM\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ISAPISearch] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ISAPISearch\Linkage] "Bind"="\\Dummy" "Export"="\\Dummy" "Route"="\\Dummy" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ISAPISearch\Performance] "Close"="DoneCIISAPIPerformanceData" "Collect"="CollectCIISAPIPerformanceData" "Open"="InitializeCIISAPIPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\ 00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "WbemAdapFileSignature"=hex:43,e4,75,89,53,f4,54,09,0c,ad,65,c3,03,79,6e,d5 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:0015e800 "WbemAdapStatus"=dword:00000000 "Last Counter"=dword:00001444 "Last Help"=dword:00001445 "First Counter"=dword:00001430 "First Help"=dword:00001431 "Object List"="5168" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp] "ErrorControl"=dword:00000003 "Group"="Boot Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000003 "Type"=dword:00000001 "HasBootConfig"=dword:00000000 "DisplayName"="PnP ISA/EISA Bus Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,73,00,61,00,70,00,6e,00,70,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp\Parameters] "ADP1502"=dword:00000001 "ADP1505"=dword:00000001 "ADP1510"=dword:00000001 "ADP1512"=dword:00000001 "ADP1515"=dword:00000001 "ADP1520"=dword:00000001 "ADP1522"=dword:00000001 "ADP3015"=dword:00000001 "ADP3215"=dword:00000001 "ADP6360"=dword:00000001 "ADP6370"=dword:00000001 "USR0014"=dword:00000001 "USR1001"=dword:00000001 "USR1002"=dword:00000001 "USR1003"=dword:00000001 "USR1004"=dword:00000001 "USR6001"=dword:00000001 "USR6002"=dword:00000001 "USR6003"=dword:00000001 "USR6004"=dword:00000001 "USR6005"=dword:00000001 "USR6006"=dword:00000001 "USR6007"=dword:00000001 "USR6008"=dword:00000001 "USR6009"=dword:00000001 "USR600A"=dword:00000001 "USR600B"=dword:00000001 "USR600C"=dword:00000001 "USR600D"=dword:00000001 "USR600E"=dword:00000001 "USR600F"=dword:00000001 "USR6010"=dword:00000001 "USR6011"=dword:00000001 "USR6012"=dword:00000001 "USR6101"=dword:00000001 "USR6020"=dword:00000001 "USR0041"=dword:00000001 "USR002C"=dword:00000001 "AZT4029"=dword:00000001 "AZT4023"=dword:00000001 "USR0040"=dword:00000001 "HAY8601"=dword:00000001 "EQX2400"=dword:00000002 "EQX0900"=dword:00000002 "EQX1B00"=dword:00000002 "EQX1700"=dword:00000002 "EQX0700"=dword:00000002 "EQX0F00"=dword:00000002 "EQX0800"=dword:00000002 "EQX1000"=dword:00000002 "EQX3F00"=dword:00000002 "EQX1200"=dword:00000002 "IBM0001"=dword:00000010 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp\Enum] "0"="PCI\\VEN_8086&DEV_2811&SUBSYS_00000000&REV_03\\3&b1bfb68&0&F8" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JavaQuickStarterService] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,5c,\ 00,6a,00,72,00,65,00,36,00,5c,00,62,00,69,00,6e,00,5c,00,6a,00,71,00,73,00,\ 2e,00,65,00,78,00,65,00,22,00,20,00,2d,00,73,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,20,00,2d,00,63,00,6f,00,6e,00,66,00,69,00,67,00,20,00,22,00,43,00,\ 3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,\ 00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,5c,00,6a,00,72,00,65,00,36,00,\ 5c,00,6c,00,69,00,62,00,5c,00,64,00,65,00,70,00,6c,00,6f,00,79,00,5c,00,6a,\ 00,71,00,73,00,5c,00,6a,00,71,00,73,00,2e,00,63,00,6f,00,6e,00,66,00,22,00,\ 00,00 "DisplayName"="Java Quick Starter" "ObjectName"="LocalSystem" "Description"="Prefetches JRE files for faster startup of Java applets and applications" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JavaQuickStarterService\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JavaQuickStarterService\Enum] "0"="Root\\LEGACY_JAVAQUICKSTARTERSERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kbdclass] "ErrorControl"=dword:00000001 "Group"="Keyboard Class" "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Keyboard Class Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6b,00,62,00,64,00,63,00,6c,00,61,\ 00,73,00,73,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kbdclass\Parameters] "ConnectMultiplePorts"=dword:00000000 "KeyboardDataQueueSize"=dword:00000064 "KeyboardDeviceBaseName"="KeyboardClass" "MaximumPortsServiced"=dword:00000003 "SendOutputToAllPorts"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kbdclass\Enum] "0"="Root\\RDP_KBD\\0000" "Count"=dword:00000004 "NextInstance"=dword:00000004 "1"="ACPI\\PNP0303\\4&374ccb25&0" "2"="HID\\HPQ0006&Col02\\3&563a312&0&0001" "3"="HID\\Vid_046d&Pid_c312\\7&221620e8&0&0000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000000 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6b,00,62,00,64,00,68,00,69,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Keyboard HID Driver" "Group"="Keyboard Port" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid\Parameters] "WorkNicely"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid\Enum] "0"="HID\\HPQ0006&Col02\\3&563a312&0&0001" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="HID\\Vid_046d&Pid_c312\\7&221620e8&0&0000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,6b,00,6d,00,69,00,78,00,65,00,72,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel Wave Audio Mixer" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KSecDD] "ErrorControl"=dword:00000001 "Group"="Base" "Start"=dword:00000000 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KSecDD\Enum] "0"="Root\\LEGACY_KSECDD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Server" "ObjectName"="LocalSystem" "Description"="Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\AutotunedParameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\DefaultSecurity] "SrvsvcConfigInfo"=hex:01,00,04,80,a0,00,00,00,ac,00,00,00,00,00,00,00,14,00,\ 00,00,02,00,8c,00,06,00,00,00,00,00,18,00,17,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,20,02,00,00,00,00,18,00,17,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,25,02,00,00,00,00,14,00,17,00,0f,00,01,01,00,00,00,00,00,05,12,\ 00,00,00,00,00,18,00,03,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,\ 00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,00,00,00,00,00,14,\ 00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcTransportEnum"=hex:01,00,04,80,8c,00,00,00,98,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,78,00,05,00,00,00,00,00,18,00,17,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,17,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,14,00,17,00,0f,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,00,00,18,00,03,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,0b,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcConnection"=hex:01,00,04,80,7c,00,00,00,88,00,00,00,00,00,00,00,14,00,\ 00,00,02,00,68,00,04,00,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,20,02,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,25,02,00,00,00,00,18,00,01,00,00,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,26,02,00,00,00,00,18,00,01,00,00,00,01,02,00,00,00,00,00,05,20,00,\ 00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00 "SrvsvcServerDiskEnum"=hex:01,00,04,80,4c,00,00,00,58,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,38,00,02,00,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\ 00,00,00,05,12,00,00,00 "SrvsvcFile"=hex:01,00,04,80,64,00,00,00,70,00,00,00,00,00,00,00,14,00,00,00,\ 02,00,50,00,03,00,00,00,00,00,18,00,11,00,0f,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,20,02,00,00,00,00,18,00,11,00,0f,00,01,02,00,00,00,00,00,05,20,00,\ 00,00,25,02,00,00,00,00,18,00,11,00,0f,00,01,02,00,00,00,00,00,05,20,00,00,\ 00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00 "SrvsvcShareFileInfo"=hex:01,00,04,80,8c,00,00,00,98,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,78,00,05,00,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,23,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,\ 00,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcSharePrintInfo"=hex:01,00,04,80,a4,00,00,00,b0,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,90,00,06,00,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,26,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,23,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcShareAdminInfo"=hex:01,00,04,80,8c,00,00,00,98,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,78,00,05,00,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,02,00,00,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,18,00,02,00,00,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,23,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,\ 00,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcShareConnect"=hex:01,00,04,80,8c,00,00,00,98,00,00,00,00,00,00,00,14,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,20,02,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,25,02,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,27,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,07,00,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 "SrvsvcShareAdminConnect"=hex:01,00,04,80,64,00,00,00,70,00,00,00,00,00,00,00,\ 14,00,00,00,02,00,50,00,03,00,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,\ 00,00,05,20,00,00,00,20,02,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,25,02,00,00,00,00,18,00,03,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,27,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\ 00,00,00,05,12,00,00,00 "SrvsvcStatisticsInfo"=hex:01,00,04,80,60,00,00,00,6c,00,00,00,00,00,00,00,14,\ 00,00,00,02,00,4c,00,03,00,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,\ 00,05,20,00,00,00,20,02,00,00,00,00,18,00,01,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,25,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,02,\ 00,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,\ 00,00,00 "AnonymousDescriptorsUpgraded"=dword:00000001 "PreviousAnonymousRestriction"=dword:00000000 "SrvsvcSessionInfo"=hex:01,00,04,80,78,00,00,00,84,00,00,00,00,00,00,00,14,00,\ 00,00,02,00,64,00,04,00,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,20,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,25,02,00,00,00,00,18,00,13,00,0f,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,23,02,00,00,00,00,14,00,01,00,00,00,01,01,00,00,00,00,00,05,0b,00,\ 00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,\ 00 "SessionSecurityDescriptorRegenerated"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,\ 2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,\ 00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,\ 46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,\ 7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,38,00,37,\ 00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,\ 45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,39,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,\ 42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,33,00,30,\ 00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,\ 36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,\ 00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,\ 65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,\ 00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,\ 38,00,35,00,2d,00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,\ 00,41,00,39,00,33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,\ 30,00,35,00,42,00,38,00,33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,\ 70,00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,\ 00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,\ 41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,\ 00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,\ 65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,\ 00,31,00,44,00,39,00,42,00,37,00,30,00,33,00,2d,00,43,00,30,00,36,00,46,00,\ 2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,34,00,44,00,36,00,2d,00,44,00,41,\ 00,43,00,35,00,42,00,33,00,34,00,44,00,42,00,32,00,36,00,41,00,7d,00,00,00,\ 5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,\ 00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,00,45,00,30,00,43,00,\ 46,00,34,00,45,00,46,00,2d,00,43,00,42,00,31,00,31,00,2d,00,34,00,35,00,35,\ 00,43,00,2d,00,41,00,33,00,31,00,30,00,2d,00,42,00,37,00,46,00,33,00,38,00,\ 36,00,39,00,38,00,42,00,36,00,42,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,\ 00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,\ 70,00,69,00,70,00,5f,00,7b,00,37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,\ 00,2d,00,38,00,37,00,46,00,34,00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,\ 46,00,42,00,39,00,2d,00,43,00,35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,\ 00,34,00,46,00,30,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,\ 00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,\ 42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,\ 00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,\ 7d,00,00,00,00,00 "Route"=hex(7):22,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,\ 00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,\ 63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,41,00,30,00,33,00,36,00,44,\ 00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,\ 38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,\ 00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,22,00,00,00,22,00,4e,00,65,00,\ 74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,\ 00,22,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,\ 38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,\ 00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,\ 39,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,\ 00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,35,00,33,00,30,00,\ 30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,\ 00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,\ 45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,22,00,00,00,22,00,4e,\ 00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,\ 22,00,20,00,22,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,\ 00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,\ 33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,\ 00,38,00,33,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,\ 20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,32,00,39,\ 00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,\ 34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,\ 00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,22,00,00,00,\ 22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,\ 00,70,00,22,00,20,00,22,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,\ 33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,\ 00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,\ 42,00,32,00,36,00,41,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,\ 00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,\ 64,00,69,00,73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,22,00,4e,00,65,\ 00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,\ 20,00,22,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,\ 00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,\ 44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,\ 00,39,00,7d,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,\ 00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,\ 74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,00,00,5c,00,44,00,65,00,76,\ 00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,\ 72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,\ 00,70,00,69,00,70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,\ 34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,\ 00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,\ 46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,\ 00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,\ 72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,\ 38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,\ 00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,\ 39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,\ 00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,5f,00,4e,00,\ 65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,\ 00,33,00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,\ 2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,\ 00,32,00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,00,00,\ 5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,\ 00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,46,00,45,00,34,\ 00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,\ 35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,\ 00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,\ 00,72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,\ 63,00,70,00,69,00,70,00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,\ 00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,\ 41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,\ 00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,\ 00,72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,\ 70,00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,33,00,2d,00,43,\ 00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,34,00,44,00,\ 36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,42,00,32,00,36,\ 00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,\ 61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,5f,00,4e,\ 00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,\ 39,00,45,00,30,00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,42,00,31,00,31,\ 00,2d,00,34,00,35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,00,2d,00,42,00,\ 37,00,46,00,33,00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,35,00,7d,00,00,\ 00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,\ 61,00,6e,00,53,00,65,00,72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,74,00,42,\ 00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,43,00,30,00,\ 30,00,42,00,31,00,42,00,46,00,2d,00,38,00,37,00,46,00,34,00,2d,00,34,00,34,\ 00,36,00,32,00,2d,00,42,00,46,00,42,00,39,00,2d,00,43,00,35,00,41,00,38,00,\ 42,00,43,00,34,00,31,00,36,00,34,00,46,00,30,00,7d,00,00,00,5c,00,44,00,65,\ 00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,\ 65,00,72,00,76,00,65,00,72,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,\ 00,63,00,70,00,69,00,70,00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,\ 37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,\ 00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,\ 38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters] "autodisconnect"=dword:0000000f "enableforcedlogoff"=dword:00000001 "enablesecuritysignature"=dword:00000000 "requiresecuritysignature"=dword:00000000 "NullSessionPipes"=hex(7):43,00,4f,00,4d,00,4e,00,41,00,50,00,00,00,43,00,4f,\ 00,4d,00,4e,00,4f,00,44,00,45,00,00,00,53,00,51,00,4c,00,5c,00,51,00,55,00,\ 45,00,52,00,59,00,00,00,53,00,50,00,4f,00,4f,00,4c,00,53,00,53,00,00,00,4c,\ 00,4c,00,53,00,52,00,50,00,43,00,00,00,62,00,72,00,6f,00,77,00,73,00,65,00,\ 72,00,00,00,00,00 "NullSessionShares"=hex(7):43,00,4f,00,4d,00,43,00,46,00,47,00,00,00,44,00,46,\ 00,53,00,24,00,00,00,00,00 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,72,00,76,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "Lmannounce"=dword:00000000 "Size"=dword:00000002 "Guid"=hex:d4,96,f1,cf,b2,5c,c0,45,b8,2d,f2,47,66,9e,05,3f "AdjustedNullSessionPipes"=dword:00000001 "CachedOpenLimit"=dword:00000000 "DisableDos"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Shares] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Shares\Security] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Enum] "0"="Root\\LEGACY_LANMANSERVER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Workstation" "Group"="NetworkProvider" "ObjectName"="LocalSystem" "Description"="Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,\ 2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,\ 00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,\ 46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,\ 7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,38,00,37,\ 00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,\ 45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,39,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,\ 42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,33,00,30,\ 00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,\ 36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,\ 00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,\ 65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,\ 00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,\ 38,00,35,00,2d,00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,\ 00,41,00,39,00,33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,\ 30,00,35,00,42,00,38,00,33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,\ 70,00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,\ 00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,\ 41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,\ 00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,\ 65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,\ 00,31,00,44,00,39,00,42,00,37,00,30,00,33,00,2d,00,43,00,30,00,36,00,46,00,\ 2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,34,00,44,00,36,00,2d,00,44,00,41,\ 00,43,00,35,00,42,00,33,00,34,00,44,00,42,00,32,00,36,00,41,00,7d,00,00,00,\ 5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,\ 00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,00,45,00,30,00,43,00,\ 46,00,34,00,45,00,46,00,2d,00,43,00,42,00,31,00,31,00,2d,00,34,00,35,00,35,\ 00,43,00,2d,00,41,00,33,00,31,00,30,00,2d,00,42,00,37,00,46,00,33,00,38,00,\ 36,00,39,00,38,00,42,00,36,00,42,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,\ 00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,\ 70,00,69,00,70,00,5f,00,7b,00,37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,\ 00,2d,00,38,00,37,00,46,00,34,00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,\ 46,00,42,00,39,00,2d,00,43,00,35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,\ 00,34,00,46,00,30,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,\ 00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,\ 42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,\ 00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,\ 7d,00,00,00,00,00 "Route"=hex(7):22,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,\ 00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,\ 63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,41,00,30,00,33,00,36,00,44,\ 00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,\ 38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,\ 00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,22,00,00,00,22,00,4e,00,65,00,\ 74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,\ 00,22,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,\ 38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,\ 00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,\ 39,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,\ 00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,35,00,33,00,30,00,\ 30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,\ 00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,\ 45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,22,00,00,00,22,00,4e,\ 00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,\ 22,00,20,00,22,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,\ 00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,\ 33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,\ 00,38,00,33,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,\ 20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,32,00,39,\ 00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,\ 34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,\ 00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,22,00,00,00,\ 22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,\ 00,70,00,22,00,20,00,22,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,\ 33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,\ 00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,\ 42,00,32,00,36,00,41,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,\ 00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,\ 64,00,69,00,73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,22,00,4e,00,65,\ 00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,\ 20,00,22,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,\ 00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,\ 44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,\ 00,39,00,7d,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,\ 00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,\ 6f,00,6e,00,5f,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,\ 6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,\ 00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,\ 70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,\ 00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,\ 39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,\ 00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,\ 61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,\ 00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,\ 70,00,69,00,70,00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,\ 00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,\ 32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,\ 00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,\ 00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,\ 00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,\ 2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,\ 00,45,00,34,00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,\ 00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,46,00,45,00,34,\ 00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,\ 35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,\ 00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,\ 00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,\ 74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,32,00,39,\ 00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,\ 34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,\ 00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,\ 00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,\ 4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,\ 00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,33,00,2d,00,43,00,30,00,36,00,\ 46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,34,00,44,00,36,00,2d,00,44,\ 00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,42,00,32,00,36,00,41,00,7d,00,\ 00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,\ 00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,\ 6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,39,00,45,00,30,00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,\ 42,00,31,00,31,00,2d,00,34,00,35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,\ 00,2d,00,42,00,37,00,46,00,33,00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,\ 35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,\ 00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,\ 69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,00,\ 2d,00,38,00,37,00,46,00,34,00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,46,\ 00,42,00,39,00,2d,00,43,00,35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,00,\ 34,00,46,00,30,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,\ 61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,\ 00,63,00,70,00,69,00,70,00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,\ 37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,\ 00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,\ 38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\NetworkProvider] "Name"="Microsoft Windows Network" "ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6e,00,74,00,6c,00,61,00,6e,00,6d,00,61,00,6e,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "DeviceName"="\\Device\\LanmanRedirector" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters] "enableplaintextpassword"=dword:00000000 "enablesecuritysignature"=dword:00000001 "requiresecuritysignature"=dword:00000000 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,6b,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "OtherDomains"=hex(7):00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\Enum] "0"="Root\\LEGACY_LANMANWORKSTATION\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lbrtfdc] "ErrorControl"=dword:00000000 "Group"="System Bus Extender" "Start"=dword:00000001 "Tag"=dword:0000000e "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ldap] "ldapclientintegrity"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseService] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseService\FilePrint] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseService\FilePrint\TermService] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LightScribeService] "Type"=dword:00000010 "Start"=dword:00000004 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,\ 00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4c,00,69,00,67,00,68,00,\ 74,00,53,00,63,00,72,00,69,00,62,00,65,00,5c,00,4c,00,53,00,53,00,72,00,76,\ 00,63,00,2e,00,65,00,78,00,65,00,22,00,00,00 "DisplayName"="LightScribeService Direct Disc Labeling Service" "ObjectName"="LocalSystem" "Description"="Used by the LightScribe software components to support 3rd party disc labeling applications using the LightScribe COM Application Programming Interface (LSCAPI). This service needs to run for LightScribe direct disc labeling to work." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LightScribeService\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LightScribeService\Enum] "0"="Root\\LEGACY_LIGHTSCRIBESERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "DisplayName"="TCP/IP NetBIOS Helper" "Group"="TDI" "DependOnService"=hex(7):4e,00,65,00,74,00,42,00,54,00,00,00,41,00,66,00,64,00,\ 00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6c,00,6d,00,68,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts\Enum] "0"="Root\\LEGACY_LMHOSTS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\massfilter] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000006 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,61,00,73,00,73,00,66,00,69,\ 00,6c,00,74,00,65,00,72,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ZTE Mass Storage Filter Driver" "Group"="PnP Filter" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\massfilter\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MDM] "Type"=dword:00000110 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,\ 00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,\ 6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,\ 00,56,00,53,00,37,00,44,00,45,00,42,00,55,00,47,00,5c,00,4d,00,44,00,4d,00,\ 2e,00,45,00,58,00,45,00,22,00,00,00 "DisplayName"="Machine Debug Manager" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MDM\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MDM\Enum] "0"="Root\\LEGACY_MDM\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mdmxsdk] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,64,00,6d,00,78,00,73,00,64,\ 00,6b,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mdmxsdk\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mdmxsdk\Enum] "0"="Root\\LEGACY_MDMXSDK\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Messenger" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,4e,00,65,00,74,00,42,\ 00,49,00,4f,00,53,00,00,00,50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,\ 00,00,52,00,70,00,63,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6d,00,73,00,67,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmdd] "ErrorControl"=dword:00000000 "Group"="Video Save" "Start"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmdd\Device0] "InstalledDisplayDrivers"=hex(7):6d,00,6e,00,6d,00,64,00,64,00,00,00,00,00 "Device Description"="NetMeeting driver" "VgaCompatible"=dword:00000000 "MirrorDriver"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmdd\Video] "VideoID"="{8B6D7859-A639-4A15-8790-7161976D057A}" "Service"="mnmdd" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmdd\Enum] "0"="Root\\LEGACY_MNMDD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmsrvc] "Type"=dword:00000110 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,6e,00,6d,\ 00,73,00,72,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="NetMeeting Remote Desktop Sharing" "ObjectName"="LocalSystem" "Description"="Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmsrvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Modem] "ErrorControl"=dword:00000000 "Group"="Extended base" "Start"=dword:00000003 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Modem\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Modem\Enum] "0"="Root\\MODEM\\0000" "Count"=dword:00000003 "NextInstance"=dword:00000003 "1"="Root\\MODEM\\0001" "2"="HDAUDIO\\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_103C1379&REV_1000\\4&1d8c0f4e&0&0102" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mouclass] "ErrorControl"=dword:00000001 "Group"="Pointer Class" "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Mouse Class Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,6f,00,75,00,63,00,6c,00,61,\ 00,73,00,73,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mouclass\Parameters] "ConnectMultiplePorts"=dword:00000000 "MaximumPortsServiced"=dword:00000003 "MouseDataQueueSize"=dword:00000064 "PointerDeviceBaseName"="PointerClass" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mouclass\Enum] "0"="Root\\RDP_MOU\\0000" "Count"=dword:00000004 "NextInstance"=dword:00000004 "1"="ACPI\\SYN0136\\4&374ccb25&0" "2"="HID\\Vid_046d&Pid_c03d\\7&205efb2c&0&0000" "3"="HID\\HID_MOUSE&Col02\\2&78cff76&0&0001" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,6f,00,75,00,68,00,69,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Mouse HID Driver" "Group"="Pointer Port" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid\Parameters] "UseOnlyMice"=dword:00000000 "TreatAbsoluteAsRelative"=dword:00000000 "TreatAbsolutePointerAsAbsolute"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid\Enum] "0"="HID\\Vid_046d&Pid_c03d\\7&205efb2c&0&0000" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="HID\\HID_MOUSE&Col02\\2&78cff76&0&0001" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MountMgr] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000008 "Type"=dword:00000001 "DisplayName"="Mount Point Manager" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MountMgr\Enum] "0"="Root\\LEGACY_MOUNTMGR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MQAC] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\ 44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,6d,00,71,00,61,00,\ 63,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Message Queuing access control" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MQAC\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MQAC\Enum] "0"="Root\\LEGACY_MQAC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mraid35x] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000002b "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mraid35x\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mraid35x\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV] "Type"=dword:00000002 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,72,00,78,00,64,00,61,00,76,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="WebDav Client Redirector" "Description"="WebDav Client Redirector" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV\Parameters] "FileInformationCacheLifeTimeInSec"=dword:0000003c "FileNotFoundCacheLifeTimeInSec"=dword:0000003c "NameCacheMaxEntries"=dword:0000012c "DAVDebugFlag"=dword:00000000 "UMRxDebugFlag"=dword:00000000 "RequestTimeoutInSec"=dword:00000258 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV\Enum] "0"="Root\\LEGACY_MRXDAV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb] "Type"=dword:00000002 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,72,00,78,00,73,00,6d,00,62,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="MRXSMB" "Group"="Network" "Description"="MRXSMB" "LastLoadStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb\Parameters] "CscEnabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb\Enum] "0"="Root\\LEGACY_MRXSMB\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,64,\ 00,74,00,63,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Distributed Transaction Coordinator" "Group"="MS Transactions" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,53,00,61,00,6d,00,\ 53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC\Security] "Security"=hex:01,00,14,80,b8,00,00,00,c4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,88,00,06,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 02,00,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\ 00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\ 02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,14,00,9d,00,02,\ 00,01,01,00,00,00,00,00,05,14,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC\Enum] "0"="Root\\LEGACY_MSDTC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC Bridge 3.0.0.0] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC Bridge 3.0.0.0\Linkage] "Export"=hex(7):4d,00,53,00,44,00,54,00,43,00,20,00,42,00,72,00,69,00,64,00,67,\ 00,65,00,20,00,33,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC Bridge 3.0.0.0\Performance] "Counter Names"=hex:4d,00,65,00,73,00,73,00,61,00,67,00,65,00,20,00,73,00,65,\ 00,6e,00,64,00,20,00,66,00,61,00,69,00,6c,00,75,00,72,00,65,00,73,00,2f,00,\ 73,00,65,00,63,00,00,00,50,00,72,00,65,00,70,00,61,00,72,00,65,00,20,00,72,\ 00,65,00,74,00,72,00,79,00,20,00,63,00,6f,00,75,00,6e,00,74,00,2f,00,73,00,\ 65,00,63,00,00,00,43,00,6f,00,6d,00,6d,00,69,00,74,00,20,00,72,00,65,00,74,\ 00,72,00,79,00,20,00,63,00,6f,00,75,00,6e,00,74,00,2f,00,73,00,65,00,63,00,\ 00,00,50,00,72,00,65,00,70,00,61,00,72,00,65,00,64,00,20,00,72,00,65,00,74,\ 00,72,00,79,00,20,00,63,00,6f,00,75,00,6e,00,74,00,2f,00,73,00,65,00,63,00,\ 00,00,52,00,65,00,70,00,6c,00,61,00,79,00,20,00,72,00,65,00,74,00,72,00,79,\ 00,20,00,63,00,6f,00,75,00,6e,00,74,00,2f,00,73,00,65,00,63,00,00,00,46,00,\ 61,00,75,00,6c,00,74,00,73,00,20,00,72,00,65,00,63,00,65,00,69,00,76,00,65,\ 00,64,00,20,00,63,00,6f,00,75,00,6e,00,74,00,2f,00,73,00,65,00,63,00,00,00,\ 46,00,61,00,75,00,6c,00,74,00,73,00,20,00,73,00,65,00,6e,00,74,00,20,00,63,\ 00,6f,00,75,00,6e,00,74,00,2f,00,73,00,65,00,63,00,00,00,41,00,76,00,65,00,\ 72,00,61,00,67,00,65,00,20,00,70,00,61,00,72,00,74,00,69,00,63,00,69,00,70,\ 00,61,00,6e,00,74,00,20,00,70,00,72,00,65,00,70,00,61,00,72,00,65,00,20,00,\ 72,00,65,00,73,00,70,00,6f,00,6e,00,73,00,65,00,20,00,74,00,69,00,6d,00,65,\ 00,00,00,41,00,76,00,65,00,72,00,61,00,67,00,65,00,20,00,70,00,61,00,72,00,\ 74,00,69,00,63,00,69,00,70,00,61,00,6e,00,74,00,20,00,70,00,72,00,65,00,70,\ 00,61,00,72,00,65,00,20,00,72,00,65,00,73,00,70,00,6f,00,6e,00,73,00,65,00,\ 20,00,74,00,69,00,6d,00,65,00,20,00,42,00,61,00,73,00,65,00,00,00,41,00,76,\ 00,65,00,72,00,61,00,67,00,65,00,20,00,70,00,61,00,72,00,74,00,69,00,63,00,\ 69,00,70,00,61,00,6e,00,74,00,20,00,63,00,6f,00,6d,00,6d,00,69,00,74,00,20,\ 00,72,00,65,00,73,00,70,00,6f,00,6e,00,73,00,65,00,20,00,74,00,69,00,6d,00,\ 65,00,00,00,41,00,76,00,65,00,72,00,61,00,67,00,65,00,20,00,70,00,61,00,72,\ 00,74,00,69,00,63,00,69,00,70,00,61,00,6e,00,74,00,20,00,63,00,6f,00,6d,00,\ 6d,00,69,00,74,00,20,00,72,00,65,00,73,00,70,00,6f,00,6e,00,73,00,65,00,20,\ 00,74,00,69,00,6d,00,65,00,20,00,42,00,61,00,73,00,65,00,00,00,00,00 "Counter Types"=hex:32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,\ 00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,32,00,37,00,\ 32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,32,00,37,00,32,00,36,00,39,\ 00,36,00,33,00,32,00,30,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,\ 32,00,30,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,\ 00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,38,00,30,00,\ 35,00,34,00,33,00,38,00,34,00,36,00,34,00,00,00,31,00,30,00,37,00,33,00,39,\ 00,33,00,39,00,34,00,35,00,38,00,00,00,38,00,30,00,35,00,34,00,33,00,38,00,\ 34,00,36,00,34,00,00,00,31,00,30,00,37,00,33,00,39,00,33,00,39,00,34,00,35,\ 00,38,00,00,00,00,00 "IsMultiInstance"=dword:00000000 "CategoryOptions"=dword:00000003 "Close"="ClosePerformanceData" "Collect"="CollectPerformanceData" "Open"="OpenPerformanceData" "Library"="NETFXPerf.dll" "Last Counter"=dword:00000f6e "Last Help"=dword:00000f6f "First Counter"=dword:00000f58 "First Help"=dword:00000f59 "Object List"="3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928 3928" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Msfs] "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000001 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Msfs\Enum] "0"="Root\\LEGACY_MSFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer] "Description"="Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start." "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,69,\ 00,65,00,78,00,65,00,63,00,2e,00,65,00,78,00,65,00,20,00,2f,00,56,00,00,00 "DisplayName"="Windows Installer" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer\Enum] "0"="Root\\LEGACY_MSISERVER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSKSSRV] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000a "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,4b,00,53,00,53,00,52,\ 00,56,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Streaming Service Proxy" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSKSSRV\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQ] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,71,00,73,\ 00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Message Queuing" "DependOnService"=hex(7):4d,00,51,00,41,00,43,00,00,00,52,00,4d,00,43,00,41,00,\ 53,00,54,00,00,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,76,\ 00,65,00,72,00,00,00,4e,00,74,00,4c,00,6d,00,53,00,73,00,70,00,00,00,52,00,\ 50,00,43,00,53,00,53,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides a communications infrastructure for distributed, asynchronous messaging applications." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQ\Performance] "Library"="MQPERF.DLL" "Open"="PerfOpen" "Close"="PerfClose" "Collect"="PerfCollect" "Last Counter"=dword:00000b58 "Last Help"=dword:00000b59 "First Counter"=dword:00000aee "First Help"=dword:00000aef "Object List"="2798 2840 2822 2866 2876 2886 2896" "WbemAdapFileSignature"=hex:18,96,1a,c0,f2,e1,14,5b,ce,59,c5,08,c0,18,80,f3 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00002000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQ\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQ\Enum] "0"="Root\\LEGACY_MSMQ\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQTriggers] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,71,00,74,\ 00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Message Queuing Triggers" "DependOnService"=hex(7):4d,00,53,00,4d,00,51,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Associates the arrival of incoming messages at a queue with functionality in a COM component or a stand-alone executable program." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQTriggers\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQTriggers\Enum] "0"="Root\\LEGACY_MSMQTRIGGERS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPCLOCK] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000008 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,50,00,43,00,4c,00,4f,\ 00,43,00,4b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Streaming Clock Proxy" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPCLOCK\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPQM] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000009 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,50,00,51,00,4d,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Streaming Quality Manager Proxy" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSPQM\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSCNTRS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,73,00,73,00,6d,00,62,00,69,\ 00,6f,00,73,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft System Management BIOS Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios\Data] "AcpiData"=hex:52,53,44,54,50,00,00,00,01,ce,48,50,20,20,20,20,33,30,43,35,20,\ 20,20,20,20,08,06,24,48,50,20,20,01,00,00,00,00,80,fc,bf,44,82,fc,bf,bc,83,\ fc,bf,f4,83,fc,bf,5c,84,fc,bf,98,84,fc,bf,0d,b3,fd,bf,37,b6,fd,bf,8d,c1,fd,\ bf,ec,c3,fd,bf,92,c4,fd,bf,46,41,43,50,84,00,00,00,02,7b,48,50,20,20,20,20,\ 33,30,43,35,20,20,20,20,02,00,00,00,48,50,20,20,01,00,00,00,80,7d,fe,bf,cc,\ 84,fc,bf,00,00,09,00,b2,00,00,00,f1,f0,f2,80,00,10,00,00,00,00,00,00,04,10,\ 00,00,00,00,00,00,20,10,00,00,08,10,00,00,28,10,00,00,00,00,00,00,04,02,01,\ 04,08,00,00,00,02,00,87,00,00,00,00,00,01,03,0d,00,32,13,00,00,a5,80,00,00,\ 01,08,00,00,00,00,00,00,00,00,00,00,00,00,00,00,44,53,44,54,41,2e,01,00,01,\ 9f,48,50,20,20,20,20,38,35,31,30,78,00,00,00,00,00,01,00,4d,53,46,54,01,00,\ 00,03,53,4c,49,43,76,01,00,00,01,ab,48,50,51,4f,45,4d,53,4c,49,43,2d,4d,50,\ 43,01,00,00,00,48,50,20,20,01,00,00,00,00,00,00,00,9c,00,00,00,06,02,00,00,\ 00,24,00,00,52,53,41,31,00,04,00,00,01,00,01,00,5b,ab,60,56,bc,58,1e,e8,c1,\ d2,a1,5c,e5,4f,bb,fd,1d,a9,8c,94,b4,ae,08,11,dc,13,59,d3,7f,f6,3e,87,31,b9,\ 95,74,10,da,3b,a4,5b,b5,19,82,7c,39,d7,0d,7c,22,ac,1c,2a,84,e9,0a,88,6d,fa,\ b1,e2,d8,e8,21,96,e1,2e,68,9a,bf,44,45,3e,3c,8e,99,90,de,37,38,57,0b,92,15,\ bc,de,ff,f2,07,7e,b5,40,8c,51,3a,c3,02,48,f6,13,12,72,fb,42,78,e6,47,88,54,\ c7,b0,f0,93,9e,fb,04,b7,b8,b8,90,de,db,ed,32,e1,fb,54,a6,01,00,00,00,b6,00,\ 00,00,00,00,02,00,48,50,51,4f,45,4d,53,4c,49,43,2d,4d,50,43,57,49,4e,44,4f,\ 57,53,20,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,30,a8,\ 7e,10,1b,0f,13,dd,2e,2d,36,c2,ab,54,a7,8c,3a,a0,2f,c6,5b,b3,b3,dd,93,ee,8e,\ 39,a9,92,d0,5a,20,e1,2d,f5,a2,1c,7a,3e,54,85,99,72,56,5f,ec,6b,07,17,63,82,\ 3e,79,02,50,40,c9,f1,d3,c5,58,39,a8,18,f1,56,91,ea,9c,54,1a,e0,ce,c9,16,f0,\ 5d,d1,90,b1,b0,9e,81,e6,ba,62,f1,3b,96,b0,7d,d7,47,10,78,03,c9,28,52,e7,2d,\ 4a,f7,70,bb,53,1f,be,cd,4f,77,d1,2f,a8,3d,5c,26,af,80,42,25,ef,7a,b2,67,ba,\ 1c,48,50,45,54,38,00,00,00,01,32,48,50,20,20,20,20,33,30,43,35,20,20,20,20,\ 01,00,00,00,48,50,20,20,01,00,00,00,01,a2,86,80,00,20,00,00,00,00,d0,fe,00,\ 00,00,00,00,80,00,00,41,50,49,43,68,00,00,00,01,10,48,50,20,20,20,20,33,30,\ 43,35,20,20,20,20,01,00,00,00,48,50,20,20,01,00,00,00,00,00,e0,fe,01,00,00,\ 00,00,08,01,00,01,00,00,00,00,08,02,01,01,00,00,00,01,0c,01,00,00,00,c0,fe,\ 00,00,00,00,02,0a,00,00,02,00,00,00,00,00,02,0a,00,09,09,00,00,00,0d,00,04,\ 06,01,05,00,01,04,06,02,05,00,01,4d,43,46,47,3c,00,00,00,01,22,48,50,20,20,\ 20,20,33,30,43,35,20,20,20,20,01,00,00,00,48,50,20,20,01,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,f8,00,00,00,00,00,00,00,3f,00,00,00,00,54,43,50,41,\ 32,00,00,00,02,90,48,50,20,20,20,20,33,30,43,35,20,20,20,20,01,00,00,00,48,\ 50,20,20,01,00,00,00,00,00,00,00,01,00,d2,3a,fb,bf,00,00,00,00,53,53,44,54,\ 2a,03,00,00,01,72,48,50,20,20,20,20,48,50,51,50,41,54,00,00,01,00,00,00,4d,\ 53,46,54,01,00,00,03,53,53,44,54,4e,01,00,00,01,09,48,50,20,20,20,20,48,50,\ 51,50,52,4e,00,00,01,00,00,00,4d,53,46,54,01,00,00,03,53,53,44,54,5f,02,00,\ 00,01,99,48,50,20,20,20,20,43,70,75,30,54,73,74,00,00,30,00,00,49,4e,54,4c,\ 17,03,06,20,53,53,44,54,a6,00,00,00,01,3e,48,50,20,20,20,20,43,70,75,31,54,\ 73,74,00,00,30,00,00,49,4e,54,4c,17,03,06,20,53,53,44,54,d7,04,00,00,01,1e,\ 48,50,20,20,20,20,43,70,75,50,6d,00,00,00,00,30,00,00,49,4e,54,4c,17,03,06,\ 20 "BiosData"=hex:0a,00,00,00,7e,00,4d,00,48,00,7a,00,00,00,04,00,00,00,04,00,00,\ 00,bd,09,00,00,2c,00,00,00,43,00,6f,00,6d,00,70,00,6f,00,6e,00,65,00,6e,00,\ 74,00,20,00,49,00,6e,00,66,00,6f,00,72,00,6d,00,61,00,74,00,69,00,6f,00,6e,\ 00,00,00,03,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,\ 00,00,26,00,00,00,43,00,6f,00,6e,00,66,00,69,00,67,00,75,00,72,00,61,00,74,\ 00,69,00,6f,00,6e,00,20,00,44,00,61,00,74,00,61,00,00,00,09,00,00,00,10,00,\ 00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,00,00,00,16,00,00,00,49,00,64,\ 00,65,00,6e,00,74,00,69,00,66,00,69,00,65,00,72,00,00,00,01,00,00,00,42,00,\ 00,00,78,00,38,00,36,00,20,00,46,00,61,00,6d,00,69,00,6c,00,79,00,20,00,36,\ 00,20,00,4d,00,6f,00,64,00,65,00,6c,00,20,00,32,00,33,00,20,00,53,00,74,00,\ 65,00,70,00,70,00,69,00,6e,00,67,00,20,00,36,00,00,00,28,00,00,00,50,00,72,\ 00,6f,00,63,00,65,00,73,00,73,00,6f,00,72,00,4e,00,61,00,6d,00,65,00,53,00,\ 74,00,72,00,69,00,6e,00,67,00,00,00,01,00,00,00,60,00,00,00,49,00,6e,00,74,\ 00,65,00,6c,00,28,00,52,00,29,00,20,00,43,00,6f,00,72,00,65,00,28,00,54,00,\ 4d,00,29,00,32,00,20,00,44,00,75,00,6f,00,20,00,43,00,50,00,55,00,20,00,20,\ 00,20,00,20,00,20,00,54,00,39,00,33,00,30,00,30,00,20,00,20,00,40,00,20,00,\ 32,00,2e,00,35,00,30,00,47,00,48,00,7a,00,00,00,22,00,00,00,55,00,70,00,64,\ 00,61,00,74,00,65,00,20,00,53,00,69,00,67,00,6e,00,61,00,74,00,75,00,72,00,\ 65,00,00,00,03,00,00,00,08,00,00,00,00,00,00,00,07,06,00,00,1c,00,00,00,55,\ 00,70,00,64,00,61,00,74,00,65,00,20,00,53,00,74,00,61,00,74,00,75,00,73,00,\ 00,00,04,00,00,00,04,00,00,00,02,00,00,00,22,00,00,00,56,00,65,00,6e,00,64,\ 00,6f,00,72,00,49,00,64,00,65,00,6e,00,74,00,69,00,66,00,69,00,65,00,72,00,\ 00,00,01,00,00,00,1a,00,00,00,47,00,65,00,6e,00,75,00,69,00,6e,00,65,00,49,\ 00,6e,00,74,00,65,00,6c,00,00,00,0c,00,00,00,4d,00,53,00,52,00,38,00,42,00,\ 00,00,0b,00,00,00,08,00,00,00,00,00,00,00,07,06,00,00,0e,00,00,00,43,00,50,\ 00,55,00,49,00,44,00,31,00,00,00,03,00,00,00,10,00,00,00,76,06,01,00,00,08,\ 02,01,bd,e3,08,00,ff,fb,eb,bf "SMBiosData"=hex:00,02,04,24,0b,05,00,00,00,18,00,00,01,02,00,e0,03,0f,80,9b,\ 09,3d,00,00,00,00,93,07,0f,13,71,36,48,65,77,6c,65,74,74,2d,50,61,63,6b,61,\ 72,64,00,36,38,4d,56,44,20,56,65,72,2e,20,46,2e,31,33,00,30,36,2f,32,34,2f,\ 32,30,30,38,00,00,01,1b,01,00,01,02,03,04,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,06,05,06,48,65,77,6c,65,74,74,2d,50,61,63,6b,61,72,64,00,48,\ 50,20,43,6f,6d,70,61,71,20,38,35,31,30,77,20,00,46,2e,31,33,00,20,20,20,20,\ 20,20,20,20,20,20,00,46,55,33,36,35,45,53,23,41,42,48,00,31,30,33,43,5f,35,\ 33,33,36,41,4e,00,00,7e,2f,40,00,20,20,20,20,20,20,20,20,00,20,20,20,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,00,31,30,33,43,5f,35,33,33,36,41,4e,00,00,\ 7e,04,40,00,00,00,02,08,02,00,01,02,03,00,48,65,77,6c,65,74,74,2d,50,61,63,\ 6b,61,72,64,00,33,30,43,35,00,4b,42,43,20,56,65,72,73,69,6f,6e,20,37,31,2e,\ 33,36,00,00,03,0d,03,00,01,0a,00,02,03,03,03,03,05,48,65,77,6c,65,74,74,2d,\ 50,61,63,6b,61,72,64,00,20,20,20,20,20,20,20,20,20,20,00,20,20,20,20,20,20,\ 20,20,20,20,00,00,7e,20,41,00,20,20,20,20,20,00,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,00,00,7e,04,41,00,00,00,04,23,04,00,01,03,b9,02,76,06,\ 01,00,ff,fb,eb,bf,03,8b,c8,00,c4,09,c4,09,41,06,05,00,06,00,ff,ff,00,00,00,\ 55,31,30,00,49,6e,74,65,6c,28,52,29,00,49,6e,74,65,6c,28,52,29,20,43,6f,72,\ 65,28,54,4d,29,32,20,44,75,6f,20,43,50,55,20,20,20,20,20,54,39,33,30,30,20,\ 20,40,20,32,2e,35,30,47,48,7a,00,00,07,13,05,00,01,80,01,40,00,40,00,08,00,\ 08,00,00,02,05,05,49,6e,74,65,72,6e,61,6c,20,4c,31,20,43,61,63,68,65,00,00,\ 07,13,06,00,01,a1,01,60,80,60,80,08,00,08,00,00,03,05,05,49,6e,74,65,72,6e,\ 61,6c,20,4c,32,20,43,61,63,68,65,00,00,09,0d,07,00,01,07,05,03,03,00,00,36,\ 01,50,43,20,43,41,52,44,2d,53,6c,6f,74,20,30,00,00,0a,06,08,00,83,01,30,00,\ 00,0b,05,09,00,02,77,77,77,2e,68,70,2e,63,6f,6d,00,41,42,53,20,37,30,2f,37,\ 31,20,37,39,20,37,41,20,37,42,20,37,43,00,00,10,0f,0a,00,03,03,03,00,00,40,\ 00,ff,ff,02,00,00,00,11,1b,0b,00,0a,00,ff,ff,40,00,40,00,00,08,0d,00,01,00,\ 13,80,00,9b,02,02,03,00,04,44,49,4d,4d,20,23,31,00,51,69,6d,6f,6e,64,61,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,00,20,20,20,20,20,20,20,\ 20,00,36,34,54,32,35,36,30,32,30,45,44,4c,33,53,43,32,20,20,00,00,11,1b,0c,\ 00,0a,00,ff,ff,40,00,40,00,00,08,0d,00,01,00,13,80,00,9b,02,02,03,00,04,44,\ 49,4d,4d,20,23,32,00,51,69,6d,6f,6e,64,61,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,20,20,20,20,00,20,20,20,20,20,20,20,20,00,36,34,54,32,35,36,30,32,\ 30,45,44,4c,33,53,43,32,20,20,00,00,13,0f,0d,00,00,00,00,00,ff,ff,3f,00,0a,\ 00,02,00,00,14,13,0e,00,00,00,00,00,ff,ff,1f,00,0b,00,0d,00,01,00,00,00,00,\ 14,13,0f,00,00,00,20,00,ff,ff,3f,00,0c,00,0d,00,02,00,00,00,00,16,1a,10,00,\ 01,02,03,04,05,06,ec,13,40,38,00,ff,00,00,00,00,00,0a,00,00,00,00,50,72,69,\ 6d,61,72,79,00,48,65,77,6c,65,74,74,2d,50,61,63,6b,61,72,64,00,30,37,2f,33,\ 30,2f,32,30,30,38,00,20,20,20,20,20,20,20,20,20,20,20,20,00,48,50,20,20,20,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,00,00,7e,1a,11,00,01,02,03,04,05,06,\ 00,00,00,00,00,ff,00,00,00,00,00,0a,00,00,00,00,4d,75,6c,74,69,42,61,79,00,\ 48,65,77,6c,65,74,74,2d,50,61,63,6b,61,72,64,00,20,20,20,20,20,20,20,20,20,\ 20,00,20,20,20,20,20,20,20,20,20,20,20,20,00,4e,6f,20,62,61,74,74,65,72,79,\ 20,20,20,20,20,20,20,20,00,00,20,0b,12,00,00,00,00,00,00,00,00,00,00,7e,08,\ 13,00,01,01,02,00,49,6e,74,65,6c,5f,41,53,46,00,49,6e,74,65,6c,5f,41,53,46,\ 5f,30,30,31,00,00,7e,14,14,00,24,41,4d,54,00,00,00,00,00,a5,00,00,00,00,00,\ 00,00,00,85,22,85,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,02,00,00,00,00,00,00,00,00,00,00,20,20,20,20,20,20,20,20,20,20,20,20,20,\ 20,20,20,00,4e,6f,20,62,61,74,74,65,72,79,20,20,20,20,20,20,20,20,00,00,86,\ 22,86,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,\ 00,00,00,00,00,00,00,00,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,00,\ 20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,20,00,00,90,1a,15,00,ff,\ ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,7f,04,\ 16,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssmbios\Enum] "0"="Root\\SYSTEM\\0002" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQL$SQLEXPRESS] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,63,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,6f,\ 00,73,00,6f,00,66,00,74,00,20,00,53,00,51,00,4c,00,20,00,53,00,65,00,72,00,\ 76,00,65,00,72,00,5c,00,4d,00,53,00,53,00,51,00,4c,00,2e,00,31,00,5c,00,4d,\ 00,53,00,53,00,51,00,4c,00,5c,00,42,00,69,00,6e,00,6e,00,5c,00,73,00,71,00,\ 6c,00,73,00,65,00,72,00,76,00,72,00,2e,00,65,00,78,00,65,00,22,00,20,00,2d,\ 00,73,00,53,00,51,00,4c,00,45,00,58,00,50,00,52,00,45,00,53,00,53,00,00,00 "DisplayName"="SQL Server (SQLEXPRESS)" "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Provides storage, processing and controlled access of data and rapid transaction processing." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQL$SQLEXPRESS\Linkage] "Export"=hex(7):53,00,51,00,4c,00,45,00,58,00,50,00,52,00,45,00,53,00,53,00,00,\ 00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQL$SQLEXPRESS\Performance] "Library"="sqlctr90.dll" "Open"="OpenSQLPerformanceData1" "Collect"="CollectSQLPerformanceData1" "Close"="CloseSQLPerformanceData1" "WbemAdapFileSignature"=hex:fe,81,8f,69,d5,0c,4d,4d,12,ed,eb,95,28,a8,d9,c6 "WbemAdapFileTime"=hex:00,76,7b,f6,7b,4e,c9,01 "WbemAdapFileSize"=dword:00010160 "WbemAdapStatus"=dword:00000000 "Last Counter"=dword:0000239a "Last Help"=dword:0000239b "First Counter"=dword:00002126 "First Help"=dword:00002127 "Library Validation Code"=hex:00,76,7b,f6,7b,4e,c9,01,60,01,01,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQL$SQLEXPRESS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQL$SQLEXPRESS\Enum] "0"="Root\\LEGACY_MSSQL$SQLEXPRESS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQLServerADHelper] "Type"=dword:00000010 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,63,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,6f,\ 00,73,00,6f,00,66,00,74,00,20,00,53,00,51,00,4c,00,20,00,53,00,65,00,72,00,\ 76,00,65,00,72,00,5c,00,39,00,30,00,5c,00,53,00,68,00,61,00,72,00,65,00,64,\ 00,5c,00,73,00,71,00,6c,00,61,00,64,00,68,00,6c,00,70,00,39,00,30,00,2e,00,\ 65,00,78,00,65,00,22,00,00,00 "DisplayName"="SQL Server Active Directory Helper" "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Enables integration with Active Directories." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQLServerADHelper\Security] "Security"=hex:01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,84,00,05,00,00,00,00,04,24,00,11,00,02,00,01,05,00,00,00,00,00,\ 05,15,00,00,00,42,c7,e6,a7,93,37,28,e0,e3,4f,67,2e,f3,03,00,00,00,00,14,00,\ fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,\ 02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,8d,01,02,00,01,01,\ 00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\ 00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msvsmon90] "Type"=dword:00000010 "Start"=dword:00000004 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,6f,\ 00,73,00,6f,00,66,00,74,00,20,00,56,00,69,00,73,00,75,00,61,00,6c,00,20,00,\ 53,00,74,00,75,00,64,00,69,00,6f,00,20,00,39,00,2e,00,30,00,5c,00,43,00,6f,\ 00,6d,00,6d,00,6f,00,6e,00,37,00,5c,00,49,00,44,00,45,00,5c,00,52,00,65,00,\ 6d,00,6f,00,74,00,65,00,20,00,44,00,65,00,62,00,75,00,67,00,67,00,65,00,72,\ 00,5c,00,78,00,38,00,36,00,5c,00,6d,00,73,00,76,00,73,00,6d,00,6f,00,6e,00,\ 2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,73,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,20,00,6d,00,73,00,76,00,73,00,6d,00,6f,00,6e,00,39,00,30,00,00,00 "DisplayName"="Visual Studio 2008 Remote Debugger" "ObjectName"="LocalSystem" "Description"="Allows members of the Administrators group to remotely debug server applications using Visual Studio 2008. Use the Visual Studio 2008 Remote Debugging Configuration Wizard to enable this service." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msvsmon90\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mup] "DisplayName"="Mup" "ErrorControl"=dword:00000001 "Group"="Network" "Start"=dword:00000000 "Tag"=dword:00000002 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mup\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mup\Enum] "0"="Root\\LEGACY_MUP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent] "DisplayName"="Network Access Protection Agent" "Description"="Allows windows clients to participate in Network Access Protection" "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "ObjectName"="localSystem" "FailureActions"=hex:5a,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,65,00,79,\ 00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\LocalConfig] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 71,00,61,00,67,00,65,00,6e,00,74,00,72,00,74,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79617] "Id"=dword:00013701 "Friendly Name"="DHCP Quarantine Enforcement Client" "Description"="Provides DHCP based enforcement for NAP" "Version"="1.0" "Vendor Name"="Microsoft Corporation" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79618] "Id"=dword:00013702 "Description"="Provides the quarantine enforcement for RAS Client" "Friendly Name"="Remote Access Quarantine Enforcement Client" "Vendor Name"="Microsoft Corporation" "Version"="1.0" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79619] "Id"=dword:00013703 "Friendly Name"="IPSec Relying Party" "Description"="Provides IPSec based enforcement for Network Access Protection" "Version"="1.0" "Vendor Name"="Microsoft Corporation" "Component Type"=dword:00000002 "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79620] "Id"=dword:00013704 "Friendly Name"="Wireless Eapol Quarantine Enforcement Client" "Description"="Provides wireless Eapol based enforcement for NAP" "Version"="1.0" "Vendor Name"="Microsoft Corporation" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79621] "Id"=dword:00013705 "Friendly Name"="TS Gateway Quarantine Enforcement Client" "Description"="Provides TS Gateway enforcement for NAP" "Version"="1.0" "Vendor Name"="Microsoft Corporation" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Qecs\79623] @="" "Id"=dword:00013707 "Enabled"=dword:00000001 "Vendor Name"="Microsoft Corporation" "Version"="1.0" "Friendly Name"="EAP Quarantine Enforcement Client" "Description"="Provides EAP based enforcement for NAP" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Shas] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\Shas\79744] "Id"=dword:00013780 "Friendly Name"="Microsoft Out-of-Box System Health Agent" "Description"="Microsoft Out-of-Box System Health Agent" "Version"="1" "Vendor Name"="Microsoft Corporation" "Info Clsid"="{7886B467-66D4-4163-82BA-D9212FDB4CA8}" "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\napagent\SohCache] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS] "DisplayName"="NDIS System Driver" "ErrorControl"=dword:00000001 "Group"="NDIS Wrapper" "Start"=dword:00000000 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\MediaTypes] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\Parameters] "ProcessorAffinityMask"=dword:ffffffff [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\Enum] "0"="Root\\LEGACY_NDIS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,74,00,61,\ 00,70,00,69,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access NDIS TAPI Driver" "Description"="Remote Access NDIS TAPI Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi\Parameters] "AsyncEventQueueSize"=dword:00000300 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisTapi\Enum] "0"="Root\\LEGACY_NDISTAPI\\0000" "Count"=dword:00000004 "NextInstance"=dword:00000004 "1"="Root\\MS_NDISWANIP\\0000" "2"="Root\\MS_PPPOEMINIPORT\\0000" "3"="Root\\MS_PPTPMINIPORT\\0000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000b "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,75,00,69,\ 00,6f,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="NDIS Usermode I/O Protocol" "Group"="NDIS" "Description"="NDIS Usermode I/O Protocol" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,41,00,30,\ 00,33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,\ 34,00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,\ 00,30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,38,00,30,00,44,00,44,00,42,\ 00,45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,\ 45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,\ 00,37,00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,\ 00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,\ 44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,\ 00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,\ 00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,\ 2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,32,00,\ 39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,\ 00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,\ 37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,33,00,43,00,46,00,39,00,\ 30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,\ 00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,\ 36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,2d,\ 00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,00,\ 38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,46,\ 00,38,00,41,00,7d,00,22,00,00,00,22,00,7b,00,38,00,30,00,44,00,44,00,42,00,\ 45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,\ 00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,\ 37,00,45,00,43,00,41,00,39,00,39,00,7d,00,22,00,00,00,22,00,7b,00,35,00,33,\ 00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,\ 34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,\ 00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,22,00,00,00,\ 22,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,\ 00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,\ 2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,\ 00,7d,00,22,00,00,00,22,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,\ 35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,\ 00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,\ 38,00,46,00,43,00,35,00,7d,00,22,00,00,00,22,00,7b,00,33,00,43,00,46,00,39,\ 00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,\ 43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,\ 00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,\ 00,73,00,75,00,69,00,6f,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,\ 34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,\ 00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,\ 32,00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,4e,00,64,00,69,00,73,00,75,00,69,00,6f,00,5f,00,7b,00,38,00,\ 30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,\ 00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,\ 31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,75,00,\ 69,00,6f,00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,00,2d,\ 00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,44,00,\ 39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,00,33,\ 00,39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,\ 4e,00,64,00,69,00,73,00,75,00,69,00,6f,00,5f,00,7b,00,41,00,46,00,45,00,34,\ 00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,\ 35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,\ 00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,75,00,69,00,6f,00,5f,\ 00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,\ 42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,\ 00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,\ 7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,\ 00,73,00,75,00,69,00,6f,00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,\ 37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,\ 00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,\ 38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio\Enum] "0"="Root\\LEGACY_NDISUIO\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,77,00,61,\ 00,6e,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access NDIS WAN Driver" "Description"="Remote Access NDIS WAN Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,31,00,30,\ 00,45,00,36,00,36,00,39,00,30,00,43,00,2d,00,30,00,32,00,41,00,45,00,2d,00,\ 34,00,32,00,32,00,38,00,2d,00,39,00,46,00,39,00,35,00,2d,00,38,00,32,00,36,\ 00,39,00,45,00,46,00,32,00,36,00,39,00,31,00,36,00,44,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,46,00,31,00,42,00,34,00,36,\ 00,45,00,35,00,42,00,2d,00,33,00,31,00,39,00,30,00,2d,00,34,00,33,00,30,00,\ 31,00,2d,00,42,00,39,00,36,00,44,00,2d,00,45,00,31,00,36,00,44,00,33,00,32,\ 00,42,00,35,00,36,00,42,00,34,00,36,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,42,00,35,00,35,00,41,00,45,00,36,00,33,00,46,\ 00,2d,00,34,00,44,00,39,00,38,00,2d,00,34,00,44,00,33,00,37,00,2d,00,41,00,\ 34,00,39,00,37,00,2d,00,30,00,35,00,45,00,43,00,31,00,46,00,42,00,46,00,36,\ 00,31,00,46,00,36,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,7b,00,32,00,33,00,30,00,46,00,41,00,30,00,34,00,31,00,2d,00,32,00,44,\ 00,36,00,44,00,2d,00,34,00,44,00,43,00,38,00,2d,00,42,00,43,00,33,00,43,00,\ 2d,00,30,00,46,00,43,00,32,00,44,00,37,00,44,00,31,00,30,00,41,00,35,00,32,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,45,00,\ 45,00,38,00,41,00,46,00,45,00,30,00,32,00,2d,00,38,00,31,00,35,00,42,00,2d,\ 00,34,00,33,00,36,00,31,00,2d,00,42,00,32,00,42,00,45,00,2d,00,38,00,43,00,\ 38,00,45,00,42,00,43,00,32,00,35,00,42,00,39,00,44,00,42,00,7d,00,00,00,00,\ 00 "Route"=hex(7):22,00,7b,00,31,00,30,00,45,00,36,00,36,00,39,00,30,00,43,00,2d,\ 00,30,00,32,00,41,00,45,00,2d,00,34,00,32,00,32,00,38,00,2d,00,39,00,46,00,\ 39,00,35,00,2d,00,38,00,32,00,36,00,39,00,45,00,46,00,32,00,36,00,39,00,31,\ 00,36,00,44,00,7d,00,22,00,00,00,22,00,7b,00,46,00,31,00,42,00,34,00,36,00,\ 45,00,35,00,42,00,2d,00,33,00,31,00,39,00,30,00,2d,00,34,00,33,00,30,00,31,\ 00,2d,00,42,00,39,00,36,00,44,00,2d,00,45,00,31,00,36,00,44,00,33,00,32,00,\ 42,00,35,00,36,00,42,00,34,00,36,00,7d,00,22,00,00,00,22,00,7b,00,42,00,35,\ 00,35,00,41,00,45,00,36,00,33,00,46,00,2d,00,34,00,44,00,39,00,38,00,2d,00,\ 34,00,44,00,33,00,37,00,2d,00,41,00,34,00,39,00,37,00,2d,00,30,00,35,00,45,\ 00,43,00,31,00,46,00,42,00,46,00,36,00,31,00,46,00,36,00,7d,00,22,00,00,00,\ 22,00,7b,00,32,00,33,00,30,00,46,00,41,00,30,00,34,00,31,00,2d,00,32,00,44,\ 00,36,00,44,00,2d,00,34,00,44,00,43,00,38,00,2d,00,42,00,43,00,33,00,43,00,\ 2d,00,30,00,46,00,43,00,32,00,44,00,37,00,44,00,31,00,30,00,41,00,35,00,32,\ 00,7d,00,22,00,00,00,22,00,7b,00,45,00,45,00,38,00,41,00,46,00,45,00,30,00,\ 32,00,2d,00,38,00,31,00,35,00,42,00,2d,00,34,00,33,00,36,00,31,00,2d,00,42,\ 00,32,00,42,00,45,00,2d,00,38,00,43,00,38,00,45,00,42,00,43,00,32,00,35,00,\ 42,00,39,00,44,00,42,00,7d,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,\ 00,73,00,57,00,61,00,6e,00,5f,00,7b,00,31,00,30,00,45,00,36,00,36,00,39,00,\ 30,00,43,00,2d,00,30,00,32,00,41,00,45,00,2d,00,34,00,32,00,32,00,38,00,2d,\ 00,39,00,46,00,39,00,35,00,2d,00,38,00,32,00,36,00,39,00,45,00,46,00,32,00,\ 36,00,39,00,31,00,36,00,44,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,00,7b,00,46,00,\ 31,00,42,00,34,00,36,00,45,00,35,00,42,00,2d,00,33,00,31,00,39,00,30,00,2d,\ 00,34,00,33,00,30,00,31,00,2d,00,42,00,39,00,36,00,44,00,2d,00,45,00,31,00,\ 36,00,44,00,33,00,32,00,42,00,35,00,36,00,42,00,34,00,36,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,\ 61,00,6e,00,5f,00,7b,00,42,00,35,00,35,00,41,00,45,00,36,00,33,00,46,00,2d,\ 00,34,00,44,00,39,00,38,00,2d,00,34,00,44,00,33,00,37,00,2d,00,41,00,34,00,\ 39,00,37,00,2d,00,30,00,35,00,45,00,43,00,31,00,46,00,42,00,46,00,36,00,31,\ 00,46,00,36,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,\ 4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,00,7b,00,32,00,33,00,30,00,46,\ 00,41,00,30,00,34,00,31,00,2d,00,32,00,44,00,36,00,44,00,2d,00,34,00,44,00,\ 43,00,38,00,2d,00,42,00,43,00,33,00,43,00,2d,00,30,00,46,00,43,00,32,00,44,\ 00,37,00,44,00,31,00,30,00,41,00,35,00,32,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,\ 00,7b,00,45,00,45,00,38,00,41,00,46,00,45,00,30,00,32,00,2d,00,38,00,31,00,\ 35,00,42,00,2d,00,34,00,33,00,36,00,31,00,2d,00,42,00,32,00,42,00,45,00,2d,\ 00,38,00,43,00,38,00,45,00,42,00,43,00,32,00,35,00,42,00,39,00,44,00,42,00,\ 7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Parameters\Protocols] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Parameters\Protocols\0] "PPPProtocolType"=dword:00000021 "ProtocolType"=dword:00000800 "ProtocolMTU"=dword:00000514 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisWan\Enum] "0"="Root\\MS_NDISWANIP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDProxy] "DisplayName"=hex(7):4e,00,44,00,49,00,53,00,20,00,50,00,72,00,6f,00,78,00,79,\ 00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="PNP_TDI" "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDProxy\Enum] "0"="Root\\LEGACY_NDPROXY\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS] "Type"=dword:00000002 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,65,00,74,00,62,00,69,00,6f,\ 00,73,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="NetBIOS Interface" "Group"="NetBIOSGroup" "Description"="NetBIOS Interface" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage] "LanaMap"=hex:01,09,01,06,01,05,01,03,01,00,01,04,00,01,00,02,01,08 "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,30,00,\ 33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,\ 00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,\ 30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,\ 00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,\ 2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,\ 00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,\ 33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,\ 00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,\ 39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,\ 41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,00,45,\ 00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,32,00,\ 33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,00,00,\ 00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,32,00,39,00,33,00,37,\ 00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,\ 35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,\ 00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,\ 00,70,00,69,00,70,00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,\ 33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,\ 00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,\ 42,00,32,00,36,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,\ 00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,\ 5f,00,7b,00,39,00,45,00,30,00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,42,\ 00,31,00,31,00,2d,00,34,00,35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,00,\ 2d,00,42,00,37,00,46,00,33,00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,35,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,\ 74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,43,\ 00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,38,00,37,00,46,00,34,00,2d,00,\ 34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,00,39,00,2d,00,43,00,35,00,41,\ 00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,46,00,30,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,\ 00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,\ 42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,\ 00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,\ 41,00,38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,\ 00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,41,00,30,00,33,00,36,00,44,00,\ 44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,\ 00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,\ 41,00,32,00,46,00,46,00,38,00,41,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,\ 00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,\ 22,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,38,\ 00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,00,\ 2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,39,\ 00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,\ 54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,35,00,33,00,30,00,30,\ 00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,\ 43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,\ 00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,22,00,00,00,22,00,4e,00,\ 65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,\ 00,20,00,22,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,\ 30,00,32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,\ 00,32,00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,\ 38,00,33,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,\ 00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,32,00,39,00,\ 33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,\ 00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,\ 35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,22,00,00,00,22,\ 00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,\ 70,00,22,00,20,00,22,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,33,\ 00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,\ 34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,42,\ 00,32,00,36,00,41,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,\ 22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,64,\ 00,69,00,73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,22,00,4e,00,65,00,\ 74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,\ 00,22,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,\ 46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,\ 00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,\ 39,00,7d,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,\ 63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,\ 00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,\ 39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,\ 00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,00,74,\ 00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,38,00,30,00,\ 44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,\ 00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,\ 41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,4f,00,\ 53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,\ 39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,\ 00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,\ 43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,\ 00,74,00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,\ 00,38,00,35,00,2d,00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,\ 2d,00,41,00,39,00,33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,\ 00,30,00,35,00,42,00,38,00,33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,\ 00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,32,00,\ 39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,\ 00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,\ 37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,\ 4f,00,53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,33,00,2d,00,\ 43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,34,00,44,\ 00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,42,00,32,00,\ 36,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,\ 00,65,00,74,00,42,00,49,00,4f,00,53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,\ 5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,00,45,00,30,00,43,00,46,\ 00,34,00,45,00,46,00,2d,00,43,00,42,00,31,00,31,00,2d,00,34,00,35,00,35,00,\ 43,00,2d,00,41,00,33,00,31,00,30,00,2d,00,42,00,37,00,46,00,33,00,38,00,36,\ 00,39,00,38,00,42,00,36,00,42,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,5f,00,4e,\ 00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,\ 37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,38,00,37,00,46,00,34,\ 00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,00,39,00,2d,00,43,00,\ 35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,46,00,30,00,7d,00,00,\ 00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,\ 49,00,4f,00,53,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,\ 2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,\ 00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,\ 33,00,32,00,39,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Parameters] "MaxLana"=dword:00000009 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Parameters\Winsock] "HelperDllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,77,00,73,00,68,00,6e,00,65,00,74,00,62,00,73,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "MaxSockAddrLength"=dword:00000014 "MinSockAddrLength"=dword:00000014 "Mapping"=hex:02,00,00,00,03,00,00,00,11,00,00,00,05,00,00,00,00,00,00,00,11,\ 00,00,00,02,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBIOS\Enum] "0"="Root\\LEGACY_NETBIOS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,65,00,74,00,62,00,74,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="NetBios over Tcpip" "Group"="PNP_TDI" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="NetBios over Tcpip" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Linkage] "OtherDependencies"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,\ 2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,\ 00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,\ 46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,\ 45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,\ 00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,\ 37,00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\ 00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,33,00,\ 30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,\ 00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,\ 38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,\ 7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,\ 00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,\ 32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,\ 69,00,70,00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,\ 00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,\ 35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,\ 00,43,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,\ 00,30,00,33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,\ 2d,00,39,00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,\ 00,44,00,42,00,32,00,36,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,00,45,00,30,\ 00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,42,00,31,00,31,00,2d,00,34,00,\ 35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,00,2d,00,42,00,37,00,46,00,33,\ 00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,35,00,7d,00,00,00,5c,00,44,00,\ 65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,\ 00,37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,38,00,37,00,46,00,\ 34,00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,00,39,00,2d,00,43,\ 00,35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,46,00,30,00,7d,00,\ 00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,\ 36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,\ 00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,\ 32,00,39,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,41,\ 00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,\ 2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,\ 00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,22,00,\ 00,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,38,00,30,\ 00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,\ 34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,\ 00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,39,00,7d,00,22,00,00,00,\ 22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,35,00,33,00,30,\ 00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,\ 36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,\ 00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,22,00,00,00,22,00,\ 54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,41,00,46,00,45,00,34,\ 00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,\ 35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,\ 00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,00,22,00,00,00,22,00,54,00,\ 63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,32,00,39,00,33,00,37,00,44,\ 00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,\ 34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,\ 00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,22,00,00,00,22,00,54,00,63,00,\ 70,00,69,00,70,00,22,00,20,00,22,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,\ 00,30,00,33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,\ 2d,00,39,00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,\ 00,44,00,42,00,32,00,36,00,41,00,7d,00,22,00,00,00,22,00,54,00,63,00,70,00,\ 69,00,70,00,22,00,20,00,22,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,49,\ 00,70,00,22,00,00,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,\ 7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,\ 00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,\ 33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,\ 00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,30,00,\ 33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,\ 00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,\ 30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,\ 00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,\ 2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,\ 00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,\ 33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,\ 00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,\ 39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,\ 41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,00,45,\ 00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,32,00,\ 33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,00,00,\ 00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,32,00,39,00,33,00,37,\ 00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,\ 35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,\ 00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,\ 00,70,00,69,00,70,00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,\ 33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,\ 00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,\ 42,00,32,00,36,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,\ 00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,\ 5f,00,7b,00,39,00,45,00,30,00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,42,\ 00,31,00,31,00,2d,00,34,00,35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,00,\ 2d,00,42,00,37,00,46,00,33,00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,35,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,\ 74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,43,\ 00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,38,00,37,00,46,00,34,00,2d,00,\ 34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,00,39,00,2d,00,43,00,35,00,41,\ 00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,46,00,30,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,\ 00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,\ 42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,\ 00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,\ 41,00,38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters] "NbProvider"="_tcp" "NameServerPort"=dword:00000089 "CacheTimeout"=dword:000927c0 "BcastNameQueryCount"=dword:00000003 "BcastQueryTimeout"=dword:000002ee "NameSrvQueryCount"=dword:00000003 "NameSrvQueryTimeout"=dword:000005dc "Size/Small/Medium/Large"=dword:00000001 "SessionKeepAlive"=dword:0036ee80 "TransportBindName"="\\Device\\" "EnableLMHOSTS"=dword:00000001 "DhcpNodeType"=dword:00000008 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{2937DCE5-1AB6-4454-A75A-347564768FC5}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 "DhcpNameServerList"=hex(7):31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,31,00,30,\ 00,2e,00,31,00,30,00,00,00,31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,31,00,\ 30,00,2e,00,31,00,38,00,00,00,31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,34,\ 00,2e,00,32,00,31,00,00,00,31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,34,00,\ 2e,00,32,00,32,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}] "NameServerList"=hex(7):00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 "NetbiosOptions"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{7C00B1BF-87F4-4462-BFB9-C5A8BC4164F0}] "NameServerList"=hex(7):00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{91D9B703-C06F-42DA-94D6-DAC5B34DB26A}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{9E0CF4EF-CB11-455C-A310-B7F38698B6B5}] "NameServerList"=hex(7):00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{AFE45985-028E-4E55-A932-232847605B83}] "NameServerList"=hex(7):00,00 "NetbiosOptions"=dword:00000000 "DhcpNameServerList"=hex(7):31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,34,00,2e,\ 00,32,00,31,00,00,00,31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,34,00,2e,00,\ 32,00,32,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Security] "Security"=hex:01,00,14,80,e8,00,00,00,f4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,b8,00,08,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\ 00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,14,\ 00,40,00,00,00,01,01,00,00,00,00,00,05,13,00,00,00,00,00,14,00,40,00,00,00,\ 01,01,00,00,00,00,00,05,14,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,\ 00,00,05,20,00,00,00,2c,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Enum] "0"="Root\\LEGACY_NETBT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE] "DependOnService"=hex(7):4e,00,65,00,74,00,44,00,44,00,45,00,44,00,53,00,44,00,\ 4d,00,00,00,00,00 "Description"="Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Network DDE" "ErrorControl"=dword:00000001 "Group"="NetDDEGroup" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,\ 00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm] "DependOnService"=hex(7):00,00 "Description"="Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. " "DisplayName"="Network DDE DSDM" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,\ 00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000004 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Net Logon" "Group"="RemoteValidation" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Supports pass-through authentication of account logon events for computers in a domain." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters] "DisablePasswordChange"=dword:00000000 "maximumpasswordage"=dword:0000001e "requiresignorseal"=dword:00000001 "requirestrongkey"=dword:00000000 "sealsecurechannel"=dword:00000001 "signsecurechannel"=dword:00000001 "Update"="no" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections." "DisplayName"="Network Connections" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000120 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6e,00,65,00,74,00,6d,00,61,00,6e,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman\Enum] "0"="Root\\LEGACY_NETMAN\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,\ 53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,4e,\ 00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,6b,00,\ 5c,00,76,00,33,00,2e,00,30,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,\ 00,20,00,43,00,6f,00,6d,00,6d,00,75,00,6e,00,69,00,63,00,61,00,74,00,69,00,\ 6f,00,6e,00,20,00,46,00,6f,00,75,00,6e,00,64,00,61,00,74,00,69,00,6f,00,6e,\ 00,5c,00,53,00,4d,00,53,00,76,00,63,00,48,00,6f,00,73,00,74,00,2e,00,65,00,\ 78,00,65,00,22,00,00,00 "DisplayName"="Net.Tcp Port Sharing Service" "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Provides ability to share TCP ports over the net.tcp protocol." "FailureActions"=hex:84,03,00,00,00,00,00,00,00,00,00,00,03,00,00,00,45,00,57,\ 00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing\Security] "Security"=hex:01,00,14,80,b8,00,00,00,c4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,88,00,06,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,\ 14,00,14,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,14,00,14,00,00,\ 00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw4x32] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000d "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,4e,00,45,00,54,00,77,00,34,00,78,\ 00,33,00,32,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Intel(R) Wireless WiFi Link Adapter Driver for Windows XP 32 Bit" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw4x32\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NETw4x32\Enum] "0"="PCI\\VEN_8086&DEV_4229&SUBSYS_11018086&REV_61\\4&29e2c51b&0&00E1" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIC1394] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000e "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,69,00,63,00,31,00,33,00,39,\ 00,34,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="1394 Net Driver" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIC1394\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIC1394\Enum] "0"="V1394\\NIC1394\\2941361023f99" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nla] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Network Location Awareness (NLA)" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,41,00,66,00,64,00,\ 00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Collects and stores network configuration and location information, and notifies applications when this information changes." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nla\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6d,00,73,00,77,00,73,00,6f,00,63,00,6b,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nla\Security] "Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nla\Enum] "0"="Root\\LEGACY_NLA\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NMIndexingService] "Type"=dword:00000010 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,\ 00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,68,00,65,00,61,00,\ 64,00,5c,00,4c,00,69,00,62,00,5c,00,4e,00,4d,00,49,00,6e,00,64,00,65,00,78,\ 00,69,00,6e,00,67,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,2e,00,65,00,\ 78,00,65,00,22,00,00,00 "DisplayName"="NMIndexingService" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NMIndexingService\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NMIndexingService\Enum] "0"="Root\\LEGACY_NMINDEXINGSERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nmwcd] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000016 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,63,00,63,00,64,00,63,00,6d,00,62,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Nokia USB Phone Parent" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nmwcd\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nmwcd\Parameters\Wdf] "KmdfLibraryVersion"="1.7" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nmwcd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nmwcdc] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,63,00,63,00,64,00,63,00,6d,00,62,\ 00,6f,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Nokia USB Generic" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nmwcdc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs] "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000001 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs\Aliases] "lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\ 00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\ 67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\ 00,6d,00,72,00,00,00,00,00 "ntsvcs"=hex(7):65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,00,00,73,00,76,\ 00,63,00,63,00,74,00,6c,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs\Enum] "0"="Root\\LEGACY_NPFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ntfs] "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000004 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ntfs\Enum] "0"="Root\\LEGACY_NTFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtLmSsp] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="NT LM Security Support Provider" "ObjectName"="LocalSystem" "Description"="Provides security to remote procedure call (RPC) programs that use transports other than named pipes." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtLmSsp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtLmSsp\Enum] "0"="Root\\LEGACY_NTLMSSP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Removable Storage" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Config] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Config\Standalone] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6e,00,74,00,6d,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ShutdownTimeout"=dword:00007530 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Enum] "0"="Root\\LEGACY_NTMSSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Null] "ErrorControl"=dword:00000001 "Group"="Base" "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Null\Enum] "0"="Root\\LEGACY_NULL\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "Tag"=dword:00000005 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,76,00,34,00,5f,00,6d,00,69,\ 00,6e,00,69,00,2e,00,73,00,79,00,73,00,00,00 "Group"="Video" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Device0] "InstalledDisplayDrivers"=hex(7):6e,00,76,00,34,00,5f,00,64,00,69,00,73,00,70,\ 00,00,00,00,00 "VgaCompatible"=dword:00000000 "VPEENABLE"=dword:00000000 "RMMaintainDevs"=dword:00000001 "RMMaintainTVStandard"=dword:00000001 "RMMaintainTVScaling"=dword:00000001 "NVZORAN.connector"=dword:00000002 "RotateFlag"=dword:00000004 "MultiFunctionSupported"=dword:00000001 "PanScanSelection"=dword:00000002 "UseBestResolution"=dword:00000001 "ModesetBlankDelay"=dword:00000001 "PowerSaverHsyncOn"=dword:00000001 "DDIgnore_DevSwitchSuppressMask"=dword:00000001 "RMHDMIForceChnStatusFreq"=dword:00000005 "Device Description"="NVIDIA Quadro FX 570M" "EdidOverrideForLinkAndMtEntry"=dword:00000002 "HotKeyUseOSResolution"=dword:00000002 "OverlayMode3"=dword:00000001 "DualViewAllow2ndViewAsPrimary"=dword:00000001 "FSDOSHotKeyPolicy"=dword:00000001 "EnableAGPFW"=dword:00000000 "NvCplDualviewMoveDesktopIcons"=dword:00000001 "NV_R&T"=hex(7):52,00,26,00,54,00,30,00,30,00,30,00,31,00,3d,00,31,00,32,00,38,\ 00,30,00,2c,00,31,00,30,00,32,00,34,00,2c,00,2a,00,2c,00,37,00,35,00,2c,00,\ 2a,00,2c,00,48,00,57,00,50,00,32,00,36,00,30,00,43,00,2e,00,48,00,57,00,50,\ 00,32,00,36,00,34,00,39,00,2e,00,48,00,57,00,50,00,32,00,36,00,32,00,46,00,\ 2c,00,4e,00,4f,00,4e,00,45,00,00,00,52,00,26,00,54,00,30,00,30,00,30,00,32,\ 00,3d,00,31,00,30,00,32,00,34,00,2c,00,37,00,36,00,38,00,2c,00,2a,00,2c,00,\ 37,00,35,00,2c,00,2a,00,2c,00,48,00,57,00,50,00,32,00,36,00,30,00,43,00,2e,\ 00,48,00,57,00,50,00,32,00,36,00,34,00,39,00,2e,00,48,00,57,00,50,00,32,00,\ 36,00,32,00,46,00,2c,00,4e,00,4f,00,4e,00,45,00,00,00,52,00,26,00,54,00,30,\ 00,30,00,30,00,33,00,3d,00,32,00,30,00,34,00,38,00,2d,00,2c,00,32,00,35,00,\ 36,00,30,00,2d,00,2c,00,2a,00,2c,00,2a,00,2c,00,30,00,31,00,39,00,30,00,2d,\ 00,2c,00,50,00,4e,00,52,00,31,00,35,00,61,00,35,00,2e,00,50,00,4e,00,52,00,\ 30,00,30,00,45,00,38,00,2c,00,48,00,44,00,4c,00,4b,00,00,00,00,00 "FailAttachment"=dword:00000001 "EnablePersistenceStorage"=dword:00000001 "LidBehavior"=dword:00000011 "RmInduceDeviceScan"=dword:00000001 "DualViewHotKeyPolicy"=dword:00000001 "EnableBrightnessControl"=dword:00000001 "EdgeBlendingData"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00 "ProfileDefault"="3D App - Default Global Settings" "DualviewPolicyID"=dword:0000000b "DualViewMobile"=dword:00000002 "DevSwitchSuppressMask"=dword:00000006 "NVIF0000000100000000"=hex:01,00,00,00 "PanelPWMFrequency"=dword:0000445c "PanelBrightnessLimits"=dword:0000ff4c "NV_Modes"=hex(7):7b,00,2a,00,7d,00,53,00,20,00,36,00,34,00,30,00,78,00,34,00,\ 30,00,30,00,3d,00,37,00,46,00,3b,00,33,00,32,00,30,00,78,00,32,00,30,00,30,\ 00,20,00,33,00,32,00,30,00,78,00,32,00,34,00,30,00,20,00,34,00,30,00,30,00,\ 78,00,33,00,30,00,30,00,20,00,34,00,38,00,30,00,78,00,33,00,36,00,30,00,20,\ 00,35,00,31,00,32,00,78,00,33,00,38,00,34,00,3d,00,46,00,3b,00,53,00,48,00,\ 56,00,20,00,31,00,39,00,32,00,30,00,78,00,31,00,32,00,30,00,30,00,20,00,31,\ 00,39,00,32,00,30,00,78,00,31,00,34,00,34,00,30,00,20,00,32,00,30,00,34,00,\ 38,00,78,00,31,00,35,00,33,00,36,00,3d,00,31,00,3b,00,31,00,34,00,30,00,30,\ 00,78,00,31,00,30,00,35,00,30,00,78,00,33,00,32,00,20,00,31,00,34,00,34,00,\ 30,00,78,00,39,00,30,00,30,00,78,00,33,00,32,00,20,00,31,00,36,00,30,00,30,\ 00,78,00,31,00,32,00,30,00,30,00,78,00,33,00,32,00,3d,00,31,00,46,00,3b,00,\ 31,00,34,00,30,00,30,00,78,00,31,00,30,00,35,00,30,00,78,00,38,00,2c,00,31,\ 00,36,00,20,00,31,00,34,00,34,00,30,00,78,00,39,00,30,00,30,00,78,00,38,00,\ 2c,00,31,00,36,00,20,00,31,00,36,00,30,00,30,00,78,00,31,00,30,00,32,00,34,\ 00,20,00,31,00,36,00,30,00,30,00,78,00,31,00,32,00,30,00,30,00,78,00,38,00,\ 2c,00,31,00,36,00,20,00,31,00,36,00,38,00,30,00,78,00,31,00,30,00,35,00,30,\ 00,3d,00,33,00,46,00,3b,00,36,00,34,00,30,00,78,00,34,00,38,00,30,00,20,00,\ 38,00,30,00,30,00,78,00,36,00,30,00,30,00,20,00,31,00,30,00,32,00,34,00,78,\ 00,37,00,36,00,38,00,20,00,31,00,31,00,35,00,32,00,78,00,38,00,36,00,34,00,\ 20,00,31,00,32,00,38,00,30,00,78,00,37,00,32,00,30,00,20,00,31,00,32,00,38,\ 00,30,00,78,00,38,00,30,00,30,00,20,00,31,00,32,00,38,00,30,00,78,00,39,00,\ 36,00,30,00,20,00,31,00,32,00,38,00,30,00,78,00,31,00,30,00,32,00,34,00,3d,\ 00,37,00,46,00,3b,00,00,00,00,00 "_deko1000.exe:OGL_46574957"=dword:00000003 "_deko1000hd.exe:OGL_46574957"=dword:00000003 "_deko3000.exe:OGL_46574957"=dword:00000003 "_deko3000hd.exe:OGL_46574957"=dword:00000003 "_inflexion3d.exe:OGL_46574957"=dword:00000003 "_oni.exe:OGL_ExtensionStringNVArch"=dword:00000004 "Acceleration.Level"=dword:00000000 "NvCplConfiguration"=dword:00100000 "PMClocksHighRes"=dword:00000001 "PMClocksHighResThreshold"=dword:00000640 "RMEnableMPSync"=dword:00000001 "PowerMizerLevel"=dword:00000002 "PerfLevelSrc"=dword:00003333 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Device1] "InstalledDisplayDrivers"=hex(7):6e,00,76,00,34,00,5f,00,64,00,69,00,73,00,70,\ 00,00,00,00,00 "VgaCompatible"=dword:00000000 "VPEENABLE"=dword:00000000 "RMMaintainDevs"=dword:00000001 "RMMaintainTVStandard"=dword:00000001 "RMMaintainTVScaling"=dword:00000001 "NVZORAN.connector"=dword:00000002 "RotateFlag"=dword:00000004 "MultiFunctionSupported"=dword:00000001 "PanScanSelection"=dword:00000002 "UseBestResolution"=dword:00000001 "ModesetBlankDelay"=dword:00000001 "PowerSaverHsyncOn"=dword:00000001 "DDIgnore_DevSwitchSuppressMask"=dword:00000001 "RMHDMIForceChnStatusFreq"=dword:00000005 "Device Description"="NVIDIA Quadro FX 570M" "EdidOverrideForLinkAndMtEntry"=dword:00000002 "HotKeyUseOSResolution"=dword:00000002 "OverlayMode3"=dword:00000001 "DualViewAllow2ndViewAsPrimary"=dword:00000001 "FSDOSHotKeyPolicy"=dword:00000001 "EnableAGPFW"=dword:00000000 "NvCplDualviewMoveDesktopIcons"=dword:00000001 "NV_R&T"=hex(7):52,00,26,00,54,00,30,00,30,00,30,00,31,00,3d,00,31,00,32,00,38,\ 00,30,00,2c,00,31,00,30,00,32,00,34,00,2c,00,2a,00,2c,00,37,00,35,00,2c,00,\ 2a,00,2c,00,48,00,57,00,50,00,32,00,36,00,30,00,43,00,2e,00,48,00,57,00,50,\ 00,32,00,36,00,34,00,39,00,2e,00,48,00,57,00,50,00,32,00,36,00,32,00,46,00,\ 2c,00,4e,00,4f,00,4e,00,45,00,00,00,52,00,26,00,54,00,30,00,30,00,30,00,32,\ 00,3d,00,31,00,30,00,32,00,34,00,2c,00,37,00,36,00,38,00,2c,00,2a,00,2c,00,\ 37,00,35,00,2c,00,2a,00,2c,00,48,00,57,00,50,00,32,00,36,00,30,00,43,00,2e,\ 00,48,00,57,00,50,00,32,00,36,00,34,00,39,00,2e,00,48,00,57,00,50,00,32,00,\ 36,00,32,00,46,00,2c,00,4e,00,4f,00,4e,00,45,00,00,00,52,00,26,00,54,00,30,\ 00,30,00,30,00,33,00,3d,00,32,00,30,00,34,00,38,00,2d,00,2c,00,32,00,35,00,\ 36,00,30,00,2d,00,2c,00,2a,00,2c,00,2a,00,2c,00,30,00,31,00,39,00,30,00,2d,\ 00,2c,00,50,00,4e,00,52,00,31,00,35,00,61,00,35,00,2e,00,50,00,4e,00,52,00,\ 30,00,30,00,45,00,38,00,2c,00,48,00,44,00,4c,00,4b,00,00,00,00,00 "FailAttachment"=dword:00000001 "EnablePersistenceStorage"=dword:00000001 "LidBehavior"=dword:00000011 "RmInduceDeviceScan"=dword:00000001 "DualViewHotKeyPolicy"=dword:00000001 "EnableBrightnessControl"=dword:00000001 "EdgeBlendingData"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00 "ProfileDefault"="3D App - Default Global Settings" "DualviewPolicyID"=dword:0000000b "DualViewMobile"=dword:00000002 "DevSwitchSuppressMask"=dword:00000006 "NVIF0000000100000000"=hex:01,00,00,00 "PanelPWMFrequency"=dword:0000445c "PanelBrightnessLimits"=dword:0000ff4c "NV_Modes"=hex(7):7b,00,2a,00,7d,00,53,00,20,00,36,00,34,00,30,00,78,00,34,00,\ 30,00,30,00,3d,00,37,00,46,00,3b,00,33,00,32,00,30,00,78,00,32,00,30,00,30,\ 00,20,00,33,00,32,00,30,00,78,00,32,00,34,00,30,00,20,00,34,00,30,00,30,00,\ 78,00,33,00,30,00,30,00,20,00,34,00,38,00,30,00,78,00,33,00,36,00,30,00,20,\ 00,35,00,31,00,32,00,78,00,33,00,38,00,34,00,3d,00,46,00,3b,00,53,00,48,00,\ 56,00,20,00,31,00,39,00,32,00,30,00,78,00,31,00,32,00,30,00,30,00,20,00,31,\ 00,39,00,32,00,30,00,78,00,31,00,34,00,34,00,30,00,20,00,32,00,30,00,34,00,\ 38,00,78,00,31,00,35,00,33,00,36,00,3d,00,31,00,3b,00,31,00,34,00,30,00,30,\ 00,78,00,31,00,30,00,35,00,30,00,78,00,33,00,32,00,20,00,31,00,34,00,34,00,\ 30,00,78,00,39,00,30,00,30,00,78,00,33,00,32,00,20,00,31,00,36,00,30,00,30,\ 00,78,00,31,00,32,00,30,00,30,00,78,00,33,00,32,00,3d,00,31,00,46,00,3b,00,\ 31,00,34,00,30,00,30,00,78,00,31,00,30,00,35,00,30,00,78,00,38,00,2c,00,31,\ 00,36,00,20,00,31,00,34,00,34,00,30,00,78,00,39,00,30,00,30,00,78,00,38,00,\ 2c,00,31,00,36,00,20,00,31,00,36,00,30,00,30,00,78,00,31,00,30,00,32,00,34,\ 00,20,00,31,00,36,00,30,00,30,00,78,00,31,00,32,00,30,00,30,00,78,00,38,00,\ 2c,00,31,00,36,00,20,00,31,00,36,00,38,00,30,00,78,00,31,00,30,00,35,00,30,\ 00,3d,00,33,00,46,00,3b,00,36,00,34,00,30,00,78,00,34,00,38,00,30,00,20,00,\ 38,00,30,00,30,00,78,00,36,00,30,00,30,00,20,00,31,00,30,00,32,00,34,00,78,\ 00,37,00,36,00,38,00,20,00,31,00,31,00,35,00,32,00,78,00,38,00,36,00,34,00,\ 20,00,31,00,32,00,38,00,30,00,78,00,37,00,32,00,30,00,20,00,31,00,32,00,38,\ 00,30,00,78,00,38,00,30,00,30,00,20,00,31,00,32,00,38,00,30,00,78,00,39,00,\ 36,00,30,00,20,00,31,00,32,00,38,00,30,00,78,00,31,00,30,00,32,00,34,00,3d,\ 00,37,00,46,00,3b,00,00,00,00,00 "_deko1000.exe:OGL_46574957"=dword:00000003 "_deko1000hd.exe:OGL_46574957"=dword:00000003 "_deko3000.exe:OGL_46574957"=dword:00000003 "_deko3000hd.exe:OGL_46574957"=dword:00000003 "_inflexion3d.exe:OGL_46574957"=dword:00000003 "_oni.exe:OGL_ExtensionStringNVArch"=dword:00000004 "Acceleration.Level"=dword:00000000 "NvCplConfiguration"=dword:00100000 "PMClocksHighRes"=dword:00000001 "PMClocksHighResThreshold"=dword:00000640 "RMEnableMPSync"=dword:00000001 "PowerMizerLevel"=dword:00000002 "PerfLevelSrc"=dword:00003333 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Video] "Service"="nv" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nv\Enum] "0"="PCI\\VEN_10DE&DEV_040C&SUBSYS_30C5103C&REV_A1\\4&171b8011&0&0008" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVIDIA Performance Driver Service] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4e,00,56,00,49,00,44,00,49,\ 00,41,00,20,00,43,00,6f,00,72,00,70,00,6f,00,72,00,61,00,74,00,69,00,6f,00,\ 6e,00,5c,00,50,00,65,00,72,00,66,00,6f,00,72,00,6d,00,61,00,6e,00,63,00,65,\ 00,20,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,6e,00,76,00,50,00,\ 44,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,22,00,00,00 "DisplayName"="NVIDIA Performance Driver Service" "ObjectName"="LocalSystem" "Description"="Provides support for NVIDIA Quadro FX cards in combination with Autodesk AutoCAD and Autodesk 3ds MAX." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVIDIA Performance Driver Service\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVIDIA Performance Driver Service\Enum] "0"="Root\\LEGACY_NVIDIA_PERFORMANCE_DRIVER_SERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVSvc] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,\ 00,76,00,73,00,76,00,63,00,33,00,32,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="NVIDIA Display Driver Service" "ObjectName"="LocalSystem" "Description"="Provides system and desktop level support to the NVIDIA display driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVSvc\Enum] "0"="Root\\LEGACY_NVSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFlt] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,77,00,6c,00,6e,00,6b,00,66,\ 00,6c,00,74,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IPX Traffic Filter Driver" "DependOnService"=hex(7):4e,00,77,00,6c,00,6e,00,6b,00,46,00,77,00,64,00,00,00,\ 00,00 "DependOnGroup"=hex(7):00,00 "Description"="IPX Traffic Filter Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFlt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFwd] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,77,00,6c,00,6e,00,6b,00,66,\ 00,77,00,64,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="IPX Traffic Forwarder Driver" "Description"="IPX Traffic Forwarder Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkFwd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ohci1394] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6f,00,68,00,63,00,69,00,31,00,33,\ 00,39,00,34,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="OHCI Compliant IEEE 1394 Host Controller" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ohci1394\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ohci1394\Enum] "0"="PCI\\VEN_1180&DEV_0832&SUBSYS_30C5103C&REV_03\\4&3b3a03b5&0&32F0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ose] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,\ 00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,\ 6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,\ 00,53,00,6f,00,75,00,72,00,63,00,65,00,20,00,45,00,6e,00,67,00,69,00,6e,00,\ 65,00,5c,00,4f,00,53,00,45,00,2e,00,45,00,58,00,45,00,22,00,00,00 "DisplayName"="Office Source Engine" "ObjectName"="LocalSystem" "Description"="Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ose\Security] "Security"=hex:01,00,14,80,d0,00,00,00,dc,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,a0,00,07,00,00,00,00,00,14,00,9d,01,00,00,01,01,00,00,00,00,00,\ 05,04,00,00,00,00,00,18,00,9d,01,00,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 22,02,00,00,00,00,14,00,9d,01,00,00,01,01,00,00,00,00,00,01,00,00,00,00,00,\ 00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,\ 0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,8d,01,02,\ 00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,\ 00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\ 01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ose\Enum] "0"="Root\\LEGACY_OSE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Outlook] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Outlook\Performance] "Debug"=dword:00000000 "Collect"="CollectPerformanceData" "Library"="C:\\PROGRA~1\\COMMON~1\\SYSTEM\\MSMAPI\\1033\\MSMAPI32.DLL" "Version"=dword:0000000d "Close"="ClosePerformanceData" "Open"="OpenPerformanceData" "WbemAdapFileSignature"=hex:26,8d,dc,23,8b,7f,48,cd,f3,90,e6,94,62,97,b1,e4 "WbemAdapFileTime"=hex:00,3c,89,d1,b6,1f,c8,01 "WbemAdapFileSize"=dword:0015ce08 "WbemAdapStatus"=dword:00000000 "Last Counter"=dword:0000264c "Last Help"=dword:0000264d "First Counter"=dword:00002628 "First Help"=dword:00002629 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Parport] "ErrorControl"=dword:00000001 "Group"="Parallel arbitrator" "Start"=dword:00000003 "Tag"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Parallel port driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,61,00,72,00,70,00,6f,00,72,\ 00,74,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Parport\Enum] "0"="ACPI\\PNP0401\\5&381fcc12&0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PartMgr] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000005 "Type"=dword:00000001 "DisplayName"="Partition Manager" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PartMgr\Enum] "0"="Root\\LEGACY_PARTMGR\\0000" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="IDE\\DiskST9200420AS_____________________________3.AHC___\\533530483547304b202020202020202020202020" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ParVdm] "DependOnGroup"=hex(7):50,00,61,00,72,00,61,00,6c,00,6c,00,65,00,6c,00,20,00,\ 61,00,72,00,62,00,69,00,74,00,72,00,61,00,74,00,6f,00,72,00,00,00,00,00 "DependOnService"=hex(7):50,00,61,00,72,00,70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000000 "Group"="Extended base" "Start"=dword:00000004 "Tag"=dword:00000002 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ParVdm\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ParVdm\Enum] "0"="Root\\LEGACY_PARVDM\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCA] "Type"=dword:00000110 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,53,00,4d,00,49,00,4e,00,53,00,54,00,5c,00,50,00,43,00,41,00,6e,00,67,\ 00,65,00,6c,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="PC Angel" "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCA\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCA\Enum] "0"="Root\\LEGACY_PCA\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pccsmcfd] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,63,00,63,00,73,00,6d,00,63,\ 00,66,00,64,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="PCCS Mode Change Filter Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pccsmcfd\DriverInfo] "RefCount"=hex(7):70,00,63,00,63,00,73,00,6d,00,63,00,66,00,64,00,5f,00,41,00,\ 33,00,42,00,33,00,39,00,31,00,36,00,45,00,35,00,44,00,38,00,31,00,33,00,38,\ 00,46,00,35,00,39,00,45,00,45,00,32,00,31,00,38,00,33,00,32,00,31,00,42,00,\ 32,00,37,00,42,00,30,00,34,00,34,00,44,00,33,00,42,00,31,00,38,00,32,00,39,\ 00,34,00,00,00,55,00,6e,00,6b,00,6e,00,6f,00,77,00,6e,00,20,00,44,00,72,00,\ 69,00,76,00,65,00,72,00,20,00,53,00,74,00,6f,00,72,00,65,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pccsmcfd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCI] "ErrorControl"=dword:00000003 "Group"="Boot Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="PCI Bus Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,63,00,69,00,2e,00,73,00,79,\ 00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCI\Parameters] "1045C621"=hex:04,00,00,00,00,00,00,00 "10950640"=hex:04,00,00,00,00,00,00,00 "80861230"=hex:04,00,00,00,00,00,00,00 "80867010"=hex:04,00,00,00,00,00,00,00 "104B0140"=hex:08,00,00,00,00,00,00,00 "11790603"=hex:08,00,00,00,00,00,00,00 "80867113"=hex:08,00,00,00,00,00,00,00 "497884C5"=hex:08,00,00,00,00,00,00,00 "11063040"=hex:08,00,00,00,00,00,00,00 "0E111000"=hex:10,00,00,00,00,00,00,00 "0E112000"=hex:10,00,00,00,00,00,00,00 "10390406"=hex:10,00,00,00,00,00,00,00 "80860482"=hex:00,40,00,00,00,00,00,00 "80860008"=hex:10,00,00,00,00,00,00,00 "10140002"=hex:10,00,00,00,00,00,00,00 "10800600"=hex:20,00,00,00,00,00,00,00 "10131100"=hex:40,00,00,00,00,00,00,00 "10B95219"=hex:80,00,00,00,00,00,00,00 "1C1C0001"=hex:00,01,00,00,00,00,00,00 "10970038"=hex:00,01,00,00,00,00,00,00 "100BD001"=hex:00,04,00,00,00,00,00,00 "808604A3"=hex:00,08,00,00,00,00,00,00 "10AA0000"=hex:00,08,00,00,00,00,00,00 "533388D1"=hex:00,00,00,00,01,00,00,00 "11790605"=hex:00,10,00,00,00,00,00,00 "10131110"=hex:00,20,00,00,00,00,00,00 "11800478"=hex:00,20,00,00,00,00,00,00 "11800475"=hex:00,20,00,00,00,00,00,00 "11800476"=hex:00,20,00,00,00,00,00,00 "10040101"=hex:00,40,00,00,00,00,00,00 "10421000"=hex:00,40,00,00,00,00,00,00 "104CAC12"=hex:00,00,01,00,00,00,00,00 "11800466"=hex:00,00,01,00,00,00,00,00 "10140095"=hex:00,00,04,00,00,00,00,00 "80862418"=hex:00,00,04,00,00,00,00,00 "80862428"=hex:00,00,04,00,00,00,00,00 "8086244E"=hex:00,00,04,00,00,00,00,00 "80862448"=hex:00,00,04,00,00,00,00,00 "8086122E"=hex:00,00,08,00,00,00,00,00 "80867000"=hex:00,00,08,00,00,00,00,00 "80867110"=hex:00,00,08,00,00,00,00,00 "80867600"=hex:00,00,08,00,00,00,00,00 "10024747"=hex:00,00,40,00,00,00,00,00 "10024754"=hex:00,00,00,00,01,00,00,00 "53338901"=hex:00,00,00,00,01,00,00,00 "101300D6"=hex:00,00,40,00,00,00,00,00 "104CAC15"=hex:00,00,40,00,00,00,00,00 "110B0004"=hex:00,00,40,00,00,00,00,00 "1000000F"=hex:00,00,40,00,00,00,00,00 "104CAC17"=hex:00,00,40,00,00,00,00,00 "10239397"=hex:00,00,40,00,00,00,00,00 "10024742"=hex:00,00,40,00,00,00,00,00 "10024744"=hex:00,00,40,00,00,00,00,00 "10024749"=hex:00,00,40,00,00,00,00,00 "10024750"=hex:00,00,40,00,00,00,00,00 "10024751"=hex:00,00,40,00,00,00,00,00 "10024755"=hex:00,00,40,00,00,00,00,00 "10024757"=hex:00,00,40,20,00,00,00,00 "10024759"=hex:00,00,40,20,00,00,00,00 "10024C42"=hex:00,00,40,00,00,00,00,00 "10024C44"=hex:00,00,40,00,00,00,00,00 "10024C47"=hex:00,00,40,00,00,00,00,00 "10024C49"=hex:00,00,40,00,00,00,00,00 "10024C50"=hex:00,00,40,00,00,00,00,00 "10024C51"=hex:00,00,40,00,00,00,00,00 "10025654"=hex:00,00,00,00,01,00,00,00 "10025655"=hex:00,00,40,00,00,00,00,00 "10025656"=hex:00,00,40,00,00,00,00,00 "121A0003"=hex:00,00,40,00,00,00,00,00 "1045C861107B9300"=hex:00,00,40,00,00,00,00,00 "1045C8611045C861"=hex:00,00,40,00,00,00,00,00 "80861231"=hex:00,00,00,01,00,00,00,00 "12730002"=hex:00,00,00,01,00,00,00,00 "1014007D"=hex:00,00,00,01,00,00,00,00 "12850100"=hex:00,00,00,01,00,00,00,00 "12176836"=hex:00,00,00,08,00,00,00,00 "12176832"=hex:00,00,00,08,00,00,00,00 "109107A0"=hex:00,00,00,20,00,00,00,00 "80867800"=hex:00,00,00,20,00,00,00,00 "10c88005"=hex:00,00,00,20,00,00,00,00 "10c88006"=hex:00,00,00,20,00,00,00,00 "10c80005"=hex:00,00,00,20,00,00,00,00 "10c80006"=hex:00,00,00,20,00,00,00,00 "102B1001"=hex:00,00,00,80,00,00,00,00 "10DD0100"=hex:00,00,00,20,00,00,00,00 "10950646"=hex:00,00,00,20,00,00,00,00 "10950670"=hex:00,00,00,20,00,00,00,00 "10950648"=hex:00,00,00,20,00,00,00,00 "10110026"=hex:00,00,00,20,00,00,00,00 "8086B154"=hex:00,00,00,20,00,00,00,00 "53338904"=hex:00,00,00,20,00,00,00,00 "11068598"=hex:00,00,00,20,00,00,00,00 "11068605"=hex:00,00,00,20,00,00,00,00 "11790609"=hex:00,00,00,40,00,00,00,00 "10140047"=hex:00,00,00,40,00,00,00,00 "102B051B"=hex:00,00,00,80,00,00,00,00 "102B0520"=hex:00,00,00,80,00,00,00,00 "102B0521"=hex:00,00,00,80,00,00,00,00 "102B1025"=hex:00,00,00,80,00,00,00,00 "102B0525"=hex:00,00,00,80,00,00,00,00 "80867121"=hex:00,00,00,80,00,00,00,00 "80867123"=hex:00,00,00,80,00,00,00,00 "80867125"=hex:00,00,00,80,00,00,00,00 "80861132"=hex:00,00,00,80,00,00,00,00 "90050050"=hex:00,00,00,80,00,00,00,00 "9005005F"=hex:00,00,00,80,00,00,00,00 "10024752"=hex:00,00,00,80,00,00,00,00 "1002474F"=hex:00,00,00,80,00,00,00,00 "1002474D"=hex:00,00,00,80,00,00,00,00 "10024753"=hex:00,00,00,80,00,00,00,00 "1002474C"=hex:00,00,00,80,00,00,00,00 "1002474E"=hex:00,00,00,80,00,00,00,00 "10024C4D"=hex:00,00,00,80,00,00,00,00 "10024C4E"=hex:00,00,00,80,00,00,00,00 "10024C52"=hex:00,00,00,80,00,00,00,00 "10024C53"=hex:00,00,00,80,00,00,00,00 "10239880"=hex:00,00,00,80,00,00,00,00 "10DE00A0"=hex:00,00,00,80,00,00,00,00 "10DE00A1"=hex:00,00,00,80,00,00,00,00 "10DE00A3"=hex:00,00,00,80,00,00,00,00 "10DE00B0"=hex:00,00,00,80,00,00,00,00 "10DE00B1"=hex:00,00,00,80,00,00,00,00 "10DE00B3"=hex:00,00,00,80,00,00,00,00 "10DE0100"=hex:00,00,00,80,00,00,00,00 "10DE0101"=hex:00,00,00,80,00,00,00,00 "10DE0102"=hex:00,00,00,80,00,00,00,00 "10DE0103"=hex:00,00,00,80,00,00,00,00 "10DE0120"=hex:00,00,00,80,00,00,00,00 "10DE0121"=hex:00,00,00,80,00,00,00,00 "10DE0122"=hex:00,00,00,80,00,00,00,00 "10DE0123"=hex:00,00,00,80,00,00,00,00 "10DE0150"=hex:00,00,00,80,00,00,00,00 "10DE0151"=hex:00,00,00,80,00,00,00,00 "10DE0152"=hex:00,00,00,80,00,00,00,00 "10DE0153"=hex:00,00,00,80,00,00,00,00 "10DE0200"=hex:00,00,00,80,00,00,00,00 "10DE0201"=hex:00,00,00,80,00,00,00,00 "10DE0202"=hex:00,00,00,80,00,00,00,00 "10DE0203"=hex:00,00,00,80,00,00,00,00 "12D20018"=hex:00,00,00,80,00,00,00,00 "12D20019"=hex:00,00,00,80,00,00,00,00 "10136003"=hex:00,00,00,80,00,00,00,00 "3D3D000A"=hex:00,00,00,80,00,00,00,00 "10024158"=hex:00,00,00,00,01,00,00,00 "10024354"=hex:00,00,00,00,01,00,00,00 "10024358"=hex:00,00,00,00,01,00,00,00 "10024554"=hex:00,00,00,00,01,00,00,00 "10024758"=hex:00,00,00,00,01,00,00,00 "10024C54"=hex:00,00,00,00,01,00,00,00 "53338810"=hex:00,00,00,00,01,00,00,00 "53338811"=hex:00,00,00,00,01,00,00,00 "53338812"=hex:00,00,00,00,01,00,00,00 "53338814"=hex:00,00,00,00,01,00,00,00 "53338880"=hex:00,00,00,00,01,00,00,00 "533388B0"=hex:00,00,00,00,01,00,00,00 "533388C0"=hex:00,00,00,00,01,00,00,00 "533388C1"=hex:00,00,00,00,01,00,00,00 "533388D0"=hex:00,00,00,00,01,00,00,00 "533388F0"=hex:00,00,00,00,01,00,00,00 "53338902"=hex:00,00,00,00,01,00,00,00 "0E11B109"=hex:00,00,00,00,02,00,00,00 "10024342"=hex:00,00,00,00,80,00,00,00 "10024362"=hex:00,00,00,00,80,00,00,00 "10024371"=hex:00,00,00,00,80,00,00,00 "100C3202"=hex:00,8a,00,00,00,00,00,00 "10668002"=hex:00,00,30,00,00,00,00,00 "10660002"=hex:00,00,30,00,00,00,00,00 "10040102"=hex:00,40,00,02,00,00,00,00 "1045C814"=hex:00,00,40,20,00,00,00,00 "10024756"=hex:00,00,40,20,00,00,00,00 "1002475A"=hex:00,00,40,20,00,00,00,00 "80861161"=hex:00,00,00,40,10,00,00,00 "80861461"=hex:00,00,00,40,10,00,00,00 "1000000B"=hex:00,00,00,a0,00,00,00,00 "10DE0020"=hex:00,00,00,a0,00,00,00,00 "10DE0028"=hex:00,00,00,a0,00,00,00,00 "10DE0029"=hex:00,00,00,a0,00,00,00,00 "10DE002A"=hex:00,00,00,a0,00,00,00,00 "10DE002B"=hex:00,00,00,a0,00,00,00,00 "10DE002C"=hex:00,00,00,a0,00,00,00,00 "10DE002D"=hex:00,00,00,a0,00,00,00,00 "10DE002E"=hex:00,00,00,a0,00,00,00,00 "10DE002F"=hex:00,00,00,a0,00,00,00,00 "101300D6101880D6"=hex:00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCI\Enum] "0"="ACPI\\PNP0A08\\2&daba3ff&0" "Count"=dword:00000006 "NextInstance"=dword:00000006 "1"="PCI\\VEN_8086&DEV_2A01&SUBSYS_00000000&REV_0C\\3&b1bfb68&0&08" "2"="PCI\\VEN_8086&DEV_283F&SUBSYS_00000000&REV_03\\3&b1bfb68&0&E0" "3"="PCI\\VEN_8086&DEV_2841&SUBSYS_00000000&REV_03\\3&b1bfb68&0&E1" "4"="PCI\\VEN_8086&DEV_2847&SUBSYS_00000000&REV_03\\3&b1bfb68&0&E4" "5"="PCI\\VEN_8086&DEV_2448&SUBSYS_00000000&REV_F3\\3&b1bfb68&0&F0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCIDump] "ErrorControl"=dword:00000000 "Group"="PCI Configuration" "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCIIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000003 "Type"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,63,00,69,00,69,00,64,00,65,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCIIde\Enum] "0"="PCI\\VEN_8086&DEV_2828&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&FA" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pcmcia] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000001 "Type"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,63,00,6d,00,63,00,69,00,61,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pcmcia\Parameters] "SoundsEnabled"=dword:00000000 "IsaIrqRescanComplete"=dword:00000001 "DisableIsaToPciRouting"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pcmcia\Enum] "0"="PCI\\VEN_1180&DEV_0476&SUBSYS_30C5103C&REV_B9\\4&3b3a03b5&0&30F0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="PCI\\VEN_1180&DEV_0476&SUBSYS_30C5103C&REV_B9\\4&3b3a03b5&0&31F0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PDCOMP] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PDFRAME] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PDRELI] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PDRFRAME] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\perc2] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\perc2\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\perc2\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\perc2hib] "ErrorControl"=dword:00000001 "Group"="Filter" "Start"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfDisk] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfDisk\Performance] "Close"="CloseDiskObject" "Collect"="CollectDiskObjectData" "Collect Timeout"=dword:000007d0 "Library"="perfdisk.dll" "Object List"="234 236" "Open"="OpenDiskObject" "Open Timeout"=dword:00001388 "WbemAdapFileSignature"=hex:ab,fb,67,3b,24,a9,b3,28,77,61,d4,97,52,9f,b5,b9 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00006800 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfNet] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfNet\Performance] "Close"="CloseNetSvcsObject" "Collect"="CollectNetSvcsObjectData" "Collect Timeout"=dword:00001388 "Library"="perfnet.dll" "Object List"="52 262 330 1300" "Open"="OpenNetSvcsObject" "Open Timeout"=dword:00001f40 "WbemAdapFileSignature"=hex:91,3a,f8,8b,02,91,d7,d3,a0,fd,c9,2f,5e,1c,c7,d7 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00004600 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfOS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfOS\Performance] "Close"="CloseOSObject" "Collect"="CollectOSObjectData" "Collect Timeout"=dword:00001f40 "Library"="perfos.dll" "Object List"="2 4 86 238 260 700" "Open"="OpenOSObject" "Open Timeout"=dword:00001388 "WbemAdapFileSignature"=hex:ac,da,fc,d1,4e,c0,ec,e8,91,98,50,37,46,a5,c1,47 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00006200 "WbemAdapStatus"=dword:00000000 "Disable Performance Counters"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfProc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfProc\Performance] "Close"="CloseSysProcessObject" "Collect"="CollectSysProcessObjectData" "Collect Timeout"=dword:00001f40 "Library"="perfproc.dll" "Object List"="230 232 786 740 816 1408 1500 1548 1760" "Open"="OpenSysProcessObject" "Open Timeout"=dword:00002710 "WbemAdapFileSignature"=hex:17,93,cc,66,06,05,f6,3b,14,fb,96,c7,70,7f,75,ba "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00008800 "WbemAdapStatus"=dword:00000000 "Disable Performance Counters"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlay] "Description"="Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "DisplayName"="Plug and Play" "ErrorControl"=dword:00000001 "Group"="PlugPlay" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "PlugPlayServiceType"=dword:00000003 "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlay\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pml Driver HPZ12] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,48,00,50,00,5a,00,31,00,32,00,00,00 "ObjectName"="NT AUTHORITY\\LocalService" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pml Driver HPZ12\Parameters] "ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,48,00,50,00,\ 5a,00,69,00,70,00,6d,00,31,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pml Driver HPZ12\Security] "Security"=hex:01,00,14,80,a4,00,00,00,b0,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,74,00,05,00,00,00,00,00,14,00,b5,01,02,00,01,01,00,00,00,00,00,\ 01,00,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\ 00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\ 02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Pml Driver HPZ12\Enum] "0"="Root\\LEGACY_PML_DRIVER_HPZ12\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="IPSEC Services" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,54,00,63,00,70,00,\ 69,00,70,00,00,00,49,00,50,00,53,00,65,00,63,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver." "PolstoreDllRegisterVersion"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent\Enum] "0"="Root\\LEGACY_POLICYAGENT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PptpMiniport] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,70,00,74,\ 00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="WAN Miniport (PPTP)" "Description"="WAN Miniport (PPTP)" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PptpMiniport\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PptpMiniport\Enum] "0"="Root\\MS_PPTPMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users." "DisplayName"="Protected Storage" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000120 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Enum] "0"="Root\\LEGACY_PROTECTEDSTORAGE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000007 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,73,00,63,00,68,00,65,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="QoS Packet Scheduler" "Group"="PNP_TDI" "DependOnService"=hex(7):47,00,70,00,63,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="QoS Packet Scheduler" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\NdisWanIp] "UpperBindings"="\\Device\\{86092EB9-4A6B-4A64-B428-B3FA7F3EBDC6}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{145638C9-949D-4442-A865-9819E776B889}] "UpperBindings"="\\Device\\{F40F4A4F-2713-478A-8530-4F35A73EA878}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{2937DCE5-1AB6-4454-A75A-347564768FC5}] "UpperBindings"="\\Device\\{7742FF7C-22DA-47FF-8FBC-FB1BEDF2F209}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{2B8DDB41-2379-4992-B9F8-DC7F41EC4817}] "UpperBindings"="\\Device\\{3617634E-F1BA-47F3-A9A0-2F1297CCBA7D}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{3223DA9C-4B2F-46F1-96EA-45C158827B15}] "UpperBindings"="\\Device\\{3822C3AF-EC35-468D-9367-6FC6D1C8085A}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}] "UpperBindings"="\\Device\\{C92E9509-7682-462E-B096-E257191FAE26}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}] "UpperBindings"="\\Device\\{F0D38888-B5C2-474E-83F9-3757606E68F4}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}] "UpperBindings"="\\Device\\{A69D5BD9-E1ED-4E22-992A-DFF021725DAD}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}] "UpperBindings"="\\Device\\{249CA95E-ECDC-4D9C-A7E8-60BEF196CE1C}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{AFE45985-028E-4E55-A932-232847605B83}] "UpperBindings"="\\Device\\{332AE45B-0B88-453E-94B2-AF34E10949EC}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{B57AD90D-90AA-474A-A4F3-051BE53F591A}] "UpperBindings"="\\Device\\{352475F5-0EAF-4241-89D3-771CA740DF0B}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{BA3CCE32-43A8-49EB-ABC0-C4F4B2AE089F}] "UpperBindings"="\\Device\\{8F1DF030-2618-44AF-B2B2-27CF672E816D}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{D70925EB-839D-49D7-AA75-9615B181C316}] "UpperBindings"="\\Device\\{8C57D371-B5B1-4987-952E-EF2271FA199A}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{F070A995-27F7-4A0F-AFD1-35BB9E058301}] "UpperBindings"="\\Device\\{BE87D1E3-B66E-460F-BF6A-5091E7FBFE80}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{F6483FC5-D0F5-49BA-9DE0-CE505408BC40}] "UpperBindings"="\\Device\\{09B77472-D962-4AC6-B6AE-3250D0E67065}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Parameters\Adapters\{FE38F880-8593-4467-BD42-E31E6A3B11D9}] "UpperBindings"="\\Device\\{986EFDA9-6549-4B15-B31C-24B311364516}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Performance] "Library"="pschdprf.dll" "Open"="OpenPschedPerformanceData" "Close"="ClosePschedPerformanceData" "Collect"="CollectPschedPerformanceData" "Last Counter"=dword:000007dc "Last Help"=dword:000007dd "First Counter"=dword:00000790 "First Help"=dword:00000791 "WbemAdapFileSignature"=hex:b4,45,9d,13,47,3d,07,fc,b4,33,65,c0,27,32,de,16 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00002a00 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PSched\Enum] "0"="Root\\MS_PSCHEDMP\\0000" "Count"=dword:00000007 "NextInstance"=dword:00000007 "1"="Root\\MS_PSCHEDMP\\0001" "2"="Root\\MS_PSCHEDMP\\0002" "3"="Root\\MS_PSCHEDMP\\0003" "4"="Root\\MS_PSCHEDMP\\0004" "5"="Root\\MS_PSCHEDMP\\0006" "6"="Root\\MS_PSCHEDMP\\0007" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ptilink] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,74,00,69,00,6c,00,69,00,6e,\ 00,6b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Direct Parallel Link Driver" "Description"="Direct Parallel Link Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ptilink\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ptilink\Enum] "0"="Root\\MS_PTIMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1080] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003d "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1080\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1080\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ql10wnt] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000023 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ql10wnt\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ql10wnt\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql12160] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003f "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql12160\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql12160\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1240] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000031 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1240\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1240\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1280] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003f "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1280\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ql1280\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,61,00,63,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access Auto Connection Driver" "Group"="Streams Drivers" "Description"="Remote Access Auto Connection Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAcd\Enum] "0"="Root\\LEGACY_RASACD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Remote Access Auto Connection Manager" "DependOnService"=hex(7):52,00,61,00,73,00,4d,00,61,00,6e,00,00,00,54,00,61,00,\ 70,00,69,00,73,00,72,00,76,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,61,00,75,00,74,00,6f,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rasl2tp] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,6c,00,32,00,74,\ 00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="WAN Miniport (L2TP)" "Description"="WAN Miniport (L2TP)" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rasl2tp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rasl2tp\Enum] "0"="Root\\MS_L2TPMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Remote Access Connection Manager" "DependOnService"=hex(7):54,00,61,00,70,00,69,00,73,00,72,00,76,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Creates a network connection." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters] "Medias"=hex(7):72,00,61,00,73,00,74,00,61,00,70,00,69,00,00,00,00,00 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,6d,00,61,00,6e,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "IpOutLowWatermark"=dword:00000001 "IpOutHighWatermark"=dword:00000005 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters\Quarantine] "Enabled"=dword:00000001 "AutoRefreshEnabled"=dword:00000000 "AutoRefreshTimeout"=dword:01808580 "WorkItemTimeout"=dword:00000bb8 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP] "MaxConfigure"=dword:0000000a "MaxFailure"=dword:0000000a "MaxReject"=dword:00000005 "MaxTerminate"=dword:00000002 "Multilink"=dword:00000000 "NegotiateTime"=dword:00000096 "RestartTimer"=dword:00000003 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\ControlProtocols] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\ControlProtocols\BuiltIn] "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,70,00,70,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\ControlProtocols\Chap] "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP] "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,70,00,70,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13] "RolesSupported"=dword:00000002 "FriendlyName"="Smart Card or other Certificate" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "InvokeUsernameDialog"=dword:00000000 "InvokePasswordDialog"=dword:00000000 "MPPEEncryptionSupported"=dword:00000001 "ConfigCLSID"="{58AB2366-D597-11d1-B90E-00C04FC9B263}" "StandaloneSupported"=dword:00000000 "NoRootRevocationCheck"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\21] "ConfigUIPath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,61,00,\ 5f,00,73,00,77,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "FriendlyName"=hex(2):53,00,65,00,63,00,75,00,72,00,65,00,57,00,32,00,00,00 "IdentityPath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,61,00,\ 5f,00,73,00,77,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "InteractiveUIPath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,\ 61,00,5f,00,73,00,77,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "Path"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,\ 00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,61,00,5f,00,\ 73,00,77,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "InvokePasswordDialog"=dword:00000000 "InvokeUsernameDialog"=dword:00000000 "MPPEEncryptionSupported"=dword:00000001 "StandaloneSupported"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\25] "FriendlyName"="Protected EAP (PEAP)" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "InvokeUsernameDialog"=dword:00000000 "InvokePasswordDialog"=dword:00000000 "MPPEEncryptionSupported"=dword:00000001 "ConfigCLSID"="{58AB2366-D597-11d1-B90E-00C04FC9B263}" "StandaloneSupported"=dword:00000001 "NoRootRevocationCheck"=dword:00000001 "RolesSupported"=dword:0000001a [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\26] "FriendlyName"="Secured password (EAP-MSCHAP v2)" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 "ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 "IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 "InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "InvokeUsernameDialog"=dword:00000000 "InvokePasswordDialog"=dword:00000000 "MPPEEncryptionSupported"=dword:00000001 "ConfigCLSID"="{2af6bcaa-f526-4803-aeb8-5777ce386647}" "StandaloneSupported"=dword:00000001 "RolesSupported"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\4] "RolesSupported"=dword:0000000a "FriendlyName"="MD5-Challenge" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00 "InvokeUsernameDialog"=dword:00000001 "InvokePasswordDialog"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Security] "Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Enum] "0"="Root\\LEGACY_RASMAN\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,70,00,70,\ 00,6f,00,65,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access PPPOE Driver" "Description"="Remote Access PPPOE Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,41,00,30,\ 00,33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,\ 34,00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,\ 00,30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,38,00,30,00,44,00,44,00,42,\ 00,45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,\ 45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,\ 00,37,00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,\ 00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,\ 44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,\ 00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,\ 00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,\ 2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,32,00,\ 39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,\ 00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,\ 37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,33,00,43,00,46,00,39,00,\ 30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,\ 00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,\ 36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,2d,\ 00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,00,\ 38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,46,\ 00,38,00,41,00,7d,00,22,00,00,00,22,00,7b,00,38,00,30,00,44,00,44,00,42,00,\ 45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,\ 00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,\ 37,00,45,00,43,00,41,00,39,00,39,00,7d,00,22,00,00,00,22,00,7b,00,35,00,33,\ 00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,\ 34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,\ 00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,22,00,00,00,\ 22,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,\ 00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,\ 2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,\ 00,7d,00,22,00,00,00,22,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,\ 35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,\ 00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,\ 38,00,46,00,43,00,35,00,7d,00,22,00,00,00,22,00,7b,00,33,00,43,00,46,00,39,\ 00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,\ 43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,\ 00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,00,22,00,00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,52,00,61,00,73,\ 00,50,00,70,00,70,00,6f,00,65,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,\ 44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,\ 00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,\ 41,00,32,00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\ 00,63,00,65,00,5c,00,52,00,61,00,73,00,50,00,70,00,70,00,6f,00,65,00,5f,00,\ 7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,38,00,37,\ 00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,\ 45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,39,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,52,00,61,00,73,00,\ 50,00,70,00,70,00,6f,00,65,00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,\ 00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,\ 2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,\ 00,45,00,34,00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,52,00,61,00,73,00,50,00,70,00,70,00,6f,00,65,00,5f,00,7b,\ 00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,00,\ 45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,32,\ 00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,00,\ 00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,52,00,61,00,73,00,50,\ 00,70,00,70,00,6f,00,65,00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,\ 45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,\ 00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,\ 36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\ 00,65,00,5c,00,52,00,61,00,73,00,50,00,70,00,70,00,6f,00,65,00,5f,00,7b,00,\ 33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,\ 00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,\ 32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,00,00,\ 00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasPppoe\Enum] "0"="Root\\MS_PPPOEMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Raspti] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,74,00,69,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Direct Parallel" "Description"="Direct Parallel" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Raspti\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Raspti\Enum] "0"="Root\\MS_PTIMINIPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rdbss] "Type"=dword:00000002 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,64,00,62,00,73,00,73,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Rdbss" "Group"="Network" "Description"="Rdbss" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rdbss\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rdbss\Enum] "0"="Root\\LEGACY_RDBSS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD] "ErrorControl"=dword:00000000 "Group"="Video Save" "ImagePath"="System32\\DRIVERS\\RDPCDD.sys" "Start"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD\Device0] "Device Description"="RDPDD Chained DD" "InstalledDisplayDrivers"=hex(7):52,00,44,00,50,00,44,00,44,00,00,00,00,00 "MirrorDriver"=dword:00000001 "VgaCompatible"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD\Video] "VideoID"="{DEB039CC-B704-4F53-B43E-9DD4432FA2E9}" "Service"="RDPCDD" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPCDD\Enum] "0"="Root\\LEGACY_RDPCDD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPDD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPDD\Device0] "InstalledDisplayDrivers"=hex(7):52,00,44,00,50,00,44,00,44,00,00,00,00,00 "VgaCompatible"=dword:00000000 "Attach.RelativeX"=dword:00000000 "Attach.RelativeY"=dword:00000000 "Attach.ToDesktop"=dword:00000001 "DefaultSettings.XResolution"=dword:00000320 "DefaultSettings.YResolution"=dword:00000258 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpdr] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,64,00,70,00,64,00,72,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Terminal Server Device Redirector Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpdr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpdr\Enum] "0"="Root\\RDPDR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP\NetworkProvider] "DeviceName"="\\Device\\RdpDr" "Name"="Microsoft Terminal Services" "ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,72,00,70,00,72,00,6f,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP\Enum] "0"="Root\\LEGACY_RDPNP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPWD] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPWD\Enum] "0"="Root\\LEGACY_RDPWD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDSessMgr] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,65,00,73,\ 00,73,00,6d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Remote Desktop Help Session Manager" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDSessMgr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\redbook] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,65,00,64,00,62,00,6f,00,6f,\ 00,6b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Digital CD Audio Playback Filter Driver" "Group"="Pnp Filter" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\redbook\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\redbook\Enum] "0"="IDE\\CdRomOptiarc_DVD_RW_AD-7560A_________________DH10____\\3033343638373034312039393838323531513131" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="SCSI\\CdRom&Ven_Generic&Prod_DVD-ROM&Rev_1.0\\2&12b1de20&1&000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess] "Type"=dword:00000020 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Routing and Remote Access" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,47,00,72,00,\ 6f,00,75,00,70,00,00,00,00,00 "ObjectName"="LocalSystem" "Description"="Offers routing services to businesses in local area and wide area network environments." @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting\Providers] "ActiveProvider"="{1AA7F846-C7F5-11D0-A376-00C04FC9DA04}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting\Providers\{1AA7F840-C7F5-11D0-A376-00C04FC9DA04}] "ConfigClsid"="{1AA7F840-C7F5-11D0-A376-00C04FC9DA04}" "DisplayName"="RADIUS Accounting" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,72,00,61,00,64,00,2e,00,64,00,6c,00,6c,00,00,00 "ProviderTypeGUID"="{76560D80-2BFD-11d2-9539-3078302C2030}" "VendorName"="Microsoft" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Accounting\Providers\{1AA7F846-C7F5-11D0-A376-00C04FC9DA04}] "ConfigClsid"="" "DisplayName"="Windows Accounting" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\ 70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 "ProviderTypeGUID"="{76560D81-2BFD-11d2-9539-3078302C2030}" "VendorName"="Microsoft" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication\Providers] "ActiveProvider"="{1AA7F841-C7F5-11D0-A376-00C04FC9DA04}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication\Providers\{1AA7F83F-C7F5-11D0-A376-00C04FC9DA04}] "ConfigClsid"="{1AA7F83F-C7F5-11D0-A376-00C04FC9DA04}" "DisplayName"="RADIUS Authentication" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\ 61,00,73,00,72,00,61,00,64,00,2e,00,64,00,6c,00,6c,00,00,00 "VendorName"="Microsoft" "ProviderTypeGUID"="{76560D00-2BFD-11d2-9539-3078302C2030}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Authentication\Providers\{1AA7F841-C7F5-11D0-A376-00C04FC9DA04}] "ConfigClsid"="" "DisplayName"="Windows Authentication" "Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\ 70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 "VendorName"="Microsoft" "ProviderTypeGUID"="{76560D01-2BFD-11d2-9539-3078302C2030}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\DemandDialManager] "DllPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,\ 00,70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces] "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\0] "InterfaceName"="Loopback" "Type"=dword:00000005 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\0\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\1] "InterfaceName"="Internal" "Type"=dword:00000004 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\1\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\10] "InterfaceName"="{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\10\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\3] "InterfaceName"="{2937DCE5-1AB6-4454-A75A-347564768FC5}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\3\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\4] "InterfaceName"="{91D9B703-C06F-42DA-94D6-DAC5B34DB26A}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\4\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\5] "InterfaceName"="{AFE45985-028E-4E55-A932-232847605B83}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\5\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\6] "InterfaceName"="{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\6\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\7] "InterfaceName"="{B57AD90D-90AA-474A-A4F3-051BE53F591A}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\7\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\8] "InterfaceName"="{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}" "Type"=dword:00000003 "Enabled"=dword:00000001 "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Interfaces\8\Ip] "ProtocolId"=dword:00000021 "InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\ 00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\ 07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\ 00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters] "RouterType"=dword:00000001 "ServerFlags"=dword:00802702 "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 6d,00,70,00,72,00,64,00,69,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\AppleTalk] "EnableIn"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ip] "AllowClientIpAddresses"=dword:00000000 "AllowNetworkAccess"=dword:00000001 "EnableIn"=dword:00000001 "IpAddress"="0.0.0.0" "IpMask"="0.0.0.0" "UseDhcpAddressing"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ip\StaticAddressPool] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ip\StaticAddressPool\0] "From"=dword:00000000 "To"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Ipx] "EnableIn"=dword:00000001 "AcceptRemoteNodeNumber"=dword:00000001 "AllowNetworkAccess"=dword:00000001 "AutoWanNetAllocation"=dword:00000001 "FirstWanNet"=dword:00000000 "GlobalWanNet"=dword:00000001 "LastWanNet"=dword:00000000 "WanNetPoolSize"=dword:000003e8 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\Nbf] "EnableIn"=dword:00000001 "AllowNetworkAccess"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Performance] "Open"="OpenRasPerformanceData" "Close"="CloseRasPerformanceData" "Collect"="CollectRasPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\ 00,61,00,73,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:00000804 "Last Help"=dword:00000805 "First Counter"=dword:000007de "First Help"=dword:000007df "WbemAdapFileSignature"=hex:b0,b0,d7,90,5a,c7,1b,c2,78,f1,7f,45,5e,18,26,11 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00002e00 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy] "ProductDir"="C:\\WINDOWS\\system32\\IAS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\01] @="IAS.ProxyPolicyEnforcer" "Requests"="0 1 2" "Responses"="0 1 2 3 4" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\02] @="IAS.NTSamNames" "Providers"="1" "Requests"="0" "Responses"="0 1 3" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\03] @="IAS.BaseCampHost" "Requests"="0 1" "Responses"="0 1 2 4" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\04] @="IAS.RadiusProxy" "Providers"="2" "Responses"="0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\05] @="IAS.NTSamAuthentication" "Providers"="1" "Requests"="0" "Responses"="0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\06] @="IAS.AccountValidation" "Providers"="1" "Requests"="0" "Responses"="0 1" "Reasons"="33" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\07] @="IAS.PolicyEnforcer" "Providers"="1" "Requests"="0" "Responses"="0 1 3" "Reasons"="33" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\08] @="IAS.NTSamPerUser" "Providers"="1" "Requests"="0" "Responses"="0 1 3" "Reasons"="33" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\09] @="IAS.EAP" "Providers"="1" "Requests"="0 2" "Responses"="0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\10] @="IAS.URHandler" "Providers"="0 1" "Requests"="0 2" "Responses"="0 1" "Reasons"="33" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\11] @="IAS.ChangePassword" "Providers"="1" "Requests"="0" "Responses"="0 1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\12] @="IAS.AuthorizationHost" "Requests"="0 1 2" "Responses"="0 1 2 4" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\13] @="IAS.Accounting" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Policy\Pipeline\14] @="IAS.MSChapErrorReporter" "Providers"="0 1" "Requests"="0" "Responses"="2" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers] "Stamp"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip] "ProtocolId"=dword:00000021 "GlobalInfo"=hex:01,00,00,00,80,00,00,00,02,00,00,00,03,00,ff,ff,08,00,00,00,\ 01,00,00,00,30,00,00,00,06,00,ff,ff,3c,00,00,00,01,00,00,00,38,00,00,00,00,\ 00,00,00,00,00,00,00,01,00,00,00,07,00,00,00,02,00,00,00,01,00,00,00,03,00,\ 00,00,0a,00,00,00,16,27,00,00,03,00,00,00,17,27,00,00,05,00,00,00,12,27,00,\ 00,07,00,00,00,0d,00,00,00,6e,00,00,00,08,00,00,00,78,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "DLLPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,69,\ 00,70,00,72,00,74,00,72,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry] "Description"="Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start." "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DisplayName"="Remote Registry" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Group"="" "Start"=dword:00000002 "Type"=dword:00000020 "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,e0,ad,08,\ 00,01,00,00,00,e8,03,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,65,00,67,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum] "0"="Root\\LEGACY_REMOTEREGISTRY\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rimmptsk] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,69,00,6d,00,6d,00,70,00,74,\ 00,73,00,6b,00,2e,00,73,00,79,00,73,00,00,00 "Group"="MMC" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rimmptsk\Parameters] "SDSystemWaitTime"=dword:00000080 "MMCClkDev"=dword:00000002 "HispeedCLK"=dword:00000001 "DriveLetter"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rimmptsk\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rimmptsk\Enum] "0"="PCI\\VEN_1180&DEV_0843&SUBSYS_30C5103C&REV_10\\4&3b3a03b5&0&34F0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rismc32] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,69,00,73,00,6d,00,63,00,33,\ 00,32,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="RICOH Smart Card Reader" "ShortProviderName"="RICOH" "ReaderName"="RICOH SmartCard Reader" "CheckETUReg"=dword:00000001 "BufferSize"=dword:00020000 "IFDType"="RICOH SmartCard Reader" "VendorName"="RICOH Company, Ltd." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rismc32\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rismc32\Enum] "0"="PCMCIA\\RICOH-Bay8Controller-F1B2\\1" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RMCAST] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\ 44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,52,00,4d,00,43,00,\ 61,00,73,00,74,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Reliable Multicast Protocol driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RMCAST\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RMCAST\Parameters\Winsock] "HelperDllName"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,\ 53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,73,\ 00,68,00,52,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00 "MaxSockAddrLength"=dword:00000010 "MinSockAddrLength"=dword:00000010 "Mapping"=hex:02,00,00,00,03,00,00,00,02,00,00,00,04,00,00,00,71,00,00,00,02,\ 00,00,00,01,00,00,00,71,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RMCAST\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RMCAST\Enum] "0"="Root\\LEGACY_RMCAST\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ROOTMODEM] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,52,00,6f,00,6f,00,74,00,4d,00,64,\ 00,6d,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Legacy Modem Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ROOTMODEM\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ROOTMODEM\Enum] "0"="Root\\MODEM\\0000" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="Root\\MODEM\\0001" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,6f,00,63,00,61,00,74,00,6f,00,72,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Remote Procedure Call (RPC) Locator" "DependOnService"=hex(7):4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,\ 6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Manages the RPC name service database." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator\Parameters] "ExpirationAge"=dword:00000e10 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator\Enum] "0"="Root\\LEGACY_RPCLOCATOR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs] "Description"="Provides the endpoint mapper and other miscellaneous RPC services." "DisplayName"="Remote Procedure Call (RPC)" "ErrorControl"=dword:00000001 "Group"="COM Infrastructure" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,72,00,70,00,\ 63,00,73,00,73,00,00,00 "ObjectName"="NT Authority\\NetworkService" "Start"=dword:00000002 "Type"=dword:00000010 "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,02,00,00,00,60,ea,00,00 "ServiceSidType"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,70,00,63,00,73,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Enum] "0"="Root\\LEGACY_RPCSS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\ 00,73,00,76,00,70,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="QoS RSVP" "DependOnService"=hex(7):54,00,63,00,70,00,49,00,70,00,00,00,41,00,66,00,64,00,\ 00,00,52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Parameters] "StartBlocker"="" "Requests"="" "Upcalls"="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Performance] "Open"="OpenRsvpPerformanceData" "Close"="CloseRsvpPerformanceData" "Collect"="CollectRsvpPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\ 00,73,00,76,00,70,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:0000078e "Last Help"=dword:0000078f "First Counter"=dword:00000738 "First Help"=dword:00000739 "WbemAdapFileSignature"=hex:f9,dd,79,9e,07,ed,50,28,db,2f,1f,fe,a7,2c,93,57 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00002600 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Security] "Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs] "Description"="Stores security information for local user accounts." "DisplayName"="Security Accounts Manager" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\ 00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 "Group"="LocalValidation" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs\Enum] "0"="Root\\LEGACY_SAMSS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,53,\ 00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,2e,00,65,00,78,00,65,00,00,00 "Description"="Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Smart Card" "DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\ 00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Group"="SmartCardGroup" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr\Security] "Security"=hex:01,00,04,80,88,00,00,00,94,00,00,00,00,00,00,00,14,00,00,00,02,\ 00,74,00,05,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,\ 00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,13,00,00,00,00,00,18,\ 00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,00,18,00,\ ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,00,00,00,00,14,00,9d,\ 01,02,00,01,01,00,00,00,00,00,02,00,00,00,00,01,01,00,00,00,00,00,05,12,00,\ 00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr\Enum] "0"="Root\\LEGACY_SCARDSVR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule] "Description"="Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start." "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Task Scheduler" "Group"="SchedulerGroup" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,05,00,03,\ 00,01,00,00,00,70,17,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00 "NextAtJobId"=dword:00000002 "AtTaskMaxHours"=dword:00000048 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,63,00,68,00,65,00,64,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceMain"="SchedServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\Enum] "0"="Root\\LEGACY_SCHEDULE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ScsiPort] "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\ 00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,63,00,73,00,69,00,70,00,\ 6f,00,72,00,74,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000007 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,64,00,62,00,75,00,73,00,2e,\ 00,73,00,79,00,73,00,00,00 "Group"="System Bus Extender" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus\Parameters] "SdCmdFlags"=hex:06,01,09,19,0a,19,0d,11,10,01,11,01,12,01,18,05,19,05,19,01,\ 1a,01,1b,01,1c,01,20,05,21,05,26,05,2a,01,34,02,35,02,37,01,38,01,22,01,23,\ 05,24,01,25,01 "SdAppCmdFlags"=hex:06,01,0d,01,16,01,17,01,33,01,12,01,19,01,1a,01,26,01,2b,\ 01,2c,01,2d,01,2e,01,2f,01,30,01,31,01 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sdbus\Enum] "0"="PCI\\VEN_1180&DEV_0822&SUBSYS_30C5103C&REV_20\\4&3b3a03b5&0&33F0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Secdrv] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,65,00,63,00,64,00,72,00,76,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Secdrv" "Description"="SafeDisc driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Secdrv\Security] "Security"=hex:01,00,14,80,78,00,00,00,84,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,48,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\ 05,04,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\ 01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon] "Description"="Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Secondary Logon" "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "Objectname"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000120 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,65,00,63,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceMain"="SvcEntry_Seclogon" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon\Enum] "0"="Root\\LEGACY_SECLOGON\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS] "DependOnService"=hex(7):45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,\ 65,00,6d,00,00,00,00,00 "Description"="Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events." "DisplayName"="System Event Notification" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Group"="Network" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,65,00,6e,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS\Enum] "0"="Root\\LEGACY_SENS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sentinel] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,53,00,45,00,4e,00,54,00,49,00,4e,00,\ 45,00,4c,00,2e,00,53,00,59,00,53,00,00,00 "DisplayName"="Sentinel" "Group"="Extended Base" "DependOnService"=hex(7):50,00,41,00,52,00,50,00,4f,00,52,00,54,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sentinel\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sentinel\Setup] @="" "UsbSupport"=dword:00000001 "EnableTSCtiming"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sentinel\Current] "MajorVersion"=dword:00000007 "MinorVersion"=dword:00000003 "RDPRevision"=dword:00000009 "VersionString"="SSD7.3.0" "MachineType"=dword:00000001 "UsbSupport"=dword:00000001 "OSVersion"=dword:00000051 "OSType"=dword:00000005 "TSCtimingInfo"=dword:000009be [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sentinel\Current\Port1] "User"=dword:00000000 "SpanOfController"=dword:00000008 "DeviceRetryCount"=dword:00000064 "PortContentionTimeOut"=dword:00002710 "PortContentionMethod"=dword:80000063 "SystemContentionInstalled"=dword:00000001 "PortAddress"=dword:00000378 "MappedAddress"=dword:00000378 "PortType"=dword:00000005 "ValidatePort"=dword:00000001 "BusNumber"=dword:00000000 "BusType"=dword:0000000f "AddressSpace"=dword:00000001 "VerifyReads"=dword:00000001 "VerifyQueries"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sentinel\Enum] "0"="Root\\LEGACY_SENTINEL\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ser2pl] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000018 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,65,00,72,00,32,00,70,00,6c,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Prolific2 Serial port driver" "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ser2pl\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serenum] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,65,00,72,00,65,00,6e,00,75,\ 00,6d,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Serenum Filter Driver" "Group"="PNP Filter" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serenum\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serenum\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serial] "ErrorControl"=dword:00000000 "Group"="Extended base" "Start"=dword:00000002 "Tag"=dword:00000001 "Type"=dword:00000001 "ForceFifoEnable"=dword:00000001 "RxFIFO"=dword:00000008 "TxFIFO"=dword:0000000e "PermitShare"=dword:00000000 "LogFifo"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serial\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Serial\Enum] "0"="Root\\LEGACY_SERIAL\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sermouse] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000006 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,65,00,72,00,6d,00,6f,00,75,\ 00,73,00,65,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Serial Mouse Driver" "Group"="Pointer Port" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sermouse\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceLayer] "Type"=dword:00000110 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,50,00,43,00,20,00,43,00,6f,\ 00,6e,00,6e,00,65,00,63,00,74,00,69,00,76,00,69,00,74,00,79,00,20,00,53,00,\ 6f,00,6c,00,75,00,74,00,69,00,6f,00,6e,00,5c,00,53,00,65,00,72,00,76,00,69,\ 00,63,00,65,00,4c,00,61,00,79,00,65,00,72,00,2e,00,65,00,78,00,65,00,22,00,\ 00,00 "DisplayName"="ServiceLayer" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceLayer\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceLayer\Enum] "0"="Root\\LEGACY_SERVICELAYER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelEndpoint 3.0.0.0] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelEndpoint 3.0.0.0\Linkage] "Export"=hex(7):53,00,65,00,72,00,76,00,69,00,63,00,65,00,4d,00,6f,00,64,00,65,\ 00,6c,00,45,00,6e,00,64,00,70,00,6f,00,69,00,6e,00,74,00,20,00,33,00,2e,00,\ 30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelEndpoint 3.0.0.0\Performance] "Counter Names"=hex:43,00,61,00,6c,00,6c,00,73,00,00,00,43,00,61,00,6c,00,6c,\ 00,73,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,\ 00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,4f,00,75,00,74,00,73,00,74,00,61,\ 00,6e,00,64,00,69,00,6e,00,67,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,\ 46,00,61,00,69,00,6c,00,65,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,\ 00,46,00,61,00,69,00,6c,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,\ 65,00,63,00,6f,00,6e,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,46,\ 00,61,00,75,00,6c,00,74,00,65,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,\ 20,00,46,00,61,00,75,00,6c,00,74,00,65,00,64,00,20,00,50,00,65,00,72,00,20,\ 00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,\ 20,00,44,00,75,00,72,00,61,00,74,00,69,00,6f,00,6e,00,00,00,43,00,61,00,6c,\ 00,6c,00,73,00,20,00,44,00,75,00,72,00,61,00,74,00,69,00,6f,00,6e,00,20,00,\ 42,00,61,00,73,00,65,00,00,00,54,00,72,00,61,00,6e,00,73,00,61,00,63,00,74,\ 00,69,00,6f,00,6e,00,73,00,20,00,46,00,6c,00,6f,00,77,00,65,00,64,00,00,00,\ 54,00,72,00,61,00,6e,00,73,00,61,00,63,00,74,00,69,00,6f,00,6e,00,73,00,20,\ 00,46,00,6c,00,6f,00,77,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,\ 65,00,63,00,6f,00,6e,00,64,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,\ 00,79,00,20,00,56,00,61,00,6c,00,69,00,64,00,61,00,74,00,69,00,6f,00,6e,00,\ 20,00,61,00,6e,00,64,00,20,00,41,00,75,00,74,00,68,00,65,00,6e,00,74,00,69,\ 00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,46,00,61,00,69,00,6c,00,75,00,\ 72,00,65,00,73,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,20,\ 00,56,00,61,00,6c,00,69,00,64,00,61,00,74,00,69,00,6f,00,6e,00,20,00,61,00,\ 6e,00,64,00,20,00,41,00,75,00,74,00,68,00,65,00,6e,00,74,00,69,00,63,00,61,\ 00,74,00,69,00,6f,00,6e,00,20,00,46,00,61,00,69,00,6c,00,75,00,72,00,65,00,\ 73,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,\ 00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,20,00,43,00,61,00,6c,00,\ 6c,00,73,00,20,00,4e,00,6f,00,74,00,20,00,41,00,75,00,74,00,68,00,6f,00,72,\ 00,69,00,7a,00,65,00,64,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,\ 79,00,20,00,43,00,61,00,6c,00,6c,00,73,00,20,00,4e,00,6f,00,74,00,20,00,41,\ 00,75,00,74,00,68,00,6f,00,72,00,69,00,7a,00,65,00,64,00,20,00,50,00,65,00,\ 72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,52,00,65,00,6c,00,69,\ 00,61,00,62,00,6c,00,65,00,20,00,4d,00,65,00,73,00,73,00,61,00,67,00,69,00,\ 6e,00,67,00,20,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,73,00,20,00,46,\ 00,61,00,75,00,6c,00,74,00,65,00,64,00,00,00,52,00,65,00,6c,00,69,00,61,00,\ 62,00,6c,00,65,00,20,00,4d,00,65,00,73,00,73,00,61,00,67,00,69,00,6e,00,67,\ 00,20,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,73,00,20,00,46,00,61,00,\ 75,00,6c,00,74,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,\ 00,6f,00,6e,00,64,00,00,00,52,00,65,00,6c,00,69,00,61,00,62,00,6c,00,65,00,\ 20,00,4d,00,65,00,73,00,73,00,61,00,67,00,69,00,6e,00,67,00,20,00,4d,00,65,\ 00,73,00,73,00,61,00,67,00,65,00,73,00,20,00,44,00,72,00,6f,00,70,00,70,00,\ 65,00,64,00,00,00,52,00,65,00,6c,00,69,00,61,00,62,00,6c,00,65,00,20,00,4d,\ 00,65,00,73,00,73,00,61,00,67,00,69,00,6e,00,67,00,20,00,4d,00,65,00,73,00,\ 73,00,61,00,67,00,65,00,73,00,20,00,44,00,72,00,6f,00,70,00,70,00,65,00,64,\ 00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,\ 00,00 "Counter Types"=hex:36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,\ 00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,\ 36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,\ 00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,\ 36,00,39,00,36,00,33,00,32,00,30,00,00,00,38,00,30,00,35,00,34,00,33,00,38,\ 00,34,00,36,00,34,00,00,00,31,00,30,00,37,00,33,00,39,00,33,00,39,00,34,00,\ 35,00,38,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,\ 00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,\ 32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,\ 00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,\ 00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,\ 00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,\ 35,00,33,00,36,00,00,00,00,00 "IsMultiInstance"=dword:00000001 "CategoryOptions"=dword:00000003 "Close"="ClosePerformanceData" "Collect"="CollectPerformanceData" "Open"="OpenPerformanceData" "Library"="NETFXPerf.dll" "Last Counter"=dword:00000fb4 "Last Help"=dword:00000fb5 "First Counter"=dword:00000f8e "First Help"=dword:00000f8f "Object List"="3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982 3982" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelOperation 3.0.0.0] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelOperation 3.0.0.0\Linkage] "Export"=hex(7):53,00,65,00,72,00,76,00,69,00,63,00,65,00,4d,00,6f,00,64,00,65,\ 00,6c,00,4f,00,70,00,65,00,72,00,61,00,74,00,69,00,6f,00,6e,00,20,00,33,00,\ 2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelOperation 3.0.0.0\Performance] "Counter Names"=hex:43,00,61,00,6c,00,6c,00,73,00,00,00,43,00,61,00,6c,00,6c,\ 00,73,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,\ 00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,4f,00,75,00,74,00,73,00,74,00,61,\ 00,6e,00,64,00,69,00,6e,00,67,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,\ 46,00,61,00,69,00,6c,00,65,00,64,00,00,00,43,00,61,00,6c,00,6c,00,20,00,46,\ 00,61,00,69,00,6c,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,\ 63,00,6f,00,6e,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,46,00,61,\ 00,75,00,6c,00,74,00,65,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,\ 46,00,61,00,75,00,6c,00,74,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,\ 00,65,00,63,00,6f,00,6e,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,\ 44,00,75,00,72,00,61,00,74,00,69,00,6f,00,6e,00,00,00,43,00,61,00,6c,00,6c,\ 00,73,00,20,00,44,00,75,00,72,00,61,00,74,00,69,00,6f,00,6e,00,20,00,42,00,\ 61,00,73,00,65,00,00,00,54,00,72,00,61,00,6e,00,73,00,61,00,63,00,74,00,69,\ 00,6f,00,6e,00,73,00,20,00,46,00,6c,00,6f,00,77,00,65,00,64,00,00,00,54,00,\ 72,00,61,00,6e,00,73,00,61,00,63,00,74,00,69,00,6f,00,6e,00,73,00,20,00,46,\ 00,6c,00,6f,00,77,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,\ 63,00,6f,00,6e,00,64,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,\ 00,20,00,56,00,61,00,6c,00,69,00,64,00,61,00,74,00,69,00,6f,00,6e,00,20,00,\ 61,00,6e,00,64,00,20,00,41,00,75,00,74,00,68,00,65,00,6e,00,74,00,69,00,63,\ 00,61,00,74,00,69,00,6f,00,6e,00,20,00,46,00,61,00,69,00,6c,00,75,00,72,00,\ 65,00,73,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,20,00,56,\ 00,61,00,6c,00,69,00,64,00,61,00,74,00,69,00,6f,00,6e,00,20,00,61,00,6e,00,\ 64,00,20,00,41,00,75,00,74,00,68,00,65,00,6e,00,74,00,69,00,63,00,61,00,74,\ 00,69,00,6f,00,6e,00,20,00,46,00,61,00,69,00,6c,00,75,00,72,00,65,00,73,00,\ 20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,53,\ 00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,20,00,43,00,61,00,6c,00,6c,00,\ 73,00,20,00,4e,00,6f,00,74,00,20,00,41,00,75,00,74,00,68,00,6f,00,72,00,69,\ 00,7a,00,65,00,64,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,\ 20,00,43,00,61,00,6c,00,6c,00,73,00,20,00,4e,00,6f,00,74,00,20,00,41,00,75,\ 00,74,00,68,00,6f,00,72,00,69,00,7a,00,65,00,64,00,20,00,50,00,65,00,72,00,\ 20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,00,00 "Counter Types"=hex:36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,\ 00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,\ 36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,\ 00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,\ 36,00,39,00,36,00,33,00,32,00,30,00,00,00,38,00,30,00,35,00,34,00,33,00,38,\ 00,34,00,36,00,34,00,00,00,31,00,30,00,37,00,33,00,39,00,33,00,39,00,34,00,\ 35,00,38,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,\ 00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,\ 32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,\ 00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,\ 00,00,00,00 "IsMultiInstance"=dword:00000001 "CategoryOptions"=dword:00000003 "Close"="ClosePerformanceData" "Collect"="CollectPerformanceData" "Open"="OpenPerformanceData" "Library"="NETFXPerf.dll" "Last Counter"=dword:00001018 "Last Help"=dword:00001019 "First Counter"=dword:00000ffa "First Help"=dword:00000ffb "Object List"="4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090 4090" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelService 3.0.0.0] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelService 3.0.0.0\Linkage] "Export"=hex(7):53,00,65,00,72,00,76,00,69,00,63,00,65,00,4d,00,6f,00,64,00,65,\ 00,6c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,33,00,2e,00,30,00,\ 2e,00,30,00,2e,00,30,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServiceModelService 3.0.0.0\Performance] "Library"="NETFXPerf.dll" "Counter Names"=hex:43,00,61,00,6c,00,6c,00,73,00,00,00,43,00,61,00,6c,00,6c,\ 00,73,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,\ 00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,4f,00,75,00,74,00,73,00,74,00,61,\ 00,6e,00,64,00,69,00,6e,00,67,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,\ 46,00,61,00,69,00,6c,00,65,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,\ 00,46,00,61,00,69,00,6c,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,\ 65,00,63,00,6f,00,6e,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,20,00,46,\ 00,61,00,75,00,6c,00,74,00,65,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,\ 20,00,46,00,61,00,75,00,6c,00,74,00,65,00,64,00,20,00,50,00,65,00,72,00,20,\ 00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,43,00,61,00,6c,00,6c,00,73,00,\ 20,00,44,00,75,00,72,00,61,00,74,00,69,00,6f,00,6e,00,00,00,43,00,61,00,6c,\ 00,6c,00,73,00,20,00,44,00,75,00,72,00,61,00,74,00,69,00,6f,00,6e,00,20,00,\ 42,00,61,00,73,00,65,00,00,00,54,00,72,00,61,00,6e,00,73,00,61,00,63,00,74,\ 00,69,00,6f,00,6e,00,73,00,20,00,46,00,6c,00,6f,00,77,00,65,00,64,00,00,00,\ 54,00,72,00,61,00,6e,00,73,00,61,00,63,00,74,00,69,00,6f,00,6e,00,73,00,20,\ 00,46,00,6c,00,6f,00,77,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,\ 65,00,63,00,6f,00,6e,00,64,00,00,00,54,00,72,00,61,00,6e,00,73,00,61,00,63,\ 00,74,00,65,00,64,00,20,00,4f,00,70,00,65,00,72,00,61,00,74,00,69,00,6f,00,\ 6e,00,73,00,20,00,43,00,6f,00,6d,00,6d,00,69,00,74,00,74,00,65,00,64,00,00,\ 00,54,00,72,00,61,00,6e,00,73,00,61,00,63,00,74,00,65,00,64,00,20,00,4f,00,\ 70,00,65,00,72,00,61,00,74,00,69,00,6f,00,6e,00,73,00,20,00,43,00,6f,00,6d,\ 00,6d,00,69,00,74,00,74,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,\ 65,00,63,00,6f,00,6e,00,64,00,00,00,54,00,72,00,61,00,6e,00,73,00,61,00,63,\ 00,74,00,65,00,64,00,20,00,4f,00,70,00,65,00,72,00,61,00,74,00,69,00,6f,00,\ 6e,00,73,00,20,00,41,00,62,00,6f,00,72,00,74,00,65,00,64,00,00,00,54,00,72,\ 00,61,00,6e,00,73,00,61,00,63,00,74,00,65,00,64,00,20,00,4f,00,70,00,65,00,\ 72,00,61,00,74,00,69,00,6f,00,6e,00,73,00,20,00,41,00,62,00,6f,00,72,00,74,\ 00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,\ 64,00,00,00,54,00,72,00,61,00,6e,00,73,00,61,00,63,00,74,00,65,00,64,00,20,\ 00,4f,00,70,00,65,00,72,00,61,00,74,00,69,00,6f,00,6e,00,73,00,20,00,49,00,\ 6e,00,20,00,44,00,6f,00,75,00,62,00,74,00,00,00,54,00,72,00,61,00,6e,00,73,\ 00,61,00,63,00,74,00,65,00,64,00,20,00,4f,00,70,00,65,00,72,00,61,00,74,00,\ 69,00,6f,00,6e,00,73,00,20,00,49,00,6e,00,20,00,44,00,6f,00,75,00,62,00,74,\ 00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,\ 53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,20,00,56,00,61,00,6c,00,69,\ 00,64,00,61,00,74,00,69,00,6f,00,6e,00,20,00,61,00,6e,00,64,00,20,00,41,00,\ 75,00,74,00,68,00,65,00,6e,00,74,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,\ 00,20,00,46,00,61,00,69,00,6c,00,75,00,72,00,65,00,73,00,00,00,53,00,65,00,\ 63,00,75,00,72,00,69,00,74,00,79,00,20,00,56,00,61,00,6c,00,69,00,64,00,61,\ 00,74,00,69,00,6f,00,6e,00,20,00,61,00,6e,00,64,00,20,00,41,00,75,00,74,00,\ 68,00,65,00,6e,00,74,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,46,\ 00,61,00,69,00,6c,00,75,00,72,00,65,00,73,00,20,00,50,00,65,00,72,00,20,00,\ 53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,53,00,65,00,63,00,75,00,72,00,69,\ 00,74,00,79,00,20,00,43,00,61,00,6c,00,6c,00,73,00,20,00,4e,00,6f,00,74,00,\ 20,00,41,00,75,00,74,00,68,00,6f,00,72,00,69,00,7a,00,65,00,64,00,00,00,53,\ 00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,20,00,43,00,61,00,6c,00,6c,00,\ 73,00,20,00,4e,00,6f,00,74,00,20,00,41,00,75,00,74,00,68,00,6f,00,72,00,69,\ 00,7a,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,\ 6e,00,64,00,00,00,49,00,6e,00,73,00,74,00,61,00,6e,00,63,00,65,00,73,00,00,\ 00,49,00,6e,00,73,00,74,00,61,00,6e,00,63,00,65,00,73,00,20,00,43,00,72,00,\ 65,00,61,00,74,00,65,00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,\ 00,6f,00,6e,00,64,00,00,00,52,00,65,00,6c,00,69,00,61,00,62,00,6c,00,65,00,\ 20,00,4d,00,65,00,73,00,73,00,61,00,67,00,69,00,6e,00,67,00,20,00,53,00,65,\ 00,73,00,73,00,69,00,6f,00,6e,00,73,00,20,00,46,00,61,00,75,00,6c,00,74,00,\ 65,00,64,00,00,00,52,00,65,00,6c,00,69,00,61,00,62,00,6c,00,65,00,20,00,4d,\ 00,65,00,73,00,73,00,61,00,67,00,69,00,6e,00,67,00,20,00,53,00,65,00,73,00,\ 73,00,69,00,6f,00,6e,00,73,00,20,00,46,00,61,00,75,00,6c,00,74,00,65,00,64,\ 00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,\ 52,00,65,00,6c,00,69,00,61,00,62,00,6c,00,65,00,20,00,4d,00,65,00,73,00,73,\ 00,61,00,67,00,69,00,6e,00,67,00,20,00,4d,00,65,00,73,00,73,00,61,00,67,00,\ 65,00,73,00,20,00,44,00,72,00,6f,00,70,00,70,00,65,00,64,00,00,00,52,00,65,\ 00,6c,00,69,00,61,00,62,00,6c,00,65,00,20,00,4d,00,65,00,73,00,73,00,61,00,\ 67,00,69,00,6e,00,67,00,20,00,4d,00,65,00,73,00,73,00,61,00,67,00,65,00,73,\ 00,20,00,44,00,72,00,6f,00,70,00,70,00,65,00,64,00,20,00,50,00,65,00,72,00,\ 20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,51,00,75,00,65,00,75,00,65,\ 00,64,00,20,00,50,00,6f,00,69,00,73,00,6f,00,6e,00,20,00,4d,00,65,00,73,00,\ 73,00,61,00,67,00,65,00,73,00,00,00,51,00,75,00,65,00,75,00,65,00,64,00,20,\ 00,50,00,6f,00,69,00,73,00,6f,00,6e,00,20,00,4d,00,65,00,73,00,73,00,61,00,\ 67,00,65,00,73,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,\ 00,64,00,00,00,51,00,75,00,65,00,75,00,65,00,64,00,20,00,4d,00,65,00,73,00,\ 73,00,61,00,67,00,65,00,73,00,20,00,52,00,65,00,6a,00,65,00,63,00,74,00,65,\ 00,64,00,00,00,51,00,75,00,65,00,75,00,65,00,64,00,20,00,4d,00,65,00,73,00,\ 73,00,61,00,67,00,65,00,73,00,20,00,52,00,65,00,6a,00,65,00,63,00,74,00,65,\ 00,64,00,20,00,50,00,65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,\ 00,00,51,00,75,00,65,00,75,00,65,00,64,00,20,00,4d,00,65,00,73,00,73,00,61,\ 00,67,00,65,00,73,00,20,00,44,00,72,00,6f,00,70,00,70,00,65,00,64,00,00,00,\ 51,00,75,00,65,00,75,00,65,00,64,00,20,00,4d,00,65,00,73,00,73,00,61,00,67,\ 00,65,00,73,00,20,00,44,00,72,00,6f,00,70,00,70,00,65,00,64,00,20,00,50,00,\ 65,00,72,00,20,00,53,00,65,00,63,00,6f,00,6e,00,64,00,00,00,00,00 "Counter Types"=hex:36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,\ 00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,\ 36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,\ 00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,\ 36,00,39,00,36,00,33,00,32,00,30,00,00,00,38,00,30,00,35,00,34,00,33,00,38,\ 00,34,00,36,00,34,00,00,00,31,00,30,00,37,00,33,00,39,00,33,00,39,00,34,00,\ 35,00,38,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,\ 00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,\ 32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,\ 00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,\ 00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,\ 00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,\ 32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,\ 00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,\ 35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,\ 00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,\ 39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,\ 00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,\ 33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,\ 00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,\ 33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,\ 00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,00,00 "IsMultiInstance"=dword:00000001 "CategoryOptions"=dword:00000003 "Close"="ClosePerformanceData" "Collect"="CollectPerformanceData" "Open"="OpenPerformanceData" "Last Counter"=dword:00000ff8 "Last Help"=dword:00000ff9 "First Counter"=dword:00000fb6 "First Help"=dword:00000fb7 "Object List"="4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022 4022" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sfloppy] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\ 70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000001 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sfloppy\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess] "DependOnGroup"=hex(7):00,00 "DependOnService"=hex(7):4e,00,65,00,74,00,6d,00,61,00,6e,00,00,00,57,00,69,00,\ 6e,00,4d,00,67,00,6d,00,74,00,00,00,00,00 "Description"="Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network." "DisplayName"="Windows Firewall/Internet Connection Sharing (ICS)" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch] "Epoch"=dword:0000fc85 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 69,00,70,00,6e,00,61,00,74,00,68,00,6c,00,70,00,2e,00,64,00,6c,00,6c,00,00,\ 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007" "2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008" "139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004" "445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005" "137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001" "138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002" "3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Static] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=dword:00000000 "DoNotAllowExceptions"=dword:00000000 "DisableNotifications"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing" "C:\\WINDOWS\\SMINST\\Scheduler.exe"="C:\\WINDOWS\\SMINST\\Scheduler.exe:*:Enabled:Scheduler " "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA" "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB" "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent" "C:\\Program Files\\AVG\\AVG9\\avgam.exe"="C:\\Program Files\\AVG\\AVG9\\avgam.exe:*:Enabled:avgam.exe" "C:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"="C:\\Program Files\\AVG\\AVG9\\avgdiagex.exe:*:Enabled:avgdiagex.exe" "C:\\Program Files\\AVG\\AVG9\\avgupd.exe"="C:\\Program Files\\AVG\\AVG9\\avgupd.exe:*:Enabled:avgupd.exe" "C:\\Program Files\\AVG\\AVG9\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG9\\avgnsx.exe:*:Enabled:avgnsx.exe" "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007" "2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008" "139:TCP"="139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004" "445:TCP"="445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005" "137:UDP"="137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001" "138:UDP"="138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002" "3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup] "ServiceUpgrade"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum] "0"="Root\\LEGACY_SHAREDACCESS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Shell Hardware Detection" "Group"="ShellSvcGroup" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides notifications for AutoPlay hardware events." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="HardwareDetectionServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ShellHWDetection\Enum] "0"="Root\\LEGACY_SHELLHWDETECTION\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Simbad] "ErrorControl"=dword:00000001 "Group"="Filter" "Start"=dword:00000004 "Tag"=dword:00000001 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMSvcHost 3.0.0.0] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMSvcHost 3.0.0.0\Linkage] "Export"=hex(7):53,00,4d,00,53,00,76,00,63,00,48,00,6f,00,73,00,74,00,20,00,33,\ 00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMSvcHost 3.0.0.0\Performance] "Counter Names"=hex:50,00,72,00,6f,00,74,00,6f,00,63,00,6f,00,6c,00,20,00,46,\ 00,61,00,69,00,6c,00,75,00,72,00,65,00,73,00,20,00,6f,00,76,00,65,00,72,00,\ 20,00,6e,00,65,00,74,00,2e,00,74,00,63,00,70,00,00,00,50,00,72,00,6f,00,74,\ 00,6f,00,63,00,6f,00,6c,00,20,00,46,00,61,00,69,00,6c,00,75,00,72,00,65,00,\ 73,00,20,00,6f,00,76,00,65,00,72,00,20,00,6e,00,65,00,74,00,2e,00,70,00,69,\ 00,70,00,65,00,00,00,44,00,69,00,73,00,70,00,61,00,74,00,63,00,68,00,20,00,\ 46,00,61,00,69,00,6c,00,75,00,72,00,65,00,73,00,20,00,6f,00,76,00,65,00,72,\ 00,20,00,6e,00,65,00,74,00,2e,00,74,00,63,00,70,00,00,00,44,00,69,00,73,00,\ 70,00,61,00,74,00,63,00,68,00,20,00,46,00,61,00,69,00,6c,00,75,00,72,00,65,\ 00,73,00,20,00,6f,00,76,00,65,00,72,00,20,00,6e,00,65,00,74,00,2e,00,70,00,\ 69,00,70,00,65,00,00,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,\ 00,6e,00,73,00,20,00,44,00,69,00,73,00,70,00,61,00,74,00,63,00,68,00,65,00,\ 64,00,20,00,6f,00,76,00,65,00,72,00,20,00,6e,00,65,00,74,00,2e,00,74,00,63,\ 00,70,00,00,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,\ 73,00,20,00,44,00,69,00,73,00,70,00,61,00,74,00,63,00,68,00,65,00,64,00,20,\ 00,6f,00,76,00,65,00,72,00,20,00,6e,00,65,00,74,00,2e,00,70,00,69,00,70,00,\ 65,00,00,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,\ 00,20,00,41,00,63,00,63,00,65,00,70,00,74,00,65,00,64,00,20,00,6f,00,76,00,\ 65,00,72,00,20,00,6e,00,65,00,74,00,2e,00,74,00,63,00,70,00,00,00,43,00,6f,\ 00,6e,00,6e,00,65,00,63,00,74,00,69,00,6f,00,6e,00,73,00,20,00,41,00,63,00,\ 63,00,65,00,70,00,74,00,65,00,64,00,20,00,6f,00,76,00,65,00,72,00,20,00,6e,\ 00,65,00,74,00,2e,00,70,00,69,00,70,00,65,00,00,00,52,00,65,00,67,00,69,00,\ 73,00,74,00,72,00,61,00,74,00,69,00,6f,00,6e,00,73,00,20,00,41,00,63,00,74,\ 00,69,00,76,00,65,00,20,00,66,00,6f,00,72,00,20,00,6e,00,65,00,74,00,2e,00,\ 74,00,63,00,70,00,00,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,61,00,74,\ 00,69,00,6f,00,6e,00,73,00,20,00,41,00,63,00,74,00,69,00,76,00,65,00,20,00,\ 66,00,6f,00,72,00,20,00,6e,00,65,00,74,00,2e,00,70,00,69,00,70,00,65,00,00,\ 00,55,00,72,00,69,00,73,00,20,00,52,00,65,00,67,00,69,00,73,00,74,00,65,00,\ 72,00,65,00,64,00,20,00,66,00,6f,00,72,00,20,00,6e,00,65,00,74,00,2e,00,74,\ 00,63,00,70,00,00,00,55,00,72,00,69,00,73,00,20,00,52,00,65,00,67,00,69,00,\ 73,00,74,00,65,00,72,00,65,00,64,00,20,00,66,00,6f,00,72,00,20,00,6e,00,65,\ 00,74,00,2e,00,70,00,69,00,70,00,65,00,00,00,55,00,72,00,69,00,73,00,20,00,\ 55,00,6e,00,72,00,65,00,67,00,69,00,73,00,74,00,65,00,72,00,65,00,64,00,20,\ 00,66,00,6f,00,72,00,20,00,6e,00,65,00,74,00,2e,00,74,00,63,00,70,00,00,00,\ 55,00,72,00,69,00,73,00,20,00,55,00,6e,00,72,00,65,00,67,00,69,00,73,00,74,\ 00,65,00,72,00,65,00,64,00,20,00,66,00,6f,00,72,00,20,00,6e,00,65,00,74,00,\ 2e,00,70,00,69,00,70,00,65,00,00,00,00,00 "Counter Types"=hex:36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,\ 00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,\ 36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,\ 00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,\ 00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,\ 00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,\ 36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,00,\ 00 "IsMultiInstance"=dword:00000000 "CategoryOptions"=dword:00000003 "Close"="ClosePerformanceData" "Collect"="CollectPerformanceData" "Open"="OpenPerformanceData" "Library"="NETFXPerf.dll" "Last Counter"=dword:00000f8c "Last Help"=dword:00000f8d "First Counter"=dword:00000f70 "First Help"=dword:00000f71 "Object List"="3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952 3952" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNTNLUSB] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000015 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,53,00,4e,00,54,00,4e,00,4c,00,55,\ 00,53,00,42,00,2e,00,53,00,59,00,53,00,00,00 "DisplayName"="SafeNet USB SuperPro/UltraPro/HardwareKey" "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNTNLUSB\Current] "VersionString"="SSD7.3.0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNTNLUSB\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNTNLUSB\Setup] "UsbSupport"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNTNLUSB\Enum] "0"="USB\\Vid_04b9&Pid_0300\\6&1633edb3&0&2" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sparrow] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000007 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sparrow\Parameters] "LegacyAdapterDetection"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sparrow\Parameters\PnpInterface] "1"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\splitter] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,70,00,6c,00,69,00,74,00,74,\ 00,65,00,72,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel Audio Splitter" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\splitter\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\splitter\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler] "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Description"="Loads files to memory for later printing." "DisplayName"="Print Spooler" "ErrorControl"=dword:00000001 "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,e8,47,0c,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00 "Group"="SpoolerGroup" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,70,00,6f,00,6f,00,6c,00,73,00,76,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000110 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Performance] "Close"="PerfClose" "Collect"="PerfCollect" "Collect Timeout"=dword:000007d0 "Library"="winspool.drv" "Object List"="1450" "Open"="PerfOpen" "Open Timeout"=dword:00000fa0 "WbemAdapFileSignature"=hex:bd,83,ab,a6,1e,8a,cc,c8,d9,ff,b8,69,f2,94,18,ce "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00023c00 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Enum] "0"="Root\\LEGACY_SPOOLER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000006 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,70,00,74,00,64,00,2e,00,73,\ 00,79,00,73,00,00,00 "Group"="Boot Bus Extender" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Enum] "0"="Root\\LEGACY_SPTD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SQLBrowser] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,63,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,6f,\ 00,73,00,6f,00,66,00,74,00,20,00,53,00,51,00,4c,00,20,00,53,00,65,00,72,00,\ 76,00,65,00,72,00,5c,00,39,00,30,00,5c,00,53,00,68,00,61,00,72,00,65,00,64,\ 00,5c,00,73,00,71,00,6c,00,62,00,72,00,6f,00,77,00,73,00,65,00,72,00,2e,00,\ 65,00,78,00,65,00,22,00,00,00 "DisplayName"="SQL Server Browser" "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Provides SQL Server connection information to client computers." "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,45,00,57,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SQLBrowser\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SQLBrowser\Enum] "0"="Root\\LEGACY_SQLBROWSER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SQLWriter] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,63,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,6f,\ 00,73,00,6f,00,66,00,74,00,20,00,53,00,51,00,4c,00,20,00,53,00,65,00,72,00,\ 76,00,65,00,72,00,5c,00,39,00,30,00,5c,00,53,00,68,00,61,00,72,00,65,00,64,\ 00,5c,00,73,00,71,00,6c,00,77,00,72,00,69,00,74,00,65,00,72,00,2e,00,65,00,\ 78,00,65,00,22,00,00,00 "DisplayName"="SQL Server VSS Writer" "ObjectName"="LocalSystem" "Description"="Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SQLWriter\Security] "Security"=hex:01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,84,00,05,00,00,00,00,04,24,00,11,00,02,00,01,05,00,00,00,00,00,\ 05,15,00,00,00,42,c7,e6,a7,93,37,28,e0,e3,4f,67,2e,f3,03,00,00,00,00,14,00,\ fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,\ 02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,8d,01,02,00,01,01,\ 00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\ 00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SQLWriter\Enum] "0"="Root\\LEGACY_SQLWRITER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr] "Type"=dword:00000002 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,72,00,2e,00,73,00,79,00,73,\ 00,00,00 "DisplayName"="System Restore Filter Driver" "Group"="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr\Parameters] "FirstRun"=dword:00000000 "DontBackup"=dword:00000000 "MachineGuid"="{1B979E5A-90BD-4339-A818-E49EB7202A10}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr\Enum] "0"="Root\\LEGACY_SR\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="System Restore Service" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\Parameters] "ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,72,00,\ 73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\Enum] "0"="Root\\LEGACY_SRSERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Srv] "Type"=dword:00000002 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000006 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,72,00,76,00,2e,00,73,00,79,\ 00,73,00,00,00 "DisplayName"="Srv" "Group"="Network" "Description"="Srv" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Srv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Srv\Enum] "0"="Root\\LEGACY_SRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "DisplayName"="SSDP Discovery Service" "DependOnService"=hex(7):48,00,54,00,54,00,50,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Enables discovery of UPnP devices on your home network." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,73,00,64,00,70,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV\Security] "Security"=hex:01,00,14,80,bc,00,00,00,c8,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,8c,00,06,00,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\ 00,00,00,00,14,00,9d,00,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,14,\ 00,70,00,02,00,01,01,00,00,00,00,00,05,13,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV\Enum] "0"="Root\\LEGACY_SSDPSRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSPORT] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\ 44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,53,00,53,00,50,00,\ 4f,00,52,00,54,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="SSPORT" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSPORT\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSPORT\Enum] "0"="Root\\LEGACY_SSPORT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 "INITSTARTFAILED"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,69,00,6d,00,67,00,73,00,76,00,63,00,00,00 "DisplayName"="Windows Image Acquisition (WIA)" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides image acquisition services for scanners and cameras." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,69,00,61,00,73,00,65,00,72,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc\Enum] "0"="Root\\LEGACY_STISVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stllssvr] "Type"=dword:00000010 "Start"=dword:00000004 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):22,00,63,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,\ 00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,75,00,72,00,65,00,\ 54,00,68,00,69,00,6e,00,67,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,\ 00,73,00,74,00,6c,00,6c,00,73,00,73,00,76,00,72,00,2e,00,65,00,78,00,65,00,\ 22,00,00,00 "DisplayName"="stllssvr" "ObjectName"="LocalSystem" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stllssvr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum] "ErrorControl"=dword:00000001 "Start"=dword:00000003 "Type"=dword:00000001 "DisplayName"="Software Bus Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,77,00,65,00,6e,00,75,00,6d,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}\{9ea331fa-b91b-45f8-9285-bd2bc77afcde}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{bf963d80-c559-11d0-8a2b-00a0c9255ac1}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{dff220f3-f70f-11d0-b917-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{dff220f3-f70f-11d0-b917-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196}\{3c0d501a-140b-11d1-b40f-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}\{53172480-4791-11D0-A5D6-28DB04C10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}\{53172480-4791-11D0-A5D6-28DB04C10000}\{53172480-4791-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\{9B365890-165F-11D0-A195-0020AFD156E4}\{a7c7a5b1-5af3-11d1-9ced-00a024bf0407}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{ad809c00-7b88-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}\{9B365890-165F-11D0-A195-0020AFD156E4}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}\{9B365890-165F-11D0-A195-0020AFD156E4}\{3e227e76-690d-11d2-8161-0000f8775bf1}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196}\{97ebaacb-95bd-11d0-a3ea-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\{ad498944-762f-11d0-8dcb-00c04fc3358c}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{ffbb6e3f-ccfe-4d84-90d9-421418b03a8e}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swenum\Enum] "0"="Root\\SYSTEM\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWIHPWMI] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,\ 20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,48,00,50,00,51,00,5c,00,53,00,68,\ 00,61,00,72,00,65,00,64,00,5c,00,53,00,69,00,65,00,72,00,72,00,61,00,20,00,\ 57,00,69,00,72,00,65,00,6c,00,65,00,73,00,73,00,5c,00,57,00,69,00,6e,00,33,\ 00,32,00,5c,00,55,00,6e,00,69,00,63,00,6f,00,64,00,65,00,5c,00,53,00,57,00,\ 49,00,48,00,50,00,57,00,4d,00,49,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="SWIHPWMI" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,57,00,69,00,6e,00,\ 4d,00,67,00,6d,00,74,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Sierra Wireless HP WMI Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWIHPWMI\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWIHPWMI\Enum] "0"="Root\\LEGACY_SWIHPWMI\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swmidi] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,77,00,6d,00,69,00,64,00,69,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel GS Wavetable Synthesizer" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swmidi\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swmidi\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SwPrv] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6c,00,6c,\ 00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,50,00,72,00,\ 6f,00,63,00,65,00,73,00,73,00,69,00,64,00,3a,00,7b,00,39,00,41,00,43,00,33,\ 00,32,00,38,00,38,00,35,00,2d,00,41,00,37,00,36,00,33,00,2d,00,34,00,44,00,\ 45,00,32,00,2d,00,42,00,45,00,37,00,31,00,2d,00,41,00,35,00,32,00,39,00,32,\ 00,37,00,45,00,41,00,37,00,39,00,36,00,37,00,7d,00,00,00 "DisplayName"="MS Software Shadow Copy Provider" "DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SwPrv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swwd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swwd\Parameters] "ExceptionTasks"=hex(7):61,00,75,00,74,00,6f,00,63,00,68,00,6b,00,2e,00,65,00,\ 78,00,65,00,00,00,63,00,68,00,6b,00,64,00,73,00,6b,00,2e,00,65,00,78,00,65,\ 00,00,00,61,00,75,00,74,00,6f,00,63,00,6f,00,6e,00,76,00,2e,00,65,00,78,00,\ 65,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc810] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000001a "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc810\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc810\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc8xx] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 "Tag"=dword:00000036 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc8xx\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\symc8xx\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_hi] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 "Tag"=dword:00000037 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_hi\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_hi\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_u3] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Type"=dword:00000001 "Tag"=dword:00000037 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_u3\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sym_u3\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SynTP] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000004 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,53,00,79,00,6e,00,54,00,50,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="Synaptics TouchPad Driver" "Group"="Pointer Port" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SynTP\Parameters] "PollForDeviceRemoval"=dword:00000001 "OEMVendorNameENum"=dword:00000001 "ForceThreeButtonOnError"=dword:00000001 "UseXtdPhoenixInfo"=dword:00000000 "TimeoutUserPresent"=dword:00000001 "IgnoreParity"=dword:00000000 "IgnoreOverrun"=dword:00000000 "DiscardBogusRelativePackets"=dword:00000001 "DetectTimeMS"=dword:0000091c "EnableKey"=dword:00000000 "DisableKey"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SynTP\Parameters\PNPDisableExclusionList] "ASUS_01"="USB\\VID_0A81&PID_0103&MI_00*" "ASUS_02"="USB\\VID_0A81&PID_0103&MI_01*" "ASUS_03"="HID\\Vid_046d&Pid_c50e&Rev_2500" "ASUS_04"="HID\\Vid_046d&Pid_c50e&Rev_2510" "ASUS_05"="HID\\Vid_0A81&Pid_0103&MI_01&Col02" "ASUS_06"="HID\\Vid_0A81&Pid_0103&MI_01&Col03" "ASUS_07"="HID\\Vid_04B8&Pid_030E&Rev_0100&MI_*" "ASUS_08"="HID\\Vid_05E3&Pid_FFE2&Rev_0001&MI_*" "ASUS_09"="HID\\Vid_0A81&Pid_0103&Rev_0110&MI_*" "BTC_01"="USB\\VID_0637&PID_0001*" "BTC_02"="HID\\Vid_046e&Pid_6782&MI_00" "BTC_03"="HID\\Vid_046e&Pid_6782&MI_01&Col01" "BTC_04"="HID\\Vid_046e&Pid_6782&MI_01&Col02" "BTC_05"="HID\\Vid_046e&Pid_6782&Rev_2110&MI_00" "BTC_06"="HID\\Vid_046e&Pid_6782&Rev_2110&MI_01&Col01" "BTC_07"="HID\\Vid_046e&Pid_6782&Rev_2110&MI_01&Col02" "Dell_355"="HID\\VID_0A5C&PID_4503&REV_0100&Col01" "Fujitsu_01"="SERENUM\\FJC5000" "Fujitsu_02"="HID\\Vid_0430&Pid_0002&Rev_0100&MI_00" "Fujitsu_03"="HID\\Vid_0430&Pid_0002&Rev_0100&MI_01" "Fujitsu_04"="HID\\Vid_0430&Pid_0002&MI_00" "Fujitsu_05"="HID\\Vid_0430&Pid_0002&MI_01" "Fujitsu_06"="HID\\FUJ02E5&Col02" "Fujitsu_07"="HID\\FUJ02E6&Col02" "Fujitsu_08"="HID\\WACOMVIRTUALHID&Col03" "Fujitsu_09"="HID\\Vid_0430&Pid_0501&Rev_5001" "Fujitsu_10"="HID\\Vid_0430&Pid_0501" "Fujitsu_11"="HID\\Vid_0430&Pid_0530&Rev_5001" "Fujitsu_12"="HID\\Vid_0430&Pid_0530" "IBM_01"="IBM0057" "IBM_02"="*IBM0057" "IBM_03"="ACPI\\IBM0057" "Microsoft_01"="HID\\IrDevice&Col08" "Sharp_01"="HID\\VID_044F&PID_E000" "Sharp_02"="HID\\VID_04F2&PID_0001&MI_01" "Sharp_03"="HID\\VID_044F&PID_B304&REV_0100&COL02" "Sharp_04"="HID\\Vid_04f2&Pid_0001&Rev_0100&MI_00" "Sharp_05"="HID\\Vid_04f2&Pid_0001&Rev_0100&MI_01" "Toshiba_01"="HID\\TOS_BT_MOU_0004&0005" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SynTP\PNPDisableExclusionList] "ASUS_01"="USB\\VID_0A81&PID_0103&MI_00*" "ASUS_02"="USB\\VID_0A81&PID_0103&MI_01*" "ASUS_03"="HID\\Vid_046d&Pid_c50e&Rev_2500" "ASUS_04"="HID\\Vid_046d&Pid_c50e&Rev_2510" "ASUS_05"="HID\\Vid_0A81&Pid_0103&MI_01&Col02" "ASUS_06"="HID\\Vid_0A81&Pid_0103&MI_01&Col03" "ASUS_07"="HID\\Vid_04B8&Pid_030E&Rev_0100&MI_*" "ASUS_08"="HID\\Vid_05E3&Pid_FFE2&Rev_0001&MI_*" "ASUS_09"="HID\\Vid_0A81&Pid_0103&Rev_0110&MI_*" "BTC_01"="USB\\VID_0637&PID_0001*" "BTC_02"="HID\\Vid_046e&Pid_6782&MI_00" "BTC_03"="HID\\Vid_046e&Pid_6782&MI_01&Col01" "BTC_04"="HID\\Vid_046e&Pid_6782&MI_01&Col02" "BTC_05"="HID\\Vid_046e&Pid_6782&Rev_2110&MI_00" "BTC_06"="HID\\Vid_046e&Pid_6782&Rev_2110&MI_01&Col01" "BTC_07"="HID\\Vid_046e&Pid_6782&Rev_2110&MI_01&Col02" "Fujitsu_01"="SERENUM\\FJC5000" "Fujitsu_02"="HID\\Vid_0430&Pid_0002&Rev_0100&MI_00" "Fujitsu_03"="HID\\Vid_0430&Pid_0002&Rev_0100&MI_01" "Fujitsu_04"="HID\\Vid_0430&Pid_0002&MI_00" "Fujitsu_05"="HID\\Vid_0430&Pid_0002&MI_01" "Fujitsu_06"="HID\\FUJ02E5&Col02" "Fujitsu_07"="HID\\FUJ02E6&Col02" "IBM_01"="IBM0057" "IBM_02"="*IBM0057" "IBM_03"="ACPI\\IBM0057" "Sharp_01"="HID\\VID_044F&PID_E000" "Sharp_02"="HID\\VID_04F2&PID_0001&MI_01" "Sharp_03"="HID\\VID_044F&PID_B304&REV_0100&COL02" "Sharp_04"="HID\\Vid_04f2&Pid_0001&Rev_0100&MI_00" "Sharp_05"="HID\\Vid_04f2&Pid_0001&Rev_0100&MI_01" "Toshiba_01"="HID\\TOS_BT_MOU_0004&0005" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SynTP\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SynTP\Enum] "0"="ACPI\\SYN0136\\4&374ccb25&0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sysaudio] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,79,00,73,00,61,00,75,00,64,\ 00,69,00,6f,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel System Audio Device" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sysaudio\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sysaudio\Enum] "0"="SW\\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\\{9B365890-165F-11D0-A195-0020AFD156E4}" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog] "Description"="Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Performance Logs and Alerts" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="NT Authority\\NetworkService" "Start"=dword:00000003 "Type"=dword:00000010 "DefaultLogFileFolder"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,44,00,\ 72,00,69,00,76,00,65,00,25,00,5c,00,50,00,65,00,72,00,66,00,4c,00,6f,00,67,\ 00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries] "Defaults Installed"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tap0801] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000013 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,74,00,61,00,70,00,30,00,38,00,30,\ 00,31,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="TAP-Win32 Adapter V8" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tap0801\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv] "DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\ 52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service." "DisplayName"="Telephony" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 74,00,61,00,70,00,69,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Performance] "Close"="CloseTapiPerformanceData" "Collect"="CollectTapiPerformanceData" "Library"="tapiperf.dll" "ObjectList"="1150" "Open"="OpenTapiPerformanceData" "WbemAdapFileSignature"=hex:69,51,b8,9b,4f,59,1a,a6,94,04,8a,6c,d0,e5,22,4a "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00001600 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Security] "Security"=hex:01,00,14,80,6c,00,00,00,78,00,00,00,14,00,00,00,34,00,00,00,02,\ 00,20,00,01,00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,20,02,00,00,02,00,38,00,02,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,\ 00,00,00,00,05,20,00,00,00,20,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,\ 00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\ 01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Enum] "0"="Root\\LEGACY_TAPISRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000003 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,74,00,63,00,70,00,69,00,70,00,2e,\ 00,73,00,79,00,73,00,00,00 "DisplayName"="TCP/IP Protocol Driver" "Group"="PNP_TDI" "DependOnService"=hex(7):49,00,50,00,53,00,65,00,63,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="TCP/IP Protocol Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage] "Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,41,00,30,\ 00,33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,\ 34,00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,\ 00,30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,38,00,30,00,44,00,44,00,42,\ 00,45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,\ 45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,\ 00,37,00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,\ 00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,\ 44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,\ 00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,\ 00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,\ 2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,32,00,\ 39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,\ 00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,\ 37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,39,00,31,00,44,00,39,00,\ 42,00,37,00,30,00,33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,\ 00,41,00,2d,00,39,00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,\ 33,00,34,00,44,00,42,00,32,00,36,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,\ 00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,49,00,\ 70,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,33,00,43,\ 00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,\ 34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,\ 00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 "Route"=hex(7):22,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,2d,\ 00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,00,\ 38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,46,\ 00,38,00,41,00,7d,00,22,00,00,00,22,00,7b,00,38,00,30,00,44,00,44,00,42,00,\ 45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,\ 00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,\ 37,00,45,00,43,00,41,00,39,00,39,00,7d,00,22,00,00,00,22,00,7b,00,35,00,33,\ 00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,\ 34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,\ 00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,22,00,00,00,\ 22,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,\ 00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,\ 2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,\ 00,7d,00,22,00,00,00,22,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,\ 35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,\ 00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,\ 38,00,46,00,43,00,35,00,7d,00,22,00,00,00,22,00,7b,00,39,00,31,00,44,00,39,\ 00,42,00,37,00,30,00,33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,\ 44,00,41,00,2d,00,39,00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,\ 00,33,00,34,00,44,00,42,00,32,00,36,00,41,00,7d,00,22,00,00,00,22,00,4e,00,\ 64,00,69,00,73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,22,00,7b,00,33,\ 00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,\ 2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,\ 00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,00,22,00,\ 00,00,00,00 "Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,\ 2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,\ 00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,\ 46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\ 00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,\ 45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,\ 00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,\ 37,00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\ 00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,33,00,\ 30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,\ 00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,\ 38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,\ 7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,\ 00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,\ 32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,\ 00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,\ 69,00,70,00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,\ 00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,\ 35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,\ 00,43,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,\ 00,30,00,33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,\ 2d,00,39,00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,\ 00,44,00,42,00,32,00,36,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,00,45,00,30,\ 00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,42,00,31,00,31,00,2d,00,34,00,\ 35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,00,2d,00,42,00,37,00,46,00,33,\ 00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,35,00,7d,00,00,00,5c,00,44,00,\ 65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,\ 00,37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,38,00,37,00,46,00,\ 34,00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,00,39,00,2d,00,43,\ 00,35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,46,00,30,00,7d,00,\ 00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,\ 36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,\ 00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,\ 32,00,39,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters] "NV Hostname"="ewi1299" "DataBasePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,74,00,63,00,00,00 "NameServer"="" "ForwardBroadcasts"=dword:00000000 "IPEnableRouter"=dword:00000000 "Domain"="" "Hostname"="ewi1299" "SearchList"="" "UseDomainNameDevolution"=dword:00000001 "EnableICMPRedirect"=dword:00000001 "DeadGWDetectDefault"=dword:00000001 "DontAddDefaultGatewayDefault"=dword:00000000 "EnableSecurityFilters"=dword:00000000 "TcpMaxDupAcks"=dword:00000001 "SackOpts"=dword:00000001 "DisableTaskOffload"=dword:00000001 "ReservedPorts"=hex(7):31,00,34,00,33,00,33,00,2d,00,31,00,34,00,33,00,34,00,\ 00,00,00,00 "DhcpNameServer"="130.89.2.2 130.89.2.3" "DhcpDomain"="cs.utwente.nl" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\NdisWanIp] "LLInterface"="WANARP" "IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\ 00,61,00,63,00,65,00,73,00,5c,00,7b,00,39,00,45,00,30,00,43,00,46,00,34,00,\ 45,00,46,00,2d,00,43,00,42,00,31,00,31,00,2d,00,34,00,35,00,35,00,43,00,2d,\ 00,41,00,33,00,31,00,30,00,2d,00,42,00,37,00,46,00,33,00,38,00,36,00,39,00,\ 38,00,42,00,36,00,42,00,35,00,7d,00,00,00,54,00,63,00,70,00,69,00,70,00,5c,\ 00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,\ 6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,00,73,00,5c,00,7b,00,37,00,43,\ 00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,38,00,37,00,46,00,34,00,2d,00,\ 34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,00,39,00,2d,00,43,00,35,00,41,\ 00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,46,00,30,00,7d,00,00,00,00,00 "NumInterfaces"=dword:00000002 "IpInterfaces"=hex:ef,f4,0c,9e,11,cb,5c,45,a3,10,b7,f3,86,98,b6,b5,bf,b1,00,7c,\ f4,87,62,44,bf,b9,c5,a8,bc,41,64,f0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{2937DCE5-1AB6-4454-A75A-347564768FC5}] "LLInterface"="" "IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\ 00,61,00,63,00,65,00,73,00,5c,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,\ 45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,\ 00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,\ 36,00,38,00,46,00,43,00,35,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}] "LLInterface"="" "IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\ 00,61,00,63,00,65,00,73,00,5c,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,\ 37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,\ 00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,\ 38,00,33,00,33,00,32,00,39,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}] "LLInterface"="" "IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\ 00,61,00,63,00,65,00,73,00,5c,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,\ 30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,\ 00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,\ 45,00,34,00,33,00,39,00,43,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}] "LLInterface"="" "IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\ 00,61,00,63,00,65,00,73,00,5c,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,\ 42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,\ 00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,\ 45,00,43,00,41,00,39,00,39,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{91D9B703-C06F-42DA-94D6-DAC5B34DB26A}] "LLInterface"="ARP1394" "IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\ 00,61,00,63,00,65,00,73,00,5c,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,\ 30,00,33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,\ 00,39,00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,\ 44,00,42,00,32,00,36,00,41,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}] "LLInterface"="" "IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\ 00,61,00,63,00,65,00,73,00,5c,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,\ 34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,\ 00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,\ 32,00,46,00,46,00,38,00,41,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{AFE45985-028E-4E55-A932-232847605B83}] "LLInterface"="" "IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\ 00,61,00,63,00,65,00,73,00,5c,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,\ 38,00,35,00,2d,00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,\ 00,41,00,39,00,33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,\ 30,00,35,00,42,00,38,00,33,00,7d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DNSRegisteredAdapters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2937DCE5-1AB6-4454-A75A-347564768FC5}] "UseZeroBroadcast"=dword:00000000 "EnableDeadGWDetect"=dword:00000001 "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DefaultGatewayMetric"=hex(7):00,00 "NameServer"="" "Domain"="" "RegistrationEnabled"=dword:00000001 "RegisterAdapterName"=dword:00000000 "TCPAllowedPorts"=hex(7):30,00,00,00,00,00 "UDPAllowedPorts"=hex(7):30,00,00,00,00,00 "RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00 "NTEContextList"=hex(7):30,00,78,00,30,00,30,00,30,00,30,00,30,00,30,00,30,00,\ 33,00,00,00,00,00 "DhcpClassIdBin"=hex: "DhcpServer"="130.89.1.145" "Lease"=dword:00001c20 "LeaseObtainedTime"=dword:4c1b2ae4 "T1"=dword:4c1b38f4 "T2"=dword:4c1b4380 "LeaseTerminatesTime"=dword:4c1b4704 "IPAutoconfigurationAddress"="0.0.0.0" "IPAutoconfigurationMask"="255.255.0.0" "IPAutoconfigurationSeed"=dword:00000000 "AddressType"=dword:00000000 "MTU"=dword:00000514 "IsServerNapAware"=dword:00000000 "DhcpIPAddress"="130.89.145.113" "DhcpSubnetMask"="255.255.255.0" "DhcpRetryTime"=dword:00000e0d "DhcpRetryStatus"=dword:00000000 "DhcpNameServer"="130.89.2.2 130.89.2.3" "DhcpDefaultGateway"=hex(7):31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,31,00,34,\ 00,35,00,2e,00,31,00,00,00,00,00 "DhcpDomain"="cs.utwente.nl" "DhcpSubnetMaskOpt"=hex(7):32,00,35,00,35,00,2e,00,32,00,35,00,35,00,2e,00,32,\ 00,35,00,35,00,2e,00,30,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}] "UseZeroBroadcast"=dword:00000000 "EnableDeadGWDetect"=dword:00000001 "EnableDHCP"=dword:00000000 "IPAddress"=hex(7):31,00,39,00,32,00,2e,00,31,00,36,00,38,00,2e,00,35,00,36,00,\ 2e,00,31,00,00,00,00,00 "SubnetMask"=hex(7):32,00,35,00,35,00,2e,00,32,00,35,00,35,00,2e,00,32,00,35,\ 00,35,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DefaultGatewayMetric"=hex(7):00,00 "NameServer"="" "Domain"="" "RegistrationEnabled"=dword:00000001 "RegisterAdapterName"=dword:00000000 "TCPAllowedPorts"=hex(7):30,00,00,00,00,00 "UDPAllowedPorts"=hex(7):30,00,00,00,00,00 "RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00 "NTEContextList"=hex(7):30,00,78,00,30,00,30,00,30,00,30,00,30,00,30,00,30,00,\ 34,00,00,00,00,00 "DhcpClassIdBin"=hex: "DhcpServer"="255.255.255.255" "Lease"=dword:00000e10 "LeaseObtainedTime"=dword:4ad5c588 "T1"=dword:4ad5cc90 "T2"=dword:4ad5d1d6 "LeaseTerminatesTime"=dword:4ad5d398 "IPAutoconfigurationAddress"="0.0.0.0" "IPAutoconfigurationMask"="255.255.0.0" "IPAutoconfigurationSeed"=dword:00000000 "AddressType"=dword:00000000 "IsServerNapAware"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}] "UseZeroBroadcast"=dword:00000000 "EnableDeadGWDetect"=dword:00000001 "EnableDHCP"=dword:00000000 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00,00,00 "DefaultGatewayMetric"=hex(7):00,00,00,00 "NameServer"="" "Domain"="" "RegistrationEnabled"=dword:00000001 "RegisterAdapterName"=dword:00000000 "TCPAllowedPorts"=hex(7):30,00,00,00,00,00 "UDPAllowedPorts"=hex(7):30,00,00,00,00,00 "RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00 "NTEContextList"=hex(7):00,00 "DhcpClassIdBin"=hex: "DhcpServer"="255.255.255.255" "Lease"=dword:00000e10 "LeaseObtainedTime"=dword:48c8df4d "T1"=dword:48c8e655 "T2"=dword:48c8eb9b "LeaseTerminatesTime"=dword:48c8ed5d "IPAutoconfigurationAddress"="0.0.0.0" "IPAutoconfigurationMask"="255.255.0.0" "IPAutoconfigurationSeed"=dword:00000000 "AddressType"=dword:00000000 "MTU"=dword:00000514 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7C00B1BF-87F4-4462-BFB9-C5A8BC4164F0}] "UseZeroBroadcast"=dword:00000000 "EnableDHCP"=dword:00000000 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "EnableDeadGWDetect"=dword:00000001 "DontAddDefaultGateway"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}] "UseZeroBroadcast"=dword:00000000 "EnableDeadGWDetect"=dword:00000001 "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DefaultGatewayMetric"=hex(7):00,00 "NameServer"="" "Domain"="" "RegistrationEnabled"=dword:00000001 "RegisterAdapterName"=dword:00000000 "TCPAllowedPorts"=hex(7):30,00,00,00,00,00 "UDPAllowedPorts"=hex(7):30,00,00,00,00,00 "RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00 "NTEContextList"=hex(7):00,00 "DhcpClassIdBin"=hex: "DhcpIPAddress"="169.254.172.68" "DhcpSubnetMask"="255.255.0.0" "DhcpServer"="255.255.255.255" "Lease"=dword:00000000 "LeaseObtainedTime"=dword:4ac1aed8 "T1"=dword:4ac1aed8 "T2"=dword:4ac1aed8 "LeaseTerminatesTime"=dword:7fffffff "IPAutoconfigurationAddress"="169.254.172.68" "IPAutoconfigurationMask"="255.255.0.0" "IPAutoconfigurationSeed"=dword:00000000 "AddressType"=dword:00000001 "IsServerNapAware"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91D9B703-C06F-42DA-94D6-DAC5B34DB26A}] "UseZeroBroadcast"=dword:00000000 "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DefaultGatewayMetric"=hex(7):00,00 "NameServer"="" "Domain"="" "RegistrationEnabled"=dword:00000001 "RegisterAdapterName"=dword:00000000 "TCPAllowedPorts"=hex(7):30,00,00,00,00,00 "UDPAllowedPorts"=hex(7):30,00,00,00,00,00 "RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00 "MTU"=dword:00000514 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9E0CF4EF-CB11-455C-A310-B7F38698B6B5}] "UseZeroBroadcast"=dword:00000000 "EnableDHCP"=dword:00000000 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "EnableDeadGWDetect"=dword:00000001 "DontAddDefaultGateway"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}] "UseZeroBroadcast"=dword:00000000 "EnableDeadGWDetect"=dword:00000001 "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DefaultGatewayMetric"=hex(7):00,00 "NameServer"="" "Domain"="" "RegistrationEnabled"=dword:00000001 "RegisterAdapterName"=dword:00000000 "TCPAllowedPorts"=hex(7):30,00,00,00,00,00 "UDPAllowedPorts"=hex(7):30,00,00,00,00,00 "RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00 "NTEContextList"=hex(7):30,00,78,00,30,00,30,00,30,00,30,00,30,00,30,00,30,00,\ 36,00,00,00,00,00 "DhcpClassIdBin"=hex: "DhcpIPAddress"="10.7.10.195" "DhcpSubnetMask"="255.255.255.248" "DhcpServer"="10.7.10.193" "Lease"=dword:00001c20 "LeaseObtainedTime"=dword:4ba2622d "T1"=dword:4ba2703d "T2"=dword:4ba27ac9 "LeaseTerminatesTime"=dword:4ba27e4d "IPAutoconfigurationAddress"="0.0.0.0" "IPAutoconfigurationMask"="255.255.0.0" "IPAutoconfigurationSeed"=dword:00000000 "AddressType"=dword:00000000 "IsServerNapAware"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{AFE45985-028E-4E55-A932-232847605B83}] "UseZeroBroadcast"=dword:00000000 "EnableDeadGWDetect"=dword:00000001 "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DefaultGatewayMetric"=hex(7):00,00 "NameServer"="" "Domain"="" "RegistrationEnabled"=dword:00000001 "RegisterAdapterName"=dword:00000000 "TCPAllowedPorts"=hex(7):30,00,00,00,00,00 "UDPAllowedPorts"=hex(7):30,00,00,00,00,00 "RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00 "NTEContextList"=hex(7):30,00,78,00,30,00,30,00,30,00,30,00,30,00,30,00,30,00,\ 32,00,00,00,00,00 "DhcpClassIdBin"=hex: "DhcpServer"="1.1.1.1" "Lease"=dword:00000708 "LeaseObtainedTime"=dword:4c1b2af1 "T1"=dword:4c1b2e75 "T2"=dword:4c1b3118 "LeaseTerminatesTime"=dword:4c1b31f9 "IPAutoconfigurationAddress"="0.0.0.0" "IPAutoconfigurationMask"="255.255.0.0" "IPAutoconfigurationSeed"=dword:6ea983dc "AddressType"=dword:00000000 "MTU"=dword:00000514 "IsServerNapAware"=dword:00000000 "DhcpIPAddress"="130.89.239.203" "DhcpSubnetMask"="255.255.240.0" "DhcpRetryTime"=dword:00000143 "DhcpRetryStatus"=dword:00000000 "DhcpNameServer"="130.89.2.2 130.89.2.3" "DhcpDefaultGateway"=hex(7):31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,32,00,32,\ 00,34,00,2e,00,31,00,00,00,00,00 "DhcpSubnetMaskOpt"=hex(7):32,00,35,00,35,00,2e,00,32,00,35,00,35,00,2e,00,32,\ 00,34,00,30,00,2e,00,30,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\PersistentRoutes] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Winsock] "UseDelayedAcceptance"=dword:00000000 "HelperDllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,77,00,73,00,68,00,74,00,63,00,70,00,69,00,70,00,2e,00,64,00,6c,00,6c,00,\ 00,00 "MaxSockAddrLength"=dword:00000010 "MinSockAddrLength"=dword:00000010 "Mapping"=hex:0b,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,06,00,00,00,02,\ 00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,06,00,00,00,00,00,\ 00,00,00,00,00,00,06,00,00,00,00,00,00,00,01,00,00,00,06,00,00,00,02,00,00,\ 00,02,00,00,00,11,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,02,00,00,00,\ 00,00,00,00,11,00,00,00,00,00,00,00,00,00,00,00,11,00,00,00,00,00,00,00,02,\ 00,00,00,11,00,00,00,02,00,00,00,03,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Performance] "Close"="CloseTcpIpPerformanceData" "Collect"="CollectTcpIpPerformanceData" "Library"="Perfctrs.dll" "Open"="OpenTcpIpPerformanceData" "Object List"="502 510 546 582 638 658" "WbemAdapFileSignature"=hex:db,e2,b6,23,53,66,0e,cc,a0,d7,5e,a3,07,a7,17,e9 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00009c00 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\ServiceProvider] "Class"=dword:00000008 "DnsPriority"=dword:000007d0 "HostsPriority"=dword:000001f4 "LocalPriority"=dword:000001f3 "ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,73,00,6f,00,63,00,6b,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 "NetbtPriority"=dword:000007d1 "Name"="TCP/IP" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Enum] "0"="Root\\LEGACY_TCPIP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDPIPE] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDTCP] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDTCP\Enum] "0"="Root\\LEGACY_TDTCP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermDD] "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,74,00,65,00,72,00,6d,00,64,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "Start"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Terminal Device Driver" "PortDriverEnable"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermDD\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermDD\Enum] "0"="Root\\RDP_KBD\\0000" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="Root\\RDP_MOU\\0000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService] "ErrorControl"=dword:00000001 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Description"="Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server." "DisplayName"="Terminal Services" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Type"=dword:00000020 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,44,00,43,00,\ 6f,00,6d,00,4c,00,61,00,75,00,6e,00,63,00,68,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "Certificate"=hex:01,00,00,00,01,00,00,00,01,00,00,00,06,00,5c,00,52,53,41,31,\ 48,00,00,00,00,02,00,00,3f,00,00,00,01,00,01,00,b3,85,0d,3e,fa,7a,93,2e,d4,\ fb,79,6a,04,6e,49,30,c6,38,97,30,95,e5,03,d9,46,d7,8a,49,91,23,f2,f0,ef,49,\ ff,2f,c4,04,85,72,b9,bd,8f,be,bb,18,b5,e1,1d,68,85,be,a5,40,34,00,54,2b,70,\ 67,d3,3d,4e,c4,00,00,00,00,00,00,00,00,08,00,48,00,8a,80,d4,06,ef,c5,3d,da,\ 68,09,fa,b4,87,46,4d,92,41,e9,dc,cf,b8,74,ef,e5,1e,91,75,6e,d7,00,24,f8,5d,\ 73,a2,71,4d,52,c7,b2,eb,ea,7b,85,6b,f9,a6,a6,be,41,80,f0,73,ab,e6,ee,bb,5e,\ 1e,1f,e4,76,71,6a,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Performance] "Close"="CloseTSObject" "Collect Timeout"=dword:000003e8 "Collect"="CollectTSObjectData" "Open Timeout"=dword:000003e8 "Open"="OpenTSObject" "Library"="perfts.dll" "Last Counter"=dword:00000886 "Last Help"=dword:00000887 "First Counter"=dword:00000806 "First Help"=dword:00000807 "Object List"="2054 2176" "Library Validation Code"=hex:34,53,4f,7d,26,be,c5,01,00,30,00,00,00,00,00,00 "WbemAdapFileSignature"=hex:7e,fd,21,14,ea,d1,ac,72,34,26,10,d7,19,2b,fb,32 "WbemAdapFileTime"=hex:00,40,4f,0a,f9,79,c4,01 "WbemAdapFileSize"=dword:00003000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Enum] "0"="Root\\LEGACY_TERMSERVICE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Themes" "Group"="UIGroup" "ObjectName"="LocalSystem" "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,6f,00,6f,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00 "Description"="Provides user experience theme management." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="ThemeServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes\Enum] "0"="Root\\LEGACY_THEMES\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr] "Type"=dword:00000010 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,74,00,6c,00,6e,\ 00,74,00,73,00,76,00,72,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Telnet" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,54,00,43,00,50,00,\ 49,00,50,00,00,00,4e,00,54,00,4c,00,4d,00,53,00,53,00,50,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"=hex(2):45,00,6e,00,61,00,62,00,6c,00,65,00,73,00,20,00,61,00,20,\ 00,72,00,65,00,6d,00,6f,00,74,00,65,00,20,00,75,00,73,00,65,00,72,00,20,00,\ 74,00,6f,00,20,00,6c,00,6f,00,67,00,20,00,6f,00,6e,00,20,00,74,00,6f,00,20,\ 00,74,00,68,00,69,00,73,00,20,00,63,00,6f,00,6d,00,70,00,75,00,74,00,65,00,\ 72,00,20,00,61,00,6e,00,64,00,20,00,72,00,75,00,6e,00,20,00,70,00,72,00,6f,\ 00,67,00,72,00,61,00,6d,00,73,00,2c,00,20,00,61,00,6e,00,64,00,20,00,73,00,\ 75,00,70,00,70,00,6f,00,72,00,74,00,73,00,20,00,76,00,61,00,72,00,69,00,6f,\ 00,75,00,73,00,20,00,54,00,43,00,50,00,2f,00,49,00,50,00,20,00,54,00,65,00,\ 6c,00,6e,00,65,00,74,00,20,00,63,00,6c,00,69,00,65,00,6e,00,74,00,73,00,2c,\ 00,20,00,69,00,6e,00,63,00,6c,00,75,00,64,00,69,00,6e,00,67,00,20,00,55,00,\ 4e,00,49,00,58,00,2d,00,62,00,61,00,73,00,65,00,64,00,20,00,61,00,6e,00,64,\ 00,20,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,2d,00,62,00,61,00,73,00,\ 65,00,64,00,20,00,63,00,6f,00,6d,00,70,00,75,00,74,00,65,00,72,00,73,00,2e,\ 00,20,00,49,00,66,00,20,00,74,00,68,00,69,00,73,00,20,00,73,00,65,00,72,00,\ 76,00,69,00,63,00,65,00,20,00,69,00,73,00,20,00,73,00,74,00,6f,00,70,00,70,\ 00,65,00,64,00,2c,00,20,00,72,00,65,00,6d,00,6f,00,74,00,65,00,20,00,75,00,\ 73,00,65,00,72,00,20,00,61,00,63,00,63,00,65,00,73,00,73,00,20,00,74,00,6f,\ 00,20,00,70,00,72,00,6f,00,67,00,72,00,61,00,6d,00,73,00,20,00,6d,00,69,00,\ 67,00,68,00,74,00,20,00,62,00,65,00,20,00,75,00,6e,00,61,00,76,00,61,00,69,\ 00,6c,00,61,00,62,00,6c,00,65,00,2e,00,20,00,49,00,66,00,20,00,74,00,68,00,\ 69,00,73,00,20,00,73,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,69,00,73,\ 00,20,00,64,00,69,00,73,00,61,00,62,00,6c,00,65,00,64,00,2c,00,20,00,61,00,\ 6e,00,79,00,20,00,73,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,20,00,74,\ 00,68,00,61,00,74,00,20,00,65,00,78,00,70,00,6c,00,69,00,63,00,69,00,74,00,\ 6c,00,79,00,20,00,64,00,65,00,70,00,65,00,6e,00,64,00,20,00,6f,00,6e,00,20,\ 00,69,00,74,00,20,00,77,00,69,00,6c,00,6c,00,20,00,66,00,61,00,69,00,6c,00,\ 20,00,74,00,6f,00,20,00,73,00,74,00,61,00,72,00,74,00,2e,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TosIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000004 "Tag"=dword:00000004 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks] "Description"="Maintains links between NTFS files within a computer or across computers in a network domain." "DisplayName"="Distributed Link Tracking Client" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 74,00,72,00,6b,00,77,00,6b,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks\Enum] "0"="Root\\LEGACY_TRKWKS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TSDDD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TSDDD\Device0] "InstalledDisplayDrivers"=hex(7):54,00,53,00,44,00,44,00,44,00,00,00,00,00 "VgaCompatible"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Udfs] "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000004 "Type"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Udfs\Enum] "0"="Root\\LEGACY_UDFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ultra] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003b "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ultra\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ultra\Parameters\PnpInterface] "5"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UltraMonMirror] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "Tag"=dword:00000002 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,55,00,6c,00,74,00,72,00,61,00,4d,\ 00,6f,00,6e,00,4d,00,69,00,72,00,72,00,6f,00,72,00,2e,00,73,00,79,00,73,00,\ 00,00 "Group"="Video" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UltraMonMirror\Device0] "MirrorDriver"=dword:00000001 "InstalledDisplayDrivers"=hex(7):55,00,6c,00,74,00,72,00,61,00,4d,00,6f,00,6e,\ 00,4d,00,69,00,72,00,72,00,6f,00,72,00,00,00,00,00 "VgaCompatible"=dword:00000000 "Attach.ToDesktop"=dword:00000001 "Device Description"="UltraMon Display Mirror Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UltraMonMirror\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UltraMonMirror\Video] "Service"="UltraMonMirror" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update] "ErrorControl"=dword:00000001 "Start"=dword:00000003 "Type"=dword:00000001 "DisplayName"="Microcode Update Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,70,00,64,00,61,00,74,00,65,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update\Devices] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update\Enum] "0"="Root\\SYSTEM\\0001" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "DisplayName"="Universal Plug and Play Device Host" "DependOnService"=hex(7):53,00,53,00,44,00,50,00,53,00,52,00,56,00,00,00,48,00,\ 54,00,54,00,50,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Provides support to host Universal Plug and Play devices." "FailureActions"=hex:ff,ff,ff,ff,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,01,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 75,00,70,00,6e,00,70,00,68,00,6f,00,73,00,74,00,2e,00,64,00,6c,00,6c,00,00,\ 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost\Security] "Security"=hex:01,00,14,80,bc,00,00,00,c8,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,8c,00,06,00,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\ 00,00,00,00,14,00,9d,00,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,14,\ 00,8f,01,02,00,01,01,00,00,00,00,00,05,13,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost\Enum] "0"="Root\\LEGACY_UPNPHOST\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upperdev] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,73,00,65,00,72,\ 00,5f,00,6c,00,6f,00,77,00,65,00,72,00,66,00,6c,00,74,00,2e,00,73,00,79,00,\ 73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upperdev\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UPS] "Description"="Manages an uninterruptible power supply (UPS) connected to the computer." "DisplayName"="Uninterruptible Power Supply" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,75,\ 00,70,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Start"=dword:00000003 "Type"=dword:00000010 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usb] "EnIdleEndPointSupportEx"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbccgp] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000017 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,63,00,63,00,67,\ 00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft USB Generic Parent Driver" "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbccgp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbehci] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "DisplayName"="Microsoft USB 2.0 Enhanced Host Controller Miniport Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,65,00,68,00,63,\ 00,69,00,2e,00,73,00,79,00,73,00,00,00 "Group"="Base" "Tag"=dword:00000010 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbehci\Enum] "0"="PCI\\VEN_8086&DEV_283A&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&D7" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="PCI\\VEN_8086&DEV_2836&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&EF" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbfpaa2] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,66,00,70,00,61,\ 00,61,00,32,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbfpaa2\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbfpaa2\Enum] "Count"=dword:00000001 "NextInstance"=dword:00000001 "0"="USB\\Vid_1495&Pid_1007\\5&570f764&0&1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBFPAB2] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,55,00,53,00,42,00,46,00,50,00,41,\ 00,42,00,32,00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBFPAB2\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBFPAB2\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "DisplayName"="Microsoft USB Standard Hub Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,68,00,75,00,62,\ 00,2e,00,73,00,79,00,73,00,00,00 "Group"="Base" "Tag"=dword:00000011 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub\Enum] "0"="USB\\ROOT_HUB\\4&2bdb31ec&0" "Count"=dword:00000008 "NextInstance"=dword:00000008 "1"="USB\\ROOT_HUB\\4&12e3745b&0" "2"="USB\\ROOT_HUB20\\4&3d411da&0" "3"="USB\\ROOT_HUB\\4&19997340&0" "4"="USB\\ROOT_HUB\\4&3072526b&0" "5"="USB\\ROOT_HUB\\4&392cb6a0&0" "6"="USB\\ROOT_HUB20\\4&26e5dc06&0" "7"="USB\\Vid_058f&Pid_6254\\5&3b8933dc&0&5" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbscan] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000001d "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,73,00,63,00,61,\ 00,6e,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="USB Scanner Driver" "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbscan\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbser] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,75,00,73,00,62,00,73,00,65,00,72,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="USB Modem Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbser\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbserFilt] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,73,00,65,00,72,\ 00,5f,00,6c,00,6f,00,77,00,65,00,72,00,66,00,6c,00,74,00,6a,00,2e,00,73,00,\ 79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbserFilt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbstor] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "DisplayName"="USB Mass Storage Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,55,00,53,00,42,00,53,00,54,00,4f,\ 00,52,00,2e,00,53,00,59,00,53,00,00,00 "massfilter"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbuhci] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "DisplayName"="Microsoft USB Universal Host Controller Miniport Driver" "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,75,00,68,00,63,\ 00,69,00,2e,00,73,00,79,00,73,00,00,00 "Group"="Base" "Tag"=dword:0000000f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbuhci\Enum] "0"="PCI\\VEN_8086&DEV_2834&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&D0" "Count"=dword:00000005 "NextInstance"=dword:00000005 "1"="PCI\\VEN_8086&DEV_2835&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&D1" "2"="PCI\\VEN_8086&DEV_2830&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&E8" "3"="PCI\\VEN_8086&DEV_2831&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&E9" "4"="PCI\\VEN_8086&DEV_2832&SUBSYS_30C5103C&REV_03\\3&b1bfb68&0&EA" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxDrv] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,56,00,42,00,6f,00,78,00,44,00,72,\ 00,76,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="VirtualBox Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxDrv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxDrv\Enum] "0"="Root\\LEGACY_VBOXDRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetAdp] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000014 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,56,00,42,00,6f,00,78,00,4e,00,65,\ 00,74,00,41,00,64,00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="VirtualBox Host-Only Ethernet Adapter" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetAdp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetAdp\Enum] "0"="Root\\NET\\0002" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000a "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,56,00,42,00,6f,00,78,00,4e,00,65,\ 00,74,00,46,00,6c,00,74,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="VBoxNetFlt Service" "Group"="PNP_TDI" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Linkage] "Bind"=hex(7):00,00 "Route"=hex(7):00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Parameters\Adapters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Parameters\Adapters\{2937DCE5-1AB6-4454-A75A-347564768FC5}] "UpperBindings"="\\Device\\{C6EE8BE7-7FBE-4F2B-9B4A-79E76773EEE6}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Parameters\Adapters\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}] "UpperBindings"="\\Device\\{D743D11A-DD86-45CA-A30B-9850B280DF26}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Parameters\Adapters\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}] "UpperBindings"="\\Device\\{16BFD16D-E32A-42AA-99E7-C59995FC9ED9}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Parameters\Adapters\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}] "UpperBindings"="\\Device\\{FE7B6605-EAF2-4754-8A4B-3CBDED9BDE9F}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Parameters\Adapters\{AFE45985-028E-4E55-A932-232847605B83}] "UpperBindings"="\\Device\\{ED396A33-9490-425F-AEAF-0C6ACD096B01}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Parameters\Adapters\{B57AD90D-90AA-474A-A4F3-051BE53F591A}] "UpperBindings"="\\Device\\{634E04B3-5875-4B14-A0E5-5B591EFCB5D5}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxNetFlt\Enum] "0"="Root\\SUN_VBOXNETFLTMP\\0000" "Count"=dword:00000005 "NextInstance"=dword:00000005 "1"="Root\\SUN_VBOXNETFLTMP\\0001" "2"="Root\\SUN_VBOXNETFLTMP\\0002" "3"="Root\\SUN_VBOXNETFLTMP\\0003" "4"="Root\\SUN_VBOXNETFLTMP\\0004" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxTAP] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000011 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,56,00,42,00,6f,00,78,00,54,00,41,\ 00,50,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="VirtualBox TAP Adapter" "Group"="NDIS" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxTAP\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxUSB] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000019 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,56,00,42,00,6f,00,78,00,55,00,53,\ 00,42,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="VirtualBox USB" "Group"="Base" "DevLoader"="*ntkern" "NTMPDriver"="VBoxUSB.sys" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxUSB\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxUSBMon] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,56,00,42,00,6f,00,78,00,55,00,53,\ 00,42,00,4d,00,6f,00,6e,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="VirtualBox USB Monitor Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxUSBMon\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VBoxUSBMon\Enum] "0"="Root\\LEGACY_VBOXUSBMON\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VgaSave] "ErrorControl"=dword:00000000 "Group"="Video Save" "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,76,00,67,00,61,00,2e,00,73,00,79,00,\ 73,00,00,00 "Start"=dword:00000001 "Tag"=dword:00000001 "Type"=dword:00000001 "Description"="Controls the VGA display adapter to provide basic display capabilities." "DisplayName"="VGA Display Controller." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VgaSave\Device0] "InstalledDisplayDrivers"=hex(7):76,00,67,00,61,00,00,00,66,00,72,00,61,00,6d,\ 00,65,00,62,00,75,00,66,00,00,00,76,00,67,00,61,00,32,00,35,00,36,00,00,00,\ 76,00,67,00,61,00,36,00,34,00,6b,00,00,00,00,00 "VgaCompatible"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VgaSave\Video] "VideoID"="{23A77BF7-ED96-40EC-AF06-9B1F4867732A}" "Service"="VgaSave" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VgaSave\Enum] "0"="Root\\LEGACY_VGASAVE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ViaIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000004 "Type"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,76,00,69,00,61,00,69,00,64,00,65,\ 00,2e,00,73,00,79,00,73,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ViaIde\Enum] "0"="Root\\LEGACY_VIAIDE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VolSnap] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000000 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VolSnap\Enum] "0"="Root\\LEGACY_VOLSNAP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vsdatant] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\ 44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,76,00,73,00,64,00,61,00,74,00,61,00,6e,00,74,00,2e,00,73,00,79,00,\ 73,00,00,00 "DisplayName"="vsdatant" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vsdatant\Security] "Security"=hex:01,00,14,80,30,00,00,00,3c,00,00,00,14,00,00,00,00,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,\ 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vsdatant\Enum] "0"="Root\\LEGACY_VSDATANT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS] "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Description"="Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Volume Shadow Copy" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,76,\ 00,73,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000010 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}] @="MS Software Shadow Copy provider 1.0" "Type"=dword:00000001 "Version"="1.0.0.7" "VersionId"="{00000001-0000-0000-0007-000000000001}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}\CLSID] @="{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings] "MSDEVersionChecking"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time] "Description"="Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. " "DisplayName"="Windows Time" "ErrorControl"=dword:00000001 "Group"="" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "Objectname"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020 "FailureActions"=hex:05,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,45,00,57,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config] "LastClockRate"=dword:0002625a "MinClockRate"=dword:000260d4 "MaxClockRate"=dword:000263e0 "FrequencyCorrectRate"=dword:00000004 "PollAdjustFactor"=dword:00000005 "LargePhaseOffset"=dword:00138800 "SpikeWatchPeriod"=dword:0000005a "HoldPeriod"=dword:00000005 "MaxPollInterval"=dword:0000000f "LocalClockDispersion"=dword:0000000a "EventLogFlags"=dword:00000002 "PhaseCorrectRate"=dword:00000001 "MinPollInterval"=dword:0000000a "UpdateInterval"=dword:00057e40 "MaxNegPhaseCorrection"=dword:0000d2f0 "MaxPosPhaseCorrection"=dword:0000d2f0 "AnnounceFlags"=dword:0000000a "MaxAllowedPhaseOffset"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters] "ServiceMain"="SvchostEntry_W32Time" "ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,33,00,\ 32,00,74,00,69,00,6d,00,65,00,2e,00,64,00,6c,00,6c,00,00,00 "NtpServer"="time.windows.com,0x1" "Type"="NTP" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient] "Enabled"=dword:00000001 "InputProvider"=dword:00000001 "AllowNonstandardModeCombinations"=dword:00000001 "CrossSiteSyncFlags"=dword:00000002 "ResolvePeerBackoffMinutes"=dword:0000000f "ResolvePeerBackoffMaxTimes"=dword:00000007 "CompatibilityFlags"=dword:80000000 "EventLogFlags"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\w32time.dll" "SpecialPollTimeRemaining"=hex(7):74,00,69,00,6d,00,65,00,2e,00,77,00,69,00,6e,\ 00,64,00,6f,00,77,00,73,00,2e,00,63,00,6f,00,6d,00,2c,00,37,00,62,00,33,00,\ 39,00,66,00,65,00,30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00 "SpecialPollInterval"=dword:00093a80 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer] "Enabled"=dword:00000001 "InputProvider"=dword:00000000 "AllowNonstandardModeCombinations"=dword:00000001 "DllName"="C:\\WINDOWS\\system32\\w32time.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Enum] "0"="Root\\LEGACY_W32TIME\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\AdvancedDataFactory] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\RDSServer.DataFactory] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wanarp] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,61,00,6e,00,61,00,72,00,70,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Remote Access IP ARP Driver" "Description"="Remote Access IP ARP Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wanarp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wanarp\Enum] "0"="Root\\LEGACY_WANARP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wdf01000] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,64,00,66,00,30,00,31,00,30,\ 00,30,00,30,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Wdf01000" "Group"="WdfLoadGroup" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wdf01000\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wdf01000\Enum] "0"="Root\\LEGACY_WDF01000\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WDICA] "ErrorControl"=dword:00000000 "Start"=dword:00000003 "Type"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wdmaud] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,77,00,64,00,6d,00,61,00,75,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft WINMM WDM Audio Compatibility Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wdmaud\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wdmaud\Enum] "0"="SW\\{cd171de3-69e5-11d2-b56d-0000f8754380}\\{9B365890-165F-11D0-A195-0020AFD156E4}" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,00,00 "DisplayName"="WebClient" "Group"="NetworkProvider" "DependOnService"=hex(7):4d,00,52,00,78,00,44,00,41,00,56,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start." "ServiceSidType"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient\NetworkProvider] "Name"="Web Client Network" "ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,61,00,76,00,63,00,6c,00,6e,00,74,00,2e,00,64,00,6c,00,6c,00,00,00 "DeviceName"="\\Device\\WebDavRedirector" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,65,00,62,00,63,00,6c,00,6e,00,74,00,2e,00,64,00,6c,00,6c,00,00,00 "ServerNotFoundCacheLifeTimeInSec"=dword:0000003c "AcceptOfficeAndTahoeServers"=dword:00000000 "ServiceDebug"=dword:00000000 "ClientDebug"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient\Enum] "0"="Root\\LEGACY_WEBCLIENT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winachsf] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,48,00,53,00,46,00,5f,00,43,00,4e,\ 00,58,00,54,00,2e,00,73,00,79,00,73,00,00,00 "SymbolicLink"="COM3" "DriverDesc"="Soft Data Fax Modem with SmartCP" "FriendlyName"="Soft Data Fax Modem with SmartCP" "Manufacturer"="CXT" "Model"="Soft Data Fax Modem with SmartCP" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winachsf\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winachsf\Enum] "0"="HDAUDIO\\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_103C1379&REV_1000\\4&1d8c0f4e&0&0102" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Workflow Foundation 3.0.0.0] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Workflow Foundation 3.0.0.0\Linkage] "Export"=hex(7):57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,57,00,6f,00,72,\ 00,6b,00,66,00,6c,00,6f,00,77,00,20,00,46,00,6f,00,75,00,6e,00,64,00,61,00,\ 74,00,69,00,6f,00,6e,00,20,00,33,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,\ 00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Workflow Foundation 3.0.0.0\Performance] "Library"="NETFXPerf.dll" "Open"="OpenPerformanceData" "Collect"="CollectPerformanceData" "Close"="ClosePerformanceData" "CategoryOptions"=dword:00000001 "IsMultiInstance"=dword:00000001 "Counter Types"=hex:36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,\ 00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,\ 32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,\ 00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,\ 00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,\ 00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,\ 32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,\ 00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,\ 35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,32,00,37,\ 00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,00,35,00,35,00,33,00,\ 36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,32,00,30,00,00,00,36,\ 00,35,00,35,00,33,00,36,00,00,00,32,00,37,00,32,00,36,00,39,00,36,00,33,00,\ 32,00,30,00,00,00,36,00,35,00,35,00,33,00,36,00,00,00,36,00,35,00,35,00,33,\ 00,36,00,00,00,00,00 "Counter Names"=hex:57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,\ 00,43,00,72,00,65,00,61,00,74,00,65,00,64,00,00,00,57,00,6f,00,72,00,6b,00,\ 66,00,6c,00,6f,00,77,00,73,00,20,00,43,00,72,00,65,00,61,00,74,00,65,00,64,\ 00,2f,00,73,00,65,00,63,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,\ 77,00,73,00,20,00,55,00,6e,00,6c,00,6f,00,61,00,64,00,65,00,64,00,00,00,57,\ 00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,55,00,6e,00,6c,00,\ 6f,00,61,00,64,00,65,00,64,00,2f,00,73,00,65,00,63,00,00,00,57,00,6f,00,72,\ 00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,4c,00,6f,00,61,00,64,00,65,00,\ 64,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,4c,\ 00,6f,00,61,00,64,00,65,00,64,00,2f,00,73,00,65,00,63,00,00,00,57,00,6f,00,\ 72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,43,00,6f,00,6d,00,70,00,6c,\ 00,65,00,74,00,65,00,64,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,\ 77,00,73,00,20,00,43,00,6f,00,6d,00,70,00,6c,00,65,00,74,00,65,00,64,00,2f,\ 00,73,00,65,00,63,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,\ 73,00,20,00,53,00,75,00,73,00,70,00,65,00,6e,00,64,00,65,00,64,00,00,00,57,\ 00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,53,00,75,00,73,00,\ 70,00,65,00,6e,00,64,00,65,00,64,00,2f,00,73,00,65,00,63,00,00,00,57,00,6f,\ 00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,54,00,65,00,72,00,6d,00,\ 69,00,6e,00,61,00,74,00,65,00,64,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,\ 00,6f,00,77,00,73,00,20,00,54,00,65,00,72,00,6d,00,69,00,6e,00,61,00,74,00,\ 65,00,64,00,2f,00,73,00,65,00,63,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,\ 00,6f,00,77,00,73,00,20,00,49,00,6e,00,20,00,4d,00,65,00,6d,00,6f,00,72,00,\ 79,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,41,\ 00,62,00,6f,00,72,00,74,00,65,00,64,00,00,00,57,00,6f,00,72,00,6b,00,66,00,\ 6c,00,6f,00,77,00,73,00,20,00,41,00,62,00,6f,00,72,00,74,00,65,00,64,00,2f,\ 00,73,00,65,00,63,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,\ 73,00,20,00,50,00,65,00,72,00,73,00,69,00,73,00,74,00,65,00,64,00,00,00,57,\ 00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,50,00,65,00,72,00,\ 73,00,69,00,73,00,74,00,65,00,64,00,2f,00,73,00,65,00,63,00,00,00,57,00,6f,\ 00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,45,00,78,00,65,00,63,00,\ 75,00,74,00,69,00,6e,00,67,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,\ 00,77,00,73,00,20,00,49,00,64,00,6c,00,65,00,2f,00,73,00,65,00,63,00,00,00,\ 57,00,6f,00,72,00,6b,00,66,00,6c,00,6f,00,77,00,73,00,20,00,52,00,75,00,6e,\ 00,6e,00,61,00,62,00,6c,00,65,00,00,00,57,00,6f,00,72,00,6b,00,66,00,6c,00,\ 6f,00,77,00,73,00,20,00,50,00,65,00,6e,00,64,00,69,00,6e,00,67,00,00,00,00,\ 00 "Last Counter"=dword:00001044 "Last Help"=dword:00001045 "First Counter"=dword:0000101a "First Help"=dword:0000101b "Object List"="4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122 4122" "WbemAdapFileSignature"=hex:31,fb,4b,33,7d,d0,9b,df,99,42,9d,7d,bb,5f,dd,48 "WbemAdapFileTime"=hex:00,a5,67,58,25,d9,c2,01 "WbemAdapFileSize"=dword:00008000 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Windows Management Instrumentation" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,02,00,00,00,05,00,03,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00 "Description"="Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,62,00,65,00,6d,00,5c,00,57,00,4d,00,49,00,73,00,76,00,63,00,2e,00,64,\ 00,6c,00,6c,00,00,00 "ServiceMain"="ServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt\Enum] "0"="Root\\LEGACY_WINMGMT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock] "ErrorControl"=dword:00000001 "Start"=dword:00000003 "Type"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock\Parameters] "Transports"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,4e,00,65,00,74,00,42,\ 00,49,00,4f,00,53,00,00,00,52,00,4d,00,43,00,41,00,53,00,54,00,00,00,00,00,\ 00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration] "Setup Version"=dword:00001009 "Provider List"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,4e,00,65,00,74,00,\ 42,00,49,00,4f,00,53,00,00,00,52,00,4d,00,43,00,41,00,53,00,54,00,00,00,00,\ 00 "Known Static Providers"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,4e,00,77,\ 00,6c,00,6e,00,6b,00,49,00,70,00,78,00,00,00,4e,00,77,00,6c,00,6e,00,6b,00,\ 53,00,70,00,78,00,00,00,41,00,70,00,70,00,6c,00,65,00,54,00,61,00,6c,00,6b,\ 00,00,00,49,00,73,00,6f,00,54,00,70,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers\NetBIOS] "WinSock 1.1 Provider Data"=hex:0e,10,00,00,11,00,00,00,14,00,00,00,14,00,00,\ 00,05,00,00,00,f7,ff,ff,ff,00,fa,00,00,16,0a,00,00,09,12,00,00,11,00,00,00,\ 14,00,00,00,14,00,00,00,02,00,00,00,f7,ff,ff,ff,00,fa,00,00,a0,09,00,00,0e,\ 10,00,00,11,00,00,00,14,00,00,00,14,00,00,00,05,00,00,00,fa,ff,ff,ff,00,fa,\ 00,00,2a,09,00,00,09,12,00,00,11,00,00,00,14,00,00,00,14,00,00,00,02,00,00,\ 00,fa,ff,ff,ff,00,fa,00,00,b4,08,00,00,0e,10,00,00,11,00,00,00,14,00,00,00,\ 14,00,00,00,05,00,00,00,fb,ff,ff,ff,00,fa,00,00,3e,08,00,00,09,12,00,00,11,\ 00,00,00,14,00,00,00,14,00,00,00,02,00,00,00,fb,ff,ff,ff,00,fa,00,00,c8,07,\ 00,00,0e,10,00,00,11,00,00,00,14,00,00,00,14,00,00,00,05,00,00,00,fd,ff,ff,\ ff,00,fa,00,00,52,07,00,00,09,12,00,00,11,00,00,00,14,00,00,00,14,00,00,00,\ 02,00,00,00,fd,ff,ff,ff,00,fa,00,00,dc,06,00,00,0e,10,00,00,11,00,00,00,14,\ 00,00,00,14,00,00,00,05,00,00,00,00,00,00,80,00,fa,00,00,66,06,00,00,09,12,\ 00,00,11,00,00,00,14,00,00,00,14,00,00,00,02,00,00,00,00,00,00,80,00,fa,00,\ 00,f0,05,00,00,0e,10,00,00,11,00,00,00,14,00,00,00,14,00,00,00,05,00,00,00,\ fc,ff,ff,ff,00,fa,00,00,7a,05,00,00,09,12,00,00,11,00,00,00,14,00,00,00,14,\ 00,00,00,02,00,00,00,fc,ff,ff,ff,00,fa,00,00,04,05,00,00,0e,10,00,00,11,00,\ 00,00,14,00,00,00,14,00,00,00,05,00,00,00,ff,ff,ff,ff,00,fa,00,00,8e,04,00,\ 00,09,12,00,00,11,00,00,00,14,00,00,00,14,00,00,00,02,00,00,00,ff,ff,ff,ff,\ 00,fa,00,00,18,04,00,00,0e,10,00,00,11,00,00,00,14,00,00,00,14,00,00,00,05,\ 00,00,00,fe,ff,ff,ff,00,fa,00,00,a2,03,00,00,09,12,00,00,11,00,00,00,14,00,\ 00,00,14,00,00,00,02,00,00,00,fe,ff,ff,ff,00,fa,00,00,2c,03,00,00,0e,10,00,\ 00,11,00,00,00,14,00,00,00,14,00,00,00,05,00,00,00,f8,ff,ff,ff,00,fa,00,00,\ b6,02,00,00,09,12,00,00,11,00,00,00,14,00,00,00,14,00,00,00,02,00,00,00,f8,\ ff,ff,ff,00,fa,00,00,40,02,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\ 5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,\ 00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,\ 42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,\ 00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,\ 7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\ 00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,33,00,43,00,\ 46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,46,00,42,00,45,00,2d,00,34,\ 00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,00,2d,00,33,00,32,00,31,00,\ 34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,39,00,7d,00,00,00,5c,00,44,\ 00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\ 54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,37,00,43,00,30,00,30,00,42,00,31,\ 00,42,00,46,00,2d,00,38,00,37,00,46,00,34,00,2d,00,34,00,34,00,36,00,32,00,\ 2d,00,42,00,46,00,42,00,39,00,2d,00,43,00,35,00,41,00,38,00,42,00,43,00,34,\ 00,31,00,36,00,34,00,46,00,30,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\ 63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\ 00,70,00,5f,00,7b,00,37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,\ 38,00,37,00,46,00,34,00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,\ 00,39,00,2d,00,43,00,35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,\ 46,00,30,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,\ 39,00,45,00,30,00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,42,00,31,00,31,\ 00,2d,00,34,00,35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,00,2d,00,42,00,\ 37,00,46,00,33,00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,35,00,7d,00,00,\ 00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,\ 54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,39,00,45,00,30,00,43,\ 00,46,00,34,00,45,00,46,00,2d,00,43,00,42,00,31,00,31,00,2d,00,34,00,35,00,\ 35,00,43,00,2d,00,41,00,33,00,31,00,30,00,2d,00,42,00,37,00,46,00,33,00,38,\ 00,36,00,39,00,38,00,42,00,36,00,42,00,35,00,7d,00,00,00,5c,00,44,00,65,00,\ 76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,\ 00,70,00,69,00,70,00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,\ 33,00,2d,00,43,00,30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,\ 00,34,00,44,00,36,00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,\ 42,00,32,00,36,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,\ 00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,\ 5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,33,00,2d,00,43,00,30,\ 00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,34,00,44,00,36,00,\ 2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,42,00,32,00,36,00,41,\ 00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,\ 74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,32,00,39,\ 00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,\ 34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,\ 00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,00,\ 44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,\ 00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,\ 43,00,45,00,35,00,2d,00,31,00,41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,\ 00,2d,00,41,00,37,00,35,00,41,00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,\ 37,00,36,00,38,00,46,00,43,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\ 00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,\ 69,00,70,00,5f,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,\ 00,30,00,32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,\ 33,00,32,00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,\ 00,38,00,33,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,\ 4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,\ 00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,32,00,38,00,\ 45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,00,2d,00,32,\ 00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,33,00,7d,00,\ 00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,\ 00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,33,00,30,00,\ 30,00,44,00,31,00,30,00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,\ 00,43,00,32,00,2d,00,42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,\ 45,00,46,00,45,00,45,00,34,00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,65,\ 00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,\ 63,00,70,00,69,00,70,00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,\ 00,41,00,2d,00,33,00,39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,\ 42,00,44,00,39,00,43,00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,\ 00,34,00,33,00,39,00,43,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,\ 38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,\ 00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,\ 39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,\ 00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,38,00,\ 30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,38,00,37,00,45,00,2d,\ 00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,00,2d,00,45,00,46,00,\ 31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,39,00,7d,00,00,00,5c,\ 00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,\ 5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,\ 00,44,00,34,00,34,00,2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,\ 38,00,2d,00,39,00,31,00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,\ 00,41,00,32,00,46,00,46,00,38,00,41,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\ 69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,\ 00,69,00,70,00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,\ 2d,00,44,00,41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,\ 00,38,00,39,00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,\ 46,00,38,00,41,00,7d,00,00,00 "WinSock 2.0 Provider ID"=hex:30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,48,a1,92 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers\RMCAST] "WinSock 1.1 Provider Data"=hex:2e,04,02,00,02,00,00,00,10,00,00,00,10,00,00,\ 00,04,00,00,00,71,00,00,00,ff,ff,ff,7f,20,00,00,00,57,00,53,00,48,00,52,00,\ 4d,00,00,00 "WinSock 2.0 Provider ID"=hex:b9,9b,95,a8,51,78,4f,4e,bc,56,5b,b3,fc,79,ba,88 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip] "WinSock 2.0 Provider ID"=hex:a0,1a,0f,e7,8b,ab,cf,11,8c,a3,00,80,5f,48,a1,92 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Well Known Guids] "IsoTp"=hex:b0,cb,e4,89,c1,b9,cf,11,95,c8,00,80,5f,48,a1,92 "McsXns"=hex:b1,cb,e4,89,c1,b9,cf,11,95,c8,00,80,5f,48,a1,92 "AppleTalk"=hex:a0,17,3b,2c,df,c6,cf,11,95,c8,00,80,5f,48,a1,92 "RMCAST"=hex:b9,9b,95,a8,51,78,4f,4e,bc,56,5b,b3,fc,79,ba,88 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters] "WinSock_Registry_Version"="2.0" "Current_NameSpace_Catalog"="NameSpace_Catalog5" "Current_Protocol_Catalog"="Protocol_Catalog9" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5] "Num_Catalog_Entries"=dword:00000003 "Serial_Access_Num"=dword:00000006 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001] "LibraryPath"="%SystemRoot%\\System32\\mswsock.dll" "DisplayString"="Tcpip" "ProviderId"=hex:40,9d,05,22,9e,7e,cf,11,ae,5a,00,aa,00,a7,11,2b "SupportedNameSpace"=dword:0000000c "Enabled"=dword:00000001 "Version"=dword:00000000 "StoresServiceClassInfo"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002] "LibraryPath"="%SystemRoot%\\System32\\winrnr.dll" "DisplayString"="NTDS" "ProviderId"=hex:ee,37,26,3b,80,e5,cf,11,a5,55,00,c0,4f,d8,d4,ac "SupportedNameSpace"=dword:00000020 "Enabled"=dword:00000001 "Version"=dword:00000000 "StoresServiceClassInfo"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003] "LibraryPath"="%SystemRoot%\\System32\\mswsock.dll" "DisplayString"="Network Location Awareness (NLA) Namespace" "ProviderId"=hex:3a,24,42,66,a8,3b,a6,4a,ba,a5,2e,0b,d7,1f,dd,83 "SupportedNameSpace"=dword:0000000f "Enabled"=dword:00000001 "Version"=dword:00000000 "StoresServiceClassInfo"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9] "Num_Catalog_Entries"=dword:00000019 "Next_Catalog_Entry_ID"=dword:00000550 "Serial_Access_Num"=dword:0000003f [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,66,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,08,00,00,00,a0,1a,0f,e7,8b,ab,cf,11,8c,a3,00,80,5f,\ 48,a1,92,e9,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,02,00,00,00,10,00,00,\ 00,10,00,00,00,01,00,00,00,06,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,54,00,63,00,70,\ 00,69,00,70,00,20,00,5b,00,54,00,43,00,50,00,2f,00,49,00,50,00,5d,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,06,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,08,00,00,00,a0,1a,0f,e7,8b,ab,cf,11,8c,a3,00,80,5f,\ 48,a1,92,ea,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,02,00,00,00,10,00,00,\ 00,10,00,00,00,02,00,00,00,11,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ bb,ff,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,54,00,63,00,70,\ 00,69,00,70,00,20,00,5b,00,55,00,44,00,50,00,2f,00,49,00,50,00,5d,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,06,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,0c,00,00,00,a0,1a,0f,e7,8b,ab,cf,11,8c,a3,00,80,5f,\ 48,a1,92,eb,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,02,00,00,00,10,00,00,\ 00,10,00,00,00,03,00,00,00,00,00,00,00,ff,00,00,00,00,00,00,00,00,00,00,00,\ bb,ff,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,54,00,63,00,70,\ 00,69,00,70,00,20,00,5b,00,52,00,41,00,57,00,2f,00,49,00,50,00,5d,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,72,73,76,70,73,70,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,26,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,08,00,00,00,e0,a9,60,9d,7a,33,d0,11,bd,88,00,00,c0,\ 82,e6,9a,ec,03,00,00,01,00,00,00,00,00,00,00,00,00,00,43,3e,00,00,00,00,00,\ 00,00,03,00,00,00,5c,fb,3b,06,00,00,00,00,06,00,00,00,02,00,00,00,10,00,00,\ 00,10,00,00,00,02,00,00,00,11,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ bb,ff,00,00,00,00,00,00,52,00,53,00,56,00,50,00,20,00,55,00,44,00,50,00,20,\ 00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,\ 69,00,64,00,65,00,72,00,00,00,8a,4d,ad,01,00,00,3b,06,f4,b6,80,7c,02,00,00,\ 00,08,02,00,00,34,fb,3b,06,ac,f6,3b,06,58,fd,3b,06,4c,f9,3b,06,6c,fb,90,7c,\ 71,fb,90,7c,00,00,00,00,cc,f9,3b,06,3d,fb,90,7c,28,f9,3b,06,78,f9,3b,06,94,\ f9,3b,06,18,ee,90,7c,78,fb,90,7c,4c,fa,3b,06,f8,2c,1c,00,05,00,00,00,80,f9,\ 3b,06,51,d0,80,7c,f8,2c,1c,00,4c,fa,3b,06,00,00,00,00,4c,fa,3b,06,05,00,00,\ 00,e6,2d,fd,7f,05,00,00,00,18,2c,97,01,4c,fa,3b,06,a8,f9,3b,06,5c,00,44,00,\ 65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,\ 00,63,00,70,00,69,00,70,00,00,00,af,9f,d4,77,4c,fa,3b,06,05,00,00,00,f0,f9,\ 3b,06,4c,a5,92,77,d8,a2,92,77,18,2c,97,01,18,2c,97,01,7c,fc,3b,06,54,fa,3b,\ 06,b0,01,00,00,dc,fa,3b,06,f8,2c,1c,00,05,00,00,00,10,fa,3b,06,51,d0,80,7c,\ f8,2c,1c,00,dc,fa,3b,06,00,00,00,00,dc,fa,3b,06,05,00,00,00,e6,2d,fd,7f,05,\ 00,00,00,18,2c,97,01,dc,fa,3b,06,38,fa,3b,06,80,9c,d4,77,09,04,00,00,00,01,\ 00,00,dc,fa,3b,06,00,00,00,00,00,00,00,00,05,00,00,00,0c,fd,3b,06,18,2c,97,\ 01,48,fa,3b,06,af,9f,d4,77,dc,fa,3b,06,05,00,00,00,96,15,91,7c,eb,06,91,7c,\ 01,00,00,00,a4,fd,3b,06,96,15,91,7c,eb,06,91,7c,00,00,00,00,00,00,00,00,58,\ 00,00,00,eb,06,91,7c,01,00,00,00,a4,fd,3b,06,01,00,00,00,ff,ff,ff,ff,d8,a2,\ 92,77,08,a3,92,77,dc,fa,3b,06,d8,fa,3b,06,02,00,00,80,9c,fa,3b,06,0c,fd,3b,\ 06,b0,01,00,00,e4,fa,3b,06,ff,ff,ff,ff,e0,fc,3b,06,ab,a5,92,77,a8,79,9d,01,\ dc,fa,3b,06,88,01,1c,00,00,00,00,00,01,00,00,00,96,15,91,7c [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,72,73,76,70,73,70,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,66,20,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,08,00,00,00,e0,a9,60,9d,7a,33,d0,11,bd,88,00,00,c0,\ 82,e6,9a,ed,03,00,00,01,00,00,00,c8,fc,3b,06,1c,0b,00,00,00,00,c3,00,1d,00,\ 02,00,4c,fd,3b,06,10,48,eb,02,00,00,00,00,06,00,00,00,02,00,00,00,10,00,00,\ 00,10,00,00,00,01,00,00,00,06,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,52,00,53,00,56,00,50,00,20,00,54,00,43,00,50,00,20,\ 00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,\ 69,00,64,00,65,00,72,00,00,00,66,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,08,00,00,00,00,00,00,00,78,03,1c,00,f2,94,80,7c,00,b0,fd,7f,0c,00,00,00,\ 08,00,00,00,00,00,00,00,22,95,80,7c,18,2c,97,01,00,00,1c,00,00,00,c3,00,00,\ 00,00,00,50,bf,a2,01,5c,0d,91,7c,00,00,1c,00,91,0e,91,7c,08,06,1c,00,6d,05,\ 91,7c,a8,79,9d,01,00,00,00,00,08,00,00,00,00,00,c3,00,01,00,00,00,48,08,cf,\ 02,00,00,c3,00,58,bf,a2,01,0c,00,00,00,00,a0,fd,7f,a8,79,9d,01,88,01,1c,00,\ 00,00,00,00,18,45,e7,02,10,02,1c,00,80,21,a3,01,d8,01,1c,00,e4,fc,3b,06,10,\ 00,00,00,60,bc,e5,02,0c,00,00,00,d8,01,1c,00,6d,05,91,7c,60,00,00,00,88,01,\ 1c,00,00,00,00,00,10,00,00,00,a0,79,9d,01,08,00,00,00,00,00,00,00,61,a8,91,\ 7c,68,79,9d,01,02,00,00,00,00,00,1c,00,00,00,1c,00,c4,79,9d,01,60,00,00,00,\ 18,5d,f1,02,00,00,00,00,00,00,01,01,3d,fb,90,7c,00,00,00,00,bc,e7,90,7c,86,\ d5,90,7c,00,00,1c,00,f8,66,aa,01,00,00,00,00,5c,fd,3b,06,5c,0d,91,7c,00,00,\ 1c,00,91,0e,91,7c,08,06,1c,00,6d,05,91,7c,94,48,eb,02,00,00,00,00,48,2c,94,\ 01,00,00,c3,00,08,00,00,00,f8,66,aa,01,00,00,00,00,00,00,00,00,58,0b,00,00,\ 00,00,00,00,00,67,aa,01,00,00,00,00,00,00,00,00,00,00,00,00,58,0b,00,00,28,\ fd,3b,06,78,03,1c,00,58,0b,00,00,01,00,00,00,03,00,00,00,00,67,aa,01,78,03,\ 1c,00,94,48,eb,02,00,02,00,00,48,2c,94,01,0c,00,0e,00,3c,56,5f,75,00,00,00,\ 00,f8,fc,3b,06,48,2c,94,01,00,00,00,00,94,48,eb,02,50,fd,3b,06,6c,fb,90,7c,\ 71,fb,90,7c,94,48,eb,02,00,00,00,00,48,2c,94,01,2c,fd,3b,06 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,2e,04,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,08,00,00,00,b9,9b,95,a8,51,78,4f,4e,bc,56,5b,b3,fc,\ 79,ba,88,0a,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,02,00,00,00,10,00,00,\ 00,10,00,00,00,04,00,00,00,71,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ ff,ff,ff,7f,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,50,00,67,00,6d,\ 00,20,00,28,00,52,00,44,00,4d,00,29,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,36,04,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,08,00,00,00,b9,9b,95,a8,51,78,4f,4e,bc,56,5b,b3,fc,\ 79,ba,88,0b,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,02,00,00,00,10,00,00,\ 00,10,00,00,00,01,00,00,00,71,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,50,00,67,00,6d,\ 00,20,00,28,00,53,00,74,00,72,00,65,00,61,00,6d,00,29,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,3e,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,f7,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,00,\ 41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,39,\ 00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,00,\ 41,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,39,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,3f,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,f7,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,41,00,30,00,33,00,36,00,44,00,44,00,34,00,34,00,2d,00,44,00,\ 41,00,44,00,34,00,2d,00,34,00,44,00,42,00,38,00,2d,00,39,00,31,00,38,00,39,\ 00,2d,00,39,00,44,00,35,00,30,00,41,00,37,00,41,00,32,00,46,00,46,00,38,00,\ 41,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,39,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,40,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,fa,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,\ 38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,\ 00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,\ 39,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,36,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,41,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,fa,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,38,00,30,00,44,00,44,00,42,00,45,00,42,00,30,00,2d,00,41,00,\ 38,00,37,00,45,00,2d,00,34,00,44,00,42,00,45,00,2d,00,39,00,32,00,37,00,39,\ 00,2d,00,45,00,46,00,31,00,41,00,37,00,44,00,37,00,45,00,43,00,41,00,39,00,\ 39,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,36,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,42,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,fb,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,\ 39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,\ 00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,\ 43,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,35,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,43,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,fb,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,35,00,33,00,30,00,30,00,44,00,31,00,30,00,41,00,2d,00,33,00,\ 39,00,42,00,30,00,2d,00,34,00,36,00,43,00,32,00,2d,00,42,00,44,00,39,00,43,\ 00,2d,00,44,00,46,00,32,00,38,00,45,00,46,00,45,00,45,00,34,00,33,00,39,00,\ 43,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,35,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,44,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,fd,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,\ 32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,\ 00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,\ 33,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,33,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,45,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,fd,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,41,00,46,00,45,00,34,00,35,00,39,00,38,00,35,00,2d,00,30,00,\ 32,00,38,00,45,00,2d,00,34,00,45,00,35,00,35,00,2d,00,41,00,39,00,33,00,32,\ 00,2d,00,32,00,33,00,32,00,38,00,34,00,37,00,36,00,30,00,35,00,42,00,38,00,\ 33,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,33,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,08,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,46,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,00,00,00,80,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,\ 41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,\ 00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,\ 35,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,08,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,47,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,00,00,00,80,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,32,00,39,00,33,00,37,00,44,00,43,00,45,00,35,00,2d,00,31,00,\ 41,00,42,00,36,00,2d,00,34,00,34,00,35,00,34,00,2d,00,41,00,37,00,35,00,41,\ 00,2d,00,33,00,34,00,37,00,35,00,36,00,34,00,37,00,36,00,38,00,46,00,43,00,\ 35,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,48,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,fc,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,33,00,2d,00,43,00,\ 30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,34,00,44,00,36,\ 00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,42,00,32,00,36,00,\ 41,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,34,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,49,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,fc,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,39,00,31,00,44,00,39,00,42,00,37,00,30,00,33,00,2d,00,43,00,\ 30,00,36,00,46,00,2d,00,34,00,32,00,44,00,41,00,2d,00,39,00,34,00,44,00,36,\ 00,2d,00,44,00,41,00,43,00,35,00,42,00,33,00,34,00,44,00,42,00,32,00,36,00,\ 41,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,34,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,4a,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,39,00,45,00,30,00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,\ 42,00,31,00,31,00,2d,00,34,00,35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,\ 00,2d,00,42,00,37,00,46,00,33,00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,\ 35,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,31,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,4b,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,39,00,45,00,30,00,43,00,46,00,34,00,45,00,46,00,2d,00,43,00,\ 42,00,31,00,31,00,2d,00,34,00,35,00,35,00,43,00,2d,00,41,00,33,00,31,00,30,\ 00,2d,00,42,00,37,00,46,00,33,00,38,00,36,00,39,00,38,00,42,00,36,00,42,00,\ 35,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,31,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000022] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,4c,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,fe,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,38,00,\ 37,00,46,00,34,00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,00,39,\ 00,2d,00,43,00,35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,46,00,\ 30,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,32,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000023] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,4d,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,fe,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,37,00,43,00,30,00,30,00,42,00,31,00,42,00,46,00,2d,00,38,00,\ 37,00,46,00,34,00,2d,00,34,00,34,00,36,00,32,00,2d,00,42,00,46,00,42,00,39,\ 00,2d,00,43,00,35,00,41,00,38,00,42,00,43,00,34,00,31,00,36,00,34,00,46,00,\ 30,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,32,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000024] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,00,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,4e,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,05,00,00,00,f8,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,\ 46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,\ 00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,\ 39,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\ 00,20,00,38,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000025] "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,09,02,02,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\ 48,a1,92,4f,05,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\ 00,14,00,00,00,02,00,00,00,f8,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\ 00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\ 65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\ 00,5f,00,7b,00,33,00,43,00,46,00,39,00,30,00,42,00,37,00,45,00,2d,00,36,00,\ 46,00,42,00,45,00,2d,00,34,00,32,00,43,00,46,00,2d,00,42,00,34,00,38,00,44,\ 00,2d,00,33,00,32,00,31,00,34,00,43,00,36,00,41,00,38,00,33,00,33,00,32,00,\ 39,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\ 00,38,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinTrust] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1] "$DLL"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,\ 73,00,53,00,69,00,70,00,31,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2] "$DLL"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,\ 73,00,53,00,69,00,70,00,32,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3] "$DLL"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,\ 73,00,53,00,69,00,70,00,33,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinTrust\TrustProviders] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinTrust\TrustProviders\Software Publisher] "$DLL"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,53,00,\ 6f,00,66,00,74,00,50,00,75,00,62,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSN] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Portable Media Serial Number Service" "ObjectName"="LocalSystem" "Description"="Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSN\Parameters] "ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,73,00,\ 50,00,4d,00,53,00,4e,00,53,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmdmPmSN\Security] "Security"=hex:01,00,14,80,a4,00,00,00,b0,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,74,00,05,00,00,00,00,00,14,00,10,00,00,00,01,01,00,00,00,00,00,\ 05,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\ 00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\ 00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\ 02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wmi] "Description"="Provides systems management information to and from drivers." "DisplayName"="Windows Management Instrumentation Driver Extensions" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wmi\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,64,00,76,00,61,00,70,00,69,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceMain"="WdmWmiServiceMain" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wmi\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiAcpi] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000003 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,6d,00,69,00,61,00,63,00,70,\ 00,69,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Windows Management Interface for ACPI" "Group"="Extended Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiAcpi\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiAcpi\Enum] "0"="ACPI\\PNP0C14\\0" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiApRpl] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance] "Library"="C:\\WINDOWS\\system32\\wbem\\wmiaprpl.dll" "Open"="WmiOpenPerfData" "Collect"="WmiCollectPerfData" "Close"="WmiClosePerfData" "Last Counter"=dword:00002666 "Last Help"=dword:00002667 "First Counter"=dword:0000264e "First Help"=dword:0000264f "Object List"="9806 9812 9824" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiApSrv] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,62,00,65,\ 00,6d,00,5c,00,77,00,6d,00,69,00,61,00,70,00,73,00,72,00,76,00,2e,00,65,00,\ 78,00,65,00,00,00 "DisplayName"="WMI Performance Adapter" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides performance library information from WMI HiPerf providers." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiApSrv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WMPNetworkSvc] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,57,00,69,00,6e,00,64,00,6f,\ 00,77,00,73,00,20,00,4d,00,65,00,64,00,69,00,61,00,20,00,50,00,6c,00,61,00,\ 79,00,65,00,72,00,5c,00,57,00,4d,00,50,00,4e,00,65,00,74,00,77,00,6b,00,2e,\ 00,65,00,78,00,65,00,22,00,00,00 "DisplayName"="Windows Media Player Network Sharing Service" "DependOnService"=hex(7):75,00,70,00,6e,00,70,00,68,00,6f,00,73,00,74,00,00,00,\ 68,00,74,00,74,00,70,00,00,00,48,00,54,00,54,00,50,00,46,00,69,00,6c,00,74,\ 00,65,00,72,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play" "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,00,00,00,\ 00,01,00,00,00,30,75,00,00,01,00,00,00,30,75,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WMPNetworkSvc\Security] "Security"=hex:01,00,14,80,a4,00,00,00,b0,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,74,00,05,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,\ 14,00,9d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WpdUsb] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000001e "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,70,00,64,00,75,00,73,00,62,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="WpdUsb" "Group"="Base" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WpdUsb\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WS2IFSL] "Start"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Security Center" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,77,00,69,00,6e,00,\ 6d,00,67,00,6d,00,74,00,00,00,00,00 "ObjectName"="LocalSystem" "Description"="Monitors system security settings and configurations." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,59,00,53,00,54,00,45,00,4d,00,52,00,4f,00,4f,\ 00,54,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,73,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Enum] "0"="Root\\LEGACY_WSCSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Automatic Updates" "ObjectName"="LocalSystem" "Description"="Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters] "ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,75,00,\ 61,00,75,00,73,00,65,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security] "Security"=hex:01,00,14,80,78,00,00,00,84,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,00,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,48,00,03,00,00,00,00,00,14,00,9d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\ 01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum] "0"="Root\\LEGACY_WUAUSERV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfPf] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000013 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Windows Driver Foundation - User-mode Driver Framework Platform Driver" "Group"="base" "Description"="Provide communciation services for UMDF components." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfPf\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfPf\Enum] "0"="Root\\LEGACY_WUDFPF\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfRd] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Windows Driver Foundation - User-mode Driver Framework Reflector" "Description"="Reflect device requests to user-mode driver drivers" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfRd\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfRd\Enum] "0"="Root\\WPD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfSvc] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\ 00,47,00,72,00,6f,00,75,00,70,00,00,00 "DisplayName"="Windows Driver Foundation - User-mode Driver Framework" "Group"="PlugPlay" "DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\ 00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages user-mode driver host processes" "FailureActions"=hex:84,03,00,00,00,00,00,00,00,00,00,00,03,00,00,00,53,00,65,\ 00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00 "ServiceSidType"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WudfSvc\Enum] "0"="Root\\LEGACY_WUDFSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WZCSVC] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Wireless Zero Configuration" "Group"="TDI" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,4e,00,64,00,69,00,\ 73,00,75,00,69,00,6f,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Provides automatic configuration for the 802.11 adapters" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WZCSVC\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,7a,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceMain"="WZCSvcMain" "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WZCSVC\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WZCSVC\Enum] "0"="Root\\LEGACY_WZCSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Manages XML configuration files on a domain basis for automatic network provisioning." "DisplayName"="Network Provisioning Service" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 78,00,6d,00,6c,00,70,00,72,00,6f,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Branding] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Branding\http://www.microsoft.com/provisioning/Branding] "QueryAlias"="branding" "SchemaFile"="branding.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Connection] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Connection\http://www.microsoft.com/provisioning/BaseEapConnectionPropertiesV1] "QueryAlias"="baseeapconnectionpropertiesv1" "SchemaFile"="baseeapconnectionpropertiesv1.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Connection\http://www.microsoft.com/provisioning/EapConnectionPropertiesV1] "QueryAlias"="eapconnectionpropertiesv1" "SchemaFile"="eapconnectionpropertiesv1.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Connection\http://www.microsoft.com/provisioning/MsChapV2ConnectionPropertiesV1] "QueryAlias"="mschapv2connectionpropertiesv1" "SchemaFile"="mschapv2connectionpropertiesv1.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Connection\http://www.microsoft.com/provisioning/MsPeapConnectionPropertiesV1] "QueryAlias"="mspeapconnectionpropertiesv1" "SchemaFile"="mspeapconnectionpropertiesv1.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Help] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Help\http://www.microsoft.com/provisioning/Help] "QueryAlias"="help" "SchemaFile"="help.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Locations] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Locations\http://www.microsoft.com/provisioning/Locations] "QueryAlias"="locations" "SchemaFile"="locations.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Master] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Master\http://www.microsoft.com/provisioning/Master] "QueryAlias"="master" "SchemaFile"="masterfile.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Register] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\Register\http://www.microsoft.com/provisioning/Register] "QueryAlias"="register" "SchemaFile"="register.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\SSID] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\SSID\http://www.microsoft.com/provisioning/SSID] "QueryAlias"="ssid" "SchemaFile"="ssid.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\User] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\User\http://www.microsoft.com/provisioning/BaseEapUserPropertiesV1] "QueryAlias"="baseeapuserpropertiesv1" "SchemaFile"="baseeapuserpropertiesv1.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\User\http://www.microsoft.com/provisioning/EapUserPropertiesV1] "QueryAlias"="eapuserpropertiesv1" "SchemaFile"="eapuserpropertiesv1.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\User\http://www.microsoft.com/provisioning/MsChapV2UserPropertiesV1] "QueryAlias"="mschapv2userpropertiesv1" "SchemaFile"="mschapv2userpropertiesv1.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\User\http://www.microsoft.com/provisioning/MsPeapUserPropertiesV1] "QueryAlias"="mspeapuserpropertiesv1" "SchemaFile"="mspeapuserpropertiesv1.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\WirelessProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters\SchemaGroups\WirelessProfile\http://www.microsoft.com/provisioning/WirelessProfile] "QueryAlias"="wirelessprofile" "SchemaFile"="wirelessprofile.xdr" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTEusbmdm6k] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,5a,00,54,00,45,00,75,00,73,00,62,\ 00,6d,00,64,00,6d,00,36,00,6b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ZTE Proprietary USB Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTEusbmdm6k\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTEusbnet] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:00000015 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,5a,00,54,00,45,00,75,00,73,00,62,\ 00,6e,00,65,00,74,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ZTE USB-NDIS miniport" "Group"="NDIS" "TextModeFlags"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTEusbnet\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTEusbnmea] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,5a,00,54,00,45,00,75,00,73,00,62,\ 00,6e,00,6d,00,65,00,61,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ZTE NMEA Port" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTEusbnmea\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTEusbser6k] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,5a,00,54,00,45,00,75,00,73,00,62,\ 00,73,00,65,00,72,00,36,00,6b,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ZTE Diagnostic Port" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZTEusbser6k\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{2937DCE5-1AB6-4454-A75A-347564768FC5}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{2937DCE5-1AB6-4454-A75A-347564768FC5}\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{2937DCE5-1AB6-4454-A75A-347564768FC5}\Parameters\Tcpip] "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DhcpIPAddress"="130.89.145.113" "DhcpSubnetMask"="255.255.255.0" "DhcpServer"="130.89.1.145" "Lease"=dword:00001c20 "LeaseObtainedTime"=dword:4c1b2ae4 "T1"=dword:4c1b38f4 "T2"=dword:4c1b4380 "LeaseTerminatesTime"=dword:4c1b4704 "DhcpDefaultGateway"=hex(7):31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,31,00,34,\ 00,35,00,2e,00,31,00,00,00,00,00 "DhcpSubnetMaskOpt"=hex(7):32,00,35,00,35,00,2e,00,32,00,35,00,35,00,2e,00,32,\ 00,35,00,35,00,2e,00,30,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{3CF90B7E-6FBE-42CF-B48D-3214C6A83329}\Parameters\Tcpip] "EnableDHCP"=dword:00000000 "IPAddress"=hex(7):31,00,39,00,32,00,2e,00,31,00,36,00,38,00,2e,00,35,00,36,00,\ 2e,00,31,00,00,00,00,00 "SubnetMask"=hex(7):32,00,35,00,35,00,2e,00,32,00,35,00,35,00,2e,00,32,00,35,\ 00,35,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DhcpIPAddress"="0.0.0.0" "DhcpSubnetMask"="255.0.0.0" "DhcpServer"="255.255.255.255" "Lease"=dword:00000e10 "LeaseObtainedTime"=dword:4ad5c588 "T1"=dword:4ad5cc90 "T2"=dword:4ad5d1d6 "LeaseTerminatesTime"=dword:4ad5d398 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{5300D10A-39B0-46C2-BD9C-DF28EFEE439C}\Parameters\Tcpip] "EnableDHCP"=dword:00000000 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DhcpIPAddress"="0.0.0.0" "DhcpSubnetMask"="255.0.0.0" "DhcpServer"="255.255.255.255" "Lease"=dword:00000e10 "LeaseObtainedTime"=dword:48c8df4d "T1"=dword:48c8e655 "T2"=dword:48c8eb9b "LeaseTerminatesTime"=dword:48c8ed5d [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{80DDBEB0-A87E-4DBE-9279-EF1A7D7ECA99}\Parameters\Tcpip] "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DhcpIPAddress"="169.254.172.68" "DhcpSubnetMask"="255.255.0.0" "DhcpServer"="255.255.255.255" "Lease"=dword:00000000 "LeaseObtainedTime"=dword:4ac1aed8 "T1"=dword:4ac1aed8 "T2"=dword:4ac1aed8 "LeaseTerminatesTime"=dword:7fffffff [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{91D9B703-C06F-42DA-94D6-DAC5B34DB26A}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{91D9B703-C06F-42DA-94D6-DAC5B34DB26A}\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{91D9B703-C06F-42DA-94D6-DAC5B34DB26A}\Parameters\Tcpip] "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{A036DD44-DAD4-4DB8-9189-9D50A7A2FF8A}\Parameters\Tcpip] "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DhcpIPAddress"="10.7.10.195" "DhcpSubnetMask"="255.255.255.248" "DhcpServer"="10.7.10.193" "Lease"=dword:00001c20 "LeaseObtainedTime"=dword:4ba2622d "T1"=dword:4ba2703d "T2"=dword:4ba27ac9 "LeaseTerminatesTime"=dword:4ba27e4d [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{AFE45985-028E-4E55-A932-232847605B83}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{AFE45985-028E-4E55-A932-232847605B83}\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{AFE45985-028E-4E55-A932-232847605B83}\Parameters\Tcpip] "EnableDHCP"=dword:00000001 "IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00 "DefaultGateway"=hex(7):00,00 "DhcpIPAddress"="130.89.239.203" "DhcpSubnetMask"="255.255.240.0" "DhcpServer"="1.1.1.1" "Lease"=dword:00000708 "LeaseObtainedTime"=dword:4c1b2af1 "T1"=dword:4c1b2e75 "T2"=dword:4c1b3118 "LeaseTerminatesTime"=dword:4c1b31f9 "DhcpDefaultGateway"=hex(7):31,00,33,00,30,00,2e,00,38,00,39,00,2e,00,32,00,32,\ 00,34,00,2e,00,31,00,00,00,00,00 "DhcpSubnetMaskOpt"=hex(7):32,00,35,00,35,00,2e,00,32,00,35,00,35,00,2e,00,32,\ 00,34,00,30,00,2e,00,30,00,00,00,00,00