Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
My computers absolutely taken over,,cant even stop crackers from uninstalling hijacck this!!
   
BullGuard Antivirus Forum > General Security > Updates and Patches > My computers absolutely taken over,,cant even stop crackers from uninstalling hijacck this!!  
Forum Quick Jump
 
New Topic Post reply to : My computers absolutely taken over,,cant even stop crackers from uninstalling hijacck this!! Printable version of : My computers absolutely taken over,,cant even stop crackers from uninstalling hijacck this!!
[ << Previous Thread | Next Thread >> ]

SirPkralot
New Member


Date Joined Aug 2006
Total Posts : 3
 
   Posted 9-26-2006 6:23 (GMT +1)    Quote: My computers absolutely taken over,,cant even stop crackers from uninstalling hijacck this!!Alert an admin about: My computers absolutely taken over,,cant even stop crackers from uninstalling hijacck this!!
 
hi i have written many paragraphd before..only to have it dissapear before posting...
so i will be brief
 
i have major takeover probs for the last 15 months..serious crackers or ..."enemie" have used remoe/messenger.windows media etc atc, and are able to gain access to, and make my computer a limited account on some ?? sever..which captures all info and is msking me frustated (15 months
 
here is a copy of SD backup systems..which I have not touched,  and should be in default mode....but I think not
 
please  give me some feedback
 
ty
 
sirpkralot
 
aka  john
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Abiosdsk]
"ErrorControl"=dword:00000000
"Group"="Primary disk"
"Start"=dword:00000004
"Tag"=dword:00000003
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000038
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPI]
"ErrorControl"=dword:00000001
"Group"="Boot Bus Extender"
"Start"=dword:00000000
"Tag"=dword:00000001
"Type"=dword:00000001
"DisplayName"="Microsoft ACPI Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,43,00,50,00,49,00,2e,00,73,\
  00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPI\Enum]
"0"="ACPI_HAL\\PNP0C08\\0"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPIEC]
"ErrorControl"=dword:00000001
"Group"="Boot Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000005
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003c
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aec]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
  72,00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,65,00,63,00,2e,00,73,00,79,\
  00,73,00,00,00
"DisplayName"="Microsoft Kernel Acoustic Echo Canceller"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aec\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
  00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,66,00,64,00,2e,00,73,00,79,00,\
  73,00,00,00
"DisplayName"="AFD Networking Support Environment"
"Group"="TDI"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD\Enum]
"0"="Root\\LEGACY_AFD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440]
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000001
"Tag"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,67,00,70,00,34,00,34,00,30,\
  00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Intel AGP Bus Filter"
"Group"="PnP Filter"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440\Enum]
"0"="PCI\\VEN_8086&DEV_1A31&SUBSYS_00000000&REV_04\\3&13c0b0c5&0&08"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000006
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x\Parameters]
"LegacyAdapterDetection"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x\Parameters\PnpInterface]
"1"=dword:00000001
"3"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000034
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000001e
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,\
  00,6c,00,67,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="Application Layer Gateway Service"
"ObjectName"="NT AUTHORITY\\LocalService"
"Description"="Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG\Enum]
"0"="Root\\LEGACY_ALG\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AliIde]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000004
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000024
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt]
"Description"="Provides software installation services such as Assign, Publish, and Remove."
"DisplayName"="Application Management"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000020
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,00,00,\
  00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt\Security]
"Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
  05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
  02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\
  18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\
  00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000029
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000039
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p\Parameters\PnpInterface]
"1"=dword:00000011
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000002a
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AsyncMac]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,73,00,79,00,6e,00,63,00,6d,\
  00,61,00,63,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="RAS Asynchronous Media Driver"
"Description"="RAS Asynchronous Media Driver"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AsyncMac\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000000
"Tag"=dword:00000019
"Type"=dword:00000001
"DisplayName"="Standard IDE/ESDI Hard Disk Controller"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,61,00,70,00,69,00,2e,\
  00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi\Parameters]
"LegacyDetection"=dword:00000001
"GhostSlave"=hex(7):53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,00,00,00,\
  00
"UseCheckPowerForFlush"=hex(7):53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,20,00,\
  57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,41,00,20,00,28,00,31,\
  00,36,00,30,00,30,00,4d,00,42,00,29,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,41,00,4d,00,53,00,55,\
  00,4e,00,47,00,20,00,57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,\
  41,00,20,00,28,00,31,00,2e,00,36,00,47,00,42,00,29,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,49,00,\
  42,00,4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,54,00,43,00,36,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,\
  4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,54,00,43,00,36,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,\
  2d,00,44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,\
  00,4c,00,38,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,\
  44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,\
  00,38,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,\
  50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,38,\
  00,49,00,41,00,41,00,34,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,\
  43,00,41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,4f,\
  00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,43,00,\
  41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,49,00,41,\
  00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,\
  2d,00,32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,4f,00,41,00,41,\
  00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,2d,00,\
  32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,49,00,41,00,41,00,32,\
  00,41,00,00,00,00,00
"NoFlushDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,5f,00,4c,00,\
  50,00,53,00,35,00,32,00,35,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,43,00,52,00,2d,00,37,00,33,\
  00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00
"PioOnlyDevice"=hex(7):20,00,20,00,20,00,20,00,43,00,6f,00,6e,00,6e,00,65,00,\
  72,00,20,00,50,00,65,00,72,00,69,00,70,00,68,00,65,00,72,00,61,00,6c,00,73,\
  00,20,00,34,00,32,00,35,00,4d,00,42,00,20,00,2d,00,20,00,43,00,46,00,53,00,\
  34,00,32,00,35,00,41,00,20,00,20,00,00,00,4d,00,41,00,54,00,53,00,48,00,49,\
  00,54,00,41,00,20,00,43,00,52,00,2d,00,35,00,38,00,31,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,46,00,58,00,\
  36,00,30,00,30,00,53,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,00,00,43,00,44,00,2d,00,34,00,34,00,45,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,\
  00,54,00,52,00,42,00,38,00,35,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,\
  54,00,55,00,4d,00,20,00,4d,00,41,00,52,00,56,00,45,00,52,00,49,00,43,00,4b,\
  00,20,00,35,00,34,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,20,\
  00,4d,00,41,00,58,00,54,00,4f,00,52,00,20,00,4d,00,58,00,54,00,2d,00,35,00,\
  34,00,30,00,20,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,31,00,32,\
  00,36,00,30,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,\
  20,00,37,00,38,00,35,00,30,00,20,00,41,00,56,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,\
  00,74,00,6f,00,72,00,20,00,37,00,35,00,34,00,30,00,20,00,41,00,56,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,33,00,20,\
  00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,\
  33,00,34,00,35,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,\
  00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,41,00,54,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,\
  61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,\
  31,00,41,00,55,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,\
  00,37,00,31,00,37,00,31,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,44,00,2d,00,\
  33,00,31,00,36,00,45,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,\
  00,53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,5f,00,53,00,43,00,52,00,2d,00,\
  32,00,34,00,33,00,30,00,00,00,43,00,52,00,2d,00,32,00,38,00,30,00,31,00,54,\
  00,45,00,00,00,00,00
"NonRemovableMedia"=hex(7):4b,00,69,00,6e,00,67,00,73,00,74,00,6f,00,6e,00,20,\
  00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,79,00,20,00,44,00,\
  61,00,74,00,61,00,50,00,61,00,6b,00,20,00,33,00,34,00,30,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,\
  73,00,6b,00,20,00,53,00,44,00,50,00,35,00,41,00,2d,00,31,00,30,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,\
  00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,\
  31,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,\
  00,33,00,42,00,2d,00,32,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,\
  20,00,53,00,44,00,50,00,33,00,42,00,2d,00,31,00,37,00,35,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,\
  00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,35,00,2d,00,32,00,2e,00,35,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,\
  43,00,61,00,6c,00,6c,00,75,00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,\
  00,6f,00,6c,00,6f,00,67,00,79,00,20,00,43,00,54,00,32,00,36,00,30,00,4d,00,\
  43,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,00,00,42,00,4e,00,2d,00,53,00,30,00,30,00,34,00,41,00,43,00,\
  2d,00,53,00,20,00,31,00,2e,00,30,00,30,00,00,00,43,00,61,00,6c,00,6c,00,75,\
  00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,\
  79,00,20,00,43,00,54,00,35,00,32,00,30,00,52,00,4d,00,00,00,48,00,69,00,74,\
  00,61,00,63,00,68,00,69,00,20,00,43,00,56,00,20,00,35,00,2e,00,31,00,2e,00,\
  31,00,00,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,41,00,5f,00,46,\
  00,4c,00,41,00,53,00,48,00,20,00,00,00,4d,00,69,00,74,00,73,00,75,00,62,00,\
  69,00,73,00,68,00,69,00,20,00,41,00,54,00,41,00,20,00,43,00,61,00,72,00,64,\
  00,20,00,00,00,4c,00,45,00,58,00,41,00,52,00,20,00,41,00,54,00,41,00,5f,00,\
  46,00,4c,00,41,00,53,00,48,00,00,00,4d,00,69,00,63,00,72,00,6f,00,6e,00,20,\
  00,4d,00,54,00,43,00,46,00,30,00,30,00,34,00,41,00,00,00,4d,00,69,00,63,00,\
  72,00,6f,00,6e,00,20,00,4d,00,54,00,43,00,46,00,30,00,30,00,38,00,41,00,00,\
  00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,33,00,\
  42,00,2d,00,31,00,31,00,30,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,\
  00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,34,00,00,00,42,00,4e,00,2d,00,\
  43,00,41,00,42,00,2d,00,54,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,\
  00,54,00,49,00,43,00,4b,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,00,\
  54,00,49,00,43,00,4b,00,20,00,20,00,20,00,38,00,4d,00,20,00,20,00,38,00,4b,\
  00,00,00,00,00
"NoPowerDownDevice"=hex(7):52,00,44,00,2d,00,44,00,52,00,43,00,30,00,30,00,31,\
  00,2d,00,4d,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,53,00,2d,00,52,00,33,00,\
  37,00,20,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00
"AutoEjectZipDevice"=hex(7):49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,\
  00,49,00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,20,00,32,00,33,00,2e,00,44,00,20,00,20,00,\
  20,00,20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,\
  00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,20,00,32,00,31,00,2e,00,44,00,20,00,20,00,20,00,\
  20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,\
  00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,\
  54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,20,00,32,00,30,00,2e,00,44,00,20,00,20,00,20,00,20,00,\
  00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,\
  00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,\
  41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,20,00,39,00,31,00,2e,00,44,00,20,00,20,00,20,00,20,00,00,00,\
  49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,\
  00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,20,00,42,00,2e,00,32,00,39,00,20,00,20,00,20,00,20,00,00,00,49,00,\
  4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,00,30,\
  00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
  20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
  00,20,00,42,00,2e,00,32,00,32,00,20,00,20,00,20,00,20,00,00,00,00,00
"NeedIdentDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,00,46,00,\
  49,00,52,00,45,00,42,00,41,00,4c,00,4c,00,00,00,00,00
"DefaultPioAtapiDevice"=hex(7):54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,\
  44,00,56,00,44,00,2d,00,52,00,4f,00,4d,00,20,00,44,00,52,00,44,00,2d,00,4e,\
  00,32,00,31,00,36,00,00,00,49,00,44,00,45,00,2d,00,43,00,44,00,20,00,52,00,\
  2f,00,52,00,57,00,20,00,32,00,78,00,32,00,78,00,32,00,34,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi\Enum]
"0"="PCIIDE\\IDEChannel\\4&e3ec092&0&0"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="PCIIDE\\IDEChannel\\4&e3ec092&0&1"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atdisk]
"ErrorControl"=dword:00000000
"Group"="Primary disk"
"Start"=dword:00000004
"Tag"=dword:00000001
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atmarpc]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:0000000b
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,6d,00,61,00,72,00,70,\
  00,63,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="ATM ARP Client Protocol"
"Group"="NDIS"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"Description"="ATM ARP Client Protocol"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atmarpc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv]
"DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\
  52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Windows Audio"
"ErrorControl"=dword:00000001
"Group"="AudioGroup"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  61,00,75,00,64,00,69,00,6f,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,\
  00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv\Enum]
"0"="Root\\LEGACY_AUDIOSRV\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,75,00,64,00,73,00,74,00,75,\
  00,62,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Audio Stub Driver"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub\Enum]
"0"="Root\\MEDIA\\MS_MMACM"
"Count"=dword:00000005
"NextInstance"=dword:00000005
"1"="Root\\MEDIA\\MS_MMDRV"
"2"="Root\\MEDIA\\MS_MMMCI"
"3"="Root\\MEDIA\\MS_MMVCD"
"4"="Root\\MEDIA\\MS_MMVID"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt]
"Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\
  31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\
  00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,61,00,6d,00,73,00,\
  76,00,72,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="AVG7 Alert Manager Server"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt\Enum]
"0"="Root\\LEGACY_AVG7ALRT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000001
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
  00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,63,00,6f,00,\
  72,00,65,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="AVG7 Kernel"
"Group"="AVG"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Parameters]
"AvgDir"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\"
"AvgLng"=dword:00000001
"TempDir"="C:\\DOCUME~1\\ALLUSE~1\\APPLIC~1\\Grisoft\\Avg7Data\\"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Enum]
"0"="Root\\LEGACY_AVG7CORE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000002
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
  00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,72,00,73,00,\
  77,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="AVG7 Wrap Driver"
"Group"="AVG"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW\Enum]
"0"="Root\\LEGACY_AVG7RSW\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000003
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
  00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,72,00,73,00,\
  78,00,70,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="AVG7 Resident Driver XP"
"Group"="AVG"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Parameters]
"Params"=dword:0005c007
"IgnoreFilesystem"=dword:000000c0
"Extensions"=hex:36,69,c4,8b,53,68,0c,c8,f7,fa,2a,09,15,f2,ab,88,44,3a,ca,67,\
  e6,cf,eb,95,e5,93,34,f4,36,6a,c4,8b,53,3c,4d,8a,28,33,ed,c5,ca,2d,74,57,44,\
  74,83,55,39,40,67,0b,3a,4c,eb,2b,36,3a,89,c9,8c,b7,d3,17,f7,ec,32,1a,ca,62,\
  3b,15,9b,e5,15,c8,e6,9f,b8,d4,3a,01,a3,68,e9,b5,1b,54,53,68,0c,c8,f7,ad,7e,\
  59,15,f2,ab,88,44,3a,ca,17,b5,de,f4,97,e5,93,34,f4,36,6a,c4,8b,53,2c,41,8b,\
  28,33,ed,c5,ca,2d,74,57,44,77,84,54,39,40,67,0b,3a,4c,eb,2b,36,27,8b,c8,8c,\
  b7,d3,17,f7,ec,32,1a,ca,61,24,14,9b,e5,15,c8,e6,9f,b8,d4,3a,1a,ae,6f,e9,b5,\
  1b,54,53,68,0c,c8,f7,a0,7e,5e,15,f2,ab,88,44,3a,ca,17,e6,9f,f7,90,3a,4c,34,\
  f4,36,6a,c4,8b,53,3e,5e,8c,28,33,ed,c5,ca,2d,74,57,44,76,87,52,39,40,67,0b,\
  3a,4c,eb,2b,36,2f,9c,ce,8c,b7,d3,17,f7,ec,32,1a,ca,6b,3d,10,9b,e5,15,c8,e6,\
  9f,b8,d4,3a,1c,a7,63,e9,b5,1b,54,53,68,0c,c8,f7,ec,66,52,ca,2d,ab,88,44,3a,\
  ca,17,e6,d6,f6,9d,e5,93,34,f4,36,6a,c4,8b,14,2d,5c,82,28,33,ed,c5,ca,2d,74,\
  57,44,7d,9a,5d,39,40,67,0b,3a,4c,eb,2b,36,6a,97,c1,53,68,d3,17,f7,ec,32,1a,\
  ca,66,3a,1b,9b,e5,15,c8,e6,9f,b8,d4,3a,4c,af,66,36,6a,1b,54,53,68,0c,c8,f7,\
  ab,61,57,15,f2,ab,88,44,3a,ca,17,e6,cc,ef,9a,e5,93,34,f4,36,6a,c4,8b,53,30,\
  4f,87,28,33,ed,c5,ca,2d,74,57,44,3a,9c,58,e6,9f,67,0b,3a,4c,eb,2b,36,32,87,\
  db,8c,b7,d3,17,f7,ec,32,1a,ca,60,33,07,9b,e5,15,c8,e6,9f,b8,d4,3a,1c,a3,7b,\
  36,b5,1b,54,53,68,0c,c8,f7,aa,7b,4a,15,f2,ab,88,44,3a,ca,17,e6,9f,f4,84,3a,\
  4c,34,f4,36,6a,c4,8b,53,2f,42,98,28,33,ed,c5,ca,2d,74,57,44,6e,85,47,39,40,\
  67,0b,3a,4c,eb,2b,36,6a,94,db,53,68,d3,17,f7,ec,32,1a,ca,7f,37,04,9b,e5,15,\
  c8,e6,9f,b8,d4,3a,1f,a3,78,e9,b5,1b,54,53,68,0c,c8,f7,a1,7f,49,15,f2,ab,88,\
  44,3a,ca,17,e6,cc,e1,87,e5,93,34,f4,36,6a,c4,8b,53,2e,45,9c,28,33,ed,c5,ca,\
  2d,74,57,44,7f,88,41,39,40,67,0b,3a,4c,eb,2b,36,39,86,dd,8c,b7,d3,17,f7,ec,\
  32,1a,ca,75,36,01,9b,e5,15,c8,e6,9f,b8,d4,3a,08,b3,7d,e9,b5,1b,54,53,68,0c,\
  c8,f7,aa,7f,4d,15,f2,ab,88,44,3a,ca,17,e6,9f,f4,8c,3a,4c,34,f4,36,6a,c4,8b,\
  53,24,41,90,28,33,ed,c5,ca,2d,74,57,44,3a,86,4d,e6,9f,67,0b,3a,4c,eb,2b,c9,\
  95,3b,74,53,68,0c,c8,f7,ec,32,1a,35,d2,8b,a8,44,3a,ca,17,e6,9f,b8,d4,c5,b3,\
  14,d4,36,6a,c4,8b,53,68,0c,c8,08,13,cd,e5,ca,2d,74,57,44,3a,ca,17,19,60,47,\
  2b,3a,4c,eb,2b,36,6a,c4,8b,ac,97,f3,37,f7,ec,32,1a,ca,2d,74,57,bb,c5,35,e8,\
  e6,9f,b8,d4,3a,4c,eb,2b,c9,95,3b,74,53,68,0c,c8,f7,ec,32,1a,35,d2,8b,a8,44,\
  3a,ca,17,e6,9f,b8,d4,c5,b3,14,d4,36,6a,c4,8b,53,68,0c,c8,08,13,cd,e5,ca,2d,\
  74,57,44,3a,ca,17,0b,6d
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Enum]
"0"="Root\\LEGACY_AVG7RSXP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc]
"Type"=dword:00000010
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\
  31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\
  00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,75,00,70,00,73,00,\
  76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="AVG7 Update Service"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc\Enum]
"0"="Root\\LEGACY_AVG7UPDSVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS]
"Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\
  31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\
  00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,65,00,6d,00,63,00,\
  2e,00,65,00,78,00,65,00,00,00
"DisplayName"="AVG E-mail Scanner"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS\Enum]
"0"="Root\\LEGACY_AVGEMS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
  00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,74,00,64,00,69,00,\
  2e,00,73,00,79,00,73,00,00,00
"DisplayName"="AVG Network Redirector"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi\Enum]
"0"="Root\\LEGACY_AVGTDI\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BattC]
"MofImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,\
  00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,62,00,61,00,74,00,74,00,63,00,\
  2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Beep]
"ErrorControl"=dword:00000001
"Group"="Base"
"Start"=dword:00000001
"Tag"=dword:00000002
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Beep\Enum]
"0"="Root\\LEGACY_BEEP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Background Intelligent Transfer Service"
"DependOnService"=hex(7):52,00,70,00,63,00,73,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Uses idle network bandwidth to transfer data."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  71,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Enum]
"0"="Root\\LEGACY_BITS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000019
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k\Parameters\PnpInterface]
"1"=dword:00000001
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003a
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt\Parameters\PnpInterface]
"1"=dword:00000011
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdaudio]
"ErrorControl"=dword:00000000
"Group"="Filter"
"Start"=dword:00000001
"Tag"=dword:00000006
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdaudio\Enum]
"Count"=dword:00000000
"NextInstance"=dword:00000000
"INITSTARTFAILED"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdfs]
"DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,43,00,44,00,52,00,4f,00,\
  4d,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,00,00
"ErrorControl"=dword:00000001
"Group"="File system"
"Start"=dword:00000004
"Type"=dword:00000002
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdfs\Enum]
"0"="Root\\LEGACY_CDFS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdrom]
"DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\
  70,00,6f,00,72,00,74,00,00,00,00,00
"ErrorControl"=dword:00000001
"Group"="SCSI CDROM Class"
"Start"=dword:00000001
"Tag"=dword:00000002
"Type"=dword:00000001
"DisplayName"="CD-ROM Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,63,00,64,00,72,00,6f,00,6d,00,2e,\
  00,73,00,79,00,73,00,00,00
"AutoRun"=dword:00000001
"AutoRunAlwaysDisable"=hex(7):4e,00,45,00,43,00,20,00,20,00,20,00,20,00,20,00,\
  4d,00,42,00,52,00,2d,00,37,00,20,00,20,00,20,00,00,00,4e,00,45,00,43,00,20,\
  00,20,00,20,00,20,00,20,00,4d,00,42,00,52,00,2d,00,37,00,2e,00,34,00,20,00,\
  00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,48,00,41,00,4e,\
  00,47,00,52,00,20,00,44,00,52,00,4d,00,2d,00,31,00,38,00,30,00,34,00,58,00,\
  00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\
  00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,33,00,32,00,34,00,58,00,\
  00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\
  00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,32,00,34,00,58,00,20,00,\
  00,00,54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,43,00,44,00,2d,00,52,\
  00,4f,00,4d,00,20,00,43,00,44,00,52,00,5f,00,43,00,33,00,36,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdrom\Enum]
"0"="IDE\\CdRomLG_CD-ROM_CRD-8521B_____________________2.00____\\5&3494138e&0&0.1.0"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Changer]
"ErrorControl"=dword:00000000
"Group"="Filter"
"Start"=dword:00000001
"Tag"=dword:00000005
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CiSvc]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language."
"DisplayName"="Indexing Service"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\
  00,69,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000120
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ClipSrv]
"DependOnService"=hex(7):4e,00,65,00,74,00,44,00,44,00,45,00,00,00,00,00
"Description"="Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="ClipBook"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\
  00,6c,00,69,00,70,00,73,00,72,00,76,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000010
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ClipSrv\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
  05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
  02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CmdIde]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000004
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
  5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6c,00,6c,\
  00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,50,00,72,00,\
  6f,00,63,00,65,00,73,00,73,00,69,00,64,00,3a,00,7b,00,30,00,32,00,44,00,34,\
  00,42,00,33,00,46,00,31,00,2d,00,46,00,44,00,38,00,38,00,2d,00,31,00,31,00,\
  44,00,31,00,2d,00,39,00,36,00,30,00,44,00,2d,00,30,00,30,00,38,00,30,00,35,\
  00,46,00,43,00,37,00,39,00,32,00,33,00,35,00,7d,00,00,00
"DisplayName"="COM+ System Application"
"DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."
"FailureActions"=hex:1e,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,52,00,49,\
  00,01,00,00,00,e8,03,00,00,01,00,00,00,88,13,00,00,00,00,00,00,e8,03,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp\Enum]
"0"="Root\\LEGACY_COMSYSAPP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter\Linkage]
"Bind"="\\Dummy"
"Export"="\\Dummy"
"Route"="\\Dummy"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter\Performance]
"Close"="DoneFILTERPerformanceData"
"Collect"="CollectFILTERPerformanceData"
"Open"="InitializeFILTERPerformanceData"
"Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\
  00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"Last Counter"=dword:000008c8
"Last Help"=dword:000008c9
"First Counter"=dword:000008c2
"First Help"=dword:000008c3
"Object List"="2242"
"WbemAdapFileSignature"=hex:9b,54,7a,f3,fd,4c,f8,29,29,9e,4f,3c,05,c4,96,40
"WbemAdapFileTime"=hex:00,a7,70,96,48,4f,c2,01
"WbemAdapFileSize"=dword:00149600
"WbemAdapStatus"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex\Linkage]
"Bind"="\\Dummy"
"Export"="\\Dummy"
"Route"="\\Dummy"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex\Performance]
"Close"="DoneCIPerformanceData"
"Collect"="CollectCIPerformanceData"
"Open"="InitializeCIPerformanceData"
"Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\
  00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"Last Counter"=dword:000008c0
"Last Help"=dword:000008c1
"First Counter"=dword:000008aa
"First Help"=dword:000008ab
"Object List"="2218"
"WbemAdapFileSignature"=hex:9b,54,7a,f3,fd,4c,f8,29,29,9e,4f,3c,05,c4,96,40
"WbemAdapFileTime"=hex:00,a7,70,96,48,4f,c2,01
"WbemAdapFileSize"=dword:00149600
"WbemAdapStatus"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000100
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray\Parameters\PnpInterface]
"2"=dword:00000001
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Cryptographic Services"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  63,00,72,00,79,00,70,00,74,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\
  00
"ServiceMain"="CryptServiceMain"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Security]
"Security"=hex:00,00,0e,00,01
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Enum]
"0"="Root\\LEGACY_CRYPTSVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k]
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000020
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k\Parameters\PnpInterface]
"2"=dword:00000001
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000020
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt\Parameters\PnpInterface]
"2"=dword:00000001
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="DHCP Client"
"Group"="TDI"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,41,00,66,00,64,00,\
  00,00,4e,00,65,00,74,00,42,00,54,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Manages network configuration by registering and updating IP addresses and DNS names."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Configurations]
"Options"=hex:32,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,\
  00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,00,\
  00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Linkage]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Linkage\Disabled]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  64,00,68,00,63,00,70,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\
  00
"{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}"=hex:0c,00,00,00,00,00,00,00,00,00,00,\
  00,00,00,00,00,a1,f3,13,45,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
  a1,f3,13,45,36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,c0,\
  a8,01,01,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,00,01,\
  51,80,0f,00,00,00,00,00,00,00,11,00,00,00,00,00,00,00,12,44,15,45,67,76,2e,\
  73,68,61,77,63,61,62,6c,65,2e,6e,65,74,00,00,00,00,06,00,00,00,00,00,00,00,\
  08,00,00,00,00,00,00,00,12,44,15,45,40,3b,a0,0d,40,3b,a0,0f,03,00,00,00,00,\
  00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,c0,a8,01,01,01,00,00,00,00,00,\
  00,00,04,00,00,00,00,00,00,00,12,44,15,45,ff,ff,ff,00,35,00,00,00,00,00,00,\
  00,01,00,00,00,00,00,00,00,12,44,15,45,05,00,00,00
"{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}"=hex:0c,00,00,00,00,00,00,00,00,00,00,\
  00,00,00,00,00,c2,6f,18,45,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
  c2,6f,18,45,36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,c0,\
  a8,01,01,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,00,01,\
  51,80,0f,00,00,00,00,00,00,00,11,00,00,00,00,00,00,00,3f,c1,19,45,67,76,2e,\
  73,68,61,77,63,61,62,6c,65,2e,6e,65,74,00,00,00,00,06,00,00,00,00,00,00,00,\
  08,00,00,00,00,00,00,00,3f,c1,19,45,40,3b,a0,0d,40,3b,a0,0f,03,00,00,00,00,\
  00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,c0,a8,01,01,01,00,00,00,00,00,\
  00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,ff,ff,ff,00,35,00,00,00,00,00,00,\
  00,01,00,00,00,00,00,00,00,3f,c1,19,45,05,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\1]
"KeyType"=dword:00000007
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
  00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
  65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
  00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
  65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
  00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,\
  65,00,74,00,4d,00,61,00,73,00,6b,00,4f,00,70,00,74,00,00,00,53,00,59,00,53,\
  00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,\
  6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,\
  00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,61,00,\
  6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,\
  00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,65,00,74,00,4d,00,61,00,\
  73,00,6b,00,4f,00,70,00,74,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\15]
"KeyType"=dword:00000001
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
  00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
  65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
  00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
  65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
  00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,\
  69,00,6e,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
  00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
  65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
  00,63,00,70,00,49,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
  65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,69,\
  00,6e,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\3]
"KeyType"=dword:00000007
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
  00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
  65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
  00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
  65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
  00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,\
  75,00,6c,00,74,00,47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,53,00,59,\
  00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,\
  43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,\
  00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,\
  61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,\
  00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,75,00,6c,00,74,00,\
  47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\44]
"KeyType"=dword:00000001
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
  00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
  65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\
  00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
  65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
  00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\
  63,00,70,00,4e,00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,4c,\
  00,69,00,73,00,74,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,\
  75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,\
  00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,\
  5c,00,4e,00,65,00,74,00,42,00,54,00,5c,00,41,00,64,00,61,00,70,00,74,00,65,\
  00,72,00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,\
  65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\46]
"KeyType"=dword:00000004
"RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpNodeType"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\47]
"KeyType"=dword:00000001
"RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpScopeID"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\6]
"KeyType"=dword:00000001
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
  00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
  65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
  00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
  65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
  00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,65,00,\
  53,00,65,00,72,00,76,00,65,00,72,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,\
  00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,\
  72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,\
  00,65,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,\
  61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,4e,\
  00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\DhcpNetbiosOptions]
"KeyType"=dword:00000004
"OptionId"=dword:00000001
"VendorType"=dword:00000001
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
  00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
  65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\
  00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
  65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
  00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\
  63,00,70,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,4f,00,70,00,74,00,69,\
  00,6f,00,6e,00,73,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
  05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  2c,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
  02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Enum]
"0"="Root\\LEGACY_DHCP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Disk]
"DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\
  70,00,6f,00,72,00,74,00,00,00,00,00
"ErrorControl"=dword:00000001
"Group"="SCSI Class"
"Start"=dword:00000000
"Tag"=dword:00000002
"Type"=dword:00000001
"DisplayName"="Disk Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,64,00,69,00,73,00,6b,00,2e,00,73,\
  00,79,00,73,00,00,00
"AutoRunAlwaysDisable"=hex(7):42,00,72,00,6f,00,74,00,68,00,65,00,72,00,20,00,\
  52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,44,00,69,00,73,00,6b,\
  00,28,00,55,00,29,00,00,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Disk\Enum]
"0"="IDE\\DiskMAXTOR_6L020J1__________________________AR1.0400\\3636313135333439323237382020202020202020"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmadmin]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\
  67,00,50,00,6c,00,61,00,79,00,00,00,44,00,6d,00,53,00,65,00,72,00,76,00,65,\
  00,72,00,00,00,00,00
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\
  00,6d,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,65,00,78,00,65,00,20,00,2f,00,\
  63,00,6f,00,6d,00,00,00
"DisplayName"="Logical Disk Manager Administrative Service"
"ObjectName"="LocalSystem"
"Description"="Configures hard disk drives and volumes. The service only runs for configuration processes and then stops."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmadmin\Parameters]
"EnableDynamicConversionFor1394"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmboot]
"Type"=dword:00000001
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"Group"="Filter"
"Tag"=dword:0000000b
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
  72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,62,00,6f,00,6f,00,74,\
  00,2e,00,73,00,79,00,73,00,00,00
"VolumeRecoveryNeeded"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmboot\Enum]
"0"="Root\\LEGACY_DMBOOT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio]
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Tag"=dword:0000000d
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
  72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,69,00,6f,00,2e,00,73,\
  00,79,00,73,00,00,00
"DisplayName"="Logical Disk Manager Driver"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio\Boot Info]
"Boot ID"="a9c72dc1-2788-11db-91ee-806d6172696f"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio\Enum]
"0"="Root\\dmio\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmload]
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Tag"=dword:0000000c
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
  72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,6c,00,6f,00,61,00,64,\
  00,2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmload\Enum]
"0"="Root\\LEGACY_DMLOAD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\
  67,00,50,00,6c,00,61,00,79,00,00,00,00,00
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Logical Disk Manager"
"ObjectName"="LocalSystem"
"Description"="Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  64,00,6d,00,73,00,65,00,72,00,76,00,65,00,72,00,2e,00,64,00,6c,00,6c,00,00,\
  00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
  05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
  02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Enum]
"0"="Root\\LEGACY_DMSERVER\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\DMusic]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
  72,00,69,00,76,00,65,00,72,00,73,00,5c,00,44,00,4d,00,75,00,73,00,69,00,63,\
  00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Kernel DLS Syntheiszer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\DMusic\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,65,00,72,00,76,\
  00,69,00,63,00,65,00,00,00
"DisplayName"="DNS Client"
"Group"="TDI"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="NT AUTHORITY\\NetworkService"
"Description"="Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start."
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  64,00,6e,00,73,00,72,00,73,00,6c,00,76,00,72,00,2e,00,64,00,6c,00,6c,00,00,\
  00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Security]
"Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
  05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  23,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2c,\
  02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,\
  00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,\
  00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Enum]
"0"="Root\\LEGACY_DNSCACHE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003c
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o\Parameters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\drmkaud]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
  72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,72,00,6d,00,6b,00,61,00,75,\
  00,64,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Kernel DRM Audio Descrambler"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\drmkaud\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Allows error reporting for services and applictions running in non-standard environments."
"DisplayName"="Error Reporting Service"
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  65,00,72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Enum]
"0"="Root\\LEGACY_ERSVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
  72,00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,73,00,31,00,33,00,37,00,31,\
  00,6d,00,70,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Creative AudioPCI (ES1371,ES1373) (WDM)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371\Enum]
"0"="PCI\\VEN_1274&DEV_5880&SUBSYS_A0001458&REV_04\\4&3ab31f7f&0&50F0"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog]
"Description"="Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped."
"DisplayName"="Event Log"
"ErrorControl"=dword:00000001
"Group"="Event log"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"PlugPlayServiceType"=dword:00000003
"Start"=dword:00000002
"Type"=dword:00000020
"ComputerName"="PCZONE11"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application]
"DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
  6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
  00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"DisplayNameID"=dword:00000100
"File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
  00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\
  6f,00,6e,00,66,00,69,00,67,00,5c,00,41,00,70,00,70,00,45,00,76,00,65,00,6e,\
  00,74,00,2e,00,45,00,76,00,74,00,00,00
"MaxSize"=dword:00080000
"PrimaryModule"="Application"
"Retention"=dword:00093a80
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\
  70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,70,\
  00,00,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,\
  6c,00,6f,00,67,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,\
  00,20,00,50,00,72,00,6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,\
  69,00,76,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,\
  00,77,00,73,00,20,00,33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,\
  74,00,69,00,6f,00,6e,00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,\
  00,74,00,00,00,56,00,53,00,53,00,00,00,56,00,42,00,52,00,75,00,6e,00,74,00,\
  69,00,6d,00,65,00,00,00,55,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,00,\
  00,55,00,73,00,65,00,72,00,65,00,6e,00,76,00,00,00,55,00,70,00,6c,00,6f,00,\
  61,00,64,00,4d,00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,53,\
  00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,00,00,00,53,00,70,00,6f,00,\
  6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,\
  00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,\
  61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,63,00,6c,00,67,00,4e,00,74,00,66,\
  00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,76,00,00,00,53,00,63,00,65,00,\
  43,00,6c,00,69,00,00,00,73,00,61,00,66,00,72,00,73,00,6c,00,76,00,00,00,53,\
  00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,50,00,65,00,72,00,66,00,50,00,\
  72,00,6f,00,63,00,00,00,50,00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,65,\
  00,72,00,66,00,4e,00,65,00,74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,00,\
  6e,00,00,00,50,00,65,00,72,00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,72,\
  00,66,00,44,00,69,00,73,00,6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,00,\
  72,00,73,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,00,65,00,20,00,46,00,69,\
  00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,65,00,79,00,00,00,6e,00,\
  74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4d,00,73,00,69,00,49,00,6e,\
  00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,\
  43,00,20,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,\
  00,43,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,76,00,63,00,00,00,4d,00,69,00,\
  63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,\
  00,20,00,54,00,65,00,6c,00,65,00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,\
  65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,\
  00,65,00,72,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,66,00,00,00,\
  4a,00,61,00,76,00,61,00,20,00,56,00,4d,00,00,00,48,00,65,00,6c,00,70,00,53,\
  00,76,00,63,00,00,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,00,52,00,65,00,\
  64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,46,00,69,00,6c,\
  00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,79,00,6d,00,65,00,6e,00,74,00,\
  00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\
  00,45,00,53,00,45,00,4e,00,54,00,00,00,45,00,41,00,50,00,4f,00,4c,00,00,00,\
  44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,6b,\
  00,51,00,75,00,6f,00,74,00,61,00,00,00,63,00,72,00,79,00,70,00,74,00,33,00,\
  32,00,00,00,43,00,4f,00,4d,00,2b,00,00,00,43,00,69,00,00,00,43,00,68,00,6b,\
  00,64,00,73,00,6b,00,00,00,41,00,76,00,67,00,45,00,6d,00,73,00,00,00,41,00,\
  76,00,67,00,37,00,55,00,70,00,64,00,53,00,76,00,63,00,00,00,41,00,76,00,67,\
  00,37,00,41,00,6c,00,72,00,74,00,00,00,41,00,56,00,47,00,37,00,00,00,41,00,\
  75,00,74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,00,65,00,6e,00,74,\
  00,00,00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,41,00,70,00,70,00,\
  6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,\
  00,67,00,65,00,6d,00,65,00,6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,\
  63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,\
  00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,\
  72,00,72,00,6f,00,72,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,\
  00,69,00,6f,00,6e,00,00,00,00,00
"RestrictGuestAccess"=dword:00000001
@="mnmsrvc"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application]
"CategoryCount"=dword:00000007
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
  6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
  00,5c,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,64,00,6c,00,\
  6c,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Error]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Hang]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Management]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
  6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
  00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
  6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Autochk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AutoEnrollment]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,70,00,61,00,75,00,74,00,6f,00,65,00,6e,00,72,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AVG7]
"EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avglog.dll"
"CategoryMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avglog.dll"
"TypesSupported"=dword:00000007
"CategoryCount"=dword:00000005
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Avg7Alrt]
"EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgamint.dll"
"CategoryMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgamint.dll"
"CategoryCount"=dword:00000001
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Avg7UpdSvc]
"EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgupsvc.dll"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AvgEms]
"EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Chkdsk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,75,00,6c,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Ci]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
  6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
  00,5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
"CategoryCount"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\COM+]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
  00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\
  4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
  57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
  00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ParameterMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
  57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
  00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypeSupported"=dword:00000007
"CategoryCount"=dword:00000075
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\crypt32]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
  00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\DiskQuota]
"EventMessageFile"="%SystemRoot%\\System32\\dskquota.dll"
"TypesSupported"="0x00000007"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\DrWatson]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,64,00,72,00,77,00,74,00,73,00,6e,00,33,00,32,00,2e,00,65,00,78,00,65,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\EAPOL]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,77,00,7a,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\ESENT]
"EventMessageFile"=hex(2):63,00,3a,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,\
  00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,00,\
  53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):63,00,3a,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,\
  77,00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,\
  00,53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryCount"=dword:00000010
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\EventSystem]
"CategoryCount"=dword:00000006
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
  57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
  00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
  00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\
  4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\File Deployment]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\
  00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
  6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
  00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
  6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Folder Redirection]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\
  00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
  6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
  00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
  6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\HelpSvc]
"EventMessageFile"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll"
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Java VM]
"EventMessageFile"="C:\\WINDOWS\\System32\\vmhelper.dll"
"TypesSupported"=hex:07,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\LoadPerf]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,6c,00,6f,00,61,00,64,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Microsoft H.323 Telephony Service Provider]
"EventMessageFile"="C:\\WINDOWS\\System32\\h323.tsp"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\mnmsrvc]
"EventMessageFile"="%SystemRoot%\\System32\\nmevtmsg.dll"
"TypeSupported"=hex:07,00,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MSDTC]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
  00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\
  4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
  57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
  00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00
"CategoryCount"=dword:0000000f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MSDTC Client]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
  00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\
  4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
  57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
  00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00
"CategoryCount"=dword:0000000f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MsiInstaller]
"EventMessageFile"="C:\\WINDOWS\\System32\\msi.dll"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\ntbackup]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Oakley]
"EventMessageFile"="%SystemRoot%\\System32\\oakley.dll"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Offline Files]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,63,00,73,00,63,00,75,00,69,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"="0x00000007"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perfctrs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,70,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfDisk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,70,00,65,00,72,00,66,00,64,00,69,00,73,00,6b,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perflib]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,70,00,72,00,66,00,6c,00,62,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perfmon]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,70,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,00,\
  00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfNet]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,70,00,65,00,72,00,66,00,6e,00,65,00,74,00,2e,00,64,00,6c,00,6c,00,00,\
  00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfOS]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,70,00,65,00,72,00,66,00,4f,00,53,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfProc]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,70,00,65,00,72,00,66,00,70,00,72,00,6f,00,63,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SAFrdms]
"EventMessageFile"="C:\\WINDOWS\\System32\\safrdm.dll"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\safrslv]
"EventMessageFile"="C:\\WINDOWS\\System32\\safrslv.dll"
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SceCli]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SceSrv]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,73,00,63,00,65,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SclgNtfy]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Software Installation]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,61,00,70,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SpoolerCtrs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,77,00,69,00,6e,00,73,00,70,00,6f,00,6f,00,6c,00,2e,00,64,00,72,00,76,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SysmonLog]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,73,00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Tlntsvr]
"EventMessageFile"="C:\\WINDOWS\\System32\\tlntsvr.exe;C:\\WINDOWS\\System32\\xpsp1res.dll"
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\UploadM]
"EventMessageFile"="C:\\WINDOWS\\PCHealth\\UploadLB\\Binaries\\UploadM.exe"
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Userenv]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,75,00,73,00,65,00,72,00,65,00,6e,00,76,00,2e,00,64,00,6c,00,6c,00,3b,\
  00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\
  5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,\
  00,70,00,31,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Userinit]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,75,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,2e,00,65,00,78,00,65,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\VBRuntime]
"EventMessageFile"="C:\\WINDOWS\\System32\\MSVBVM60.DLL"
"TypesSupported"=dword:00000004
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\VSS]
"TypesSupported"=dword:00000007
"EventMessageFile"="C:\\WINDOWS\\System32\\vssvc.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WebClient]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Windows 3.1 Migration]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,61,00,64,00,76,00,61,00,70,00,69,00,33,00,32,00,2e,00,64,00,6c,00,6c,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Windows Product Activation]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,64,00,70,00,63,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Winlogon]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\
  00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WinMgmt]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,\
  00,52,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WmdmPmSp]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
  00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\
  73,00,70,00,6d,00,73,00,70,00,73,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WMIAdapter]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,4d,00,49,00,41,00,70,00,52,00,65,\
  00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WSH]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
  00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
  5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security]
"DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
  6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
  00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"DisplayNameID"=dword:00000101
"File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
  00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\
  6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,65,00,63,00,45,00,76,00,65,00,6e,\
  00,74,00,2e,00,45,00,76,00,74,00,00,00
"MaxSize"=dword:00080000
"PrimaryModule"="Security"
"Retention"=dword:00093a80
"Sources"=hex(7):53,00,70,00,6f,00,6f,00,6c,00,65,00,72,00,00,00,53,00,65,00,\
  63,00,75,00,72,00,69,00,74,00,79,00