|
hi i have written many paragraphd before..only to have it dissapear before posting...
so i will be brief
i have major takeover probs for the last 15 months..serious crackers or ..."enemie" have used remoe/messenger.windows media etc atc, and are able to gain access to, and make my computer a limited account on some ?? sever..which captures all info and is msking me frustated (15 months
here is a copy of SD backup systems..which I have not touched, and should be in default mode....but I think not
please give me some feedback
ty
sirpkralot
aka john
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Abiosdsk] "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000004 "Tag"=dword:00000003 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000038 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5\Parameters\PnpInterface] "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPI] "ErrorControl"=dword:00000001 "Group"="Boot Bus Extender" "Start"=dword:00000000 "Tag"=dword:00000001 "Type"=dword:00000001 "DisplayName"="Microsoft ACPI Driver" "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,43,00,50,00,49,00,2e,00,73,\ 00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPI\Enum] "0"="ACPI_HAL\\PNP0C08\\0" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPIEC] "ErrorControl"=dword:00000001 "Group"="Boot Bus Extender" "Start"=dword:00000004 "Tag"=dword:00000005 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003c "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m\Parameters\PnpInterface] "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aec] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,65,00,63,00,2e,00,73,00,79,\ 00,73,00,00,00 "DisplayName"="Microsoft Kernel Acoustic Echo Canceller"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aec\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,66,00,64,00,2e,00,73,00,79,00,\ 73,00,00,00 "DisplayName"="AFD Networking Support Environment" "Group"="TDI"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD\Enum] "0"="Root\\LEGACY_AFD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,67,00,70,00,34,00,34,00,30,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Intel AGP Bus Filter" "Group"="PnP Filter"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440\Enum] "0"="PCI\\VEN_8086&DEV_1A31&SUBSYS_00000000&REV_04\\3&13c0b0c5&0&08" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000006 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x\Parameters] "LegacyAdapterDetection"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x\Parameters\PnpInterface] "1"=dword:00000001 "3"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000034 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2\Parameters\PnpInterface] "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000001e "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx\Parameters\PnpInterface] "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,\ 00,6c,00,67,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="Application Layer Gateway Service" "ObjectName"="NT AUTHORITY\\LocalService" "Description"="Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG\Enum] "0"="Root\\LEGACY_ALG\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AliIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000004 "Tag"=dword:00000004 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000024 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint\Parameters\PnpInterface] "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt] "Description"="Provides software installation services such as Assign, Publish, and Remove." "DisplayName"="Application Management" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000020
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,00,00,\ 00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000029 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc\Parameters\PnpInterface] "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000039 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p\Parameters\PnpInterface] "1"=dword:00000011
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000002a "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550\Parameters\PnpInterface] "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AsyncMac] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,73,00,79,00,6e,00,63,00,6d,\ 00,61,00,63,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="RAS Asynchronous Media Driver" "Description"="RAS Asynchronous Media Driver"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AsyncMac\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000000 "Tag"=dword:00000019 "Type"=dword:00000001 "DisplayName"="Standard IDE/ESDI Hard Disk Controller" "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,61,00,70,00,69,00,2e,\ 00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi\Parameters] "LegacyDetection"=dword:00000001 "GhostSlave"=hex(7):53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,00,00,00,\ 00 "UseCheckPowerForFlush"=hex(7):53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,20,00,\ 57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,41,00,20,00,28,00,31,\ 00,36,00,30,00,30,00,4d,00,42,00,29,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,41,00,4d,00,53,00,55,\ 00,4e,00,47,00,20,00,57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,\ 41,00,20,00,28,00,31,00,2e,00,36,00,47,00,42,00,29,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,49,00,\ 42,00,4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,54,00,43,00,36,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,\ 4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,54,00,43,00,36,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,\ 2d,00,44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,\ 00,4c,00,38,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,\ 44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,\ 00,38,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,\ 50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,38,\ 00,49,00,41,00,41,00,34,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,\ 43,00,41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,4f,\ 00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,43,00,\ 41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,49,00,41,\ 00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,\ 2d,00,32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,4f,00,41,00,41,\ 00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,2d,00,\ 32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,49,00,41,00,41,00,32,\ 00,41,00,00,00,00,00 "NoFlushDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,5f,00,4c,00,\ 50,00,53,00,35,00,32,00,35,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,43,00,52,00,2d,00,37,00,33,\ 00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00 "PioOnlyDevice"=hex(7):20,00,20,00,20,00,20,00,43,00,6f,00,6e,00,6e,00,65,00,\ 72,00,20,00,50,00,65,00,72,00,69,00,70,00,68,00,65,00,72,00,61,00,6c,00,73,\ 00,20,00,34,00,32,00,35,00,4d,00,42,00,20,00,2d,00,20,00,43,00,46,00,53,00,\ 34,00,32,00,35,00,41,00,20,00,20,00,00,00,4d,00,41,00,54,00,53,00,48,00,49,\ 00,54,00,41,00,20,00,43,00,52,00,2d,00,35,00,38,00,31,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,46,00,58,00,\ 36,00,30,00,30,00,53,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,00,00,43,00,44,00,2d,00,34,00,34,00,45,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,\ 00,54,00,52,00,42,00,38,00,35,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,\ 54,00,55,00,4d,00,20,00,4d,00,41,00,52,00,56,00,45,00,52,00,49,00,43,00,4b,\ 00,20,00,35,00,34,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,20,\ 00,4d,00,41,00,58,00,54,00,4f,00,52,00,20,00,4d,00,58,00,54,00,2d,00,35,00,\ 34,00,30,00,20,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,31,00,32,\ 00,36,00,30,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,\ 20,00,37,00,38,00,35,00,30,00,20,00,41,00,56,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,\ 00,74,00,6f,00,72,00,20,00,37,00,35,00,34,00,30,00,20,00,41,00,56,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,33,00,20,\ 00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,\ 33,00,34,00,35,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,\ 00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,41,00,54,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,\ 61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,\ 31,00,41,00,55,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,\ 00,37,00,31,00,37,00,31,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,44,00,2d,00,\ 33,00,31,00,36,00,45,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,\ 00,53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,5f,00,53,00,43,00,52,00,2d,00,\ 32,00,34,00,33,00,30,00,00,00,43,00,52,00,2d,00,32,00,38,00,30,00,31,00,54,\ 00,45,00,00,00,00,00 "NonRemovableMedia"=hex(7):4b,00,69,00,6e,00,67,00,73,00,74,00,6f,00,6e,00,20,\ 00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,79,00,20,00,44,00,\ 61,00,74,00,61,00,50,00,61,00,6b,00,20,00,33,00,34,00,30,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,\ 73,00,6b,00,20,00,53,00,44,00,50,00,35,00,41,00,2d,00,31,00,30,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,\ 00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,\ 31,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,\ 00,33,00,42,00,2d,00,32,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,\ 20,00,53,00,44,00,50,00,33,00,42,00,2d,00,31,00,37,00,35,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,\ 00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,35,00,2d,00,32,00,2e,00,35,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,\ 43,00,61,00,6c,00,6c,00,75,00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,\ 00,6f,00,6c,00,6f,00,67,00,79,00,20,00,43,00,54,00,32,00,36,00,30,00,4d,00,\ 43,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,00,00,42,00,4e,00,2d,00,53,00,30,00,30,00,34,00,41,00,43,00,\ 2d,00,53,00,20,00,31,00,2e,00,30,00,30,00,00,00,43,00,61,00,6c,00,6c,00,75,\ 00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,\ 79,00,20,00,43,00,54,00,35,00,32,00,30,00,52,00,4d,00,00,00,48,00,69,00,74,\ 00,61,00,63,00,68,00,69,00,20,00,43,00,56,00,20,00,35,00,2e,00,31,00,2e,00,\ 31,00,00,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,41,00,5f,00,46,\ 00,4c,00,41,00,53,00,48,00,20,00,00,00,4d,00,69,00,74,00,73,00,75,00,62,00,\ 69,00,73,00,68,00,69,00,20,00,41,00,54,00,41,00,20,00,43,00,61,00,72,00,64,\ 00,20,00,00,00,4c,00,45,00,58,00,41,00,52,00,20,00,41,00,54,00,41,00,5f,00,\ 46,00,4c,00,41,00,53,00,48,00,00,00,4d,00,69,00,63,00,72,00,6f,00,6e,00,20,\ 00,4d,00,54,00,43,00,46,00,30,00,30,00,34,00,41,00,00,00,4d,00,69,00,63,00,\ 72,00,6f,00,6e,00,20,00,4d,00,54,00,43,00,46,00,30,00,30,00,38,00,41,00,00,\ 00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,33,00,\ 42,00,2d,00,31,00,31,00,30,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,\ 00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,34,00,00,00,42,00,4e,00,2d,00,\ 43,00,41,00,42,00,2d,00,54,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,\ 00,54,00,49,00,43,00,4b,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,00,\ 54,00,49,00,43,00,4b,00,20,00,20,00,20,00,38,00,4d,00,20,00,20,00,38,00,4b,\ 00,00,00,00,00 "NoPowerDownDevice"=hex(7):52,00,44,00,2d,00,44,00,52,00,43,00,30,00,30,00,31,\ 00,2d,00,4d,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,53,00,2d,00,52,00,33,00,\ 37,00,20,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00 "AutoEjectZipDevice"=hex(7):49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,\ 00,49,00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,20,00,32,00,33,00,2e,00,44,00,20,00,20,00,\ 20,00,20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,\ 00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,20,00,32,00,31,00,2e,00,44,00,20,00,20,00,20,00,\ 20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,\ 00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,\ 54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,20,00,32,00,30,00,2e,00,44,00,20,00,20,00,20,00,20,00,\ 00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,\ 00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,\ 41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,20,00,39,00,31,00,2e,00,44,00,20,00,20,00,20,00,20,00,00,00,\ 49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,\ 00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,20,00,42,00,2e,00,32,00,39,00,20,00,20,00,20,00,20,00,00,00,49,00,\ 4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,00,30,\ 00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\ 20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\ 00,20,00,42,00,2e,00,32,00,32,00,20,00,20,00,20,00,20,00,00,00,00,00 "NeedIdentDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,00,46,00,\ 49,00,52,00,45,00,42,00,41,00,4c,00,4c,00,00,00,00,00 "DefaultPioAtapiDevice"=hex(7):54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,\ 44,00,56,00,44,00,2d,00,52,00,4f,00,4d,00,20,00,44,00,52,00,44,00,2d,00,4e,\ 00,32,00,31,00,36,00,00,00,49,00,44,00,45,00,2d,00,43,00,44,00,20,00,52,00,\ 2f,00,52,00,57,00,20,00,32,00,78,00,32,00,78,00,32,00,34,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi\Enum] "0"="PCIIDE\\IDEChannel\\4&e3ec092&0&0" "Count"=dword:00000002 "NextInstance"=dword:00000002 "1"="PCIIDE\\IDEChannel\\4&e3ec092&0&1"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atdisk] "ErrorControl"=dword:00000000 "Group"="Primary disk" "Start"=dword:00000004 "Tag"=dword:00000001 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atmarpc] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "Tag"=dword:0000000b "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,6d,00,61,00,72,00,70,\ 00,63,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="ATM ARP Client Protocol" "Group"="NDIS" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "Description"="ATM ARP Client Protocol"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atmarpc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv] "DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\ 52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Windows Audio" "ErrorControl"=dword:00000001 "Group"="AudioGroup" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 61,00,75,00,64,00,69,00,6f,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,\ 00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv\Enum] "0"="Root\\LEGACY_AUDIOSRV\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,75,00,64,00,73,00,74,00,75,\ 00,62,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Audio Stub Driver"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub\Enum] "0"="Root\\MEDIA\\MS_MMACM" "Count"=dword:00000005 "NextInstance"=dword:00000005 "1"="Root\\MEDIA\\MS_MMDRV" "2"="Root\\MEDIA\\MS_MMMCI" "3"="Root\\MEDIA\\MS_MMVCD" "4"="Root\\MEDIA\\MS_MMVID"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt] "Type"=dword:00000110 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\ 31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\ 00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,61,00,6d,00,73,00,\ 76,00,72,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="AVG7 Alert Manager Server" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt\Enum] "0"="Root\\LEGACY_AVG7ALRT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000001 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,63,00,6f,00,\ 72,00,65,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AVG7 Kernel" "Group"="AVG"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Parameters] "AvgDir"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\" "AvgLng"=dword:00000001 "TempDir"="C:\\DOCUME~1\\ALLUSE~1\\APPLIC~1\\Grisoft\\Avg7Data\\"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Enum] "0"="Root\\LEGACY_AVG7CORE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000002 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,72,00,73,00,\ 77,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AVG7 Wrap Driver" "Group"="AVG"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW\Enum] "0"="Root\\LEGACY_AVG7RSW\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP] "Type"=dword:00000001 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000003 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,72,00,73,00,\ 78,00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AVG7 Resident Driver XP" "Group"="AVG"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Parameters] "Params"=dword:0005c007 "IgnoreFilesystem"=dword:000000c0 "Extensions"=hex:36,69,c4,8b,53,68,0c,c8,f7,fa,2a,09,15,f2,ab,88,44,3a,ca,67,\ e6,cf,eb,95,e5,93,34,f4,36,6a,c4,8b,53,3c,4d,8a,28,33,ed,c5,ca,2d,74,57,44,\ 74,83,55,39,40,67,0b,3a,4c,eb,2b,36,3a,89,c9,8c,b7,d3,17,f7,ec,32,1a,ca,62,\ 3b,15,9b,e5,15,c8,e6,9f,b8,d4,3a,01,a3,68,e9,b5,1b,54,53,68,0c,c8,f7,ad,7e,\ 59,15,f2,ab,88,44,3a,ca,17,b5,de,f4,97,e5,93,34,f4,36,6a,c4,8b,53,2c,41,8b,\ 28,33,ed,c5,ca,2d,74,57,44,77,84,54,39,40,67,0b,3a,4c,eb,2b,36,27,8b,c8,8c,\ b7,d3,17,f7,ec,32,1a,ca,61,24,14,9b,e5,15,c8,e6,9f,b8,d4,3a,1a,ae,6f,e9,b5,\ 1b,54,53,68,0c,c8,f7,a0,7e,5e,15,f2,ab,88,44,3a,ca,17,e6,9f,f7,90,3a,4c,34,\ f4,36,6a,c4,8b,53,3e,5e,8c,28,33,ed,c5,ca,2d,74,57,44,76,87,52,39,40,67,0b,\ 3a,4c,eb,2b,36,2f,9c,ce,8c,b7,d3,17,f7,ec,32,1a,ca,6b,3d,10,9b,e5,15,c8,e6,\ 9f,b8,d4,3a,1c,a7,63,e9,b5,1b,54,53,68,0c,c8,f7,ec,66,52,ca,2d,ab,88,44,3a,\ ca,17,e6,d6,f6,9d,e5,93,34,f4,36,6a,c4,8b,14,2d,5c,82,28,33,ed,c5,ca,2d,74,\ 57,44,7d,9a,5d,39,40,67,0b,3a,4c,eb,2b,36,6a,97,c1,53,68,d3,17,f7,ec,32,1a,\ ca,66,3a,1b,9b,e5,15,c8,e6,9f,b8,d4,3a,4c,af,66,36,6a,1b,54,53,68,0c,c8,f7,\ ab,61,57,15,f2,ab,88,44,3a,ca,17,e6,cc,ef,9a,e5,93,34,f4,36,6a,c4,8b,53,30,\ 4f,87,28,33,ed,c5,ca,2d,74,57,44,3a,9c,58,e6,9f,67,0b,3a,4c,eb,2b,36,32,87,\ db,8c,b7,d3,17,f7,ec,32,1a,ca,60,33,07,9b,e5,15,c8,e6,9f,b8,d4,3a,1c,a3,7b,\ 36,b5,1b,54,53,68,0c,c8,f7,aa,7b,4a,15,f2,ab,88,44,3a,ca,17,e6,9f,f4,84,3a,\ 4c,34,f4,36,6a,c4,8b,53,2f,42,98,28,33,ed,c5,ca,2d,74,57,44,6e,85,47,39,40,\ 67,0b,3a,4c,eb,2b,36,6a,94,db,53,68,d3,17,f7,ec,32,1a,ca,7f,37,04,9b,e5,15,\ c8,e6,9f,b8,d4,3a,1f,a3,78,e9,b5,1b,54,53,68,0c,c8,f7,a1,7f,49,15,f2,ab,88,\ 44,3a,ca,17,e6,cc,e1,87,e5,93,34,f4,36,6a,c4,8b,53,2e,45,9c,28,33,ed,c5,ca,\ 2d,74,57,44,7f,88,41,39,40,67,0b,3a,4c,eb,2b,36,39,86,dd,8c,b7,d3,17,f7,ec,\ 32,1a,ca,75,36,01,9b,e5,15,c8,e6,9f,b8,d4,3a,08,b3,7d,e9,b5,1b,54,53,68,0c,\ c8,f7,aa,7f,4d,15,f2,ab,88,44,3a,ca,17,e6,9f,f4,8c,3a,4c,34,f4,36,6a,c4,8b,\ 53,24,41,90,28,33,ed,c5,ca,2d,74,57,44,3a,86,4d,e6,9f,67,0b,3a,4c,eb,2b,c9,\ 95,3b,74,53,68,0c,c8,f7,ec,32,1a,35,d2,8b,a8,44,3a,ca,17,e6,9f,b8,d4,c5,b3,\ 14,d4,36,6a,c4,8b,53,68,0c,c8,08,13,cd,e5,ca,2d,74,57,44,3a,ca,17,19,60,47,\ 2b,3a,4c,eb,2b,36,6a,c4,8b,ac,97,f3,37,f7,ec,32,1a,ca,2d,74,57,bb,c5,35,e8,\ e6,9f,b8,d4,3a,4c,eb,2b,c9,95,3b,74,53,68,0c,c8,f7,ec,32,1a,35,d2,8b,a8,44,\ 3a,ca,17,e6,9f,b8,d4,c5,b3,14,d4,36,6a,c4,8b,53,68,0c,c8,08,13,cd,e5,ca,2d,\ 74,57,44,3a,ca,17,0b,6d
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Enum] "0"="Root\\LEGACY_AVG7RSXP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc] "Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\ 31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\ 00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,75,00,70,00,73,00,\ 76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "DisplayName"="AVG7 Update Service" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc\Enum] "0"="Root\\LEGACY_AVG7UPDSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS] "Type"=dword:00000110 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\ 31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\ 00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,65,00,6d,00,63,00,\ 2e,00,65,00,78,00,65,00,00,00 "DisplayName"="AVG E-mail Scanner" "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS\Enum] "0"="Root\\LEGACY_AVGEMS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi] "Type"=dword:00000001 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,74,00,64,00,69,00,\ 2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AVG Network Redirector"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi\Enum] "0"="Root\\LEGACY_AVGTDI\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BattC] "MofImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,\ 00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,62,00,61,00,74,00,74,00,63,00,\ 2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Beep] "ErrorControl"=dword:00000001 "Group"="Base" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Beep\Enum] "0"="Root\\LEGACY_BEEP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS] "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Background Intelligent Transfer Service" "DependOnService"=hex(7):52,00,70,00,63,00,73,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Uses idle network bandwidth to transfer data."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 71,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Enum] "0"="Root\\LEGACY_BITS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000019 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k\Parameters\PnpInterface] "1"=dword:00000001 "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003a "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt\Parameters\PnpInterface] "1"=dword:00000011
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdaudio] "ErrorControl"=dword:00000000 "Group"="Filter" "Start"=dword:00000001 "Tag"=dword:00000006 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdaudio\Enum] "Count"=dword:00000000 "NextInstance"=dword:00000000 "INITSTARTFAILED"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdfs] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,43,00,44,00,52,00,4f,00,\ 4d,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="File system" "Start"=dword:00000004 "Type"=dword:00000002
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdfs\Enum] "0"="Root\\LEGACY_CDFS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdrom] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\ 70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="SCSI CDROM Class" "Start"=dword:00000001 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="CD-ROM Driver" "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,63,00,64,00,72,00,6f,00,6d,00,2e,\ 00,73,00,79,00,73,00,00,00 "AutoRun"=dword:00000001 "AutoRunAlwaysDisable"=hex(7):4e,00,45,00,43,00,20,00,20,00,20,00,20,00,20,00,\ 4d,00,42,00,52,00,2d,00,37,00,20,00,20,00,20,00,00,00,4e,00,45,00,43,00,20,\ 00,20,00,20,00,20,00,20,00,4d,00,42,00,52,00,2d,00,37,00,2e,00,34,00,20,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,48,00,41,00,4e,\ 00,47,00,52,00,20,00,44,00,52,00,4d,00,2d,00,31,00,38,00,30,00,34,00,58,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,33,00,32,00,34,00,58,00,\ 00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,32,00,34,00,58,00,20,00,\ 00,00,54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,43,00,44,00,2d,00,52,\ 00,4f,00,4d,00,20,00,43,00,44,00,52,00,5f,00,43,00,33,00,36,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdrom\Enum] "0"="IDE\\CdRomLG_CD-ROM_CRD-8521B_____________________2.00____\\5&3494138e&0&0.1.0" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Changer] "ErrorControl"=dword:00000000 "Group"="Filter" "Start"=dword:00000001 "Tag"=dword:00000005 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CiSvc] "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Description"="Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language." "DisplayName"="Indexing Service" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\ 00,69,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000120
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ClipSrv] "DependOnService"=hex(7):4e,00,65,00,74,00,44,00,44,00,45,00,00,00,00,00 "Description"="Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="ClipBook" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\ 00,6c,00,69,00,70,00,73,00,72,00,76,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000003 "Type"=dword:00000010
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ClipSrv\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CmdIde] "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Start"=dword:00000004 "Tag"=dword:00000004 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp] "Type"=dword:00000010 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6c,00,6c,\ 00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,50,00,72,00,\ 6f,00,63,00,65,00,73,00,73,00,69,00,64,00,3a,00,7b,00,30,00,32,00,44,00,34,\ 00,42,00,33,00,46,00,31,00,2d,00,46,00,44,00,38,00,38,00,2d,00,31,00,31,00,\ 44,00,31,00,2d,00,39,00,36,00,30,00,44,00,2d,00,30,00,30,00,38,00,30,00,35,\ 00,46,00,43,00,37,00,39,00,32,00,33,00,35,00,7d,00,00,00 "DisplayName"="COM+ System Application" "DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "FailureActions"=hex:1e,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,52,00,49,\ 00,01,00,00,00,e8,03,00,00,01,00,00,00,88,13,00,00,00,00,00,00,e8,03,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp\Enum] "0"="Root\\LEGACY_COMSYSAPP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter\Linkage] "Bind"=" \\Dummy" "Export"=" \\Dummy" "Route"=" \\Dummy"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter\Performance] "Close"="DoneFILTERPerformanceData" "Collect"="CollectFILTERPerformanceData" "Open"="InitializeFILTERPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\ 00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:000008c8 "Last Help"=dword:000008c9 "First Counter"=dword:000008c2 "First Help"=dword:000008c3 "Object List"="2242" "WbemAdapFileSignature"=hex:9b,54,7a,f3,fd,4c,f8,29,29,9e,4f,3c,05,c4,96,40 "WbemAdapFileTime"=hex:00,a7,70,96,48,4f,c2,01 "WbemAdapFileSize"=dword:00149600 "WbemAdapStatus"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex\Linkage] "Bind"=" \\Dummy" "Export"=" \\Dummy" "Route"=" \\Dummy"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex\Performance] "Close"="DoneCIPerformanceData" "Collect"="CollectCIPerformanceData" "Open"="InitializeCIPerformanceData" "Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\ 00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "Last Counter"=dword:000008c0 "Last Help"=dword:000008c1 "First Counter"=dword:000008aa "First Help"=dword:000008ab "Object List"="2218" "WbemAdapFileSignature"=hex:9b,54,7a,f3,fd,4c,f8,29,29,9e,4f,3c,05,c4,96,40 "WbemAdapFileTime"=hex:00,a7,70,96,48,4f,c2,01 "WbemAdapFileSize"=dword:00149600 "WbemAdapStatus"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000100 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "DisplayName"="Cryptographic Services" "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 63,00,72,00,79,00,70,00,74,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ServiceMain"="CryptServiceMain"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Security] "Security"=hex:00,00,0e,00,01
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Enum] "0"="Root\\LEGACY_CRYPTSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k] "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000020 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:00000020 "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt\Parameters\PnpInterface] "2"=dword:00000001 "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="DHCP Client" "Group"="TDI" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,41,00,66,00,64,00,\ 00,00,4e,00,65,00,74,00,42,00,54,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="LocalSystem" "Description"="Manages network configuration by registering and updating IP addresses and DNS names."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Configurations] "Options"=hex:32,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,\ 00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,00,\ 00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Linkage]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Linkage\Disabled]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,68,00,63,00,70,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}"=hex:0c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,a1,f3,13,45,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ a1,f3,13,45,36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,c0,\ a8,01,01,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,00,01,\ 51,80,0f,00,00,00,00,00,00,00,11,00,00,00,00,00,00,00,12,44,15,45,67,76,2e,\ 73,68,61,77,63,61,62,6c,65,2e,6e,65,74,00,00,00,00,06,00,00,00,00,00,00,00,\ 08,00,00,00,00,00,00,00,12,44,15,45,40,3b,a0,0d,40,3b,a0,0f,03,00,00,00,00,\ 00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,c0,a8,01,01,01,00,00,00,00,00,\ 00,00,04,00,00,00,00,00,00,00,12,44,15,45,ff,ff,ff,00,35,00,00,00,00,00,00,\ 00,01,00,00,00,00,00,00,00,12,44,15,45,05,00,00,00 "{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}"=hex:0c,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,c2,6f,18,45,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ c2,6f,18,45,36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,c0,\ a8,01,01,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,00,01,\ 51,80,0f,00,00,00,00,00,00,00,11,00,00,00,00,00,00,00,3f,c1,19,45,67,76,2e,\ 73,68,61,77,63,61,62,6c,65,2e,6e,65,74,00,00,00,00,06,00,00,00,00,00,00,00,\ 08,00,00,00,00,00,00,00,3f,c1,19,45,40,3b,a0,0d,40,3b,a0,0f,03,00,00,00,00,\ 00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,c0,a8,01,01,01,00,00,00,00,00,\ 00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,ff,ff,ff,00,35,00,00,00,00,00,00,\ 00,01,00,00,00,00,00,00,00,3f,c1,19,45,05,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\1] "KeyType"=dword:00000007 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,\ 65,00,74,00,4d,00,61,00,73,00,6b,00,4f,00,70,00,74,00,00,00,53,00,59,00,53,\ 00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,\ 6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,\ 00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,61,00,\ 6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,\ 00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,65,00,74,00,4d,00,61,00,\ 73,00,6b,00,4f,00,70,00,74,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\15] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,\ 69,00,6e,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,49,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,69,\ 00,6e,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\3] "KeyType"=dword:00000007 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,\ 75,00,6c,00,74,00,47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,53,00,59,\ 00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,\ 43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,\ 00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,\ 61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,\ 00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,75,00,6c,00,74,00,\ 47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\44] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\ 63,00,70,00,4e,00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,4c,\ 00,69,00,73,00,74,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,\ 75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,\ 00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,\ 5c,00,4e,00,65,00,74,00,42,00,54,00,5c,00,41,00,64,00,61,00,70,00,74,00,65,\ 00,72,00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,\ 65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\46] "KeyType"=dword:00000004 "RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpNodeType"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\47] "KeyType"=dword:00000001 "RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpScopeID"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\6] "KeyType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\ 00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,65,00,\ 53,00,65,00,72,00,76,00,65,00,72,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,\ 00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,\ 72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,\ 61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,4e,\ 00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\DhcpNetbiosOptions] "KeyType"=dword:00000004 "OptionId"=dword:00000001 "VendorType"=dword:00000001 "RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\ 00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\ 65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\ 00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\ 65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\ 00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\ 63,00,70,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,4f,00,70,00,74,00,69,\ 00,6f,00,6e,00,73,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 2c,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Enum] "0"="Root\\LEGACY_DHCP\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Disk] "DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\ 70,00,6f,00,72,00,74,00,00,00,00,00 "ErrorControl"=dword:00000001 "Group"="SCSI Class" "Start"=dword:00000000 "Tag"=dword:00000002 "Type"=dword:00000001 "DisplayName"="Disk Driver" "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\ 52,00,49,00,56,00,45,00,52,00,53,00,5c,00,64,00,69,00,73,00,6b,00,2e,00,73,\ 00,79,00,73,00,00,00 "AutoRunAlwaysDisable"=hex(7):42,00,72,00,6f,00,74,00,68,00,65,00,72,00,20,00,\ 52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,44,00,69,00,73,00,6b,\ 00,28,00,55,00,29,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Disk\Enum] "0"="IDE\\DiskMAXTOR_6L020J1__________________________AR1.0400\\3636313135333439323237382020202020202020" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmadmin] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\ 67,00,50,00,6c,00,61,00,79,00,00,00,44,00,6d,00,53,00,65,00,72,00,76,00,65,\ 00,72,00,00,00,00,00 "Type"=dword:00000020 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\ 00,6d,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,65,00,78,00,65,00,20,00,2f,00,\ 63,00,6f,00,6d,00,00,00 "DisplayName"="Logical Disk Manager Administrative Service" "ObjectName"="LocalSystem" "Description"="Configures hard disk drives and volumes. The service only runs for configuration processes and then stops."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmadmin\Parameters] "EnableDynamicConversionFor1394"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmboot] "Type"=dword:00000001 "Start"=dword:00000004 "ErrorControl"=dword:00000001 "Group"="Filter" "Tag"=dword:0000000b "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,62,00,6f,00,6f,00,74,\ 00,2e,00,73,00,79,00,73,00,00,00 "VolumeRecoveryNeeded"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmboot\Enum] "0"="Root\\LEGACY_DMBOOT\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Tag"=dword:0000000d "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,69,00,6f,00,2e,00,73,\ 00,79,00,73,00,00,00 "DisplayName"="Logical Disk Manager Driver"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio\Boot Info] "Boot ID"="a9c72dc1-2788-11db-91ee-806d6172696f"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio\Enum] "0"="Root\\dmio\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmload] "Type"=dword:00000001 "Start"=dword:00000000 "ErrorControl"=dword:00000001 "Group"="System Bus Extender" "Tag"=dword:0000000c "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,6c,00,6f,00,61,00,64,\ 00,2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmload\Enum] "0"="Root\\LEGACY_DMLOAD\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\ 67,00,50,00,6c,00,61,00,79,00,00,00,00,00 "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Logical Disk Manager" "ObjectName"="LocalSystem" "Description"="Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,6d,00,73,00,65,00,72,00,76,00,65,00,72,00,2e,00,64,00,6c,00,6c,00,00,\ 00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Enum] "0"="Root\\LEGACY_DMSERVER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\DMusic] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,44,00,4d,00,75,00,73,00,69,00,63,\ 00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel DLS Syntheiszer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\DMusic\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,65,00,72,00,76,\ 00,69,00,63,00,65,00,00,00 "DisplayName"="DNS Client" "Group"="TDI" "DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00 "DependOnGroup"=hex(7):00,00 "ObjectName"="NT AUTHORITY\\NetworkService" "Description"="Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 64,00,6e,00,73,00,72,00,73,00,6c,00,76,00,72,00,2e,00,64,00,6c,00,6c,00,00,\ 00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 23,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2c,\ 02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,\ 00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Enum] "0"="Root\\LEGACY_DNSCACHE\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o] "ErrorControl"=dword:00000001 "Group"="SCSI miniport" "Start"=dword:00000004 "Tag"=dword:0000003c "Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o\Parameters\PnpInterface] "5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\drmkaud] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,72,00,6d,00,6b,00,61,00,75,\ 00,64,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Microsoft Kernel DRM Audio Descrambler"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\drmkaud\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="Allows error reporting for services and applictions running in non-standard environments." "DisplayName"="Error Reporting Service" "ErrorControl"=dword:00000000 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000020
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 65,00,72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Enum] "0"="Root\\LEGACY_ERSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371] "Type"=dword:00000001 "Start"=dword:00000003 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\ 72,00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,73,00,31,00,33,00,37,00,31,\ 00,6d,00,70,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="Creative AudioPCI (ES1371,ES1373) (WDM)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371\Enum] "0"="PCI\\VEN_1274&DEV_5880&SUBSYS_A0001458&REV_04\\4&3ab31f7f&0&50F0" "Count"=dword:00000001 "NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog] "Description"="Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped." "DisplayName"="Event Log" "ErrorControl"=dword:00000001 "Group"="Event log" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "PlugPlayServiceType"=dword:00000003 "Start"=dword:00000002 "Type"=dword:00000020 "ComputerName"="PCZONE11"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application] "DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "DisplayNameID"=dword:00000100 "File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\ 6f,00,6e,00,66,00,69,00,67,00,5c,00,41,00,70,00,70,00,45,00,76,00,65,00,6e,\ 00,74,00,2e,00,45,00,76,00,74,00,00,00 "MaxSize"=dword:00080000 "PrimaryModule"="Application" "Retention"=dword:00093a80 "Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\ 70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,70,\ 00,00,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,\ 6c,00,6f,00,67,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,\ 00,20,00,50,00,72,00,6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,\ 69,00,76,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,\ 00,77,00,73,00,20,00,33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,\ 74,00,69,00,6f,00,6e,00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,\ 00,74,00,00,00,56,00,53,00,53,00,00,00,56,00,42,00,52,00,75,00,6e,00,74,00,\ 69,00,6d,00,65,00,00,00,55,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,00,\ 00,55,00,73,00,65,00,72,00,65,00,6e,00,76,00,00,00,55,00,70,00,6c,00,6f,00,\ 61,00,64,00,4d,00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,53,\ 00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,00,00,00,53,00,70,00,6f,00,\ 6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,\ 00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,\ 61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,63,00,6c,00,67,00,4e,00,74,00,66,\ 00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,76,00,00,00,53,00,63,00,65,00,\ 43,00,6c,00,69,00,00,00,73,00,61,00,66,00,72,00,73,00,6c,00,76,00,00,00,53,\ 00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,50,00,65,00,72,00,66,00,50,00,\ 72,00,6f,00,63,00,00,00,50,00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,65,\ 00,72,00,66,00,4e,00,65,00,74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,00,\ 6e,00,00,00,50,00,65,00,72,00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,72,\ 00,66,00,44,00,69,00,73,00,6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,00,\ 72,00,73,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,00,65,00,20,00,46,00,69,\ 00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,65,00,79,00,00,00,6e,00,\ 74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4d,00,73,00,69,00,49,00,6e,\ 00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,\ 43,00,20,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,\ 00,43,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,76,00,63,00,00,00,4d,00,69,00,\ 63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,\ 00,20,00,54,00,65,00,6c,00,65,00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,\ 65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,\ 00,65,00,72,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,66,00,00,00,\ 4a,00,61,00,76,00,61,00,20,00,56,00,4d,00,00,00,48,00,65,00,6c,00,70,00,53,\ 00,76,00,63,00,00,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,00,52,00,65,00,\ 64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,46,00,69,00,6c,\ 00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,79,00,6d,00,65,00,6e,00,74,00,\ 00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\ 00,45,00,53,00,45,00,4e,00,54,00,00,00,45,00,41,00,50,00,4f,00,4c,00,00,00,\ 44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,6b,\ 00,51,00,75,00,6f,00,74,00,61,00,00,00,63,00,72,00,79,00,70,00,74,00,33,00,\ 32,00,00,00,43,00,4f,00,4d,00,2b,00,00,00,43,00,69,00,00,00,43,00,68,00,6b,\ 00,64,00,73,00,6b,00,00,00,41,00,76,00,67,00,45,00,6d,00,73,00,00,00,41,00,\ 76,00,67,00,37,00,55,00,70,00,64,00,53,00,76,00,63,00,00,00,41,00,76,00,67,\ 00,37,00,41,00,6c,00,72,00,74,00,00,00,41,00,56,00,47,00,37,00,00,00,41,00,\ 75,00,74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,00,65,00,6e,00,74,\ 00,00,00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,41,00,70,00,70,00,\ 6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,\ 00,67,00,65,00,6d,00,65,00,6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,\ 63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,\ 00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,\ 72,00,72,00,6f,00,72,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,\ 00,69,00,6f,00,6e,00,00,00,00,00 "RestrictGuestAccess"=dword:00000001 @="mnmsrvc"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application] "CategoryCount"=dword:00000007 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,64,00,6c,00,\ 6c,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Error] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Hang] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Management] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Autochk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AutoEnrollment] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,61,00,75,00,74,00,6f,00,65,00,6e,00,72,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AVG7] "EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avglog.dll" "CategoryMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avglog.dll" "TypesSupported"=dword:00000007 "CategoryCount"=dword:00000005
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Avg7Alrt] "EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgamint.dll" "CategoryMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgamint.dll" "CategoryCount"=dword:00000001 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Avg7UpdSvc] "EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgupsvc.dll" "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AvgEms] "EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe" "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Chkdsk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,6c,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Ci] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007 "CategoryCount"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\COM+] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "ParameterMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypeSupported"=dword:00000007 "CategoryCount"=dword:00000075
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\crypt32] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\DiskQuota] "EventMessageFile"="%SystemRoot%\\System32\\dskquota.dll" "TypesSupported"="0x00000007"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\DrWatson] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,72,00,77,00,74,00,73,00,6e,00,33,00,32,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\EAPOL] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,7a,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\ESENT] "EventMessageFile"=hex(2):63,00,3a,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,\ 00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,00,\ 53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryMessageFile"=hex(2):63,00,3a,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,\ 77,00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,\ 00,53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00 "CategoryCount"=dword:00000010 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\EventSystem] "CategoryCount"=dword:00000006 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\File Deployment] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Folder Redirection] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\ 6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\ 00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\HelpSvc] "EventMessageFile"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll" "TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Java VM] "EventMessageFile"="C:\\WINDOWS\\System32\\vmhelper.dll" "TypesSupported"=hex:07,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\LoadPerf] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6c,00,6f,00,61,00,64,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Microsoft H.323 Telephony Service Provider] "EventMessageFile"="C:\\WINDOWS\\System32\\h323.tsp" "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\mnmsrvc] "EventMessageFile"="%SystemRoot%\\System32\\nmevtmsg.dll" "TypeSupported"=hex:07,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MSDTC] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00 "CategoryCount"=dword:0000000f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MSDTC Client] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\ 4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00 "TypesSupported"=dword:00000007 "CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\ 57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\ 00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00 "CategoryCount"=dword:0000000f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MsiInstaller] "EventMessageFile"="C:\\WINDOWS\\System32\\msi.dll" "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\ntbackup] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Oakley] "EventMessageFile"="%SystemRoot%\\System32\\oakley.dll" "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Offline Files] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,63,00,73,00,63,00,75,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"="0x00000007"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perfctrs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfDisk] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,64,00,69,00,73,00,6b,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perflib] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,72,00,66,00,6c,00,62,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perfmon] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,00,\ 00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfNet] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,6e,00,65,00,74,00,2e,00,64,00,6c,00,6c,00,00,\ 00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfOS] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,4f,00,53,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfProc] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,70,00,65,00,72,00,66,00,70,00,72,00,6f,00,63,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SAFrdms] "EventMessageFile"="C:\\WINDOWS\\System32\\safrdm.dll" "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\safrslv] "EventMessageFile"="C:\\WINDOWS\\System32\\safrslv.dll" "TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SceCli] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SceSrv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,65,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SclgNtfy] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Software Installation] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,70,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SpoolerCtrs] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,73,00,70,00,6f,00,6f,00,6c,00,2e,00,64,00,72,00,76,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SysmonLog] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,73,00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Tlntsvr] "EventMessageFile"="C:\\WINDOWS\\System32\\tlntsvr.exe;C:\\WINDOWS\\System32\\xpsp1res.dll" "TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\UploadM] "EventMessageFile"="C:\\WINDOWS\\PCHealth\\UploadLB\\Binaries\\UploadM.exe" "TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Userenv] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,73,00,65,00,72,00,65,00,6e,00,76,00,2e,00,64,00,6c,00,6c,00,3b,\ 00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\ 5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,\ 00,70,00,31,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Userinit] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,75,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\VBRuntime] "EventMessageFile"="C:\\WINDOWS\\System32\\MSVBVM60.DLL" "TypesSupported"=dword:00000004
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\VSS] "TypesSupported"=dword:00000007 "EventMessageFile"="C:\\WINDOWS\\System32\\vssvc.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WebClient] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Windows 3.1 Migration] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,61,00,64,00,76,00,61,00,70,00,69,00,33,00,32,00,2e,00,64,00,6c,00,6c,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Windows Product Activation] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,70,00,63,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Winlogon] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\ 00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WinMgmt] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,\ 00,52,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WmdmPmSp] "EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\ 00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\ 73,00,70,00,6d,00,73,00,70,00,73,00,76,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WMIAdapter] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,4d,00,49,00,41,00,70,00,52,00,65,\ 00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WSH] "EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\ 00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\ 5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00 "TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security] "DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ 00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 "DisplayNameID"=dword:00000101 "File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\ 6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,65,00,63,00,45,00,76,00,65,00,6e,\ 00,74,00,2e,00,45,00,76,00,74,00,00,00 "MaxSize"=dword:00080000 "PrimaryModule"="Security" "Retention"=dword:00093a80 "Sources"=hex(7):53,00,70,00,6f,00,6f,00,6c,00,65,00,72,00,00,00,53,00,65,00,\ 63,00,75,00,72,00,69,00,74,00,79,00 |